Security, compliance, and FedRAMP certification progress for Tarly Cowork — published for our federal customers and updated at least quarterly.
Review the current result for every Key Security Indicator, including unmet or partially met indicators, check totals, remediation target dates, and evidence-manifest integrity hashes. The independent Git history preserves how Tarly Cowork's reported posture changes over time.
Tarly Cowork is an AI-powered procurement workspace for government acquisition teams. It helps contracting professionals run market research, draft acquisition documents (IGCEs, solicitations, evaluation materials), and manage procurement files with grounded citations to authoritative federal data sources (SAM.gov, USAspending, the FAR and agency supplements).
Core Tarly Cowork web and Trust Center endpoints are checked daily from the compliance runner. The resulting status history is published in a public GitHub repository that remains available independently of the Tarly Cowork production request path.
Evidence-backed daily availability monitoring began August 8, 2026. The Class C requirement for a complete rolling 30-day history will remain open until 30 consecutive daily observations have accumulated. The publisher records current service state, daily history, and derived availability incidents in both human-readable Markdown and machine-readable JSON.
The next synchronous Tarly Cowork FedRAMP Quarterly Review is targeted for October 13, 2026 at 2:00 p.m. Eastern, five business days after the October 6 Ongoing Certification Report. Necessary parties may register by email or download the calendar file. Connection details will be sent to registered agency and assessment participants.
Questions and feedback on an Ongoing Certification Report may be submitted asynchronously to the Tarly security team. Feedback is desensitized and summarized in the subsequent report.
No quarterly report has been released yet. The example Ongoing Certification Report shows the format and every required section — certification-data changes, planned changes, accepted vulnerabilities, transformative changes, updated recommendations, agencies directly using the product, reportable incidents, and incident lessons learned — in human-readable Markdown and machine-readable JSON. Each released report is published under its own quarter alongside it.
All services below are included in the planned Tarly Cowork FedRAMP Minimum Assessment Scope and use the offering-wide FIPS 199 Moderate security categorization: confidentiality Moderate, integrity Moderate, and availability Moderate.
Service names below are the names agency users see in the product, so a listing can be checked against Tarly Cowork itself without translation.
| Included service | Function | Available since | Security category |
|---|---|---|---|
| Conversations | The AI procurement assistant: citation-grounded acquisition research, FAR and agency-supplement analysis, and document drafting, over uploaded evidence, connected sources, authoritative federal data, and read-only fetches of public web pages. Includes explicit, revocable share links for individual conversations (since March 19, 2026). | 2026-03-13 | FIPS 199 Moderate C: M · I: M · A: M |
| Procurement Files | The system of record for an acquisition: overview and contract data, conversations, artifacts, sources and evidence, reviews, membership and access, and an append-only audit log, with role-based privileges enforced per file. | 2026-03-13 | FIPS 199 Moderate C: M · I: M · A: M |
| Workflows | Guided, multi-step acquisition workflows producing market research, IGCEs, solicitations, and evaluation materials, with versioning, validation, and export to Word and PDF. | 2026-03-13 | FIPS 199 Moderate C: M · I: M · A: M |
| Resources | The customer-managed reference library plus the indexed corpus of the FAR, agency supplements, and document templates the assistant retrieves and cites from. | 2026-03-13 | FIPS 199 Moderate C: M · I: M · A: M |
| Workspace | Isolated execution environment for reading and writing working files and analyzing customer-supplied evidence. Scoped to one procurement file or conversation, in a dedicated sandbox container with no direct database access and only its own storage share mounted. | 2026-05-12 | FIPS 199 Moderate C: M · I: M · A: M |
| Approval Paths | Administrator-defined review and approval routing for procurement files and artifacts, with per-step assignment, approval state, and audit history. | 2026-07-29 | FIPS 199 Moderate C: M · I: M · A: M |
Supplemental information — outside Tarly Cowork and not FedRAMP Certified:
The items below are clearly separated from the Tarly Cowork cloud service offering and its Minimum Assessment Scope. They are provided only to prevent product-name or deployment-model ambiguity; none is claimed as included in, assessed with, or FedRAMP Certified as part of Tarly Cowork.
Third-party information resources within the planned Minimum Assessment Scope, per the FedRAMP 20x
Minimum Assessment Scope rules. The machine-readable equivalent is the
thirdPartyInformationResources object in
fedramp.json.
| Resource | FedRAMP ID | Use |
|---|---|---|
| Microsoft Azure Commercial FedRAMP High, Authorized |
F1603047324 | Sole hosting platform for the Tarly Cowork authorization boundary, with its core production resources in Azure Central US: Container Apps, PostgreSQL Flexible Server, Storage Account blobs and file shares, Key Vault, Container Registry, Front Door Premium with managed WAF, Azure DNS, Entra ID, Log Analytics and Azure Monitor, Microsoft Defender for Cloud, Azure AI Foundry model deployments, Azure AI Search, Azure AI Document Intelligence, and Azure Communication Services Email. Cowork does not use Service Bus as a direct runtime connection; the Tarly-operated shared-data ingestion plane has a Service Bus namespace that can affect the public records later read by Cowork. Physical, hypervisor, storage-media, and platform-cryptography controls are inherited from this package. |
| Resource | Provider | Use and data disclosed |
|---|---|---|
| SAM.gov Data Services API | U.S. General Services Administration | Read-only retrieval of entity registrations, contract opportunities, and opportunity attachments for citation. Search parameters and public identifiers only; no federal customer content. |
| USAspending.gov API | U.S. Department of the Treasury | Read-only retrieval of federal award and spending records for market research and pricing comparison. Query parameters and public identifiers only; no federal customer content. |
| GSA acquisition APIs (FAS, FPDS) | U.S. General Services Administration | Read-only retrieval of schedule, catalog, and federal procurement data system records. Query parameters and public identifiers only; no federal customer content. |
| eCFR and Acquisition.gov | U.S. Government Publishing Office and GSA | One-way ingestion of the FAR and agency supplements into the in-boundary regulation corpus. No federal customer content leaves the boundary. |
| Bureau of Labor Statistics public data API | U.S. Department of Labor, Bureau of Labor Statistics | One-way ingestion of public occupational employment and wage data into Tarly's shared Azure public-data platform. Public series identifiers and subscription credentials only; no federal customer content. |
| Regulations.gov public API | GSA eRulemaking Program | One-way ingestion and retrieval of public rulemaking dockets, documents, and comments through a subscription-key-protected API. Public query parameters only; no federal customer content. |
| Brave Search API | Brave Software, Inc. | Discovery-only web search. A short query string derived from the user's request is sent; titles, URLs, and snippets are returned. Results are never cited directly — any source relied upon is fetched and captured as evidence inside the boundary. Procurement file contents, evidence, and artifacts are not transmitted. |
| Public web content retrieval | Various public website operators | Read-only outbound HTTPS retrieval of specific pages identified by the user or by search results, so cited material can be captured as evidence inside the boundary. The request URL is the only information disclosed. |
| Tarly Microsoft 365 / SharePoint Online integration | Microsoft Corporation; tenant operated by Tarly | A test placeholder for a future customer-operated SharePoint tenant. It is configured to a Tarly-operated SharePoint site so the import path can be exercised, and it searches that site and imports a user-selected document into Cowork evidence storage. No agency or customer tenant is connected, so no federal customer data flows through it today. This page does not claim the current tenant is agency-operated or covered by an agency authorization. |
Tarly Cowork is intended for direct use by federal agency customers: agency acquisition personnel use the hosted service as an AI assistant for procurement work — drafting acquisition documents, running market research, and checking compliance with the FAR and agency supplements, with citations back to authoritative federal sources. When an agency places Tarly Cowork in a federal information system, the agency will authorize that use through its Authorization to Operate (ATO) process. A pre-certification pilot with the U.S. Department of Housing and Urban Development (HUD) concluded in August 2026.
| Milestone | Target | Status |
|---|---|---|
| NIST SP 800-171 self-assessment completed and filed in SPRS | May 2026 | ✓ Complete |
| Independent assessor (3PAO) selection and engagement — A-LIGN formally engaged for the FedRAMP 20x Class C Gap Assessment and Certification Assessment | August 2026 | ✓ Complete |
| Continuous-compliance pipeline in CI — evidence extracted from infrastructure-as-code, runtime, and security findings; evaluated against the FedRAMP 20x Key Security Indicators (Consolidated Rules 2026 catalog) on every change and nightly | July 2026 | ✓ Complete |
| FedRAMP package validated and approved; package ID FR2628650874 assigned | July 2026 | ✓ Complete |
| Gap remediation and machine-readable evidence package complete | Q4 2026 | In progress |
The service boundary consists of managed Azure services in U.S. commercial regions:
Signed-in agency and assessment parties can browse the current FedRAMP packages organized by 204 rules. Each rule brings together its README, automated checks, and supporting evidence, with individual rule ZIPs and a download of all rule packages.
Use the Trust Center access token issued by the Tarly security team. Everything else on this page is public and needs no sign-in.
Agency pricing is sized to federal procurement thresholds; usage caps protect cost of service.
| Stage | Price | Procurement path | Included |
|---|---|---|---|
| Pilot | $9,500 flat 60-day pilot |
Under micro-purchase threshold ($10,000 MPT · P-card/GPC) | Up to 3 seats · unlimited standard runs · 10 deep-research runs/mo · public-data only, no J&A or IT review |
| Year 1 | $75K–$245K / yr $245K PO ceiling |
Under Simplified Acquisition ($250K SAT · FAR Part 13) | Up to 25 seats · unlimited standard runs · 100 deep-research runs/mo |
| Enterprise | $250K–$750K per office, per year |
Above SAT (FAR 6.302-1 sole source) | Up to 75 seats · unlimited standard runs · 400 deep-research runs/mo · full ATO · custom integrations |
| Gov-wide | $1M+ per agency, per year |
Multi-office / agency-wide (GSA Schedule, IDIQ) | Agency-wide seats · unlimited standard runs · custom deep-research · cross-office deployment · on-prem / GovCloud |
Questions: cary@tarly.co.
Updated at least quarterly, per FedRAMP Marketplace continuous-progress requirements (MKT-IIP-DCP).
Tarly formally engaged A-LIGN Compliance and Security, Inc. dba A-LIGN (FedRAMP assessor ID 138665) as its independent assessor for the FedRAMP 20x Class C Gap Assessment and Certification Assessment.
FedRAMP validated and approved the Tarly Cowork package and assigned package ID FR2628650874. Package approval is a registration milestone and does not represent FedRAMP certification of the service. The Trust Center and machine-readable offering data are published. The certification path is FedRAMP 20x, Class C (Moderate), hosted on Azure commercial U.S. regions. The current CPO, provider SDR, and example OCR validate against the published schemas, but the strict readiness gate remains blocked pending control remediation, historical metrics or an accepted initial-certification exception, and independent-assessor content. 3PAO engagement remains targeted for August 2026.
Tarly has been assessed as Awardable on the Chief Digital and Artificial Intelligence Office (CDAO) Tradewinds Solutions Marketplace, the Department of War's marketplace of post-competition, readily awardable solutions. Our solution video is available to Government Customers on the marketplace (government login required).
Security researchers: please report vulnerabilities to security@tarly.co with "SECURITY" in the subject line.