Skip to main content
Use Case

Governing AI across federal and public sector workloads.

Government agencies are deploying AI for grants management, procurement analysis, policy drafting, and citizen services. Every prompt is a potential CUI exposure vector. Arbitex puts a governance layer in front of every AI call — inspecting, enforcing, and logging before any data reaches a model.

The challenge

AI in government moves faster than authorization boundaries.

Federal agencies and public sector organizations are adopting AI tools faster than procurement and ATO processes can keep pace. Employees use AI applications for grants analysis, policy research, case management notes, and constituent correspondence — often submitting prompts that contain CUI, PII, or agency-sensitive data without recognizing the exposure.

Most commercial AI gateways are designed for enterprise productivity environments, not federal compliance requirements. They offer no CUI-specific detection, no FedRAMP-aligned data boundary controls, and produce audit logs that don't satisfy NIST SP 800-53 AU control requirements. A SaaS-only gateway where government data transits vendor infrastructure creates authorization boundary violations that block ATO approval.

Arbitex was built for environments where every data handling decision has regulatory consequences. The Hybrid Outpost model keeps AI traffic inside the agency boundary. The tamper-proof audit log meets FISMA requirements. The DLP pipeline inspects every prompt and response before any model call is made, covering PII with its shipped detectors and CUI markings or agency-specific data through rules your team authors.

Capabilities

Built for government compliance requirements.

FedRAMP-Aligned Data Sovereignty

The Hybrid Outpost model keeps every AI prompt, response, and enforcement decision inside your agency VPC. No CUI or government data transits Arbitex-controlled infrastructure. The data plane you operate satisfies the boundary requirements that cloud-only AI gateways cannot meet for federal workloads.

CUI and PII Detection at Every Layer

The 3-tier DLP pipeline inspects every AI request and response for Controlled Unclassified Information, PII, and agency-specific sensitive data categories. Tier 1 applies 80+ regex patterns, with checksum validation where applicable (IBAN, ABA routing, NPI, DEA, ITIN, EIN, and similar regulated identifiers) for structured identifiers. Tier 2 uses ML-based entity recognition for free-text detection. Tier 3 applies contextual analysis to resolve ambiguity before enforcement.

FISMA Audit Controls — Tamper-proof Logs

Every detection, enforcement action, and policy decision is written to an tamper-proof, append-only audit log. Records cannot be modified or deleted by any user, including account owners. Retention is configurable to meet NIST SP 800-53 AU control requirements. Signed exports support IG and GAO audit requests.

Zero-Trust Identity Integration

Arbitex integrates with agency identity providers via SAML 2.0 and OIDC — works with existing PIV/CAC authentication infrastructure. SCIM 2.0 synchronizes user and group access from your directory. Every AI request carries an identity context, enabling attribute-based access control policies aligned with OMB M-22-09 zero-trust requirements.

Air-Gapped Outpost Deployment

Hybrid Outpost packages are GPG-signed for deployments in classified or restricted networks where external connectivity is unavailable. Signature verification runs at startup and on each policy sync — tampered packages are rejected. Policy bundles can be distributed via offline media with full integrity verification.

Multi-Agency Policy Isolation

Multi-tenant architecture with cryptographic tenant isolation supports shared-service deployments across agency components or bureaus. Each tenant operates with independent policy bundles, audit log partitions, and budget controls. A single Outpost deployment can serve multiple components without cross-contamination of data or policy state.

How it works

01

Agency employee initiates an AI request

A program analyst, grants manager, or procurement officer submits a prompt through an agency AI application. The request enters the Arbitex gateway before reaching any model endpoint. The 3-tier DLP pipeline begins immediately — Tier 1 catches SSNs, EINs, contract numbers, and structured CUI markers. Tier 2 applies ML-based detection to identify people, organizations, and locations in free text. Tier 3 contextual analysis confirms ambiguous matches against agency-specific policy definitions.

02

Policy enforces data handling rules in-path

Based on your configured compliance bundle, the gateway blocks, redacts, or routes the request per agency policy. Role-based access controls ensure users only interact with AI capabilities authorized for their clearance and function. Every enforcement decision is recorded — the policy version that governed the action, the detection result, the enforcement action taken, and the authenticated identity of the requestor.

03

Tamper-evident log supports oversight and audit

Every event — request received, CUI detection, enforcement action, model response, response inspection — is written to the tamper-proof audit log. Records are tamper-evident by construction and cannot be modified after creation. Signed exports support IG requests, GAO inquiries, and FISMA annual assessments. Log retention is configurable to meet NIST SP 800-53 AU-11 requirements.

Compliance mapping

Frameworks covered by the government bundle.

Each framework requirement maps to a specific Arbitex capability — not a general claim.

FedRAMP Moderate / High
NIST SP 800-53 Rev 5

Data boundary enforcement via Hybrid Outpost — AI traffic stays inside the agency authorization boundary. Supports ATO documentation for cloud AI integrations.

FISMA / NIST 800-53
AU, AC, SI Control Families

tamper-proof audit logs satisfy AU control requirements. RBAC and ABAC enforcement covers AC-2 and AC-3. DLP pipeline addresses SI-12 information handling.

CJIS Security Policy
v5.9 — Section 5.4, 5.9

Criminal justice information detection and access controls for law enforcement and justice agencies. Outpost deployment keeps CJIS data within compliant infrastructure boundaries.

OMB M-22-09 Zero Trust
Identity Pillar

SAML 2.0 + OIDC integration with existing PIV/CAC infrastructure. Every AI request carries verified identity context — supports continuous validation requirements.

Related Resources

Government Industry

FedRAMP and FISMA compliance

Identity & Access

SAML, SCIM, and WebAuthn

Compliance Frameworks

Pre-built regulatory policy packs

Outpost Deployment

Air-gap on-premises AI governance

Ready to govern AI across your agency?

Talk to an Arbitex engineer about CUI detection configuration, FedRAMP-aligned Hybrid Outpost deployment, and FISMA audit log setup for your environment.