FedRAMP package ID: FR2628650874
This page documents human and programmatic access to Tarly Cowork certification data. The machine-readable access manifest is /trust/access.json.
Decision: Tarly publicly shares a selected, desensitized subset of the certification package. Publishing offering identity and scope, secure-use guidance, high-level KSI status, availability, and desensitized recurring reports is not expected to enable unauthorized access, disrupt operations, or otherwise adversely affect Tarly Cowork.
Credentials, tokens, keys, recovery material, federal customer data, agency or personal identities, internal resource identifiers and network paths, raw logs and scanner payloads, exploit-enabling vulnerability detail, unredacted findings, detailed SDR evidence, independent assessments, and unmodified FedRAMP Certification Reports remain controlled.
| Artifact | Human-readable | Programmatic |
|---|---|---|
| Certification Package Overview | Trust Center | fedramp.json |
| KSI status | KSI-STATUS.md | ksi-results.json |
| Availability | STATUS.md | status.json |
| Secure Configuration Guide | HTML guide | secure-configuration-guide.json |
| Quarterly Review | meeting details | calendar file |
Authorized agency and assessment personnel may request the Security Decision Record, evidence manifests, the paired human-readable and JSON policy/procedure index and its referenced documents, Ongoing Certification Reports, vulnerability reports, Significant Change history, reportable-incident reports, and assessment reports by emailing the Tarly security team. Parties that already hold an entitlement can browse and download the certification package, organized by 204 rules, with each rule’s README, checks, supporting evidence, and ZIP download, or browse Significant Change history on the gated Significant Change Notices page without using the API by hand.
Decision policy: The FedRAMP Program Owner presumes verified agency requests should be approved. Tarly verifies the requester's agency affiliation and official purpose, confirms the request concerns package FR2628650874 and supports authorization, assessment, oversight, or procurement, and requires acceptance of the controlled handling method. Tarly denies only when identity or affiliation cannot be verified, the material is unrelated to the package or official purpose, or delivery would violate law, contract, FedRAMP direction, or another agency's confidentiality; when possible, Tarly offers a safe subset instead. The response target is five business days.
Approved requests receive a time-limited authenticated HTTPS bundle. The bundle includes human-readable files, JSON, manifest.json, SHA-256 hashes, media types, schema identifiers, and signature verification metadata so agency systems can retrieve and verify every artifact programmatically. Tarly retains the delivery and expiration timestamps, bundle receipt, and manifest SHA-256 in the controlled inventory.
For every FedRAMP Reportable Incident, Tarly sends each approved Initial, Ongoing, and Final Incident Report through all three required routes: FedRAMP at fedramp_security@fedramp.gov, every affected agency through its agency-specific incident procedure, and all necessary parties through an update to this entitlement-gated controlled certification-data channel. Public status notices or support messages do not substitute for those routes.
The controlled update contains the exact validated human-readable and JSON report pair in an incident-reports manifest category. The publisher rejects simulations, schema or content failures, altered human/JSON pairs, unsigned manifests, and digest mismatches; it uploads a complete immutable generation before advancing the served pointer. Each delivery retains report digests, UTC timestamps, recipient and channel, method-specific receipt, publication receipt, and served-byte readback.
No FedRAMP Reportable Incident has occurred, so the current manifest truthfully declares that no real incident-report artifact exists. That empty event population does not change the readiness of the documented reporting procedure. The executable procedure is listed in the controlled policy/procedure index and is exercised without sending false live notifications.
Approved reviewers can browse and download certification documents through the Trust Center or its authenticated API. Request access using your official email address, organization, and review purpose. After approval, enter your issued Trust Center access token to view documents, API instructions, and access-management options.
Request access · Sign in to package
Browser and API access use the same Trust Center token. Approved access remains available until expiry or revocation, without another approval for each download. Downloads are logged.
Retrievals through the gov.tarly.co Trust Center are logged by Azure Front Door and summarized in the central security workspace for at least 365 days. Reads of the independent GitHub trust repository are summarized through GitHub's repository traffic statistics, captured on a recurring schedule and archived with the access-evidence set; a capture failure is recorded as an explicit coverage gap. Controlled-bundle retrievals are logged by the interface above to an immutable retrieval log retained for well over six months (database history plus the Locked 400-day evidence archive). If an agency request is denied, Tarly records the reason, notifies FedRAMP through the [CSP] Agency Access Denial form within five business days, and retains the submission receipt.