
Advent Business Company Inc. · UEI C7LGVA7B5JT1 · CAGE 627S4 · 20x Class C (Program path) · impact Moderate
FedRAMP ID: FR2628647239 · Status: Initial Implementation (approved 2026-07-17) · Marketplace listing
This page is the human-readable half of Advent's FedRAMP Certification Data. Everything on it is rendered from the same document served as JSON at the Certification Package Overview, so the two formats cannot disagree (CDS-CSO-CBF). Generated 2026-09-21T07:13:48Z.
| # | Required item | Value |
|---|---|---|
| 1 | FedRAMP ID | FR2628647239 · package id ADVENTBUSINESS-ENB · FedRAMP Marketplace listing |
| 2 | Service Model | SaaS, PaaS |
| 3 | Deployment Model | Government Community Cloud |
| 4 | Business Category | Cybersecurity & Risk Management; Development Tools; Data Management; Artificial Intelligence (AI); System Administration; Mobile Device Management (MDM); Governance, Risk, and Compliance (GRC); Content Management System (CMS); Operations Management; Finance |
| 5 | UEI Number | C7LGVA7B5JT1 · CAGE 627S4 |
| 6 | Sales Contact | sales@adventbusiness.com |
| 7 | Security Contact | fedramp-security@adventbusiness.com · FedRAMP Security Inbox: fedramp-security@adventbusiness.com |
| 8 | Product Website | https://enablement.company |
| 9 | Product Logo | https://enablement.cc/assets/enablement/logo.png |
| 10 | Overall Service Description | See Service description below. |
| 11 | Services and Security Categories | See Certified services below (9 services, each with its security category, plus what is out of scope). |
| 12 | Secure Configuration Guidance | https://enablement.cc/ml/20x/scg |
| 13 | Documentation Overview | See Documentation below (38 document repositories). |
| 14 | Trust Center | https://enablement.cc/ml/20x/trust (this page) · access instructions in Access-controlled data below. |
| 15 | Next Ongoing Certification Report | 2026-10-20 |
| 16 | Independent Assessment Service | SteelToad Consulting LLC (FedRAMP assessor id 203203; internal record id 203203) · Dean Rock (Lead Assessor); Andy Cooper (Assessor) |
Providers MUST demonstrate continuous progress towards a FedRAMP Certification, documented in their Trust Center or website and updated at least quarterly; progress is measured by the provider against documented goals and milestones.
Statement date: 2026-08-11 · updated
at least quarterly · next update due by
2026-11-11.
This is the first statement in this series. Every statement carries its own date and the date the next one is due, so the cadence can be checked from the statements alone.
Enablement is listed in the FedRAMP Marketplace under FedRAMP ID FR2628647239 at the Initial Implementation stage. It is not FedRAMP certified and holds zero FedRAMP authorizations. Nothing in this statement claims otherwise.
The certification being pursued is a FedRAMP 20x Class C Program Certification. No date for obtaining it is promised anywhere on this page, because that decision belongs to FedRAMP, not to Advent.
Advent tracks 45 FedRAMP rules covering certification data sharing, trust center operation, cryptographic module use, minimum assessment scope, and vulnerability detection and response against its own implementation. Current standing: 22 met, 15 partially met, 2 with known gaps, 3 not applicable to this offering, and 3 not currently triggered. These counts are recomputed from the rule-by-rule verdict data every time this page is generated, so they can move between quarterly statements; the dated figures elsewhere in this statement stay as written.
All 46 Key Security Indicators report at least one active automated validation method, and 42 of 46 report two or more. Verified against the daily evidence snapshot of 2026-08-11. Per-indicator evidence is available to agencies and assessors through the access-controlled endpoints listed on this page.
| Goal | How progress is measured |
|---|---|
| Apply to FedRAMP for a FedRAMP 20x Class C certification. | Measured by whether an application has been submitted. As of 2026-09-14 it has not. Under FedRAMP's certification process the provider applies by submitting its Certification Package Overview and Security Decision Record, with trust center access, once the independent assessor has delivered its assessment reports. SteelToad Consulting LLC is carrying out that assessment and has not yet delivered its reports. Advent commits to submitting the application within three months after they arrive. The offering has been listed on the FedRAMP Marketplace as FedRAMP 20x Class C, Initial Implementation, since 2026-07-17. |
| Engage an independent assessment service. | Measured by a signed engagement and a real assessor id in the published package. Reached on 2026-08-25: the package now names SteelToad Consulting LLC, FedRAMP assessor id 203203, replacing the unassigned placeholder this statement originally reported. Engaging the assessor is not the same as being assessed, so the goal that follows it, completing the assessment, is now the item on the critical path. |
| Bring every Key Security Indicator to two or more active automated validation methods. | Measured by the daily evidence snapshots: 42 of 46 as of 2026-08-11. The remaining four are the yardstick for the next statement. |
| Move partially met rules to met and close the known gaps. | Measured by the same rule verdicts summarized above: 15 partially met and 2 with known gaps at page generation. The next statement will report the same counts, so movement, or the lack of it, will be visible. |
| Build the six-month persistent validation history that Class C reporting expects. | Daily snapshots have run since 2026-07-09, so an unbroken six-month record cannot exist before January 2027. The record grows by observation only and is never backfilled. |
| Date | Milestone |
|---|---|
| 2026-07-09 | Daily automated Key Security Indicator evidence snapshots began. |
| 2026-07-17 | FedRAMP Marketplace listing approved at the Initial Implementation stage. |
| 2026-08-25 | Independent assessment service engaged and named in the published package: SteelToad Consulting LLC, FedRAMP assessor id 203203. |
| 2026-08-28 | Assessment team named in the published package: Dean Rock, Lead Assessor, and Andy Cooper, Assessor, both of SteelToad Consulting LLC. |
Sources for the external facts above: FedRAMP Marketplace listing · FedRAMP 2026 timeline · FedRAMP certification process.
Current and 30-day historical availability of core services, including availability incidents: status page (human-readable) · availability report (JSON). Both are public; no token is required.
limitations block in the JSON
for what the measurement does and does not cover.That is why an independent observation exists off this infrastructure: external availability observation (JSON) · mirror landing page. A job in the AWS commercial partition fetches these public URLs every 15 minutes; when it cannot reach them, it publishes that fact — with a first-failure time and a running duration — from infrastructure this outage does not touch. The mirrored copy of the availability report is last-known-good and stamped with when it was taken; the external observation is live.
Enablement®: Own your compliance. Send nothing out. Need no experts, no AI.
Most compliance platforms make you hire specialists, wire in third-party services, and increasingly hand your data to AI you cannot audit. Enablement flips that. It is a self-contained, deterministic, zero-trust platform where your teams build and run everything visually, and nothing ever leaves your boundary.
1. No-code process building. No developers, no AI, no token bills. Business users design complete workflows (BPMN) visually and get web and mobile interfaces generated automatically. No coding, no integration team, no consultants. The engine is deterministic rather than generative: it never hallucinates, never invents an answer, and costs nothing per token. What you design is exactly what runs, the same way every time, fully auditable.
2. Deploy anywhere. True portability. Run Enablement in any commercial cloud, any government cloud, your own data center, or as a fully self-contained appliance. No cloud lock-in, no vendor-specific dependency. Move it, mirror it, or air-gap it.
3. Rapid CMMC Level 2 compliance, with continuous monitoring built in. CMMC Level 2 readiness comes out of the box, backed by native, always-on continuous monitoring. No separate scanning products to buy, license, or integrate. Assess, monitor, and produce authorization evidence from day one, on a single system.
4. A genuine zero-trust boundary. Your data never touches a third party. Your source code lives in its own repository. No data is sent to any outside service for authentication, code analysis, container scanning, file scanning, or continuous monitoring. Nothing is shipped to a SaaS, a scanning vendor, or an AI provider. What happens in your boundary stays in your boundary.
5. Access control and document marking that remove human error. Fine-grained role-based and attribute-based access control (RBAC and ABAC) governs exactly who can see and do what. Documents are marked automatically to federal standards (DoW and NARA). No manual labeling, no inconsistent tags, no mislabeled files. The platform does the marking so people cannot get it wrong.
6. Stop data leaks before they happen. Human error is the number one cause of data spillage. Enablement checks every share and warns before a document reaches unauthorized personnel, catching the mistake at the moment of sharing rather than after a breach. A potential disclosure, and the liability that follows, becomes a blocked action.
7. Every authentication method, and your password never reaches the server. Passkeys, single sign-on (SSO), authenticator apps, email, and more. The password is proven with a challenge-response, so the secret never leaves the user's device; the server stores only a verifier and salt, never the password or any recoverable form of it. Strong, flexible, phishing-resistant sign-in without ever transmitting the credential.
8. One control set, three frameworks. Policies and controls are written once and mapped to FedRAMP 20x Key Security Indicators, CMMC Level 2 practices, and SOC 2 Trust Services Criteria. A Section 508 Accessibility Conformance Report (VPAT 2.5) is available on request. Built by CMMI-appraised, ISO-certified Advent.
Intended agency use. Enablement is intended for both FedRAMP use cases: direct use by agency customers, and indirect use as a third-party information resource inside other cloud service offerings that agencies use directly.
Live evidence: FedRAMP Trust Center · Secure Configuration Guide · enablement.company
| Service | Description | Model | Security category | In Minimum Assessment Scope | Date available |
|---|---|---|---|---|---|
| No-Code Process Designer | The PaaS platform-build layer: business users author complete BPMN processes and applications visually and get web and mobile interfaces generated automatically, with no coding. Customer-authored content is treated as untrusted and runs under server-authoritative tenant binding. Public description capability 1; Secure Configuration Guide §14. | PaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Process Execution Engine | Deterministic server-side execution of published processes — forms, tasks, approvals, and integrations. No generative model is in the execution path, so a process behaves identically on every run and never invents an answer. Public description capability 1. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Mobile Access | Mobile client for the same processes and forms as the web application, with device binding on authenticated sessions. Referenced in the public description as the automatically generated mobile interface. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Identity, Authentication and Access Control | Role-based and attribute-based access control (RBAC/ABAC), user lifecycle, time-boxed privileged grants, and the full authentication range: passkeys, SAML SSO, authenticator apps, and email OTP. The password is proven by challenge-response and is never transmitted to the server. Public description capabilities 5 and 7; Secure Configuration Guide §2–§7. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Secured Files and Secured Email | Encrypted file storage and sharing, secured email, watermarked read-only viewing, and malware scanning of every upload — all inside the boundary, with no file content sent to an external scanning service. Secure Configuration Guide §10.2–§10.5. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Automated Marking and Share-Time Leak Prevention | Automatic CUI and distribution-statement marking to federal standards (DoW and NARA), plus a share-time authorization check that warns or blocks before a document reaches unauthorized personnel. Public description capabilities 5 and 6; Secure Configuration Guide §10.1. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Audit and Activity Monitoring | Tamper-evident audit capture of user and administrative activity with scoped audit-log access for customer administrators, plus execution-pattern anomaly detection and an operator kill switch for a runaway process or account. Secure Configuration Guide §9. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Process Scheduler | Scheduled and recurring execution of published processes, operated inside the boundary with no external scheduler or orchestration service. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-07-17 |
| Continuous Monitoring | Native, always-on continuous monitoring operated entirely within the authorization boundary, covering network vulnerability, container/IaC, cloud-posture, and host configuration/CVE assessment, producing OSCAL + FedRAMP CR26 machine-readable compliance evidence. No data is sent to any external scanning or monitoring service. | SaaS | Moderate (Class C) FIPS 199 system categorization: High System-wide FIPS 199 high-water mark; not separately derived for this service. | Yes MINIMUM_ASSESSMENT_SCOPE.md §2.1-2.3, §2.6 | 2026-04-17 |
dateAvailable is the date the service entered the declared FedRAMP 20x certification scope (Initial Implementation approval, 2026-07-17), not a commercial general-availability date. The platform capabilities predate the FedRAMP effort; their original ship dates are not published here because they are not the dates that matter to this certification.
Every service listed in certifiedServices is inside the FedRAMP Minimum Assessment Scope; servicesNotIncluded names what is outside it. Both lists are public and require no access to underlying FedRAMP Certification Data, which is what this rule requires.
Rule CDS-CSO-SVC · securityCategory, inMinimumAssessmentScope, and serviceModel are additional properties. The pinned FedRAMP CPO schema (fedramp-certification-package-overview-schema-2026-06-24.json) defines no field for a service security category; when it does, these move into it.
| Item | Why it is out of scope | Reference |
|---|---|---|
| Enablement® deployed outside Advent's GovCloud environment | This certification covers exactly one deployment: the Advent-operated multi-tenant instance in AWS GovCloud us-gov-east-1. The public description correctly says the software is portable to any cloud, to a customer data center, or to a self-contained appliance — none of those customer-operated deployments is inside this authorization boundary or covered by this certification. | MINIMUM_ASSESSMENT_SCOPE.md §2.1 |
| Non-production environments (test.enablement.cc) | Physically separate host holding synthetic data only; no federal customer data. Note the CI/CD pipeline that deploys to production runs on that host and IS in scope — the test application environment is not. | MINIMUM_ASSESSMENT_SCOPE.md §4 and §9.1 item 2 |
| Customer-controlled components | Customer premise equipment, customer browsers and devices, the customer's own SSO identity provider, and customer logging systems are outside the provider boundary. The interfaces to them are in scope; the systems themselves are not. | MINIMUM_ASSESSMENT_SCOPE.md §4 |
| Corporate workstations and code-analysis tooling | Developer workstations and source-code analysis tooling process no federal customer data and sit outside the boundary; the development team has no access to production inside the boundary. | MINIMUM_ASSESSMENT_SCOPE.md §4 |
MAS-CSO-TPR · MINIMUM_ASSESSMENT_SCOPE.md §5, reconciled against §9.2. Edit that table, not this structure.
| Resource | FedRAMP status | Use case | Mitigation measures | Compensating controls | Reference |
|---|---|---|---|---|---|
| AWS GovCloud (US) Amazon Web Services | FedRAMP ID F1603047866 https://www.fedramp.gov/marketplace/products/F1603047866/ Class D (formerly High baseline) | Hosts the entire offering. EC2, S3, KMS, IAM, Config, Inspector, Security Hub, GuardDuty, CloudTrail, CloudWatch and networking in us-gov-east-1. | Inherited controls documented in the SSP; platform firewall manager governs subnet ACLs; encryption at rest through KMS and in transit through TLS. All four EBS volumes verified encrypted on 2026-08-07. | US-persons environment. Root account MFA enabled and no IAM user carries console access, so the control plane is reachable only by key-based programmatic call, verified 2026-08-07. | MINIMUM_ASSESSMENT_SCOPE.md §5, §2.1 |
| Amazon SES (commercial, us-east-1) Amazon Web Services | FedRAMP ID AGENCYAMAZONEW https://www.fedramp.gov/marketplace/products/AGENCYAMAZONEW/ Class C (formerly Moderate baseline) | Outbound notification and one-time-passcode delivery. GovCloud cannot call the commercial SES API from inside the boundary, so delivery egresses to the AWS US East/West authorized environment. | SMTP STARTTLS enforced. Message bodies are categorical only: an alert says that something happened, never what, and any detail requires the recipient to authenticate to the platform. | No federal customer data and no file content leaves the boundary by this path. A one-time passcode is single-use and time-boxed, and is not sufficient to authenticate on its own. | MINIMUM_ASSESSMENT_SCOPE.md §5, §9.2 svc-ses-email |
| Amazon Route 53 (commercial account) Amazon Web Services | Not FedRAMP certified | Authoritative DNS for enablement.cc. Route 53 is not available in GovCloud, so the zone is hosted in the commercial account. DNS carries no customer data. | DNSSEC signing is enabled on the enablement.cc hosted zone (ServeSignature SIGNING, verified 2026-08-07), which supersedes the 'not enabled' entry at §9.2 svc-route53-dnssec. Zone changes are restricted to key-based programmatic access; the account has no console-enabled IAM user and root MFA is enabled. | A failover DNS flip is a documented manual recovery step rather than an automatic one, so a zone change is a deliberate operator action. Certificates are issued and renewed by Let's Encrypt through certbot on the host, so a DNS compromise alone does not yield a trusted certificate. | MINIMUM_ASSESSMENT_SCOPE.md §5, §9.2 svc-route53-dnssec |
| Vendor definition and threat-intelligence feeds Greenbone Community Feed, ClamAV signature mirrors, Trivy vulnerability database, CISA Known Exploited Vulnerabilities catalog | Not FedRAMP certified | Scanner, anti-virus and vulnerability-prioritization content updates. Required for detection efficacy; without them the continuous-monitoring capability degrades silently. | Pull-only over HTTPS 443. Nothing is pushed outward and no feed provider is granted inbound access. Content is digitally signed and validated before install. | Feeds carry detection content, never customer data. A poisoned feed degrades detection rather than granting access, and feed staleness is itself monitored. | MINIMUM_ASSESSMENT_SCOPE.md §5 |
certified[] carries the schema-required fedRampCertifiedThirdPartyInformationResource (the FedRAMP ID) and useCase. mitigationMeasures, compensatingControls, name, provider, fedRampClass, marketplaceUrl and reference are additional properties. MAS-CSO-TPR requires the mitigation and compensating-control attributes, and the pinned FedRAMP CPO schema (fedramp-certification-package-overview-schema-2026-06-24.json) defines no field for either; when it does, these move into it. This is the same pattern used for securityCategory under certifiedServicesNote.
| Basis | FIPS 199 high-water mark across the 13 NIST SP 800-60 information types the platform handles (Personal Identity & Authentication rated High/High/High is the driver), per SSP §3 Table 3.1 and Appendix K Table K.1. Digital identity level IAL2/AAL2/FAL2, with IAL3/AAL3/FAL3 supported where an agency requires it. |
|---|---|
| Reconciliation | Two categorizations are in force at once and both are accurate. The Rev5 authorization package of record categorises the system FIPS 199 High. The FedRAMP 20x certification being pursued is Class C, which corresponds to Moderate impact; that declaration was made by the System Owner on 2026-07-10 and is tracked as an open, deliberate reconciliation item. Class D (the 20x High path) is the intended upgrade when FedRAMP opens it, estimated 2027. A prospective customer should read this as: the system is built and assessed to a High water mark, and the certification currently being sought is Class C / Moderate. |
| Per-service categorization | NOT declared per service. Every service below handles the same federal customer data inside one authorization boundary, on the same in-scope components, so the system-level high-water mark applies uniformly. No service carries a separately derived C/I/A triad, and none is invented here to fill the column. |
| Authority | MINIMUM_ASSESSMENT_SCOPE.md §3 (information flows and security categories) and §9.1 item 8 (Class C declaration). Available token-gated at https://enablement.cc/ml/20x/doc/mas. |
KSI evidence reports, the Security Decision Record, vulnerability artifacts (VDR/AVI/historical), Ongoing Certification Reports, and the assessment documents are shared with federal agencies, FedRAMP, and assessors over bearer-token API access with per-access logging (CDS-TRC-USH / PAC / AAI).
How to get access: email
fedramp-security@adventbusiness.com identifying your agency or
assessment organization and what you need. Advent issues a bearer token
out-of-band. Then send Authorization: Bearer <token> to any
endpoint below. Requests without a token return HTTP 401 with these same
instructions in the response body; they do not fail silently.
| Endpoint | Repository type | Contents | Access |
|---|---|---|---|
| https://enablement.cc/ml/20x/vdr?src_id=1711 | Machine-Readable Authorization Data | Vulnerability Detail Report (VER-RPT-VDT) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/avi?src_id=1711 | Machine-Readable Authorization Data | Accepted Vulnerability Info (VER-RPT-AVI) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/historical?src_id=1711 | Machine-Readable Authorization Data | Historical VER activity for automated retrieval (VER-TFR-MRH) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/ocr?src_id=1711 | Machine-Readable Authorization Data | Ongoing Certification Report (CCM-OCR-AVL) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/sdr?src_id=1711 | Machine-Readable Authorization Data | Security Decision Record (SDR-CSO-FRR) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/ksi?src_id=1711 | Machine-Readable Authorization Data | KSI evidence report (FRC-CSX-VVK / FRC-CSX-MOT) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/sdr.html?src_id=1711 | Human-Readable Authorization Data | Security Decision Record, human-readable page rendered from the same document as the JSON Security Decision Record (SDR-CSO-FRR, CDS-CSO-CBF) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| Endpoint | Repository type | Document | Access |
|---|---|---|---|
| https://enablement.cc/ml/20x/doc/cds-procedures | Assessment Documentation | How a FedRAMP Certification Report is received and published unmodified, how an agency access denial is decided, recorded and notified to FedRAMP, the reference to relevant policies and procedures, and the historical certification data snapshot taken at each Ongoing Certification Report | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/fedramp-security-inbox | Assessment Documentation | The designated FedRAMP Security Inbox and how it is operated: the address and its hosting, dual monitoring and forwarding, automatic acknowledgment, the per-designator handling matrix with the Class C reaction deadline, escalation to the senior security official, the default-trust rule for @fedramp.gov/@gsa.gov with its anti-phishing verification step, address-change notification duties, and a rule-by-rule compliance mapping of all 16 AFC rules | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/iec-runbook | Assessment Documentation | How an incident is evaluated, reported and communicated, including federal notification timeframes | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/ksi-self-assessment | Assessment Documentation | 46 Class C KSIs with implementation, evidence pointers, and self-verdicts (IVV Verify-step input) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/mas | Assessment Documentation | The information resources assessed for FedRAMP Certification, their flows and security categories, exclusions, third-party resources and metadata | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-access-control | Assessment Documentation | How access to the offering is authorized, resolved and revoked: the user-group-role-authorization chain, tenant scoping, time-boxed privileged grants, and the limitations stated rather than omitted | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-access-review | Assessment Documentation | The periodic review that confirms every account, grant, and non-person identity on the offering is still authorized: what is reviewed, on what cadence, by whom, the signed record each review produces, and the clock on fixing what the review finds. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-asset-management | Assessment Documentation | What counts as an asset of the Enablement offering, which inventory is the record for each asset class, how assets enter and leave service, and which inventory claims Advent does not make. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-audit-logging | Assessment Documentation | What is logged, where it is retained and for how long, how it is reviewed, and where automated review is real rather than asserted | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-breach-notification | Assessment Documentation | The personal-data branch of incident response: when a security incident is also a personal-data breach, who assesses it, who gets told and on what clock, what the notification says, and what record survives. An annex to the Incident Response Policy, which continues to govern detection, containment and recovery. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-change-management | Assessment Documentation | How changes reach production, which configuration-management procedure governs, and the second-approver position stated as a deviation rather than implied | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-code-of-conduct | Assessment Documentation | The ethical commitments and rules of behavior binding every person who operates or accesses the Enablement® cloud service offering: evidence honesty, acceptable use of production access, remote-work obligations, and how acknowledgment is recorded. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-contingency | Assessment Documentation | Backup siting and encryption, recovery verification, the trust-centre availability position and its stated monthly target | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-continuous-monitoring | Assessment Documentation | How Advent continuously monitors the Enablement platform: what is scanned and by which tool, on what schedule, against which deadlines and freshness thresholds, how results reach customers and assessors, and how exceptions, known exploited vulnerabilities, and risk acceptances are decided and escalated. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-cryptography | Assessment Documentation | Which cryptography the platform uses and where, key custody and rotation including the AWS-managed key position, and the plaintext master-seed exception stated explicitly | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-cui-marking | Assessment Documentation | How CUI is identified when it arrives or is created in a tenant, what marking the platform actually affixes to the file bytes, how marked content behaves on sharing and email, the handling rules that follow from the classification level, what decontrol means for a service that designates nothing, and the precise boundary of what marking evidence proves. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-data-classification | Assessment Documentation | The classification levels for data held in or about the Enablement offering, the handling rule set for each level, the CUI/FCI position, and the honest state of marking enforcement. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-data-retention | Assessment Documentation | One retention schedule for every record class the Enablement offering holds, the disposal mechanism for each, the tenant-exit path, and the enforcement state stated honestly per class. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-data-subject-request | Assessment Documentation | How a request to access, correct, delete, port, object to or restrict personal information is received, verified, located, fulfilled and recorded, including which requests Advent answers itself and which belong to the customer as controller. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-incident-response | Assessment Documentation | Incident evaluation, PAIN rating, notification timelines and recipients, and the per-tenant agency contact register that supplies the addresses | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-index | Assessment Documentation | The human- and machine-readable policy reference CDS-CSO-IRP requires: one row per policy carrying name, file, summary, word count, version, date and related FedRAMP practices, plus the policy-to-control-family and policy-to-implementing-system maps | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-information-security | Assessment Documentation | The umbrella policy over Advent's security program for the Enablement® cloud service offering: management's commitment and intent, the fifteen subordinate policies that implement the program, who owns them, how they are reviewed, and the path an exception must take. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-kev-remediation | Assessment Documentation | The step by step handling of a CISA Known Exploited Vulnerability at Advent, from the daily catalog pull that flags it, through selection into the KEV tracker, the test first workflow with a second reviewer gate before production, the deadline that governs it, and the deploy gate that blocks a test image built with a KEV in it. Closes catalog row 29. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-media-sanitization | Assessment Documentation | Every class of media the offering touches, the NIST SP 800-88 category applied to each, the sanitization method, the verification step, and the record produced. Written for a service that owns no physical device: Advent's method is cryptographic erasure, and physical destruction is inherited from AWS GovCloud. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-personnel-governance | Assessment Documentation | Who holds authority, how governance records are produced and signed, the co-signature class introduced 2026-08-10, and the screening non-applicability with its stated trigger | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-personnel-screening | Assessment Documentation | What must happen before any new person (employee, contractor, or subcontractor) is granted access to the offering, the checklist that grants it, the checklist that removes it, and the record each step leaves behind. Closes the commitment in Personnel Security and Governance Policy §6 and `policies/INDEX.md` §6.1 decision 14. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-physical-environmental | Assessment Documentation | The formal statement that every physical facility hosting the offering belongs to AWS GovCloud, which physical and environmental controls are inherited under AWS's attestations, what Advent must operate on its own side for the inheritance to hold, and the remote-workstation residual that inheritance cannot cover. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-privacy-notice | Assessment Documentation | The notice a person reads before using the Enablement platform: what personal information the service collects, why, on what basis, how long it is kept, who receives it, and how to exercise a right over it. Written to the content list that GDPR Articles 13 and 14 and the CCPA notice at collection require, and stated against what the platform does today. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-risk-assessment | Assessment Documentation | How Advent assesses risk to the Enablement® offering: the declared objectives risk is measured against, the continuous IRV/LEV/PAIN methodology for the vulnerability class, the signed annual entity-level reviews, how fraud and change risk are considered, and how controls are selected and gaps recorded. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-scan-configuration | Assessment Documentation | Advent's actual scanning configuration for the Enablement platform as held in the platform's scan configuration record for the assessment tenant: what is targeted, from which vantage, with which credentials, on what schedule, with what exclusions, and in what validation and synchronization state, together with the scanner families whose cadence lives outside that record. A record of configured fact, not a policy statement. Closes catalog row 56. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-security-awareness-training | Assessment Documentation | The procedure behind Advent's training records: who is trained on the Enablement® offering, the three-area curriculum with role-based tracks, the annual and quarterly cadence, the on-grant trigger for new access, how completion becomes a signed governance record, and what happens on lapse. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-system-maintenance | Assessment Documentation | What maintenance is for a cloud service that owns no hardware: the five maintenance classes, what triggers each and by when, the windows and notification path, how a remote maintenance session is established and ended, how maintenance tooling is checked, who performs the work, and the records left behind. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-vendor-risk | Assessment Documentation | How Advent inventories, tiers, assesses and reviews the third parties the Enablement offering depends on, and what happens when one is retired. Written to close the 'documented inventory but no periodic vendor review' limitation stated in the Personnel Security and Governance Policy section 8, and to give SOC 2 TSC CC9.2 a named artifact. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-vulnerability-exception-review | Assessment Documentation | How a finding that will not be remediated inside its response deadline is reviewed, classified, decided, signed, recorded and re-reviewed at Advent: the evaluation model that decides what a person even sees, the review workflow and its single writer, the four decision classes and the artifact each produces, the two signature requirement, and the clocks that make an acceptance temporary rather than permanent. Closes catalog row 30. | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/policy-vulnerability-management | Assessment Documentation | Detection coverage and cadence, response deadlines by PAIN rating, acceptance and deviation handling, and the KEV gate position | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/doc/scn-process | Assessment Documentation | How a change is classified and notified: the routine, adaptive, transformative and certification-class flow and its notification timelines | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/docs | Assessment Documentation, Evidence Repository | Assessment document index + supporting evidence records (SSP appendices, signed records, boundary diagrams) | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| https://enablement.cc/ml/20x/access-log-summary | Assessment Documentation | Trust-center access-log summary + retention statement (CDS-TRC-ACL) — monthly access counts by endpoint and outcome, so an assessor can verify access logging without a database account | Token Request tenant-scoped API access from fedramp-security@adventbusiness.com. |
| Endpoint | Repository type | Contents | Access |
|---|---|---|---|
| https://enablement.cc/ml/20x/availability | Availability Reporting | Availability report (CDS-CSO-AVR): current state and 30-day historical availability of core services with availability incidents, machine-readable. Public, no token required. | Public No request needed. |
| https://enablement.cc/ml/20x/status | Availability Reporting | Public availability status service (CDS-CSO-AVR): current state, 30-day history, and availability incidents. Machine-readable JSON at https://enablement.cc/ml/20x/availability. This endpoint is hosted on the infrastructure it measures and therefore cannot report an outage it is part of; the off-CSO mirror below can, and does. Availability status page (CDS-CSO-AVR), human-readable rendering of the same data. Public, no token required. The independent-hosting arm of CDS-CSO-AVR. The mirror's refresher is itself an external probe running in the AWS commercial partition: every 15 minutes it records whether this offering answered, and when it did not, it publishes that — with a first-failure time and a running duration — from infrastructure the outage does not touch. The mirrored copy of the availability report is last-known-good and stamped; the external observation is live. https://trust.enablement.cc/index.html | Public No request needed. |
| https://enablement.cc/ml/20x/trust | Trust Center | Enablement FedRAMP Trust Center: public offering summary and SCG; token-gated programmatic access to certification artifacts with per-access logging (CDS-TRC-USH/PAC/AAI). Point-in-time copy of the PUBLIC trust-center artifacts (this CPO, the trust page, the SCG, and both availability formats), refreshed every 15 minutes into the AWS commercial partition (a separate account, us-east-1) and served from S3 via CloudFront. It shares no partition, account, region, host, database, web server, TLS certificate or DNS zone with production, so it stays reachable during an outage of this offering. It is not authoritative: each artifact is stamped with mirroredAt in https://trust.enablement.cc/mirror-manifest.json, and the live endpoints take precedence whenever they answer. No token-gated certification data is mirrored. https://trust.enablement.cc | Public Public page. Tokens for access-controlled artifacts: fedramp-security@adventbusiness.com |
| https://enablement.cc/ml/20x/scg | Secure Configuration Guidance | Enablement® Secure Configuration Guide — recommended secure configuration, use instructions, and secure defaults for customer administrators. | Public No request needed. |
| authoritative | False |
|---|---|
| availability | https://trust.enablement.cc/availability.json |
| base | https://trust.enablement.cc |
| mirrorExternalObservation | https://trust.enablement.cc/mirror-availability.json |
| mirrorExternalObservationHistory | https://trust.enablement.cc/external-probe-history.json |
| mirrorManifest | https://trust.enablement.cc/mirror-manifest.json |
| note | Point-in-time copies, not the live endpoints. Read mirroredAt in mirrorManifest before relying on any of them. Rules served: CDS-TRC-USH, CDS-CSO-UTC, and the independent-hosting arm of CDS-CSO-AVR. |
| package | https://trust.enablement.cc/package.json |
| refreshIntervalMinutes | 15 |
| scg | https://trust.enablement.cc/scg.md |
| status | https://trust.enablement.cc/status.html |
| trust | https://trust.enablement.cc/trust.html |
| Resource | Provider | Use |
|---|---|---|
| Amazon Route 53 (commercial account) | Amazon Web Services | Authoritative DNS for enablement.cc. Route 53 is not available in GovCloud, so the zone is hosted in the commercial account. DNS carries no customer data. |
| Vendor definition and threat-intelligence feeds | Greenbone Community Feed, ClamAV signature mirrors, Trivy vulnerability database, CISA Known Exploited Vulnerabilities catalog | Scanner, anti-virus and vulnerability-prioritization content updates. Required for detection efficacy; without them the continuous-monitoring capability degrades silently. |
| Machine-readable | Human-readable | Rendered by |
|---|---|---|
| https://enablement.cc/ml/20x/package?src_id=1711 | https://enablement.cc/ml/20x/trust | The trust center page, rendered from this Certification Package Overview at request time |
| https://enablement.cc/ml/20x/availability | https://enablement.cc/ml/20x/status | The status page, rendered from the availability report at request time |
https://enablement.cc/ml/20x/scn/<yyyy>/<change-id>/scn-<milestone>.json | https://enablement.cc/ml/20x/scn/<yyyy>/<change-id>/scn-<milestone>.html | Each notification page, rendered from that notification's JSON record at request time index: https://enablement.cc/ml/20x/scn Token-gated (CDS-CSO-RIS). One pair for each published Significant Change Notification, all of them listed at the index. |
| https://enablement.cc/ml/20x/sdr?src_id=1711 | https://enablement.cc/ml/20x/sdr.html?src_id=1711 | The Security Decision Record page, rendered from the same Security Decision Record at request time Token-gated (CDS-CSO-RIS), like the JSON Security Decision Record. |
| How staleness is prevented | Structurally, not procedurally. Each human-readable page is RENDERED FROM the machine-readable document at request time and is handed no other source of facts — no database handle, no second query, no cached copy. A stale HTML rendering is therefore not a state this service can be in. |
|---|---|
| How omission is prevented | Single-sourcing stops the page contradicting the JSON; it does not stop the page omitting part of it, which is the failure that actually occurred when availability endpoints were added to the document after the HTML tables were written. An automated comparison walks every value in each JSON document and confirms it reached the page, so a new field must be either rendered or added to a named exemption list carrying its reason. |
| Verify it yourself | Fetch both formats and compare them yourself. The provider's release checks fail on any divergence, and its automated tests re-run the comparison across an outage, a measurement gap, a partial day, a single-endpoint window and an empty log. |
| What this check does not do | For the trust and status pages it runs at release time, not on every request, so it gates a release rather than a response. For Significant Change Notifications and the Security Decision Record it also runs on every request, and a page that would leave out a value is withheld: notifications are written by hand and can be published without a release, and the Security Decision Record carries live evidence that changes between releases. It compares values one way (every JSON scalar must appear in the HTML); the reverse needs no check because the page has no other source. Booleans and nulls are matched by field rather than by literal, since a page renders them as words. |
| What is logged | Every access to every /20x/* endpoint, public and token-gated alike, is recorded with endpoint, outcome, client IP, and timestamp. |
|---|---|
| Retention policy | Advent retains trust-center access summaries for at least 24 months from the date of access, which exceeds the 6-month CDS-TRC-ACL floor. Records are never purged earlier for convenience, capacity, or at a consumer's request. |
| Enforcement status | Stated policy, not yet machine-enforced at write time. No purge job, TTL, scheduled event, or partition-drop targets the trust-center access log, so records currently accumulate indefinitely — retention is achieved by the absence of deletion rather than by an enforced retention job. The log began on 2026-07-11, so a full 6-month retention period has not yet elapsed and cannot yet be demonstrated by observation. What IS enforced is DETECTION: every /20x/access-log-summary response recomputes a retentionIntegrity verdict that compares the oldest surviving record against the code-pinned table-creation watermark and against the six-month floor, and reports BREACH if a record that must still exist has gone. See retentionIntegrity and the retentionDemonstrated flag in /20x/access-log-summary for the live answer rather than trusting this sentence. |
| Access summary | https://enablement.cc/ml/20x/access-log-summary (token-gated) |
| Responsible official | Rajesh Gupta · President, System Owner and ISSO, Advent Business Company Inc. · rajesh@adventbusiness.com |
|---|---|
| Version | 1.0.0+8459cf56 |
| Last updated | 2026-09-16T01:17:06Z |
| Source of update | Generated at request time by the deployed certification-data service; content changes reach it only through the automated build and deployment pipeline under Advent's change management procedure. |
| Security | Security Team · fedramp-security@adventbusiness.com |
|---|---|
| Sales | Sales Team · sales@adventbusiness.com |
| Support | Support Team · support@adventbusiness.com |
| FedRAMP Security Inbox | FedRAMP Security Inbox (AFC-CSO-INB) · fedramp-security@adventbusiness.com |
| Ongoing Certification Report Feedback | Ongoing Certification Report feedback (CCM-OCR-FBM) · fedramp-security@adventbusiness.com |
| Website | https://enablement.company |
Every rule below carries one command you can run, and the public ones need no credential at all. An index nobody can find is no better than the `ssh` commands it replaced, so it is linked here and served without a token: https://enablement.cc/ml/20x/verify · one rule: https://enablement.cc/ml/20x/verify?rule=CDS-CSO-AVR. It also publishes what it does not yet cover.
CCM-OCR-FBM. The human-readable half of the mechanism the Certification Package Overview publishes; both render from one definition, so they cannot disagree.
| How | Email, asynchronous, monitored during US business days |
|---|---|
| Where | fedramp-security@adventbusiness.com |
| What to expect | Send feedback or questions about any Ongoing Certification Report to this address, naming the report period. Receipt is acknowledged automatically, and a substantive answer is sent within 5 US business days. No account, portal registration or CAPTCHA is required, and no token is needed to use this channel. |
| Acknowledgement | Automatic on receipt (AFC-CSO-ACK mechanism, shared). |
| Open to | All necessary parties: FedRAMP, agency customers, prospective agency customers and their assessors. |
| Where answers are published | An anonymized, desensitized summary of feedback, questions and answers is published as an addendum to the report it concerns, or in the next Ongoing Certification Report, whichever comes first (CCM-OCR-AFS). |
Schema pin 2026-06-24 (synced 2026-09-04) · rules 2026.07.01.01 · page generated 2026-09-21T07:13:48Z.