Talvium · World Secure ComputeView assurance status

Trust / Assurance

Government and international assurance catalog

Talvium is engineering its World Secure Compute environments against the government, security, privacy, service, AI, and continuity frameworks below. Each item remains a target until an authoritative record identifies the exact service, region, facility, assessor, scope, and dates.

Certification program · targets unless evidenced

Evidence matrix

U.S. government authorization and compliance program

Full certification, authorization, or framework nameTalvium intended scopeCurrent public status
Federal Risk and Authorization Management Program (FedRAMP) High — JAB Provisional Authority to Operate (P-ATO)Eligible U.S. government cloud service offering and named regionsTarget; Talvium is not authorized or listed
State Risk and Authorization Management Program (StateRAMP) HighEligible state, local, education, and partner workloadsTarget; Talvium is not authorized
Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 2 (IL2)Public and non-controlled DoD information where contractually applicableArchitecture target; no Provisional Authorization (PA)
Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 4 (IL4)Controlled unclassified information and mission workloads where contractually applicableArchitecture target; no Provisional Authorization (PA)
Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 5 (IL5)Higher-sensitivity CUI and mission workloads where contractually applicableArchitecture target; no Provisional Authorization (PA)
Department of Defense Cloud Computing Security Requirements Guide (DoD Cloud SRG) Impact Level 6 (IL6)Dedicated classified environment only with the responsible government sponsorFuture sponsor-gated target; no Provisional Authorization (PA)
Intelligence Community Directive 503 (ICD 503) Authorization to Operate (ATO)Named information-system authorization boundaryFuture sponsor-gated target; no ATO
Intelligence Community Directive 705 (ICD 705) facility accreditationNamed Sensitive Compartmented Information Facility boundary where applicableFuture sponsor-gated target; no facility accreditation
Joint Special Access Program Implementation Guide (JSIG) Protection Level 3 (PL-3) Authorization to Operate (ATO)Special access program environment only under sponsor authorityFuture sponsor-gated target; no ATO
Criminal Justice Information Services (CJIS) Security PolicyCriminal-justice information workloads in eligible U.S. environmentsControl-mapping target
Internal Revenue Service Publication 1075 (IRS 1075)Federal tax information workloads in eligible U.S. environmentsControl-mapping target
Defense Federal Acquisition Regulation Supplement (DFARS) 252.204-7012Defense industrial base contracts and covered defense informationContract and control-mapping target
NIST Special Publication 800-171Controlled unclassified information in nonfederal systemsControl-mapping target
Cybersecurity Maturity Model Certification (CMMC)Defense industrial base organizations and contract scopesAssessment program target
International Traffic in Arms Regulations (ITAR)Defense articles and technical data with validated persons, locations, and support pathsLegal and technical design target
Export Administration Regulations (EAR)Export-controlled commercial and dual-use workloadsLegal and technical design target
Health Insurance Portability and Accountability Act (HIPAA)Protected health information in eligible configurations and contractsControl and contracting target
Federal Information Processing Standard (FIPS) 140-3 Cryptographic Module Validation ProgramNamed cryptographic modules in named service configurationsValidated modules required; none claimed for Talvium services
Federal Information Processing Standard (FIPS) 140-2 Cryptographic Module Validation ProgramLegacy modules only where an applicable transition rule permitsNo Talvium service validation claimed
Agency Authorization to Operate (ATO)A named customer system using a named Talvium service boundaryCustomer- and agency-specific; none claimed

Evidence matrix

International, security, privacy, AI, and resilience program

Assurance familyTalvium intended scopeCurrent public status
ISO/IEC 27001Information security management systemCertification target
ISO/IEC 27017Cloud security controlsControl-mapping target
ISO/IEC 27018Protection of personal information in public cloud servicesControl-mapping target
ISO/IEC 27701Privacy information management systemCertification target
ISO/IEC 20000-1IT service management systemCertification target
ISO 22301Business continuity management systemCertification target
ISO/IEC 42001Artificial intelligence management systemCertification target
SOC 2 Type IISecurity, availability, confidentiality, processing integrity, and privacy controlsIndependent report target
CSA CCM / STARCloud control mapping and assurance registryMapping and registry target
PCI DSSCardholder-data environments where explicitly includedFuture scoped target
GDPR and national privacy lawRegion-specific controller, processor, transfer, residency, and rights obligationsJurisdiction profiles and legal review required
NIST AI RMFAI inventory, measurement, governance, and risk treatmentOperating-framework target

Capability set

Required claim record

What

Certification, attestation, authorization, validation, or alignment.

Who

Issuer, auditor, authorizing authority, legal entity, and internal owner.

Where

Service boundary, products, regions, facilities, and operating entities.

When

Control version, assessment period, issue date, expiry, and next review.

Evidence

Certificate, report, package, registry identifier, and access conditions.

Responsibility

Provider, partner, customer, and configuration caveats.

Evidence note

Authoritative status matters

For U.S. federal cloud offerings, the FedRAMP Marketplace is the authoritative public source for status. Talvium currently makes no FedRAMP authorization claim.

FedRAMP Marketplace
World Secure Compute/Accessibility/accessibilityCapacity brief builder/capacity-briefBegin with a nonsensitive, bounded requirement/contactInfrastructure evidence beneath the compute promise/energy-materialsStorage is a tested service component, not a sustainability prop/energy-materials/battery-resilienceDesign repair and end-of-life before deployment/energy-materials/circularityStart with contracted, measurable power/energy-materials/clean-powerMake power and thermal state part of workload eligibility/energy-materials/energy-aware-schedulingTreat mineral potential as an option until proven/energy-materials/materialsDesign the power system for the service promise/energy-materials/powerNo region without a site evidence index/energy-materials/site-evidenceFollow infrastructure inputs through their evidence chain/energy-materials/traceabilitySelect the control boundary before the service catalog/environmentsLocal compute with controlled synchronization/environments/disconnected-edgeRegional enterprise foundation/environments/global-computeDedicated infrastructure and local authority/environments/private-national-cloudIsolated capacity for sensitive workloads/environments/secure-enclaveJurisdiction-aware operations and control/environments/sovereign-regionDirect answers about Talvium's current state/faqBuild regions through bounded roles and measurable evidence/partnersBring one bounded capability or region pathway/partners/becomeDeliver the physical service boundary/partners/energy-infrastructureA qualified directory—not an open catalog/partners/marketplaceBuild local operating authority—not a flag-shaped reseller/partners/national-regionalCompare equivalent scopes before commitment/partners/procurementQualify components inside a declared configuration/partners/technologyA verifiable chain from site rights to workload execution/platformAI that stays inside the approved boundary/platform/aiA portable runtime between infrastructure and mission software/platform/application-platformSecure compute cells that declare their operating envelope/platform/computeGoverned data services with residency visible/platform/dataLocal operation when connectivity is constrained or absent/platform/edgeConnect authorized services without erasing boundaries/platform/federationSecurity claims scoped to the system that earned them/platform/securityThe operational portal is not yet open/portalPrice the verified service boundary—not an imaginary GPU hour/pricingBuild the inputs before asking for a number/pricing/calculatorMatch commitment to mission certainty/pricing/capacity-optionsOptimize cost, capacity, energy, and control together/pricing/finopsChoose the accountable contracting path/pricing/purchase-optionsPrivacy/privacyProduct directory/productsA region is an evidence record, not a dot on a map/regionsA candidate site program governed by evidence gates/regions/africa-site-01Published lifecycle before procurement/regions/availabilityPublish every place data can exist/regions/data-residencyA geography explorer with no decorative availability dots/regions/mapA region enters the roadmap through evidence gates/regions/plannedArchitecture, assurance, and mission preparation/resourcesNo customer outcome is published without approval and evidence/resources/customer-storiesDocumentation organized by decision boundary/resources/documentationBriefings and demonstrations only when the evidence is ready/resources/eventsA dated record of what Talvium has actually changed/resources/newsroomStart with an evidence-producing sequence/resources/quickstartsThree physical patterns, one evidence discipline/resources/reference-architecturesResearch references/resources/referencesDecision briefs for secure compute programs/resources/reportsTreat storage as an engineered service input/solutions/battery-storageCoordinate flexible compute with measured energy conditions/solutions/clean-energyLocal resilience for systems that cannot wait for the network/solutions/critical-infrastructureMove governed decisions—not uncontrolled data/solutions/data-aiA sponsor-specific path from unclassified proof to approved service/solutions/defense-intelligencePublic services with data control built into the deployment/solutions/governmentModernize without losing the control record/solutions/migration-modernizationOperate the mission without turning geology into a marketing claim/solutions/mining-mineralsMake the operating boundary inspectable/solutions/regulated-industriesAccelerated compute with collaboration boundaries intact/solutions/research-industryAccelerated research without surrendering collaboration boundaries/solutions/research-scienceCurrent Talvium lifecycle and availability/statusSupport matched to the service lifecycle/supportTerms/termsEvidence before assurance language/trustGovernment and international assurance catalog/trust/assuranceProtect approved workloads while data is in use/trust/confidential-computingBind data use to purpose, place, people, and time/trust/data-privacyDeclare custody instead of saying ‘encrypted’/trust/encryption-key-controlGovern the model, system, decision, and outcome/trust/responsible-aiName who must make each control true/trust/shared-responsibilitySovereignty is a control model, not a location slogan/trust/sovereigntyPublish readiness, change, and failure at the right scope/trust/transparency