What
Certification, attestation, authorization, validation, or alignment.
Trust / Assurance
Talvium is engineering its World Secure Compute environments against the government, security, privacy, service, AI, and continuity frameworks below. Each item remains a target until an authoritative record identifies the exact service, region, facility, assessor, scope, and dates.
Evidence matrix
| Full certification, authorization, or framework name | Talvium intended scope | Current public status |
|---|---|---|
| Federal Risk and Authorization Management Program (FedRAMP) High — JAB Provisional Authority to Operate (P-ATO) | Eligible U.S. government cloud service offering and named regions | Target; Talvium is not authorized or listed |
| State Risk and Authorization Management Program (StateRAMP) High | Eligible state, local, education, and partner workloads | Target; Talvium is not authorized |
| Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 2 (IL2) | Public and non-controlled DoD information where contractually applicable | Architecture target; no Provisional Authorization (PA) |
| Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 4 (IL4) | Controlled unclassified information and mission workloads where contractually applicable | Architecture target; no Provisional Authorization (PA) |
| Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 5 (IL5) | Higher-sensitivity CUI and mission workloads where contractually applicable | Architecture target; no Provisional Authorization (PA) |
| Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 6 (IL6) | Dedicated classified environment only with the responsible government sponsor | Future sponsor-gated target; no Provisional Authorization (PA) |
| Intelligence Community Directive 503 (ICD 503) Authorization to Operate (ATO) | Named information-system authorization boundary | Future sponsor-gated target; no ATO |
| Intelligence Community Directive 705 (ICD 705) facility accreditation | Named Sensitive Compartmented Information Facility boundary where applicable | Future sponsor-gated target; no facility accreditation |
| Joint Special Access Program Implementation Guide (JSIG) Protection Level 3 (PL-3) Authorization to Operate (ATO) | Special access program environment only under sponsor authority | Future sponsor-gated target; no ATO |
| Criminal Justice Information Services (CJIS) Security Policy | Criminal-justice information workloads in eligible U.S. environments | Control-mapping target |
| Internal Revenue Service Publication 1075 (IRS 1075) | Federal tax information workloads in eligible U.S. environments | Control-mapping target |
| Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012 | Defense industrial base contracts and covered defense information | Contract and control-mapping target |
| NIST Special Publication 800-171 | Controlled unclassified information in nonfederal systems | Control-mapping target |
| Cybersecurity Maturity Model Certification (CMMC) | Defense industrial base organizations and contract scopes | Assessment program target |
| International Traffic in Arms Regulations (ITAR) | Defense articles and technical data with validated persons, locations, and support paths | Legal and technical design target |
| Export Administration Regulations (EAR) | Export-controlled commercial and dual-use workloads | Legal and technical design target |
| Health Insurance Portability and Accountability Act (HIPAA) | Protected health information in eligible configurations and contracts | Control and contracting target |
| Federal Information Processing Standard (FIPS) 140-3 Cryptographic Module Validation Program | Named cryptographic modules in named service configurations | Validated modules required; none claimed for Talvium services |
| Federal Information Processing Standard (FIPS) 140-2 Cryptographic Module Validation Program | Legacy modules only where an applicable transition rule permits | No Talvium service validation claimed |
| Agency Authorization to Operate (ATO) | A named customer system using a named Talvium service boundary | Customer- and agency-specific; none claimed |
Evidence matrix
| Assurance family | Talvium intended scope | Current public status |
|---|---|---|
| ISO/IEC 27001 | Information security management system | Certification target |
| ISO/IEC 27017 | Cloud security controls | Control-mapping target |
| ISO/IEC 27018 | Protection of personal information in public cloud services | Control-mapping target |
| ISO/IEC 27701 | Privacy information management system | Certification target |
| ISO/IEC 20000-1 | IT service management system | Certification target |
| ISO 22301 | Business continuity management system | Certification target |
| ISO/IEC 42001 | Artificial intelligence management system | Certification target |
| SOC 2 Type II | Security, availability, confidentiality, processing integrity, and privacy controls | Independent report target |
| CSA CCM / STAR | Cloud control mapping and assurance registry | Mapping and registry target |
| PCI DSS | Cardholder-data environments where explicitly included | Future scoped target |
| GDPR and national privacy law | Region-specific controller, processor, transfer, residency, and rights obligations | Jurisdiction profiles and legal review required |
| NIST AI RMF | AI inventory, measurement, governance, and risk treatment | Operating-framework target |
Capability set
Certification, attestation, authorization, validation, or alignment.
Issuer, auditor, authorizing authority, legal entity, and internal owner.
Service boundary, products, regions, facilities, and operating entities.
Control version, assessment period, issue date, expiry, and next review.
Certificate, report, package, registry identifier, and access conditions.
Provider, partner, customer, and configuration caveats.
Evidence note
For U.S. federal cloud offerings, the FedRAMP Marketplace is the authoritative public source for status. Talvium currently makes no FedRAMP authorization claim.
FedRAMP Marketplace