Compliance
FedRAMP Moderate path
How we map Aegis to FedRAMP Moderate controls for US public-sector design partners.
Aegis is designed for tenants that will eventually require FedRAMP Moderate. Today we ship control-mapping exports and a documented architecture path; formal authorization is a roadmap milestone.
Inheritance model
- IaaS/PaaS: Railway / Vercel / Neon inherit physical and network controls from underlying providers (customer responsibility matrix applies).
- Aegis API: tenant isolation, signed audit logs, encryption in transit (TLS 1.2+), secrets via environment — no customer private signing keys stored for BYOK customer-held keys.
- Customer: BYOK key custody, agent runtime, SIEM retention, export storage after download.
Control families we map today
- AC / IA — API keys, console sessions, org-scoped RBAC
- AU — append-only signed events, export bundles, OTel SIEM forwarding
- CM — immutable active policies, versioned drafts
- IR — approval workflows, trace reconstruction, incident export ZIPs
- SC — Ed25519 signatures, Merkle witness batches, transparency log
Path to authorization
- Complete SOC 2 Type I → Type II (2026)
- Document SSP on FedRAMP templates using Aegis export evidence
- Engage 3PAO assessment for Moderate baseline
- Target agency sponsorship or JAB path for Q2 2027
Questions: security@salanor.com · Platform status