Skip to main content
    SectorsPublic sector and defense

    Define where the work runs and who can access it.

    Reign supports dedicated single-tenant, customer-cloud, air-gapped and sovereign deployment. The deployment record identifies where applications, data and evidence sit, how administrative access works and who operates each part.

    We hold no FedRAMP authorization, no 3PAO-validated package, no Marketplace listing and no readiness designation, and none of those is in progress today.

    What we can take today said first
    Available today Single-tenant dedicated instance Your own cloud AWS or Azure account A named engineer visible in the record Also supported air-gapped operation sovereign deployment both supported single-tenant Not our program CMMC Controlled unclassified ITAR no claim of any kind FedRAMP Not authorized. No agency ATO, package or listing. If the constraint is in the third column, we are not the supplier. We would rather the conversation ended early and accurately.
    The deployment shapes we support, and the certifications we do not claim, both belong near the top of the page rather than the bottom.
    Deployment and access

    Put the program’s requirements in writing before work begins.

    01Where it runs

    Select a dedicated deployment in infrastructure iTmethods operates, in the program’s AWS or Azure account, or in a supported air-gapped or sovereign environment.

    02What it can reach

    Record the network connections, approved models and tools, data locations, key management, logging and evidence-retention settings for the selected deployment.

    03Who can act

    Connect administrative and workload access to the agreed identity model. Record the approval owners and the operating responsibilities assigned to iTmethods and the program.

    Confirm before scoping

    Match the deployment and supplier qualifications to the program.

    The program identifies its authorization boundary, data-handling rules, network restrictions and required supplier credentials. iTmethods confirms the supported deployment and operating scope against those requirements before an engagement proceeds.

    When a program requires those supplier qualifications, we would work with an organization that holds the required credential or mandate. iTmethods is not FedRAMP authorized or CMMC certified, does not handle controlled unclassified information and does not claim ITAR compliance, so we confirm the supplier path before scoping begins.

    Air-gapped and sovereign deployment are supported. The program’s security, acquisition, legal and assessment functions determine whether a proposed deployment and supplier meet its requirements.

    iTmethods makes no compliance, certification or accreditation claim under any framework. We design our controls against the NIST SP 800-53 Moderate baseline. We are not FedRAMP authorized: we have no agency ATO, no 3PAO-validated package, no Marketplace listing and no reciprocity of any kind. A federal agency cannot rely on that control design to meet a FedRAMP requirement. Regulatory alignment →
    Next step

    Discuss your deployment and program requirements.

    Let’s start with where the work must run, what it can connect to and the supplier qualifications the program requires.