VirtualDojo Trust Center
FedRAMP 20x, Certification Class C

VirtualDojo AI CRM Trust Center

Authorization data, security posture, and continuous-monitoring evidence for the VirtualDojo AI CRM, published for federal agencies and FedRAMP under the Consolidated Rules for 2026.

Initial Implementation Phase, pursuing FedRAMP 20x Certification (Class C) Program (no agency sponsor) Impact level: Moderate
FedRAMP ID
FR2615441197
Service model
SaaS
Deployment
Public Cloud
Next Certification Report
2026-10-02

Compliance & certifications

status is reported honestly, pursuing, not yet certified
FedRAMP 20x Certification (Class C)
In Progress
Program path; Consolidated Rules for 2026
SOC 2 (Security / Common Criteria)
In Progress
Type II, Security scope; independent CPA examination

The FedRAMP 20x Key Security Indicators are derived from the NIST SP 800-53 Rev 5 Moderate baseline. This reflects the scope of an in-progress FedRAMP Certification and is not itself a separate certification.

Cloud service offering

Public information
Offering
VirtualDojo AI CRM
Provider
VirtualDojo, Inc.
UEI
JZCAH18DEDC8
CAGE
142E1
Category
Customer Relationship Management
Website
https://virtualdojo.com

VirtualDojo AI CRM is a cloud-based customer relationship management platform with AI-powered proposal generation, contact management, pipeline forecasting, and document automation. The platform is designed for government contractors and federal agencies managing procurement workflows, storing Controlled Unclassified Information (CUI) including government contract data, customer PII, proposal documents, and financial/pricing data.

Security contact
Devin Henderson · devin@virtualdojo.com
Sales contact
Cyrus Calloway · cyrus@virtualdojo.com
Assessor
Anthony Timbers LLC · FedRAMP-recognized 3PAO (#203181)

Services & security categories

Services in the FedRAMP assessment scope
ServiceConfidentialityIntegrityAvailabilityIn scope
Contact & Account Management
CRM contact records, account hierarchies, activity tracking
Moderate Moderate Moderate Yes
AI Proposal Generation
AI-powered proposal drafting using Google Vertex AI
Moderate Moderate Low Yes
Pipeline & Forecasting
Sales pipeline management, revenue forecasting, analytics
Moderate Moderate Low Yes
Document Management
Proposal documents, quotes, attachments stored in GCS
Moderate Moderate Moderate Yes
Tenant Administration
Multi-tenant provisioning, user management, RBAC
Moderate High Moderate Yes

Security & availability

continuous monitoring

Continuous control monitoring

46 Key Security Indicators continuously monitored · last validated 2026-08-27

Service availability

100.0%rolling 30-day, measured
30 days agoToday

Measured by Google Cloud uptime checks (5-minute interval) on app.virtualdojo.com. Machine-readable in public_info.json.

Privacy & data

data protection & residency
Privacy Policy
Privacy Policy
Impact level
Moderate (CUI)

Data residency

All customer data stays in the United States, inside the Google Cloud Assured Workloads FedRAMP Moderate boundary.

us-central1
Iowa · Primary region
Cloud Run compute, most Vertex AI inference, the AlloyDB primary, Memorystore Redis, Secret Manager, and the primary application services. All encrypted with customer-managed keys (CMEK).
us (multi-region)
United States · Storage and batch AI
Durable object storage (Cloud Storage US multi-region) and the CUI-classifier batch jobs on Vertex AI via the US REP endpoint. The location org policy allows us and denies global. CMEK encrypted.
us-east4
Virginia · Disaster recovery
AlloyDB cross-region CMEK backups (every 4 hours, 35-day retention) and Cloud Storage file replication. Recovery objectives RTO 12h / RPO 4h.

* All customer data is stored and processed only in the United States, on Google Cloud under Assured Workloads (policy DATA_BOUNDARY_FOR_FEDRAMP_MODERATE, which Google enforces so resources cannot be created outside the FedRAMP Moderate US region set; the policy denies non-US and global locations). Compute and most AI inference run in us-central1 (Iowa); the CUI-classifier batch jobs run on Vertex AI in the US multi-region; durable object storage uses the US multi-region; and disaster-recovery backups replicate to us-east4 (Virginia). All of these are US locations inside the same FedRAMP Moderate Assured Workloads enclave, so data never leaves the US authorization boundary. Every copy is encrypted with customer-managed keys (CMEK) that VirtualDojo controls.

Subprocessors

third parties in the data path
SubprocessorPurposeData handledLocation
Google Cloud PlatformApplication hosting, storage, database, AI/ML (Vertex AI)In-boundary CUI (contract data, PII, documents)US us-central1 (Assured Workloads)
MicrosoftIdentity (Entra ID), endpoint management (Intune), productivity (M365)Administrator identities and device postureUS M365 GCC / Azure
SendGrid (Twilio)Transactional email deliverySystem notifications only no CUIUS
StripeSubscription payment processingBilling metadata only (plan, tenant ID) no CUI/PIIUS
GitHubSource code management and CI/CDSource code no customer dataUS

Documentation

Public documents; detailed procedures available to agencies
DocumentSummaryAccess
Secure Configuration GuideHow to securely configure and operate the service View →
Data Retention ScheduleRetention periods by data type Agencies
Contingency & Disaster Recovery ProceduresBackup, recovery, and contingency testing Agencies
Operational Security ProceduresDetection, response, and operational controls Agencies
Personnel Security ProceduresScreening, onboarding, and access management Agencies
Supply Chain Risk Management PlanThird-party and supply-chain risk controls Agencies
Incident Response ProceduresIncident detection, response, and reporting (dissemination controls preclude portal delivery; supplied directly to agencies) Agencies
Privacy Impact AssessmentPrivacy analysis of data handling (dissemination controls preclude portal delivery; supplied directly to agencies) Agencies
Risk & Vulnerability Management ProceduresVulnerability detection, evaluation, and remediation SLAs (dissemination controls preclude portal delivery) Agencies
Continuous Monitoring SOPOngoing security-monitoring program (CUI marking review in progress; supplied directly to agencies meanwhile) Agencies
FedRAMP Certification Package (CPO · SDR · OCR)Full authorization package (human-readable + machine-readable JSON at /reports) Agencies

Frequently asked questions

security due diligence
Where is my data stored?
All customer data is stored and processed within the United States in Google Cloud under Assured Workloads (DATA_BOUNDARY_FOR_FEDRAMP_MODERATE). The primary region is us-central1 and disaster-recovery backups are replicated to us-east4; both are inside the same FedRAMP Moderate Assured Workloads enclave, so data never leaves the US boundary. All copies are encrypted with customer-managed keys (CMEK).
How is data encrypted?
Data is encrypted at rest with customer-managed encryption keys (CMEK) in Google Cloud KMS, and in transit with TLS 1.2+. Cryptography uses FIPS 140-validated modules.
What compliance frameworks do you follow?
VirtualDojo is pursuing FedRAMP 20x Certification (Class C) and a SOC 2 (Security) examination. The service is built on Google Cloud and Microsoft services that hold FedRAMP authorizations. Current status is shown on this page.
Is VirtualDojo FedRAMP High or Moderate?
VirtualDojo AI CRM is being built and assessed to the FedRAMP Moderate baseline through FedRAMP 20x Certification Class C, the applicable Certification Class for the Controlled Unclassified Information this service handles. The service runs on Google Cloud under the Assured Workloads FedRAMP Moderate data boundary and leverages Google Cloud's FedRAMP Moderate authorization for its infrastructure controls; VirtualDojo AI CRM itself has not yet completed FedRAMP Certification. Google Cloud also offers a FedRAMP High regime; VirtualDojo uses the Moderate boundary, so we describe our environment as Moderate rather than High.
Who are your subprocessors?
Google Cloud, Microsoft, SendGrid, Stripe, and GitHub. Each subprocessor, its purpose, the data it handles, and its location are listed in the Subprocessors section above.
How do you control access?
Access requires multi-factor authentication and Conditional Access via Microsoft Entra ID, enforces role-based access control and least privilege, and is continuously monitored by the automated KSI validator.
How do you handle security incidents?
VirtualDojo maintains documented incident-response procedures with continuous monitoring and defined notification timelines. Suspected incidents can be reported to security@virtualdojo.com.
How is availability monitored?
Service availability is measured by a Google Cloud uptime check on app.virtualdojo.com, and 46 Key Security Indicators are validated nightly in-boundary. A rolling availability percentage publishes on this page as monitoring history accrues.
What data does the service handle?
The service handles Controlled Unclassified Information (CUI) including government contract data, customer PII, proposal documents, and pricing data, at the FedRAMP Moderate impact level.
How can a federal agency access the full certification package?
The Certification Package (Certification Package Overview, Security Decision Record, and Ongoing Certification Reports) is available through authenticated self-service access at trust.virtualdojo.com/request-access federal (.gov/.mil) requesters are granted access automatically; other requests are reviewed under NDA. After signing in, human-readable report pages and the machine-readable JSON are both available under /reports.

Continuous progress toward certification

Updated quarterly
Marketplace listing, Initial Implementation Phase
Public trust center live; offering listed as in-progress
2026
Automated KSI validation in production
46 Key Security Indicators, 2 or more automated methods each (Class C); running nightly in-boundary
Live
Independent assessment (3PAO)
Fresh independent assessment by Anthony Timbers LLC, current step
In progress
FedRAMP Certification application
Certification Package (CPO, SDR, OCR) submitted to FedRAMP
Planned
FedRAMP review and Certification decision
FedRAMP evaluates the Certification Package and, if accepted, grants FedRAMP Certified status
Planned
Ongoing Certification and continuous monitoring
Quarterly Ongoing Certification Reports and nightly KSI monitoring; periodic reassessment to renew the certification
Planned

Leveraged authorizations

underlying FedRAMP-authorized providers
Provider & serviceFedRAMP IDImpactType
Google Cloud Platform · GCP Assured Workloads, including Vertex AI in-boundary (us-central1 for interactive inference; us multi-region via US REP endpoint for CUI-classifier batch jobs; org policy denies global)FR1805580474ModerateJAB P-ATO
Microsoft · Microsoft 365 GCCMSO365MTModerateAgency ATO
Microsoft · Azure Commercial Cloud (EMS for GCC)F1209051525HighJAB P-ATO

Access to certification data

For agencies, FedRAMP & customers

Public information above is open to everyone. The full FedRAMP Certification Package (Certification Package Overview, Security Decision Record, Ongoing Certification Reports) and the validation run reports are available through authenticated, self-service access.

Federal agency and FedRAMP personnel with a .gov or .mil email are provisioned automatically. Customers and prospective customers are reviewed by the security team (a non-disclosure or customer agreement must be on file). Every document is available as a human-readable page and as machine-readable JSON; all access is logged.

Log in  Request access →