Skip to content

About

Why FedXchange exists

Federal security policies should say what an agency actually does. Most don't, because writing them that way and keeping them current takes time no one has.

Specific policies, without the busywork

A policy that says “the organization employs automated mechanisms” passes a checklist and helps no one. Staff can't follow it, and assessors have to ask which mechanism you mean. A policy that names your identity provider, your ticketing system, and the office that owns each task is one people can use.

Much of what those policies need is already public: your agency's FedRAMP authorizations, the government shared services on offer, and the directives and memoranda that set the requirements. FedXchange puts those together, asks you to confirm each choice, and writes from what you confirmed. Then it keeps watching the sources, so you hear about a change before an assessor does.

FedXchange is free to use.

Who runs it

Varry LLC

Varry LLC is a small business that builds tools and training for federal security work. Its other product, RMF Coach, teaches the NIST Risk Management Framework and FedRAMP through courses and a hands-on authorization simulation.

How we build it

A few rules we hold to

You confirm, then we write

No proposal reaches a document until a person at your agency accepts it.

Plain language

Every document must pass a plain-language writing standard before export.

Say what we are

FedXchange is not FedRAMP authorized, and it says so. It holds only what an outside service should.

Your AI, if any

We run no AI model. If you tailor wording with AI, you choose the assistant and its terms.