You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: src/data/pages/home.yaml
+5-11Lines changed: 5 additions & 11 deletions
Original file line number
Diff line number
Diff line change
@@ -1,7 +1,6 @@
1
1
title: Faster, easier, and more secure digital services for government agencies
2
2
description: A platform-as-a-service built for government. Deploy secure, compliant sites and apps without managing infrastructure.
3
3
4
-
5
4
hero:
6
5
heading: "Faster, easier, and built for government from the start"
7
6
intro: |
@@ -69,19 +68,14 @@ mandatesHandled:
69
68
art: "compliance-alt"
70
69
color: "primary-vivid"
71
70
intro: |
72
-
Cloud.gov is already FedRAMP Authorized (Moderate), so your agency can reuse our compliance package. That means on day one, you can check these off your list:
71
+
Cloud.gov is already FedRAMP Authorized (Moderate), so your agency can reuse our compliance package. That means on day one, your **platform layer** already meets these mandates:
73
72
content: |
74
-
- Built-in continuous monitoring, monthly vulnerability scans, POA&M updates, incident reporting, and annual assessments that satisfy key **FY 2025 FISMA CIO metrics under OMB M-25-04**.
75
-
76
-
- Integrated platform patching, automated backups, centralized logging, and incident alerting mapped to **NIST 800-53 Rev. 5 control families like SI, AU, and CM**.
77
-
73
+
- Continuous monitoring, monthly vulnerability scans, POA&M updates, incident reporting, and annual assessments — all performed for the **platform itself**, satisfying key FY 2025 FISMA CIO metrics under OMB M-25-04.
74
+
- Platform patching, automated backups, centralized logging, and incident alerting mapped to **NIST 800-53 Rev. 5 control families like SI, AU, and CM**.
78
75
- Encrypted, isolated networking between containers with short-lived credentials and granular access policies — aligned with **EO 14028 and CISA’s Zero Trust Maturity Model**.
79
76
80
-
- **FIPS 140-2** compliant environment with cryptographic modules validated against **FIPS 140-3**.
Copy file name to clipboardExpand all lines: src/data/pages/security.yaml
+21-24Lines changed: 21 additions & 24 deletions
Original file line number
Diff line number
Diff line change
@@ -7,73 +7,70 @@ hero:
7
7
We handle the infrastructure. You focus on your application.
8
8
9
9
content: |
10
-
When you build on Cloud.gov, **you inherit hundreds of security and operational controls** from our FedRAMP-authorized platform—reducing the time, effort, and risk required to achieve an ATO.
10
+
When you build on Cloud.gov, **you inherit hundreds of security and operational controls** from our FedRAMP-authorized (Moderate) platform. That means less time, less effort, and lower risk in getting your Authority to Operate (ATO).
11
11
12
12
art: "compliance"
13
13
14
14
g2g:
15
-
heading: "Zero-trust infrastructure that meets every government expectation"
16
-
intro: "Cloud.gov provides you with a FIPS 140-2 compliant environment designed for U.S. federal workloads, where we can offer top-requested security features like:"
15
+
heading: "Zero-trust infrastructure that meets government expectations"
16
+
intro: "Cloud.gov provides you with a secure environment designed for U.S. federal workloads, where we can offer top-requested security features like:"
17
17
align: "center"
18
18
color: "primary-vivid"
19
19
items:
20
20
- heading: "Supply-chain hardening"
21
-
text: "100% of our images are built using pre-scanned, signed, and reproducible buildpacks."
21
+
text: "Our images are built using pre-scanned and reproducible buildpacks."
22
22
icon: "verified_user"
23
23
- heading: "Per-app isolation"
24
-
text: "Every container runs in its own trust zone with mutual encryption enforced on every route."
24
+
text: "Every container runs in its own trust zone with mutual encryption protecting every route."
25
25
icon: "safety_divider"
26
26
- heading: "Least privilege strategy"
27
-
text: "We deny service-to-service access by default and grant it only through explicit policies."
Skip months of security configuration. Our multi-availability zone platform includes enterprise-level protections designed to meet the most stringent federal requirements.
35
-
36
-
content: |
37
-
When you run your FISMA Low or Moderate system on Cloud.gov, you automatically inherit coverage for more than 300 of the NIST 800-53 Rev 5 controls. That means on day one, you can check these off your list:
34
+
Skip months of security configuration. Our multi-availability zone platform includes enterprise-level protections designed to meet the most stringent federal requirements.
35
+
36
+
content: |
37
+
When you run your FISMA Low or Moderate system on Cloud.gov, you automatically inherit coverage for more than 155 of the NIST 800-53 Rev 5 controls. That means on day one, you can check these off your list:
- heading: Intelligent web application firewall (WAF) rules
43
+
- heading: Intelligent web application firewall (WAF) rules
45
44
- heading: Searchable application logging
46
-
- heading: Elastic infrastructure scaling for sudden traffic surges
47
-
- heading: Continuous monitoring that meets every 2025 FISMA metric for OMB M-25-04
48
-
- heading: A completely “Zero Trust” model that satisfies Executive Order 14028
49
-
- heading: Cryptographic modules that are validated against the FIPS 140-3 Standard
45
+
- heading: Elastic infrastructure scaling for traffic surges
46
+
- heading: Continuous monitoring aligned with OMB M-25-04 and 2025 FISMA metrics
47
+
- heading: A “Zero Trust” model that aligns with Executive Order 14028
50
48
- heading: Physical and environmental protections (PE family)
51
49
- heading: Network and boundary controls (SC-7, AC-17)
52
50
- heading: Platform patching, backups, and system monitoring (SI, AU, CM families)
53
-
- heading: A FIPS 140-2 compliant environment
51
+
54
52
outro: |
55
53
You don’t have to set up your own platform team to meet federal compliance requirements. **We’re already operating one for you.**
56
54
57
-
58
55
AtoMedia:
59
56
heading: "Designed for the way government launches software"
60
57
intro: "Cloud.gov’s shared responsibility model gives federal teams a head start, whether you’re seeking a new ATO or reauthorizing an existing system. With Cloud.gov’s position, context, and expertise inside government, we understand firsthand what’s hard for agency customers."
61
58
items:
62
59
- heading: "Guided security support with our in-house experts"
63
-
text: "We work directly with your security and compliance staff to provide system diagrams and boundary documentation, walk your team through inherited control mappings, and even **provide boilerplate text and evidence** for your System Security Plan (SSP) and Security Impact Assessments (SIA)."
60
+
text: "Cloud.gov is built for self-service—our documentation and tooling give your team what they need to move quickly and independently. But you’re not on your own: our in-house experts are available to point you to the right resources and answer your security and compliance questions."
text: "Cloud.gov isn’t just _technically_ compliant—it’s built with the realities of federal security in mind. We’ve supported dozens of agencies through audits, ATOs, and reauthorizations, and we’ve shaped our platform and docs around what teams actually need to succeed."
70
68
mediaComponent: "Illustration-Security"
71
69
button:
72
-
label: "Review our compliance docs on Connect.gov"
intro: "Employees and contractors can focus on developing mission-critical applications, leaving server infrastructure management to us. We support the platform—you own the application. That means you’re in control of things like:"
0 commit comments