{
  "serviceIdentification": {
    "fedRampPackageId": "FR2631258132",
    "ueiNumber": "",
    "providerName": "Harness, Inc.",
    "serviceName": "Harness for Government",
    "serviceAcronym": "HARG",
    "serviceDescription": "Harness.io Software-as-a-Service (SaaS) is a fully managed, cloud-native software delivery platform that provides continuous integration, continuous delivery, security testing, and related DevSecOps capabilities using a cloud computing environment. It enables its customers to focus on building and shipping software instead of managing the underlying infrastructure supporting their delivery pipelines. It is available to public, federal, state, local and tribal governments, as well as research institutions, federal contractors, and government contractors. The Harness offering is comprised of two components - the SaaS Control Plane and the customer-deployed Harness Agents. The Control Plane is hosted in Amazon Web Services (AWS) GovCloud on Amazon Elastic Kubernetes Service, and is used by customers to configure, orchestrate, and monitor their pipelines and workloads. Customers deploy one or more Agents inside their own environment - such as their AWS GovCloud tenancy - to execute pipeline operations. The Agents initiate a single outbound HTTPS connection to the Harness Control Plane to receive task instructions; no inbound connection from the Control Plane into the customer's environment is required. All customer source code (unless using Harness Code), artifacts, and workload data remain within the customer's environment where the Agents operate, and no such customer data is transmitted to or retained in the Control Plane.",
    "certificationType": "20x",
    "website": "https://www.harness.io",
    "logo": "https://cdn.prod.website-files.com/69e786e187c925d08ee02b90/69e786e187c925d08ee02bda_6222d7526cc398da63a4f639_nav-logo.svg"
  },
  "serviceProperties": {
    "serviceType": [
      "SaaS"
    ],
    "deploymentModel": "Government Community Cloud",
    "businessCategory": [
      "Collaboration",
      "Cybersecurity & Risk Management",
      "Development Tools"
    ],
    "nextOngoingCertificationReportDate": "2026-10-01",
    "trustCenter": {
      "repositoryType": [
        "Trust Center"
      ],
      "url": "https://trust.paramify.com/harness/harness-for-government",
      "repositoryDescription": "Harness Federal Trust Center",
      "authenticationRequired": true,
      "accessRequestInstructions": "https://support.paramify.com/hc/en-us/articles/48690571994003-Trust-Center-Deliverables-in-Paramify-Cloud"
    },
    "secureConfigurationGuidance": {
      "repositoryType": [
        "Secure Configuration Guidance"
      ],
      "url": "https://developer.harness.io/",
      "repositoryDescription": "Harness Platform",
      "authenticationRequired": false
    },
    "additionalRepositories": [
      {
        "repositoryType": [
          "Commercial Assessment Reports and Documents"
        ],
        "url": "https://trust.harness.io/",
        "repositoryDescription": "Commercial Trust Center",
        "authenticationRequired": false,
        "accessRequestInstructions": "https://help.drata.com/en/articles/16153632-safebase-trust-center-access-levels-training-video"
      }
    ]
  },
  "contactInformation": [
    {
      "contactType": "Security",
      "contactName": "Kevin Moy",
      "contactEmail": "security@harnessgov.com",
      "contactPhone": "310-775-7247"
    },
    {
      "contactType": "Sales",
      "contactName": "David Clarke",
      "contactEmail": "sales@harness.io",
      "contactPhone": "000-000-0000"
    },
    {
      "contactType": "Primary",
      "contactName": "Kevin Moy",
      "contactEmail": "kevin.moy@harness.io",
      "contactPhone": "310-775-7247"
    }
  ],
  "assessor": {
    "name": "N/A",
    "assessorID": "000000"
  },
  "certifiedServices": [
    {
      "serviceName": "Harness Platform",
      "serviceDescription": "Software Delivery Platform",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness CI (Continuous Integration)",
      "serviceDescription": "Continuous Integration",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness CD (Continuous Delivery)",
      "serviceDescription": "Continuous Delivery & GitOps",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness STO (Security Testing Orchestration)",
      "serviceDescription": "Security Testing Orchestration",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness IaCM (Infrastructure as Code Management)",
      "serviceDescription": "Infrastructure as Code Management",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness CODE (Code Repository)",
      "serviceDescription": "Code Repository",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness SCS (Supply Chain Security)",
      "serviceDescription": "Supply Chain Security",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness DB DevOps (DBD)",
      "serviceDescription": "Database DevOps",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    },
    {
      "serviceName": "Harness Resilience Testing",
      "serviceDescription": "Resilience Testing",
      "dateAvailable": "2026-08-03",
      "securityCategory": "Class A"
    }
  ],
  "informationResourcesFlowsAndSecurityCategories": [
    {
      "securityCategory": "Category 1: Primary Customer Data & Storage Tier",
      "informationResourcesIncluded": [
        "AWS - RDS/Aurora/PostgreSQL",
        "AWS - S3"
      ],
      "handledDataTypes": "Federal Customer Data, Controlled Unclassified Information (CUI), PII, application backups, analytical event logs",
      "riskSensitivityClassification": "High Sensitivity (High Impact / Federal Customer Data Boundary)"
    },
    {
      "securityCategory": "Category 2: Core Workloads & In-Memory Compute",
      "informationResourcesIncluded": [
        "AWS - Elastic Kubernetes Service (EKS) / Virtual Machines (EC2)"
      ],
      "handledDataTypes": "Microservice execution state, in-flight transaction payloads, temporary user session caches",
      "riskSensitivityClassification": "High / Moderate Sensitivity (Core Workload & Processing Boundary)"
    },
    {
      "securityCategory": "Category 3: Identity & Access Management (IAM)",
      "informationResourcesIncluded": [
        "AWS IAM",
        "Okta",
        "OIDC Providers",
        "AWS Secrets Manager"
      ],
      "handledDataTypes": "User credentials, SAML/OIDC assertions, MFA secrets, RBAC rules, administrative tokens",
      "riskSensitivityClassification": "High Sensitivity (Privileged Management & Authentication Boundary)"
    },
    {
      "securityCategory": "Category 4: Network Perimeter & Ingress Defense",
      "informationResourcesIncluded": [
        "AWS - VPC",
        "AWS - WAF",
        "AWS - Elastic Load Balancing",
        "AWS - Security Groups"
      ],
      "handledDataTypes": "Network routing tables, TLS-encrypted traffic, HTTP headers, public IP metadata, WAF inspection rules",
      "riskSensitivityClassification": "Low to Moderate Sensitivity (Public Edge & Network Routing Boundary)"
    },
    {
      "securityCategory": "Category 5: Observability, Security & Audit Logging",
      "informationResourcesIncluded": [
        "AWS - SecurityHub / GuardDuty",
        "AWS - CloudTrail / CloudWatch",
        "Google SecOps"
      ],
      "handledDataTypes": "System API call audits, runtime security alerts, infrastructure metrics, security telemetry, dashboard configs",
      "riskSensitivityClassification": "Moderate Sensitivity (System Management & Audit Boundary)"
    },
    {
      "securityCategory": "Category 6: External Enterprise & Support SaaS",
      "informationResourcesIncluded": [
        "Google Workspace",
        "Zendesk"
      ],
      "handledDataTypes": "Support tickets, customer communication logs, internal documentation",
      "riskSensitivityClassification": "Low to Moderate Sensitivity (Third-Party SaaS Service Boundary)"
    }
  ],
  "thirdPartyInformationResources": {
    "certified": [
      {
        "fedRampCertifiedThirdPartyInformationResource": "Amazon Web Services",
        "fedRampPackageId": "F1603047866",
        "useCase": "Cloud Hosting Provider"
      }
    ],
    "nonCertified": [
      {
        "name": "Zendesk",
        "provider": "Zendesk",
        "website": "https://www.zendesk.com/",
        "useCase": "Support Tickets"
      },
      {
        "name": "Okta Workforce",
        "provider": "Okta",
        "website": "https://www.okta.com/",
        "useCase": "IDP"
      },
      {
        "name": "Google SecOps",
        "provider": "Google",
        "website": "https://cloud.google.com/security/products/security-information-event-management",
        "useCase": "SIEM"
      },
      {
        "name": "Google Workspace",
        "provider": "Google",
        "website": "https://workspace.google.com/",
        "useCase": "E-mail and Collaboration"
      }
    ]
  },
  "cryptographicModuleDocumentation": [
    {
      "resource": "6 KMS CMKs",
      "resourceType": "KMS Keys",
      "cryptoModule": "AWS KMS Hardware Security Module (HSM)",
      "cmvpCert": "#4523",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3",
      "sunsetDate": "Active - 2028-03-15",
      "status": "Compliant"
    },
    {
      "resource": "55 S3 Buckets",
      "resourceType": "S3 Buckets",
      "cryptoModule": "AWS KMS HSM (SSE-S3 AES-256, GovCloud default)",
      "cmvpCert": "#4523",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3",
      "sunsetDate": "Active - 2028-03-15",
      "status": "Compliant"
    },
    {
      "resource": "EBS Volumes (all sampled)",
      "resourceType": "EBS Volumes",
      "cryptoModule": "AWS KMS CMK (key/18c6a199-...)",
      "cmvpCert": "#4523",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3",
      "sunsetDate": "Active - 2028-03-15",
      "status": "Compliant"
    },
    {
      "resource": "4 RDS Instances (3 PostgreSQL, 1 MySQL)",
      "resourceType": "RDS Instances",
      "cryptoModule": "AWS KMS CMK (storage) / AWS-LC TLS (rds-ca-rsa4096-g1)",
      "cmvpCert": "#4523 (KMS) / #4631 (TLS)",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3 (KMS) / Level 1 (TLS)",
      "sunsetDate": "Active - 2028-03-15 / 2028-06-20",
      "status": "Partial Compliant"
    },
    {
      "resource": "39 EC2 Instances (Bottlerocket)",
      "resourceType": "EC2 Instances",
      "cryptoModule": "AWS-LC Cryptographic Module",
      "cmvpCert": "#4631",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 1",
      "sunsetDate": "Active - 2028-06-20",
      "status": "Compliant"
    },
    {
      "resource": "1 EKS Cluster (prod-k8s-eks-pri)",
      "resourceType": "EKS Clusters",
      "cryptoModule": "AWS KMS Envelope Encryption / AWS-LC (Bottlerocket worker nodes)",
      "cmvpCert": "#4523 (KMS) / #4631 (AWS-LC)",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3 (KMS) / Level 1 (AWS-LC)",
      "sunsetDate": "Active - 2028-03-15 / 2028-06-20",
      "status": "Compliant"
    },
    {
      "resource": "2 ElastiCache Clusters (Redis)",
      "resourceType": "ElastiCache (Redis)",
      "cryptoModule": "AWS KMS CMK (at-rest) / AWS-LC TLS (in-transit, mode=preferred)",
      "cmvpCert": "#4523 (KMS) / #4631 (TLS)",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3 (KMS) / Level 1 (TLS)",
      "sunsetDate": "Active - 2028-03-15 / 2028-06-20",
      "status": "Partial Compliant"
    },
    {
      "resource": "90+ Secrets Manager Secrets (13 tagged, 30+ unconfirmed)",
      "resourceType": "Secrets Manager",
      "cryptoModule": "AWS Managed Key (default KMS)",
      "cmvpCert": "#4523 (unconfirmed on 30+ secrets)",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3",
      "sunsetDate": "Active - 2028-03-15",
      "status": "Partial Compliant"
    },
    {
      "resource": "2 ACM Certificates (*.harnessgov.com, *.harness.io)",
      "resourceType": "ACM Certificates",
      "cryptoModule": "AWS Certificate Manager (RSA-2048) via AWS-LC TLS",
      "cmvpCert": "#4631",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 1",
      "sunsetDate": "Active - 2028-06-20 (certs expire 2026-12-02 / 2026-12-23)",
      "status": "Compliant"
    },
    {
      "resource": "2 Load Balancers / 4 Listeners (ALB & NLB)",
      "resourceType": "Load Balancers",
      "cryptoModule": "ELBSecurityPolicy-TLS13-1-2-FIPS-2023-04 (AWS-LC) / 1 HTTP listener (plaintext, port 10000)",
      "cmvpCert": "#4631",
      "fipsStandard": "FIPS 140-3 (3 of 4 listeners)",
      "securityLevel": "Level 1",
      "sunsetDate": "Active - 2028-06-20",
      "status": "Partial Compliant"
    },
    {
      "resource": "1 VPC Flow Log (prod-vpc)",
      "resourceType": "VPC Flow Logs",
      "cryptoModule": "CloudWatch Logs (AWS-managed encryption)",
      "cmvpCert": "#4523",
      "fipsStandard": "FIPS 140-3",
      "securityLevel": "Level 3",
      "sunsetDate": "Active - 2028-03-15",
      "status": "Compliant"
    }
  ],
  "certificationPackageOverviewMetadata": {
    "name": "Kevin Moy",
    "title": "Director, GRC",
    "contactInformation": "kevin.moy@harness.io",
    "role": "Responsible and accountable for the FedRAMP Certification Package",
    "versionHistory": [
      {
        "version": "1.0",
        "dateTime": "2026-08-11T00:00:00Z",
        "source": "Manual"
      },
      {
        "version": "2.0",
        "dateTime": "2026-08-20T00:00:00Z",
        "source": "Manual"
      },
      {
        "version": "2.1",
        "dateTime": "2026-09-11T15:30:53Z",
        "source": "Auto Generated"
      }
    ]
  }
}
