Skip to content

Kiteworks USA, LLC: Kiteworks Federal Cloud

FedRAMP AuthorizedRev5Moderate · since June 1, 2017

What its stage means

An agency or the FedRAMP program authorized it. Agencies can reuse that authorization.

See it on the FedRAMP Marketplace

Share this page:LinkedInXEmail

The provider's description

The Kiteworks Private Data Network is a FedRAMP Authorized service at the Moderate Impact Level that provides data security, governance, and compliance capabilities. The service consists of the following core components and functions:

System Components

- Virtual private cloud (VPC) environment with dedicated servers for each customer - Encrypted file storage system - Data transfer protocols including SFTP, HTTPS, and SMTP - Authentication and authorization services - Audit logging and monitoring systems - Security scanning and threat detection services

Core Functions

- File transfer and sharing capabilities via web interface, email, SFTP, MFT, and APIs - Role- and attribute-based access control and user authentication - File encryption at rest and in transit using FIPS 140-3 validated cryptographic modules - Audit logging of all system and user activities - Integration with customer directory services (LDAP/Active Directory, etc., see below) - Multi-factor authentication support - DLP integration - Embedded antivirus

Possessionless Editing (SafeEDIT) System Components and Functions

- File streaming service for secure remote data access and collaboration - Data rendering system for file type conversion - Audit logging system for data interactions - Versioning system for file changes - Authorization validation service - File integrity verification system - Session management service - Access revocation controls - Activity monitoring system

Security Features

- Customer-managed encryption keys - Single-tenant deployment providing data isolation between customers - Continuous security monitoring and scanning - File-level role- and attributed-based access controls - Remote device management capabilities - Security event logging and reporting - Integration with customer SIEM systems

Compliance Capabilities

- Audit log generation and retention - Policy enforcement mechanisms - Compliance reporting tools - Data locality controls - Access tracking and monitoring - Chain of custody documentation

Integration Interfaces

- REST APIs for system integration and SCIM authentication support - SMTP interface for email services - SFTP/FTPS/CIFS/SMB interfaces for file transfer - LDAP/AD, SAML 2.0, Kerberos, PIV/CAC, time-based one-time password (TOTP) authenticators, SMS, and SFTP certificate connectors for authentication - SIEM integration for security monitoring - DLP and CDR system integrations - The system operates within a defined authorization boundary and undergoes continuous monitoring and regular security assessments in accordance with FedRAMP requirements.

To learn more about what Kiteworks can do for government agencies, please visit: https://www.kiteworks.com/solutions/government/

What FedXchange has recorded

  1. Kiteworks Federal Cloud from Kiteworks USA, LLC gained an agency authorization, 16 in all.