{
  "meta": {
    "name": "20x Moderate - Phase Two Pilot",
    "type": "FEDRAMP_20x_P2",
    "thisOrganization": "Paramify, Inc."
  },
  "system": {
    "systemName": "Paramify Cloud",
    "systemShortName": "Paramify Cloud",
    "systemDescription": "The Paramify Cloud (Paramify) is a software platform that automates risk management processes - including compliance planning, solution implementation, gap assessments, and continuous reporting - for cloud service providers, government agencies, and members of the Defense Industrial Base (DIB). Trusted by leading CSPs like Adobe, Cisco, Trellix, Palo Alto Networks, and Flock Safety. Living Gap Assessment Visualize compliance progress with Paramify's intuitive real-time dashboard. Track controls, manage gaps, and easily organize people, places, and components, ensuring audit readiness for FedRAMP 20X, GovRAMP, and other frameworks. Instant Audit-Ready Documentation Automate compliance, generate audit-ready deliverables like System Security Plans (SSPs), POA&Ms, and Customer Responsibility Matrices in days, not months. Continuously validate compliance with real-time automated validation tools for FedRAMP 20X and other frameworks. Fast, Cost-Effective Monitoring Continuously monitor, validate, and report compliance 90% faster at a quarter of the cost. Paramify's automated tools and Evidence Repository simplify compliance, reducing costs and enhancing efficiency. Integrated with issue management tools like Jira, it streamlines workflows, helping you meet tight deadlines.",
    "packageId": "FR2428769635XL",
    "cloudServiceModels": [
      "SAAS"
    ],
    "cloudDeploymentModel": "PUBLIC",
    "authorizationType": "FEDRAMP_AGENCY",
    "operationalStatus": null
  },
  "securityObjectives": {
    "confidentialityImpactLevel": "MODERATE",
    "confidentialityImpactRemarks": null,
    "integrityImpactLevel": "MODERATE",
    "integrityImpactRemarks": null,
    "availabilityImpactLevel": "MODERATE",
    "availabilityImpactRemarks": null,
    "digitalIdentity": "Level 2: AAL2, IAL2, FAL2",
    "digitalIdentityRemarks": "Digital identity assurance levels for Paramify Cloud: IAL2 (identity proofing), AAL2 (authentication), FAL2 (federation). Not a Certification Package Overview field: FedRAMP removed serviceProperties.digitalIdentityLevel in schema version 0.1.2.",
    "programImpactLevels": [
      {
        "programImpactLevel": "FEDRAMP_20x_P2_MODERATE",
        "remarks": null
      }
    ]
  },
  "contacts": [
    {
      "name": "Authorizing Official",
      "role": "authorizing-official",
      "partyName": "Federal Risk and Authorization Management Program Program Management Office"
    },
    {
      "name": "Prepared For",
      "role": "prepared-for",
      "partyName": "Paramify, Inc."
    },
    {
      "name": "System Security Plan Approver",
      "role": "content-approver",
      "partyName": "Brad Bartholomew"
    },
    {
      "name": "Information System Technical Point of Contact",
      "role": "system-poc-technical",
      "partyName": "Isaac Teuscher"
    },
    {
      "name": "Information System Security Officer",
      "role": "information-system-security-officer",
      "partyName": "Brad Bartholomew"
    },
    {
      "name": "Information System Owner",
      "role": "system-owner",
      "partyName": "Mike Cook"
    },
    {
      "name": "Information System Management Point of Contact",
      "role": "system-poc-management",
      "partyName": "Kenny Scott"
    },
    {
      "name": "Privacy Official's Point of Contact",
      "role": "privacy-poc",
      "partyName": "Paramify, Inc. POC"
    },
    {
      "name": "Prepared By",
      "role": "prepared-by",
      "partyName": "Paramify, Inc."
    },
    {
      "name": "Authorizing Official Point of Contact",
      "role": "authorizing-official-poc",
      "partyName": "20x@fedramp.gov"
    }
  ],
  "projectControls_SUMMARY": {
    "count": 237
  },
  "infoTypes": {
    "inheritProjectInformationTypes": false,
    "types": [
      "C.3.5.1",
      "C.3.5.8",
      "C.2.8.12",
      "C.2.8.7"
    ],
    "customInformationTypes": []
  },
  "systemPrivacy": {
    "hasIdFormCollection": true,
    "hasPrivacyImpactAssesment": false,
    "privacySensitive": false,
    "hasPublicCollection": false,
    "hasSorn": false,
    "sornName": null,
    "sornId": null
  },
  "attachments": [
    {
      "title": "Untitled",
      "fileName": "",
      "remarks": null,
      "status": "NOT_STARTED",
      "type": "other",
      "class": "",
      "required": false
    }
  ],
  "serviceIdentification": {
    "fedRampPackageId": "FR2428769635XL",
    "ueiNumber": "FWWNSFKDWPJ8",
    "providerName": "Paramify, Inc.",
    "serviceName": "Paramify Cloud",
    "serviceAcronym": "Paramify Cloud",
    "serviceDescription": "The Paramify Cloud (Paramify) is a software platform that automates risk management processes - including compliance planning, solution implementation, gap assessments, and continuous reporting - for cloud service providers, government agencies, and members of the Defense Industrial Base (DIB). Trusted by leading CSPs like Adobe, Cisco, Trellix, Palo Alto Networks, and Flock Safety. Living Gap Assessment Visualize compliance progress with Paramify's intuitive real-time dashboard. Track controls, manage gaps, and easily organize people, places, and components, ensuring audit readiness for FedRAMP 20X, GovRAMP, and other frameworks. Instant Audit-Ready Documentation Automate compliance, generate audit-ready deliverables like System Security Plans (SSPs), POA&Ms, and Customer Responsibility Matrices in days, not months. Continuously validate compliance with real-time automated validation tools for FedRAMP 20X and other frameworks. Fast, Cost-Effective Monitoring Continuously monitor, validate, and report compliance 90% faster at a quarter of the cost. Paramify's automated tools and Evidence Repository simplify compliance, reducing costs and enhancing efficiency. Integrated with issue management tools like Jira, it streamlines workflows, helping you meet tight deadlines.",
    "certificationType": "20x",
    "website": "https://www.paramify.com/",
    "logo": "https://www.fedramp.gov/assets/img/logos/CSP_logos/Paramify%20Logo.png"
  },
  "serviceProperties": {
    "serviceType": [
      "SaaS"
    ],
    "deploymentModel": "Public Cloud",
    "businessCategory": [
      "Collaboration",
      "Cybersecurity & Risk Management",
      "Data Management",
      "Governance, Risk, and Compliance (GRC)",
      "Operations Management"
    ],
    "trustCenter": {
      "repositoryType": [
        "Trust Center"
      ],
      "url": "https://trust.paramify.com/paramify/paramify-cloud",
      "repositoryDescription": "Paramify Cloud FedRAMP Trust Center. Publishes compliance programs (20x Moderate Phase Two Pilot, 20x Low Phase One Pilot, Paramify Cloud FedRAMP High), controls, third-party interconnections, and package deliverables.",
      "authenticationRequired": false
    },
    "additionalRepositories": [
      {
        "repositoryType": [
          "Assessment Reports",
          "Policies and Procedures"
        ],
        "url": "https://trust.paramify.com/paramify/paramify-cloud/deliverables",
        "repositoryDescription": "Package deliverables. Includes the Paramify 20x FedRAMP Moderate Authorization Letter, Coalfire - Paramify FedRAMP 20x Moderate Methodology, Coalfire Paramify KSI Validation (human- and machine-readable), Coalfire Assessment Paramify FR 20x Low, 2026 FedRAMP High Readiness Assessment Report (RAR), 2026 Paramify System Boundary Diagram, Paramify Penetration Test 2025-2026 Attestation, Paramify Vulnerability Disclosure Policy, Paramify Cloud CIS/CRM SSP Appendix J, Paramify OAR Q2 2026, and Paramify AI Approach.",
        "authenticationRequired": true,
        "accessRequestInstructions": "Select Log In on the Trust Center and request access to the Deliverables section. Access is granted to federal agencies, prospective federal customers, and their assessors."
      }
    ],
    "secureConfigurationGuidance": {
      "repositoryType": [
        "Secure Configuration Guidance"
      ],
      "url": "https://support.paramify.com/hc/en-us/sections/47348382411923-Recommended-Secure-Configuration",
      "repositoryDescription": "Recommended Secure Configuration guidance for Paramify Cloud, published in the Paramify Help Center (SCG-CSO-RSC).",
      "authenticationRequired": false
    },
    "nextOngoingCertificationReportDate": "2026-08-31"
  },
  "contactInformation": [
    {
      "contactType": "Security",
      "contactName": "Paramify FedRAMP Team",
      "contactEmail": "fedramp@paramify.com"
    },
    {
      "contactType": "Sales",
      "contactName": "Paramify Federal Sales",
      "contactEmail": "federal@paramify.com"
    }
  ],
  "assessor": {
    "name": "Coalfire Systems, Inc.",
    "assessorID": "138514"
  },
  "_marketplace_listing": {
    "url": "https://www.fedramp.gov/marketplace/products/FR2428769635XL",
    "status": "FedRAMP Certified",
    "statusAsOf": "2026-03-06",
    "certifiedSince": "2026-03-06",
    "phase": "Ongoing Certification",
    "certificationProfile": {
      "type": "20x",
      "path": "Program",
      "class": "Class C (Moderate)"
    },
    "authorizations": 1
  },
  "certifiedServices": [
    {
      "serviceName": "Paramify Cloud",
      "serviceDescription": "Software platform that automates risk management and compliance processes for cloud service providers, government agencies, and members of the Defense Industrial Base. Supports compliance planning, solution implementation, gap assessments, and continuous reporting, including Living Gap Assessment dashboards, automated generation of SSPs, POA&Ms and Customer Responsibility Matrices, an Evidence Repository, and automated validation for FedRAMP 20x and related frameworks.",
      "dateAvailable": "2026-03-06"
    }
  ],
  "thirdPartyInformationResources": {
    "certified": [
      {
        "fedRampCertifiedThirdPartyInformationResource": "F1603047866",
        "useCase": "Paramify Cloud is hosted in AWS GovCloud. Route 53 provides DNS for the offering and the ECR/EKS container platform hosts and deploys the application. Amazon GuardDuty monitors CloudTrail audit log activity and sends alerts to SentinelOne and AWS Security Hub for investigation and remediation of unauthorized or malicious activity in the Paramify Cloud AWS environment."
      },
      {
        "fedRampCertifiedThirdPartyInformationResource": "F1206081364",
        "useCase": "Google Workspace provides user directory authentication for Paramify Cloud."
      },
      {
        "fedRampCertifiedThirdPartyInformationResource": "FR2131856836",
        "useCase": "Okta IDaaS Government High Cloud (GHC) provides identity and access management for Paramify Cloud."
      },
      {
        "fedRampCertifiedThirdPartyInformationResource": "FR1919071020A",
        "useCase": "SentinelOne Singularity Platform High provides security logging and monitoring for Paramify Cloud and receives GuardDuty alerts for investigation and remediation. Referenced in the System Security Plan under SI-4 for identifying unauthorized use of the system."
      },
      {
        "fedRampCertifiedThirdPartyInformationResource": "FR2201340492",
        "useCase": "KnowBe4 Platform provides security awareness training for Paramify personnel."
      },
      {
        "fedRampCertifiedThirdPartyInformationResource": "FR1823447014",
        "useCase": "Slack receives system event notifications from Paramify Cloud. Event content is obfuscated before transmission."
      },
      {
        "fedRampCertifiedThirdPartyInformationResource": "GitLab SaaS",
        "useCase": "GitLab SaaS provides source control and CI/CD for Paramify Cloud. ECR images are pulled after CI/CD completion and approval."
      }
    ],
    "nonCertified": [
      {
        "name": "Replicated",
        "provider": "Replicated, Inc.",
        "website": "https://www.replicated.com",
        "useCase": "Replicated is the repository from which Paramify Cloud stable releases are pulled. Replicated also receives deployment status and application version updates from EKS."
      }
    ]
  }
}