FedRAMP & CUI

    FedRAMP & CUI handling, in one place

    Regulated communications and evidence stay inside the authorized secure boundary. Athena Fortify-CMMC runs the assessment workflow on approved metadata, opaque references, responsibilities, status, and sanitized conclusions. Everything below is a surface that either enforces that separation or explains it.

    Operate the boundary

    Configure and monitor the separation between the authorized secure boundary (AWS Wickr) and Athena's SaaS. Regulated content never enters Athena; Athena carries sanitized metadata, references, status, and conclusions.

    Scope and mark regulated data

    Decide what is actually in scope before you spend money assessing it, then label it so handling rules survive an assessor challenge.

    Understand the authorization position

    Athena's SaaS is not FedRAMP authorized, and no component's authorization transfers to Athena. These pages state the position precisely so proposals and assessors get the same answer.