Skip to content

Security and privacy

What FedXchange holds, and how it protects it

FedXchange is built for content that can sit in an outside cloud service: policies written from public federal sources, plus your agency's choice of services and the names of its roles.

The short version

Not FedRAMP authorized, and designed with that in mind

FedXchange runs on a standard Cloudflare account owned by Varry LLC. It is not FedRAMP authorized. Using it means using an outside cloud service, so it holds only what your agency would be comfortable placing in one.

Please don't put these in FedXchange

  • Controlled Unclassified Information (CUI) or classified information
  • System details such as addresses, host names, configurations, or findings
  • Personal information beyond the names and work emails of the people who use it

For this reason, the System Security and Privacy Plan generator, which needs system details, stays out of the app.

What it holds

A short list, on purpose

About people

  • Name and work email of each member
  • Passkeys and two-factor settings they add
  • Their role in the agency

About your agency

  • The service you chose for each function
  • Your titles for offices and roles
  • Your decisions on governance changes
  • The audit log of changes

From this website

  • What you send through the contact or early-access form, kept 12 months
  • No cookies, analytics, or advertising trackers on this site

The full details are in the privacy notice.

How it's protected

Controls built into the design

No passwords

People sign in with a link sent by email, a passkey, or both. Once someone sets up an authenticator app, an email link alone isn't enough.

One agency can't see another's data

Every record carries its agency's ID, and the service adds that ID to every query. No request can name a different agency. Tests check that one agency can't read another's records.

Roles decide what people can do

Each member is an owner, editor, reviewer, or viewer. AI assistants and access tokens act as the person who connected them, with that person's role.

Changes are previewed and recorded

Every change, from the web app, an assistant, or the governance watch, is written to your agency's audit log with who made it, how, and when.

Encrypted in transit and at rest

All traffic uses TLS. The database runs on Cloudflare D1, which encrypts stored data with AES-256.

Tokens are never stored in the clear

Personal access tokens are shown once and kept only as hashes. Assistant connections use one-hour tokens and end when you remove them.

Leaving

Your setup is yours

Download your agency's setup as a file at any time. To have your agency's data deleted, ask us and we'll delete it.

Found a security problem?

Tell us through the contact form and choose “Security report”. Please don't test against other people's accounts or data. We'll reply by email.