Skip to main content
Government

Federal AI. Governed at the boundary.

Government agencies adopting AI face strict data handling obligations: CUI cannot leave the authorized environment uncontrolled, and every AI interaction must produce a tamper-resistant audit record. Arbitex puts a compliance-grade governance layer in front of every AI call — inspecting, enforcing, and logging before any data reaches a model.

Capabilities

AI governance built for federal data environments.

CUI Detection — NIST SP 800-171 Category Coverage

Controlled Unclassified Information spans dozens of category markings — from CUI//PRVCY and CUI//MED to CUI//LAW and CUI//FEDCON. Arbitex inspects every AI request in-path before any model processes it. The shipped detectors cover the personally identifiable information subject to federal handling requirements — names, identifiers, contact and health data. Arbitex does not ship CUI marking detectors: agencies author org DLP rules for the specific category markings, contract number formats, and acquisition-sensitive patterns in scope, and those rules run through the same three inspection tiers.

FedRAMP-Aligned Data Sovereignty

FedRAMP authorization requirements mandate that federal data processed by cloud services remain within an authorized boundary. Arbitex Hybrid Outpost deploys the data plane inside your agency VPC or on-premises enclave — the control plane handles configuration and policy delivery, while all AI traffic inspection runs inside your authorized environment. No agency data transits Arbitex-controlled cloud infrastructure. The deployment model is documented for inclusion in System Security Plans (SSPs) and ATO packages.

NIST 800-53 Controls Mapping

Arbitex enforcement controls align to NIST SP 800-53 Rev. 5 control families across AU (Audit and Accountability), AC (Access Control), SC (System and Communications Protection), and SI (System and Information Integrity). The compliance bundle maps each DLP enforcement action to a specific control identifier — AU-2 (Event Logging), AU-9 (Protection of Audit Information), AC-3 (Access Enforcement), SC-8 (Transmission Confidentiality), and SI-12 (Information Management and Retention). Audit exports include the control mapping for NIST-based assessments.

Air-Gap Deployment for Classified Workflows

Agencies operating at Classification Level or supporting IL4/IL5 workloads require data processing entirely within a disconnected or physically isolated environment. Arbitex Hybrid Outpost supports fully air-gapped deployment: the data plane operates without a persistent internet connection to the Arbitex control plane. Policy bundles are delivered via signed configuration packages that can be transferred through removable media or an approved secure transfer mechanism. AI governance runs without requiring continuous cloud connectivity.

FISMA Audit Controls — Tamper-proof Evidence Trail

FISMA requires federal agencies to maintain documented, tamper-resistant audit records for information system activity. Every Arbitex enforcement event is written to an tamper-proof, append-only audit log: AI request received, detection tier result, enforcement action (allow/block/redact), model response, response scan result. No user — including system administrators — can modify or delete log entries. Signed exports in JSONL and CSV support FISMA annual assessments, IG audits, and continuous monitoring submissions.

IL4/IL5 Readiness — Zero-Trust Identity Enforcement

Impact Level 4 and IL5 DoD workloads require identity verification for every access event. Arbitex enforces zero-trust identity controls at the AI gateway: every request is authenticated via SAML 2.0 or OIDC before DLP inspection runs. SCIM 2.0 provisioning keeps identity grants synchronized with your agency directory. Role-based access controls limit which personnel can query which model endpoints. WebAuthn/FIDO2 phishing-resistant MFA is available for privileged access. Every identity assertion is logged alongside the AI transaction for IL4/IL5 audit packages.

How it works

01

Deploy inside your agency boundary

The Arbitex data plane installs in your authorized cloud environment or on-premises infrastructure using Docker Compose or Kubernetes. All AI traffic — analyst queries, mission workflow automation, citizen-service interactions — routes through the gateway before reaching any model endpoint. CUI detection, policy enforcement, and audit logging run entirely inside your authorized boundary. No agency data transits Arbitex-controlled infrastructure.

02

Policy enforcement activates in-path

Your configured compliance bundle activates the relevant NIST 800-53 control set. CUI category patterns run at Tier 1 (structural regex with format validation). Tier 2 applies ML-based detection to identify PII and sensitive identifiers in free-text content. Contextual validation at Tier 3 resolves ambiguous detections — distinguishing a literary reference from a real person's protected record. Enforcement runs before any data reaches the model. Every decision is logged with control mapping.

03

Audit evidence ready for assessment and ATO

The tamper-proof audit log accumulates a complete evidence trail for every AI interaction. Signed exports include control identifiers mapped to each enforcement action — ready for FISMA annual assessments, Inspector General audits, and ATO package submissions. Continuous monitoring integrations deliver enforcement metrics to your SIEM for real-time visibility into AI data handling across the agency.

Compliance mapping

Six frameworks. One policy layer.

Each compliance obligation maps to a specific Arbitex capability. All bundles are active simultaneously — no separate configuration per framework or agency requirement.

FISMA
Federal Information Security Modernization Act

Annual assessment controls, continuous monitoring, and tamper-proof audit evidence for agency AI operations.

FedRAMP
Federal Risk and Authorization Management Program

Authorized boundary data sovereignty via Hybrid Outpost. SSP documentation package for ATO submissions.

NIST 800-53 Rev. 5
AU · AC · SC · SI Control Families

Audit and accountability, access enforcement, transmission protection, and information integrity — all mapped to Arbitex enforcement actions.

NIST SP 800-171
CUI Protection — 110 Requirements

All 110 CUI security requirements mapped to enforcement actions. Detection covers every CUI category marking.

CJIS Security Policy
FBI Criminal Justice Information Services

Access control, audit logging, encryption, and identity management for agencies handling criminal justice information.

IL4 / IL5
DoD Impact Level Readiness

Zero-trust identity enforcement, air-gap deployment, phishing-resistant WebAuthn/FIDO2 MFA. Every identity assertion logged.

Related Resources

Government Use Case

FedRAMP-aligned CUI detection

Identity & Access

SAML, SCIM, and WebAuthn for AI governance

Compliance Frameworks

Pre-built policy packs for regulatory requirements

DLP Protection

Inspect every AI prompt for sensitive data

Ready to put governance in front of your federal AI?

Talk to an Arbitex engineer about custom detection rules for CUI, FedRAMP-aligned deployment, and policy configuration for your agency environment.