FedRAMP Class D (High) Certified · U.S. Department of Energy ATO
CoLab GovCloud
A dedicated, single-tenant deployment of CoLab for U.S. federal and defense programs — certified at FedRAMP Class D (High), hosted entirely in AWS GovCloud (US), and operated by U.S. persons.
CoLab GovCloud is a separate environment from CoLab's commercial platform. Looking for our commercial security posture (SOC 2, ISO 27001/27017/27018, TISAX, Controlled Goods)? See CoLab commercial security →
AUTHORIZATION RECORD
CERTIFICATION CLASS
Class D (High)
CONTROL BASELINE
NIST SP 800-53 Rev 5
AGENCY ATO
U.S. Department of Energy
PACKAGE ID
FR2600044765
Continuously monitored under the FedRAMP program. Verify our listing on the FedRAMP Marketplace →
01 - Isolation
A dedicated, single-tenant environment
Each customer is served by its own dedicated, single-tenant environment — not a shared multi-tenant instance.
CoLab GovCloud provisions a dedicated environment per customer, isolated from every other customer and operated entirely separately from CoLab's commercial platform. This isolation model is documented in full in our FedRAMP package.
Single-tenant by design — a dedicated environment per customer, not logical separation within a shared instance
Isolated from other customers at the infrastructure and application layers
Fully separate from CoLab's commercial platform and its subprocessors
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
ITAR
Supported. As a SaaS provider, CoLab is not itself the ITAR-regulated party. The environment — U.S. persons, GovCloud (US), and access controls — is built to support customers processing ITAR-controlled technical data.
Controlled Unclassified Information (CUI)
Supported. The Class D (High) baseline provides a security foundation that supports customers handling CUI. CoLab operates as the cloud service provider; specific contractual security terms are scoped per engagement.
FOCI
Mitigated. U.S.-hosted GovCloud infrastructure and U.S.-person-only access address foreign ownership, control, or influence concerns.
02 - Residency & personnel
U.S. data residency and U.S.-person access
All customer data is stored and processed in AWS GovCloud (US). Administrative access is restricted to U.S. persons.
CoLab GovCloud does not use CoLab's commercial regions. Customer content never leaves AWS GovCloud (US), and privileged access to production is limited to U.S. persons operating under strict administrative controls.
Data resident in AWS GovCloud (US) — no Canadian or commercial regions in the boundary
U.S.-person-only administrative accessadministrative access to production infrastructure
No customer data on endpoints — administrators work through AWS WorkSpaces virtual desktops, so customer data does not land on laptops
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
ITAR
Supported. As a SaaS provider, CoLab is not itself the ITAR-regulated party. The environment — U.S. persons, GovCloud (US), and access controls — is built to support customers processing ITAR-controlled technical data.
Controlled Unclassified Information (CUI)
Supported. The Class D (High) baseline provides a security foundation that supports customers handling CUI. CoLab operates as the cloud service provider; specific contractual security terms are scoped per engagement.
FOCI
Mitigated. U.S.-hosted GovCloud infrastructure and U.S.-person-only access address foreign ownership, control, or influence concerns.
03 - Identity
Identity and authentication
Users authenticate through your own identity provider — CoLab GovCloud issues no local accounts.
Access is federated from your existing identity provider, so account lifecycle and authentication policy stay under your control. Privileged access requires phishing-resistant, hardware-backed authentication, including PIV/CAC.
Federated to your IdP — no local accounts in the environment
Phishing-resistant MFA, including PIV/CAC, for privileged access
Least-privilege access, continuously audited
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
ITAR
Supported. As a SaaS provider, CoLab is not itself the ITAR-regulated party. The environment — U.S. persons, GovCloud (US), and access controls — is built to support customers processing ITAR-controlled technical data.
Controlled Unclassified Information (CUI)
Supported. The Class D (High) baseline provides a security foundation that supports customers handling CUI. CoLab operates as the cloud service provider; specific contractual security terms are scoped per engagement.
FOCI
Mitigated. U.S.-hosted GovCloud infrastructure and U.S.-person-only access address foreign ownership, control, or influence concerns.
04 - Cryptography
Encryption and FIPS-validated cryptography
Data is encrypted in transit and at rest using FIPS 140-validated cryptographic modules.
All network communication uses TLS 1.2 backed by FIPS 140-validated modules. Customer data at rest is encrypted with AES-256. Customer-managed encryption keys (BYOK) are available for customers who require key custody.
TLS 1.2 with FIPS 140-validated cryptographic modules
AES-256 at rest
Customer-managed keys (BYOK) available on request
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
ITAR
Supported. As a SaaS provider, CoLab is not itself the ITAR-regulated party. The environment — U.S. persons, GovCloud (US), and access controls — is built to support customers processing ITAR-controlled technical data.
Controlled Unclassified Information (CUI)
Supported. The Class D (High) baseline provides a security foundation that supports customers handling CUI. CoLab operates as the cloud service provider; specific contractual security terms are scoped per engagement.
FOCI
Mitigated. U.S.-hosted GovCloud infrastructure and U.S.-person-only access address foreign ownership, control, or influence concerns.
05 - AI
AI in CoLab GovCloud
AI inference runs inside the FedRAMP authorization boundary. The external commercial AI providers used by CoLab's commercial product are not part of this environment.
CoLab GovCloud's AI capabilities run entirely within the authorization boundary. Customer data used for inference stays inside that boundary and is not retained after a request is processed. AI output is advisory: results are surfaced as suggestions and require human review and acceptance before they affect any drawing or feedback.
Inference within the authorization boundary — no data sent to external AI providers
No data retention — customer data is used only to serve a request
Human-in-the-loop — AI output is never applied automatically
Important distinction: The external AI providers referenced on CoLab's commercial security page do not process CoLab GovCloud data and are not part of this authorization boundary.
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
ITAR
Supported. As a SaaS provider, CoLab is not itself the ITAR-regulated party. The environment — U.S. persons, GovCloud (US), and access controls — is built to support customers processing ITAR-controlled technical data.
Controlled Unclassified Information (CUI)
Supported. The Class D (High) baseline provides a security foundation that supports customers handling CUI. CoLab operates as the cloud service provider; specific contractual security terms are scoped per engagement.
FOCI
Mitigated. U.S.-hosted GovCloud infrastructure and U.S.-person-only access address foreign ownership, control, or influence concerns.
06 - Operations
Continuous monitoring and resilience
CoLab GovCloud is continuously monitored under FedRAMP and engineered for recovery within defined objectives.
Security posture is maintained through ongoing continuous monitoring, vulnerability scanning, and reporting consistent with FedRAMP requirements. The environment is deployed across multiple AWS GovCloud (US) availability zones, and disaster-recovery procedures are tested on a recurring basis.
Continuous monitoring (ConMon) under the FedRAMP program
Defined recovery objectives documented in the FedRAMP package
Multi-AZ deployment across AWS GovCloud (US)
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
ITAR
Supported. As a SaaS provider, CoLab is not itself the ITAR-regulated party. The environment — U.S. persons, GovCloud (US), and access controls — is built to support customers processing ITAR-controlled technical data.
Controlled Unclassified Information (CUI)
Supported. The Class D (High) baseline provides a security foundation that supports customers handling CUI. CoLab operates as the cloud service provider; specific contractual security terms are scoped per engagement.
FOCI
Mitigated. U.S.-hosted GovCloud infrastructure and U.S.-person-only access address foreign ownership, control, or influence concerns.
07 - Regulatory fit
How CoLab GovCloud supports your compliance obligations
CoLab GovCloud is continuously monitored under FedRAMP and engineered for recovery within defined objectives.
CoLab operates as the cloud service provider. CoLab GovCloud is architected to support customers operating under U.S. export and defense regimes — it does not assume your regulatory obligations.
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
Defined recovery objectives documented in the FedRAMP package
Multi-AZ deployment across AWS GovCloud (US)
FedRAMP Class D (High)
Certified. Assessed against the NIST SP 800-53 Rev 5 High baseline, with an agency Authority to Operate (ATO) issued by the U.S. Department of Energy (package FR2600044765).
ITAR
Supported. As a SaaS provider, CoLab is not itself the ITAR-regulated party. The environment — U.S. persons, GovCloud (US), and access controls — is built to support customers processing ITAR-controlled technical data.
Controlled Unclassified Information (CUI)
Supported. The Class D (High) baseline provides a security foundation that supports customers handling CUI. CoLab operates as the cloud service provider; specific contractual security terms are scoped per engagement.
FOCI
Mitigated. U.S.-hosted GovCloud infrastructure and U.S.-person-only access address foreign ownership, control, or influence concerns.