essay · fedramp-active-defense
Threxen resources

FedRAMP active defense

A cornerstone for federal contractors: how Threxen’s FedRAMP-aligned tenants sit inside the authorization boundary, run continuous monitoring as a first-class workload, and turn active-defense containment into a control the agency can sign off on.

Agency cloud workloads have to land on one of three baselines, and the choice binds the rest of the package. FedRAMP Low covers low-impact information — public-facing services whose compromise would have limited adverse effect; Moderate, the most common baseline for federal contractors, covers information whose loss could have serious adverse effect on operations or individuals; High covers information whose loss could have catastrophic effect. A Threxen tenant is pinned to the chosen baseline at provisioning, the FedRAMP toggle under /app/settings/policy is what flips it on, and the policy pack that follows pins US-only data egress, the FIPS 140-3-validated key envelope, and the NIST 800-53 control families the authorizing official will be asked to attest to. The agency-facing boundary of an authorization package is the System Security Plan — the SSP — and the SSP-written perimeter is exactly where the Threxen tenant sits, no wider and no narrower.

Continuous monitoring is not a quarterly report; it is a runnable workload inside the boundary. ConMon cadence is laid out in the pack: monthly vulnerability scans, an annual penetration test, a Plan of Action and Milestones (POA&M) that tracks every weakness to closure, and significant-change reviews whenever a control or deployment shape moves. Threxen’s detectors and the policy-pack rule feed run inside the authorization boundary rather than as an out-of-band export — which means a finding is a control evidence item from the moment it is raised, attached to the same identity, network, and data-store perimeter the SSP describes. Reversal of containment, ATO re-attestation, and listing on a sponsor’s marketplace all read off that perimeter directly.

Active-defense containment is what an authorized tenant looks like under attack. Containment runs host isolation, session revocation, and tunnel teardown; an evidence packet is emitted on every action — hash-chained, FIPS-validated crypto on every signature, sector-pinned so that the data-plane residence cannot drift out of the US-only jurisdiction the SSP attested. The auditor sees the same perimeter the analyst sees: the trust page at /trust states the boundary, the how-it-works walkthrough explains the agent loop, and the policy toggle under /app/settings/policy is the one surface a federal administrator operates to keep the ATO current. Nothing in active defense crosses the boundary the SSP did not draw, and nothing the SSP promised is left to investigator judgement when an incident happens.

All resourcessecurity & compliance posture →Threxen · static essay · drift-free by construction
compare across all five frameworks

Read this regulator alongside its four peers.

The same four capabilities — host isolation, live credential poisoning, decoy surface, and the hash-chained evidence packet — are mapped onto each named article, requirement, or control of every regulated framework Threxen ships a policy pack for. The comparison matrix is the single page that lays them side by side.

▸ four sibling pillars · one matrix page · biometric-style read-across without re-reading five essays · security & compliance posture on the trust center