Tarly logo
Tarly · Trust Center

Trust Center

Security, compliance, and FedRAMP certification progress for Tarly Cowork — published for our federal customers and updated at least quarterly.

FedRAMP status: The Tarly Cowork package has FedRAMP assigned package ID FR2628650874 and is actively preparing for a FedRAMP 20x Certification, Class C (Moderate) certification. An assigned package ID is a registration milestone and does not mean the service is FedRAMP certified. The accountable official is Patrick Phillips, System Owner and FedRAMP Program Owner (security@tarly.co, 585-474-2276). CPO version 2026.09.15.1 was last updated 2026-09-15T18:28:14Z from the Tarly compliance repository source revision. Security and compliance changes are regularly published against below.
Updated nightly

FedRAMP 20x KSI status

Review the current result for every Key Security Indicator, including unmet or partially met indicators, check totals, remediation target dates, and evidence-manifest integrity hashes. The independent Git history preserves how Tarly Cowork's reported posture changes over time.

The offering

Tarly Cowork is an AI-powered procurement workspace for government acquisition teams. It helps contracting professionals run market research, draft acquisition documents (IGCEs, solicitations, evaluation materials), and manage procurement files with grounded citations to authoritative federal data sources (SAM.gov, USAspending, the FAR and agency supplements).

Service model Software as a Service (SaaS)
Deployment model Public cloud — Microsoft Azure (commercial), U.S. regions only
Business category Artificial Intelligence (AI) · Collaboration · Data Management · Legal & Policy · Operations Management · Research
Provider Pincus Technologies Inc · UEI RKCYVMCNUK45
Target certification FedRAMP 20x, Class C (Moderate)
FedRAMP package ID FR2628650874 (FedRAMP Marketplace listing)
Underlying infrastructure Inherits from the Azure Commercial FedRAMP High P-ATO
Independent assessor (3PAO) A-LIGN Compliance and Security, Inc. dba A-LIGN · FedRAMP assessor ID 138665 · initial assessment completed September 8, 2026; updated results received September 11
Product website gov.tarly.co
FedRAMP Certification Package Overview fedramp.json
Independent availability status human-readable status · status.json
Next ongoing certification report October 6, 2026
Next quarterly review October 13, 2026 at 2:00 p.m. Eastern · calendar file

Service availability

Core Tarly Cowork web and Trust Center endpoints are checked daily from the compliance runner. The resulting status history is published in a public GitHub repository that remains available independently of the Tarly Cowork production request path.

Evidence-backed daily availability monitoring began August 8, 2026. The Class C requirement for a complete rolling 30-day history will remain open until 30 consecutive daily observations have accumulated. The publisher records current service state, daily history, and derived availability incidents in both human-readable Markdown and machine-readable JSON.

Quarterly review

The next synchronous Tarly Cowork FedRAMP Quarterly Review is targeted for October 13, 2026 at 2:00 p.m. Eastern, five business days after the October 6 Ongoing Certification Report. Necessary parties may register by email or download the calendar file. Connection details will be sent to registered agency and assessment participants.

Questions and feedback on an Ongoing Certification Report may be submitted asynchronously to the Tarly security team. Feedback is desensitized and summarized in the subsequent report.

No quarterly report has been released yet. The example Ongoing Certification Report shows the format and every required section — certification-data changes, planned changes, accepted vulnerabilities, transformative changes, updated recommendations, agencies directly using the product, reportable incidents, and incident lessons learned — in human-readable Markdown and machine-readable JSON. Each released report is published under its own quarter alongside it.

Public service list & security categories

All services below are included in the planned Tarly Cowork FedRAMP Minimum Assessment Scope and use the offering-wide FIPS 199 Moderate security categorization: confidentiality Moderate, integrity Moderate, and availability Moderate.

Service names below are the names agency users see in the product, so a listing can be checked against Tarly Cowork itself without translation.

Included serviceFunctionAvailable sinceSecurity category
ConversationsThe AI procurement assistant: citation-grounded acquisition research, FAR and agency-supplement analysis, and document drafting, over uploaded evidence, connected sources, authoritative federal data, and read-only fetches of public web pages. Includes explicit, revocable share links for individual conversations (since March 19, 2026).2026-03-13FIPS 199 Moderate
C: M · I: M · A: M
Procurement FilesThe system of record for an acquisition: overview and contract data, conversations, artifacts, sources and evidence, reviews, membership and access, and an append-only audit log, with role-based privileges enforced per file.2026-03-13FIPS 199 Moderate
C: M · I: M · A: M
WorkflowsGuided, multi-step acquisition workflows producing market research, IGCEs, solicitations, and evaluation materials, with versioning, validation, and export to Word and PDF.2026-03-13FIPS 199 Moderate
C: M · I: M · A: M
ResourcesThe customer-managed reference library plus the indexed corpus of the FAR, agency supplements, and document templates the assistant retrieves and cites from.2026-03-13FIPS 199 Moderate
C: M · I: M · A: M
WorkspaceIsolated execution environment for reading and writing working files and analyzing customer-supplied evidence. Scoped to one procurement file or conversation, in a dedicated sandbox container with no direct database access and only its own storage share mounted.2026-05-12FIPS 199 Moderate
C: M · I: M · A: M
Approval PathsAdministrator-defined review and approval routing for procurement files and artifacts, with per-step assignment, approval state, and audit history.2026-07-29FIPS 199 Moderate
C: M · I: M · A: M

Supplemental information — outside Tarly Cowork and not FedRAMP Certified:

The items below are clearly separated from the Tarly Cowork cloud service offering and its Minimum Assessment Scope. They are provided only to prevent product-name or deployment-model ambiguity; none is claimed as included in, assessed with, or FedRAMP Certified as part of Tarly Cowork.

  • Tarly Scanner at tarly.co is a separate public procurement-opportunity scanning product.
  • Development, test, staging, and corporate business systems do not process production Tarly Cowork federal customer data and are outside the planned authorization boundary.
  • Alternative deployment models, including customer-hosted, on-premises, and Azure Government deployments, are not included in this Marketplace listing or planned Minimum Assessment Scope.

Third-party information resources

Third-party information resources within the planned Minimum Assessment Scope, per the FedRAMP 20x Minimum Assessment Scope rules. The machine-readable equivalent is the thirdPartyInformationResources object in fedramp.json.

FedRAMP authorized

ResourceFedRAMP IDUse
Microsoft Azure Commercial
FedRAMP High, Authorized
F1603047324 Sole hosting platform for the Tarly Cowork authorization boundary, with its core production resources in Azure Central US: Container Apps, PostgreSQL Flexible Server, Storage Account blobs and file shares, Key Vault, Container Registry, Front Door Premium with managed WAF, Azure DNS, Entra ID, Log Analytics and Azure Monitor, Microsoft Defender for Cloud, Azure AI Foundry model deployments, Azure AI Search, Azure AI Document Intelligence, and Azure Communication Services Email. Cowork does not use Service Bus as a direct runtime connection; the Tarly-operated shared-data ingestion plane has a Service Bus namespace that can affect the public records later read by Cowork. Physical, hypervisor, storage-media, and platform-cryptography controls are inherited from this package.

Not FedRAMP authorized

ResourceProviderUse and data disclosed
SAM.gov Data Services APIU.S. General Services AdministrationRead-only retrieval of entity registrations, contract opportunities, and opportunity attachments for citation. Search parameters and public identifiers only; no federal customer content.
USAspending.gov APIU.S. Department of the TreasuryRead-only retrieval of federal award and spending records for market research and pricing comparison. Query parameters and public identifiers only; no federal customer content.
GSA acquisition APIs (FAS, FPDS)U.S. General Services AdministrationRead-only retrieval of schedule, catalog, and federal procurement data system records. Query parameters and public identifiers only; no federal customer content.
eCFR and Acquisition.govU.S. Government Publishing Office and GSAOne-way ingestion of the FAR and agency supplements into the in-boundary regulation corpus. No federal customer content leaves the boundary.
Bureau of Labor Statistics public data APIU.S. Department of Labor, Bureau of Labor StatisticsOne-way ingestion of public occupational employment and wage data into Tarly's shared Azure public-data platform. Public series identifiers and subscription credentials only; no federal customer content.
Regulations.gov public APIGSA eRulemaking ProgramOne-way ingestion and retrieval of public rulemaking dockets, documents, and comments through a subscription-key-protected API. Public query parameters only; no federal customer content.
Brave Search APIBrave Software, Inc.Discovery-only web search. A short query string derived from the user's request is sent; titles, URLs, and snippets are returned. Results are never cited directly — any source relied upon is fetched and captured as evidence inside the boundary. Procurement file contents, evidence, and artifacts are not transmitted.
Public web content retrievalVarious public website operatorsRead-only outbound HTTPS retrieval of specific pages identified by the user or by search results, so cited material can be captured as evidence inside the boundary. The request URL is the only information disclosed.
Tarly Microsoft 365 / SharePoint Online integrationMicrosoft Corporation; tenant operated by TarlyA test placeholder for a future customer-operated SharePoint tenant. It is configured to a Tarly-operated SharePoint site so the import path can be exercised, and it searches that site and imports a user-selected document into Cowork evidence storage. No agency or customer tenant is connected, so no federal customer data flows through it today. This page does not claim the current tenant is agency-operated or covered by an agency authorization.

Federal use case (Direct Use)

Tarly Cowork is intended for direct use by federal agency customers: agency acquisition personnel use the hosted service as an AI assistant for procurement work — drafting acquisition documents, running market research, and checking compliance with the FAR and agency supplements, with citations back to authoritative federal sources. When an agency places Tarly Cowork in a federal information system, the agency will authorize that use through its Authorization to Operate (ATO) process. A pre-certification pilot with the U.S. Department of Housing and Urban Development (HUD) concluded in August 2026.

Certification roadmap

MilestoneTargetStatus
NIST SP 800-171 self-assessment completed and filed in SPRSMay 2026✓ Complete
Independent assessor (3PAO) selection and engagement — A-LIGN formally engaged for the FedRAMP 20x Class C Gap Assessment and Certification AssessmentAugust 2026✓ Complete
Continuous-compliance pipeline in CI — evidence extracted from infrastructure-as-code, runtime, and security findings; evaluated against the FedRAMP 20x Key Security Indicators (Consolidated Rules 2026 catalog) on every change and nightlyJuly 2026✓ Complete
FedRAMP package validated and approved; package ID FR2628650874 assignedJuly 2026✓ Complete
Gap remediation and machine-readable evidence package completeQ4 2026In progress

Current security posture

Architecture & boundary summary

The service boundary consists of managed Azure services in U.S. commercial regions:

Edge Azure Front Door + managed DNS
Compute Azure Container Apps (containerized frontend & API)
Data Azure Database for PostgreSQL (Flexible Server), Azure Storage
Messaging No direct Cowork Service Bus runtime path; the Tarly-operated shared-data ingestion plane uses Azure Service Bus
Secrets Azure Key Vault
AI services Azure-hosted model endpoints (U.S. regions)
Registry Azure Container Registry
Monitoring Azure Log Analytics (centralized audit & security logging)

Documentation & access

Certification package (sign-in required)

Signed-in agency and assessment parties can browse the current FedRAMP packages organized by 204 rules. Each rule brings together its README, automated checks, and supporting evidence, with individual rule ZIPs and a download of all rule packages.

Use the Trust Center access token issued by the Tarly security team. Everything else on this page is public and needs no sign-in.

Pricing

Agency pricing is sized to federal procurement thresholds; usage caps protect cost of service.

StagePriceProcurement pathIncluded
Pilot$9,500 flat
60-day pilot
Under micro-purchase threshold ($10,000 MPT · P-card/GPC) Up to 3 seats · unlimited standard runs · 10 deep-research runs/mo · public-data only, no J&A or IT review
Year 1$75K–$245K / yr
$245K PO ceiling
Under Simplified Acquisition ($250K SAT · FAR Part 13) Up to 25 seats · unlimited standard runs · 100 deep-research runs/mo
Enterprise$250K–$750K
per office, per year
Above SAT (FAR 6.302-1 sole source) Up to 75 seats · unlimited standard runs · 400 deep-research runs/mo · full ATO · custom integrations
Gov-wide$1M+
per agency, per year
Multi-office / agency-wide (GSA Schedule, IDIQ) Agency-wide seats · unlimited standard runs · custom deep-research · cross-office deployment · on-prem / GovCloud

Questions: cary@tarly.co.

Progress updates

Updated at least quarterly, per FedRAMP Marketplace continuous-progress requirements (MKT-IIP-DCP).

August 4, 2026

Tarly formally engaged A-LIGN Compliance and Security, Inc. dba A-LIGN (FedRAMP assessor ID 138665) as its independent assessor for the FedRAMP 20x Class C Gap Assessment and Certification Assessment.

July 17, 2026

FedRAMP validated and approved the Tarly Cowork package and assigned package ID FR2628650874. Package approval is a registration milestone and does not represent FedRAMP certification of the service. The Trust Center and machine-readable offering data are published. The certification path is FedRAMP 20x, Class C (Moderate), hosted on Azure commercial U.S. regions. The current CPO, provider SDR, and example OCR validate against the published schemas, but the strict readiness gate remains blocked pending control remediation, historical metrics or an accepted initial-certification exception, and independent-assessor content. 3PAO engagement remains targeted for August 2026.

Recognitions

Tradewinds Solutions Marketplace Awardable badge

Tarly has been assessed as Awardable on the Chief Digital and Artificial Intelligence Office (CDAO) Tradewinds Solutions Marketplace, the Department of War's marketplace of post-competition, readily awardable solutions. Our solution video is available to Government Customers on the marketplace (government login required).

Contacts

Sales Cary Volpert — CEO · cary@tarly.co · 310-883-8302
Security Patrick Phillips — Founding Engineer, FedRAMP program owner · security@tarly.co · 585-474-2276

Security researchers: please report vulnerabilities to security@tarly.co with "SECURITY" in the subject line.