Feith is FedRAMP Moderate Authorized · High In Process Read the release
Feith
Security & compliance

Compliance, built into the record.

Feith enforces federal records compliance on the record itself, from capture through disposition. Zero Trust aligned, FedRAMP authorized, and DISA-JITC certified continuously since 2002.

47 yearsBuilding federal records platforms since 1979
24 yearsContinuous DISA-JITC certification since 2002
21 authorizationsAcross DoD IL4–IL6, FedRAMP, and FISMA High
4 boundariesCloud, on-prem, classified, and air-gapped
Records-level enforcement

Compliance lives on the record.

Other systems enforce compliance at the folder or the perimeter. Feith enforces it on each record: six controls that travel with the record and resolve at query time, not at the directory.

Classification & markings

CUI, PII, and classification markings applied automatically on capture.

Native classification markings (U//FOUO, CUI, SECRET, and the rest) plus custom agency taxonomies, rule- and ML-driven.

Engine
Rule + ML
Trigger
On ingest
Output
A marked record

Retention enforcement

Schedule-driven retention, with disposition locked to the schedule.

Records can’t be deleted outside the schedule. Holds suspend disposition without altering the schedule itself.

Engine
Schedule
Trigger
Event + age
Output
A disposition action

PII detection

Pattern-based and ML-assisted PII identification across every record type.

Configurable taxonomies for agency-specific PII, CUI categories, and sensitive program data. Keyword alerts flag sensitive communications.

Engine
Rule + ML
Trigger
Ingest + on demand
Output
A flagged record

Multilevel security (MLS)

Classification, nationality, and supplemental markings enforced at the record level.

Clearance and caveats travel with the record. ABAC evaluates user attributes against record markings at query time.

Engine
ABAC + clearance
Trigger
On query
Output
A filtered result set

Role- & attribute-based access

Directory-integrated roles with attribute filters on every query.

Access lives at the record level, resolved on every query. RBAC and ABAC combine; CAC, PIV, PKI, MFA, and biometrics are all supported.

Engine
Directory + ABAC
Trigger
On query
Output
A filtered result set

Redaction

Automated redaction with reviewer accept/reject and FOIA exemption coding.

Every redaction decision, including AI suggestions the reviewer rejected, lands in the audit log.

Engine
Rule + ML
Trigger
Release request
Output
A redacted release copy

Who can open what

Admins assign users to roles in the directory; roles are cumulative, so a higher clearance inherits every lower tier. ABAC filters each query at run time, so access resolves at the record level.

Role / group UnclassifiedCUISecret
Resource Mgt Unclassified only
Resource Mgt · CUI CUI + Unclassified
Resource Mgt · Secret Secret + CUI + Unclassified
The compliance matrix

Eight federal regimes. One platform under them.

From the Federal Records Act to FRCP eDiscovery, the same platform satisfies the capabilities each regime demands. A capability is listed only where Feith demonstrably satisfies it.

Federal Records Act

44 U.S.C. Ch. 31

Capture & metadataClassification & markingsRetention & dispositionAccess controlsAudit & chain of custodySearch & retrieval

Not applicable: Redaction & release.

NARA UERM

OMB M-23-07 · M-19-21

Capture & metadataClassification & markingsRetention & dispositionAccess controlsAudit & chain of custodySearch & retrieval

Not applicable: Redaction & release.

DoDM 8180.01 · DoD 5015.02-STD

DoD records

Capture & metadataClassification & markingsRetention & dispositionAccess controlsAudit & chain of custodySearch & retrievalRedaction & release

FOIA

5 U.S.C. § 552

Capture & metadataClassification & markingsRetention & dispositionAccess controlsAudit & chain of custodySearch & retrievalRedaction & release

Privacy Act

5 U.S.C. § 552a

Capture & metadataClassification & markingsRetention & dispositionAccess controlsAudit & chain of custodySearch & retrievalRedaction & release

Section 508

Accessibility

Access controlsSearch & retrievalRedaction & release

Not applicable: Capture & metadata, Classification & markings, Retention & disposition, Audit & chain of custody.

CUI handling

32 CFR 2002 · NIST 800-171

Capture & metadataClassification & markingsRetention & dispositionAccess controlsAudit & chain of custodySearch & retrievalRedaction & release

FRCP (eDiscovery)

Federal Rules

Capture & metadataClassification & markingsRetention & dispositionAccess controlsAudit & chain of custodySearch & retrievalRedaction & release
Chain of custody

Defensibility is what the audit log looks like when someone has to prove it.

Write-once and hash-chained. Every event embeds the cryptographic hash of the one before it, so the chain itself is the proof.

Anatomy of one event Seven fields · append-only
event_id
Globally unique. UUIDv7, time-ordered.
record_ref
The record this event is about.
actor
User, service account, or system.
action
Capture · classify · access · hold · dispose…
timestamp_utc
NTP-synced UTC, millisecond precision.
payload
Action-specific fields. Schema-versioned.
prev_hash
Cryptographic hash of the prior event.

hash = SHA-256( event_id ‖ record_ref ‖ actor ‖ action ‖ timestamp ‖ payload ‖ prev_hash )

No anonymous events. No nullable actor. Schema-versioned and backwards compatible.

Capture hash
Classify hash
Access hash
Legal hold hash
Disposition hash

Each event embeds the hash of the prior event. The chain is the proof.

Tamper-evident

Modifying any field of any event invalidates that event’s hash, which breaks every later link. A change is mathematically detectable, not silent.

Forward to SIEMSplunk · QRadar · Sentinel
RetentionFor the life of the record, plus holds
TransferCustody record accompanies NARA accession
AccessRead-only API, ABAC-filtered

Attribution

Every capture, classification, access, modification, hold, and disposition is logged with the actor that triggered it. Service accounts, system actions, and human users each carry a distinct identity through the chain. No anonymous events.

Immutability

The audit log is append-only. Each event references the cryptographic hash of the prior event, and anti-tamper digests guard against manipulation. A break in the chain is detectable, not silent.

Legal hold & eDiscovery

Holds attach to records, queries, custodians, or schedules. Suspended dispositions stay suspended until the hold is released, and releases are documented. FRCP obligations are met without forensic recovery.

NARA-compliant disposition

When a record reaches the end of its schedule, the disposition (transfer to NARA, deletion, or accession) is documented with the same rigor as any other event. The custody record travels with the transfer.

Platform security architecture

Identity on top. Vault at the center. Audit underneath.

One identity layer authorizes every path in. One encrypted, single-tenant vault holds the records. One append-only audit layer records everything, with operations watching the floor.

EncryptionAES-256 at rest · TLS 1.3 in transit · FIPS 140-2/140-3 validated · columnar encryption · customer-managed keys
IdentitySAML 2.0 · OIDC · AD / LDAP · CAC · PIV · PKI · MFA · biometrics
TenancySingle-tenant by default · infrastructure-level isolation · customer-controlled maintenance windows · no noisy neighbors
AuditAppend-only · hash-chained · anti-tamper · Splunk / SIEM shipping
OperationsContinuous monitoring per FedRAMP · anomalous-access alerts · WAF / IPS compatible · 24/7 SOC integration
Secure SDLCStatic + dynamic analysis every release · CVE tracking against the SBOM · documented patch cadence · CISA KEV SLAs
Incident responseDocumented runbooks · classified-environment IR paths · federal customer notification SLAs
TestingPenetration testing · Burp · Acunetix · Nessus · STIG-hardened baselines
AI compliance

AI inside your records. Your records inside your AI.

Data sovereignty isn’t a setting. It’s the architecture. AI runs inside your boundary, against records that never leave it.

Records never leave your security boundary.

AI orchestration runs inside the deployment. Cloud, on-prem, or air-gapped, the model talks to records that already sit behind your accreditation, not across an external API.

No model training on your records.

Vendor-agnostic across cloud and on-premises foundation models. Azure OpenAI and open-weight models are supported, and your records never enter a vendor training corpus.

AI decisions in the audit log.

Every AI-assisted action is logged with the model reference, input, output, and the reviewer’s accept-or-reject decision. Audit-grade AI: explainable, reversible, accountable.

Credentials & authorizations

Twenty-seven plates. Five bands.

The credentials a federal records officer screenshots before sending the meeting invite. Each plate names the specific posture the authorization actually grants: authorized, certified, validated, aligned, or ready.

1979 Founded
2002 DISA-JITC certified
2025 FedRAMP Moderate authorized
27 Authorizations & alignments Across five bands
8 Cloud & network FedRAMP · IL4–IL6 · FISMA
5 Records standards 8180.01 · UERM · FRA
6 Security frameworks NIST · FIPS · SOC · ISO
2 Cross-cutting 508 · HIPAA
6 Federal cyber Zero Trust · SBOM · MFA · STIG

Cloud & network authorizations

FedRAMP · DoD IL4–IL6 · FISMA
FedRAMP Moderate Authorized 2025 · sponsor USDA · RMA iQ for Government
FedRAMP High In process Feith-controlled tenant under USDA Office of General Counsel
DISA-JITC 2002–2023 DoD 5015.02-STD classified records management (program retired)
DoD Impact Level 4 Authorized AWS GovCloud and equivalent
DoD Impact Level 5 Authorized DoD networks
DoD Impact Level 6 Authorized AWS GovCloud Top Secret, classified DoD networks
FISMA High ATO Multiple on-premises and GovCloud deployments
Army network certification Achieved Army enterprise networks

Records standards

DoDM 8180.01 · NARA UERM · FRA · Privacy Act
DoDM 8180.01 Compliant DoD's electronic records management framework (2023)
DoD 5015.02-STD Certified (legacy) JITC-tested 2002–2023; program now retired
NARA UERM Ready M-23-07, M-19-21 alignment
Federal Records Act Ready 44 U.S.C. Ch. 31
Privacy Act Ready 5 U.S.C. § 552a

Security frameworks

NIST · FIPS · SOC 2 · ISO · CMMC
NIST SP 800-53 Rev 5 Aligned Moderate baseline + relevant High overlays
NIST SP 800-171 Aligned CUI handling
FIPS 140-2 / 140-3 Validated Encryption at rest and in transit, AES-256
SOC 2 Type II Aligned Control set; report available under NDA
ISO 27001 Aligned ISMS controls mapped to ISO 27001 Annex A
CMMC Level 2 Aligned CMMC Level 2 control set implemented

Cross-cutting

Section 508 · HIPAA
Section 508 Conformant Platform UI and reporting
HIPAA Ready · BAA available PHI workloads on supported deployments

Federal cyber alignment

M-22-09 · EO 14028 · BOD 22-01 · STIG
Zero Trust architecture Aligned M-22-09 · NIST 800-207 · ABAC at the record level
Software bill of materials On request M-22-18 · EO 14028 · SPDX per release
Phishing-resistant MFA CAC · PIV · FIDO2 M-22-09 · NIST 800-63B AAL3 · hardware-backed
Vulnerability disclosure Published BOD 20-01 · intake, SLAs, safe harbor
CISA KEV response Tracked BOD 22-01 · SBOM monitored against KEV catalog
STIG-hardened baselines Continuous DISA STIG applied at deployment; drift monitored
Deployment models

Same platform, three boundaries.

Cloud, on-premises, and classified air-gapped deployments all share one Records API, one compliance posture, and one audit log. Bit-for-bit identical, no degraded mode.

Cloud

USDA DISC, FedRAMP ModerateAWS GovCloud (IL4, IL6)Azure for Government
  • FedRAMP Moderate authorized
  • FedRAMP High in process
  • Pre-STIGed systems
  • Auto-scaling capacity
  • 24/7 SOC integration
Best for

Civilian agencies that want managed services and rapid deployment.

On-premises

Behind your firewallYour infrastructureYour security tools
  • Full platform capability
  • AD / LDAP integration
  • Customer-controlled keys
  • Customer-defined retention
  • Customer-managed backup
Best for

Agencies with data-sovereignty requirements or legacy integration constraints.

Classified & air-gapped

Inside the air gapFacility-clearedCleared support on-net
  • Identical platform capability
  • On-prem foundation models
  • On-net engineering support
  • Classified-environment IR
  • No degraded mode
Best for

Defense and intelligence missions that require air-gap operation.

Identical platform capabilities across all three models: same Records API, same compliance enforcement, same audit posture.

Secure networks supported

NIPRNet

Non-classified IP Router Network. DoD unclassified operations.

SIPRNet

Secret IP Router Network. DoD Secret-level operations.

JWICS

Joint Worldwide Intelligence Communications System. TS/SCI operations.

AWS TS C2S + Secret

Government cloud environments at higher classification levels.

Classified & IC deployments

The same platform, on the other side of the air gap.

What civilian agencies run in the FedRAMP cloud is what Feith delivers inside accredited facilities: no external connectivity, no degraded mode.

Facility clearance

Feith holds a Facility Security Clearance. Sensitive workloads can be hosted in Feith-cleared environments where a customer’s accreditation requires it.

Cleared personnel

63% of Feith staff hold a Secret or higher clearance; 49% hold SCI. Every administrator of a sensitive federal system is a US resident with an active TS/SCI clearance. Program leadership includes retired senior Intelligence and Special Operations personnel.

Multilevel security

Classification, nationality, and supplemental markings are enforced at the record level. A user’s clearance filters results without revealing that inaccessible records exist.

Cross-domain solutions

The integrated Declassification Review module supports cross-domain workflows (Automatic (ADR), Mandatory (MDR), and Systematic (SDR) review) in compliance with Executive Order 13526.

Secure reading rooms

Interagency consultation happens inside the classified boundary. Multiple cleared agencies coordinate over the same records without removing them from controlled environments.

Capability parity

Classification, retention, redaction, AI orchestration, and audit logging operate identically inside the boundary. No degraded mode, no reduced feature set: the Records API, workflow engine, and audit log are bit-for-bit the same.

Supply chain security

A clean supply chain is in place today.

US-only, FOCI-clean, and FAR-compliant today, hardened in partnership with the US Intelligence Community and DoD.

US-only operations

Support, development, services, and engineering performed exclusively within the United States.

US-only code

No non-US proprietary code or tools in development or continuous monitoring of the platform.

FOCI-clean

Free of foreign ownership, control, or influence. Facility Security Clearance maintained.

No forced-tech-transfer countries

No engagement with Forced Technology Transfer countries. No Covered Equipment in the platform stack.

FAR compliant

Fully compliant with Federal Acquisition Regulation 52.204-24 and 52.204-26.

Customer proof

Federal agencies on the platform.

Across three tiers: named civilian agencies, the Department of Defense, and the Intelligence Community.

Tier 1 Civilian agencies, named Public record

Named civilian customers, including:

U.S. Dept. of AgricultureDepartment of LaborFood & Drug AdminNOAADepartment of EnergyVeterans AffairsLibrary of CongressDepartment of Commerce

Plus cabinet-level departments, independent agencies, and additional civilian customers.

Tier 2 Department of Defense & Joint / Combatant Commands Names withheld

DoD components and Joint / Combatant Commands, deployed across:

Electronic & physical records managementDocument & case managementFOIA & Privacy Act managementDeclassificationTask & workflow automationLegacy systems integration
Tier 3 Intelligence Community Withheld · no counts

US Intelligence Community customers, deployed across:

Electronic records managementDeclassification (ADR, MDR, SDR)Cross-domain solutionsSecure reading roomsAir-gapped deployment
Schedule an architecture review

Walk us through your compliance posture.

Schedule a 30-minute architecture review with a Feith security engineer. Bring your framework; we’ll map it.

Download the compliance brief
Contract vehicles
  • GSA MASMultiple Award Schedule
  • SEWPNASA-wide GWAC
  • Navy IWRPInformation Warfare RP
  • DoC CATTSDOC technical services
Available for direct procurement
Request a review