Compliance posture · reviewed 2026-05-15

A status and a date on every claim.

On-prem and air-gapped are available now. CMMC L2 and SOC 2 are in remediation. FedRAMP Moderate is planned.

Posture today

Where we stand.

Each item carries a status and a review date: available now, in remediation, or planned. Reviewed 2026-05-15. Historical snapshots are preserved and available on request.

Standard
Posture
Verification
On-prem & air-gapped
Available now · Reviewed 2026-05-15
Deploy on your own hardware, behind your own perimeter, or fully offline. Data at rest is sealed with quantum-safe storage (CRYSTALS-Kyber + X25519, AES-256-GCM). No outbound dependency, no shared tenancy. This ships today.
On-prem deployment · live
CMMC L2 · SOC 2
In remediation · Reviewed 2026-05-15
On the commercial track. Per-practice gap analysis is complete. Consolidation is in progress, with narratives and a Plan of Action and Milestones drafted. We make no claim of conformance today. The first defensible response is targeted for 2026.
C3PAO + CPA records when issued
FedRAMP Moderate
Planned · Reviewed 2026-05-15
Sponsor-gated. Cloud delivery follows agency sponsor identification and an ATO grant. We offer the on-prem deployment first, so regulated work does not wait on the authorization queue.
Authorization letter when granted
◆ Available now  ·  ◐ In remediation  ·  ○ Planned  ·  Reviewed 2026-05-15  ·  Next review 2026-06-15
What we already have

Built to be checked, not trusted.

Cryptographic primitives chosen against NIST guidance, and the engineering discipline that makes claims provable. Every item below is in code today.

Cryptographic primitives (NIST-aligned)

  • Ed25519 · native signing (RFC 8032)
  • secp256k1 ECDSA · EVM compatibility
  • Argon2id · wallet keystore at rest
  • AES-256-GCM · encrypted storage with secure cleanup
  • ECVRF-P256-SHA256-TAI · proposer election (RFC 9381)
  • Noise XX · mutually-authenticated peer transport
  • CRYSTALS-Kyber + X25519 · hybrid quantum-safe storage
  • HKDF-SHA-256 · tenant sub-secret derivation
  • aws-lc-rs · FIPS-track cryptographic backend (CMVP queued)

Engineering discipline

  • 121+ TLA+ formal specifications across the workspace
  • 50B+ states explored on transaction signing
  • 5,377 Rust tests · 1,343 Foundry tests
  • Zero in-codebase mocks. Every path names its real data source.
  • 28 Semgrep CI tripwire rules pinned to specific historical findings
  • 26-item POA&M drafted against the 110 NIST 800-171 r2 practices
  • A disclaimer-check CI workflow that enforces compliance-claim language on every public repository
  • CycloneDX + SPDX SBOMs on every release
  • SLSA build provenance on every artifact
What we do not yet do

What we do not yet promise.

Bidding on a contract whose requirements we cannot meet would violate FAR 52.203-13, so these are stated plainly.

  1. 01
    We are not yet FedRAMP-authorized for cloud delivery. We offer the on-prem deployment first. Cloud delivery follows agency sponsorship and an ATO grant.
  2. 02
    We do not yet hold a CMMC Level 2 certificate. Gap analysis is complete and consolidation is in progress. The first defensible response is targeted for 2026.
  3. 03
    We do not yet ship a FIPS 140-3 validated cryptographic module. Migration is documented. The CMVP queue is the bottleneck.
  4. 04
    We will not handle classified data or controlled unclassified information on any network we operate until federal certification is complete.
  5. 05
    We make no representations about token pricing or token-economic returns to anyone, ever. Our commercial model is denominated in dollars, on standard contract vehicles.
Verification path

Independently verify every claim on this page.

  • Live testnethttps://rpc.citrate.ai · Chain ID 40204
  • TLA+ spec inventory121+ specs · 50B+ states · on request via /resources#verify
  • Deployed contracts60+ deployed on 40204 · addresses published per release
  • Audit historyDated, on the record, available on request
  • Compliance posture briefTwo-business-day NDA-protected response · /contact
Request the verification packet
Talk to us

Compliance is a conversation, not a checkbox.

If you need a written posture summary for a procurement file, we will send the most recent snapshot under NDA within two business days.

Request a compliance reviewRequest the verification packet