Security & compliance

Compliance isn't a checkbox. It's the architecture.

Permiso is built to operate inside your existing security boundary, under your existing controls, with full evidentiary support for the audits and FOIA requests that follow.

FedRAMP

Authorized infrastructure, agency ATO for the application.

Permiso deploys on FedRAMP-authorized cloud infrastructure inside your agency tenant. The application itself reaches Authority to Operate through your agency's normal ATO process — we provide the documentation, security architecture, and engineering support to get there inside the contract period.

We've initiated and supported ATOs across federal agencies. The mechanics are familiar. The gates are well-understood. Phase 1 typically targets ATO-ready posture within four months of award.

Zero Trust

Built to ML2+ from day one.

Identity-based access at every layer. Login.gov for external users. Microsoft Entra ID or your equivalent IDP for internal. Mutual TLS between services. Per-request authorization, not perimeter trust.

01Login.gov for external identity
02Entra ID / agency IDP for internal
03mTLS between services
04Per-request authorization
05Continuous logging to your SIEM
Data, privacy, records

Privacy by construction. Records compliance by default.

01CUI handling built into the data classification layer
02Privacy Impact Assessment + SORN drafting support
03FOIA-ready audit history with chain of custody
04No deletion by design — NARA-compliant retention
05Section 508 accessibility on every applicant- and reviewer-facing surface
AI safety

AI that an Inspector General can sign off on.

Prompt injection defense at four independent layers. Every AI output traceable to source evidence. Cross-vendor QA on high-risk outputs. Human authority preserved at every decision point.

Drafts labeled as drafts. We treat legal defensibility as a system property — and we test for it the way you'd test for any other failure mode.

Tell us about your backlog.

A 45-minute briefing tailored to your agency, your authorization types, and your compliance environment. No generic deck.