Skip to content

Ironclad Inc.: Ironclad CLM

FedRAMP ReadyRev5Moderate · since February 25, 2026

What its stage means

An independent assessor found the provider ready to pursue an authorization. It is not an authorization.

See it on the FedRAMP Marketplace

Share this page:LinkedInXEmail

The provider's description

An authorization boundary provides a diagrammatic illustration of a CSO’s internal services, components, and other devices, along with connections to external services and systems. Please note that external services include external cloud services that are not FedRAMP Authorized, corporate shared services, and the external entities to which the system must connect to receive updates for products installed within the system boundary.

An authorization boundary accounts for all federal information, data, and metadata that flow through a CSO. If the CSO has strong configuration management and change management built into the system development life cycle, the development environment can be outside the CSO boundary. This means that there is a 3PAO validated, reproducible and effective way to make service changes without impacting the production environment.

The authorization boundary diagram displays all in-scope system components for the Ironclad FedRAMP environment and is depicted with a prominent red border. All components outside of the authorization boundary are shown externally to the red border. The authorization boundary encompasses the Ironclad application and supporting infrastructure hosted entirely within GCP in the us-central1 region. All components depicted within the boundary directly support the operation, security, monitoring, and administration of the CLM system.

Within the authorization boundary, the FedRAMP environment consists of customer-facing application services, internal application services, and data storage components deployed on GCP. Application components communicate with one another using Google-managed networking services and all internal data flows are encrypted in transit using TLS 1.2 or higher. Data at rest within the authorization boundary is encrypted using customer-specific encryption keys and uses FIPS 140-2-validated cryptographic modules or higher where available.

Ingress and egress to the authorization boundary are controlled through a load balancer and WAF that provide a single logical entry point for external connections. The WAF is configured to restrict and allow traffic based on approved ports, protocols, and services defined in the PPSM list. Network traffic entering or leaving the environment traverses these boundary protection mechanisms, and all external communications are encrypted in transit using TLS 1.2 or higher.

Development and test environments are depicted and logically separated from the production environment. Access to development and test environments is restricted to authorized Ironclad personnel. Backup storage is provided through Google-managed backup services within the authorized environment and is depicted on the diagram. Backup data is encrypted at rest and in transit using FIPS-validated cryptographic modules.

What FedXchange has recorded

No change since FedXchange began following it on April 14, 2026. Each change of stage, impact level, or number of authorizations appears here.