FedRAMP-compatible trust center
Where a provider's package lives once it exists.
Each provider on this service has its own page. There, government customers request access, retrieve the current Certification Package on the web or through the API, and check every file against a published manifest of hashes. Every access is logged and reportable.
Same bytes as the provider's repositoryPasskeys only, no passwordsProgrammatic access
Same bytes
- The provider builds.
One command compiles the package from their repository; nothing leaves their machine.
- The provider publishes.
The files arrive here with a manifest of hashes; the trust center refuses anything that does not match.
- You ask, once.
Federal agency staff are provisioned on arrival; everyone else is approved by the provider. Access is standing, not per document.
- Every retrieval is a log line.
Yours to see, the provider's to report, FedRAMP's on request.