Federal AI. Governed at the boundary.
Government agencies adopting AI face strict data handling obligations: CUI cannot leave the authorized environment uncontrolled, and every AI interaction must produce a tamper-resistant audit record. Arbitex puts a compliance-grade governance layer in front of every AI call — inspecting, enforcing, and logging before any data reaches a model.
AI governance built for federal data environments.
CUI Detection — NIST SP 800-171 Category Coverage
Controlled Unclassified Information spans dozens of category markings — from CUI//PRVCY and CUI//MED to CUI//LAW and CUI//FEDCON. Arbitex inspects every AI request in-path before any model processes it. The shipped detectors cover the personally identifiable information subject to federal handling requirements — names, identifiers, contact and health data. Arbitex does not ship CUI marking detectors: agencies author org DLP rules for the specific category markings, contract number formats, and acquisition-sensitive patterns in scope, and those rules run through the same three inspection tiers.
FedRAMP-Aligned Data Sovereignty
FedRAMP authorization requirements mandate that federal data processed by cloud services remain within an authorized boundary. Arbitex Hybrid Outpost deploys the data plane inside your agency VPC or on-premises enclave — the control plane handles configuration and policy delivery, while all AI traffic inspection runs inside your authorized environment. No agency data transits Arbitex-controlled cloud infrastructure. The deployment model is documented for inclusion in System Security Plans (SSPs) and ATO packages.
NIST 800-53 Controls Mapping
Arbitex enforcement controls align to NIST SP 800-53 Rev. 5 control families across AU (Audit and Accountability), AC (Access Control), SC (System and Communications Protection), and SI (System and Information Integrity). The compliance bundle maps each DLP enforcement action to a specific control identifier — AU-2 (Event Logging), AU-9 (Protection of Audit Information), AC-3 (Access Enforcement), SC-8 (Transmission Confidentiality), and SI-12 (Information Management and Retention). Audit exports include the control mapping for NIST-based assessments.
Air-Gap Deployment for Classified Workflows
Agencies operating at Classification Level or supporting IL4/IL5 workloads require data processing entirely within a disconnected or physically isolated environment. Arbitex Hybrid Outpost supports fully air-gapped deployment: the data plane operates without a persistent internet connection to the Arbitex control plane. Policy bundles are delivered via signed configuration packages that can be transferred through removable media or an approved secure transfer mechanism. AI governance runs without requiring continuous cloud connectivity.
FISMA Audit Controls — Tamper-proof Evidence Trail
FISMA requires federal agencies to maintain documented, tamper-resistant audit records for information system activity. Every Arbitex enforcement event is written to an tamper-proof, append-only audit log: AI request received, detection tier result, enforcement action (allow/block/redact), model response, response scan result. No user — including system administrators — can modify or delete log entries. Signed exports in JSONL and CSV support FISMA annual assessments, IG audits, and continuous monitoring submissions.
IL4/IL5 Readiness — Zero-Trust Identity Enforcement
Impact Level 4 and IL5 DoD workloads require identity verification for every access event. Arbitex enforces zero-trust identity controls at the AI gateway: every request is authenticated via SAML 2.0 or OIDC before DLP inspection runs. SCIM 2.0 provisioning keeps identity grants synchronized with your agency directory. Role-based access controls limit which personnel can query which model endpoints. WebAuthn/FIDO2 phishing-resistant MFA is available for privileged access. Every identity assertion is logged alongside the AI transaction for IL4/IL5 audit packages.
How it works
Deploy inside your agency boundary
The Arbitex data plane installs in your authorized cloud environment or on-premises infrastructure using Docker Compose or Kubernetes. All AI traffic — analyst queries, mission workflow automation, citizen-service interactions — routes through the gateway before reaching any model endpoint. CUI detection, policy enforcement, and audit logging run entirely inside your authorized boundary. No agency data transits Arbitex-controlled infrastructure.
Policy enforcement activates in-path
Your configured compliance bundle activates the relevant NIST 800-53 control set. CUI category patterns run at Tier 1 (structural regex with format validation). Tier 2 applies ML-based detection to identify PII and sensitive identifiers in free-text content. Contextual validation at Tier 3 resolves ambiguous detections — distinguishing a literary reference from a real person's protected record. Enforcement runs before any data reaches the model. Every decision is logged with control mapping.
Audit evidence ready for assessment and ATO
The tamper-proof audit log accumulates a complete evidence trail for every AI interaction. Signed exports include control identifiers mapped to each enforcement action — ready for FISMA annual assessments, Inspector General audits, and ATO package submissions. Continuous monitoring integrations deliver enforcement metrics to your SIEM for real-time visibility into AI data handling across the agency.
Six frameworks. One policy layer.
Each compliance obligation maps to a specific Arbitex capability. All bundles are active simultaneously — no separate configuration per framework or agency requirement.
Annual assessment controls, continuous monitoring, and tamper-proof audit evidence for agency AI operations.
Authorized boundary data sovereignty via Hybrid Outpost. SSP documentation package for ATO submissions.
Audit and accountability, access enforcement, transmission protection, and information integrity — all mapped to Arbitex enforcement actions.
All 110 CUI security requirements mapped to enforcement actions. Detection covers every CUI category marking.
Access control, audit logging, encryption, and identity management for agencies handling criminal justice information.
Zero-trust identity enforcement, air-gap deployment, phishing-resistant WebAuthn/FIDO2 MFA. Every identity assertion logged.
Related Resources
Ready to put governance in front of your federal AI?
Talk to an Arbitex engineer about custom detection rules for CUI, FedRAMP-aligned deployment, and policy configuration for your agency environment.