OneVizion GovCloud Security and Authorization Information
This page provides public security and authorization information for the OneVizion GovCloud environment supporting OneVizion’s FedRAMP authorization activities.
Scope Notice: The information on this page applies only to the OneVizion GovCloud environment within the FedRAMP authorization boundary. It does not describe, represent, or make commitments regarding OneVizion commercial cloud environments, commercial customer deployments, or non-FedRAMP services.
Last Updated: [June 18, 2026] Page Version: [v1.0]
1. System Name and Description
OneVizion GovCloud Platform
The OneVizion GovCloud Platform is a cloud-based software-as-a-service environment designed to support federal and government-oriented customer use cases. The platform provides configurable workflow, data management, reporting, and operational management capabilities through a managed application environment.
The GovCloud environment is operated separately from OneVizion’s commercial cloud environments and is designed to support OneVizion’s FedRAMP authorization activities
2. Authorization Boundary Summary
The OneVizion GovCloud authorization boundary includes the systems, services, infrastructure, applications, personnel processes, and operational controls used to deliver the OneVizion GovCloud Platform.
The authorization boundary is hosted in a U.S. government cloud environment and includes the production application environment, supporting infrastructure, security monitoring capabilities, deployment mechanisms, administrative access controls, and operational processes required to operate the OneVizion GovCloud Platform.
Sensitive infrastructure details, security tooling, vendor names, internal network architecture, and implementation-specific configurations are not published on this public page. Additional details may be made available to authorized assessors, sponsoring agencies, and government stakeholders through controlled channels.
.
3. Service Offering Description
The OneVizion GovCloud Platform provides a managed SaaS environment that supports configurable business workflows, data-driven operational processes, reporting, and collaboration for authorized users.
Core capabilities may include:
- Configurable workflow and process management
- Structured data management
- Role-based user access
- Reporting and dashboards
- Document and record management
- Integration support, where authorized
- Administrative configuration capabilities
- Operational audit and activity tracking
The specific capabilities available to a customer may vary based on contract scope, configuration, and authorized use.
4. Data Types Handled
The OneVizion GovCloud Platform may process, store, or transmit customer-provided data associated with authorized government use cases.
Depending on customer authorization and configuration, data types may include:
- Federal customer operational data
- Business process and workflow data
- User account and access information
- System activity and audit records
- Customer-managed documents and records
- Controlled Unclassified Information, where contractually authorized and appropriately configured
OneVizion does not publish customer-specific data descriptions, tenant-specific configurations, or sensitive data handling details on this public page.
Customers are responsible for ensuring that data placed into the platform is consistent with their contract, authorization, configuration, and applicable laws, regulations, and agency requirements.
5. Customer Responsibilities
Security of the OneVizion GovCloud Platform follows a shared responsibility model. OneVizion is responsible for operating and securing the FedRAMP authorization boundary under OneVizion’s control. Customers are responsible for their own users, data, configurations, and use of the platform.
OneVizion Responsibilities
OneVizion is responsible for:
- Operating and maintaining the GovCloud platform environment
- Implementing system-level security controls within the authorization boundary
- Managing platform infrastructure and application operations
- Monitoring the environment for security-relevant events
- Maintaining vulnerability management and remediation processes
- Performing incident response activities for the platform
- Managing administrative access to the GovCloud environment
- Maintaining FedRAMP authorization evidence and continuous monitoring artifacts
Customer Responsibilities
Customers are responsible for:
- Managing their authorized end users
- Assigning appropriate user roles and permissions
- Ensuring user activity complies with agency policy
- Determining what data is appropriate to place in the platform
- Maintaining customer-side integrations, where applicable
- Reviewing customer-specific reports, exports, workflows, and configurations
- Reporting suspected security issues to OneVizion in a timely manner
6. Security Controls Overview
The OneVizion GovCloud Platform is designed to align with applicable FedRAMP security control requirements for the authorized environment.
Security capabilities include, but are not limited to:
- Identity and access management
- Role-based access controls
- Administrative access restrictions
- Multi-factor authentication for privileged access
- Centralized logging and monitoring
- Security event detection and alerting
- Endpoint and workload protection
- Network security controls
- Application-layer protection
- Secure configuration management
- Vulnerability identification and remediation
- Change management
- Incident response procedures
- Backup and recovery processes
- Audit logging and accountability
- Continuous monitoring and evidence management
For security reasons, OneVizion does not publicly disclose specific internal tools, vendors, rule logic, detection content, network topology, or implementation-level control details. Such details are available to authorized assessors and government stakeholders through controlled assessment and authorization channels.
7. Continuous Monitoring Approach
OneVizion performs continuous monitoring for the GovCloud environment to support ongoing security oversight and FedRAMP authorization requirements.
Continuous monitoring activities include:
- Collection and review of security-relevant logs
- Monitoring of cloud, application, and infrastructure events
- Vulnerability scanning and tracking
- Review of security alerts and anomalous activity
- Assessment of system changes
- Tracking of remediation activities
- Periodic control review and evidence updates
- Maintenance of authorization artifacts
- Reporting to authorized stakeholders as required
Continuous monitoring information is maintained as part of OneVizion’s FedRAMP evidence and governance process. Detailed monitoring procedures, evidence artifacts, and system-specific records are not published publicly.
8. Incident Response Summary and Security Contact
OneVizion maintains an incident response process for identifying, investigating, containing, remediating, and reporting security incidents involving the OneVizion GovCloud Platform.
Incident response activities may include:
- Security event triage
- Impact analysis
- Containment and remediation
- Customer and stakeholder notification, where required
- Evidence preservation
- Root cause analysis
- Corrective action tracking
- Post-incident review
Security Contact
Security inquiries related to the OneVizion GovCloud Platform may be submitted to:
Email: security@onevizion.com
For suspected security incidents, please include:
- Description of the issue
- Date and time observed
- Affected account, tenant, or system, if known
- Contact information for follow-up
- Any supporting evidence that can be safely shared
Do not include sensitive government data, credentials, secrets, or controlled information in an unencrypted email.
9. Vulnerability Disclosure
OneVizion accepts good-faith reports of potential security vulnerabilities affecting the OneVizion GovCloud Platform.
Reports should be sent to:
Email: security@onevizion.com
Please include:
- Description of the suspected vulnerability
- Steps to reproduce, if applicable
- Potential impact
- Affected URL, endpoint, or component, if known
- Your contact information
OneVizion requests that researchers and reporters:
- Avoid accessing, modifying, or deleting customer data
- Avoid disrupting service availability
- Avoid social engineering, phishing, or physical attacks
- Avoid testing against systems outside the authorized OneVizion GovCloud scope
- Provide OneVizion a reasonable opportunity to investigate and remediate
OneVizion will review submitted reports and respond as appropriate.
10. Service Availability and Status
OneVizion monitors the operational availability of the GovCloud Platform.
Current service status and planned maintenance information may be made available through designated customer communication channels or a dedicated status page.
Status Page: [Insert URL if applicable] Support Contact: [Insert support contact or portal URL]
Customer-specific availability commitments, maintenance windows, and service-level terms are governed by applicable contracts and agreements.
11. FedRAMP Authorization Status
OneVizion is pursuing FedRAMP authorization for the OneVizion GovCloud Platform.
Current Status: FedRAMP authorization in progress / ATO pending Environment: OneVizion GovCloud Platform Authorization Boundary: GovCloud environment only Commercial Cloud Applicability: Not applicable to this page
This page does not represent that OneVizion has received a FedRAMP Authorization to Operate unless and until such authorization has been formally granted and listed through appropriate FedRAMP channels.
Once authorization status changes, OneVizion will update this page accordingly.
12. External Dependencies and Supporting Services
The OneVizion GovCloud Platform relies on external cloud, security, identity, monitoring, and operational services to support secure delivery of the GovCloud environment.
Publicly disclosed dependency categories include:
- Government cloud infrastructure services
- Identity and access management services
- Privileged access management services
- Security monitoring and logging services
- Endpoint and workload protection services
- Cloud-native threat detection services
- Application-layer protection services
- Secure software delivery and deployment services
- Governance, risk, and compliance support services
For security and operational risk management reasons, OneVizion does not publicly disclose the specific vendors, products, detection tooling, internal service names, or detailed architecture used to operate the GovCloud security environment.
Detailed dependency information is maintained in OneVizion’s authorization package and may be provided to authorized assessors, sponsoring agencies, and government stakeholders through controlled disclosure processes.
13. Update Cadence
OneVizion reviews and updates this page as needed to reflect material changes to the OneVizion GovCloud authorization posture, public security information, contact information, service description, and applicable FedRAMP status.
At minimum, this page is reviewed periodically as part of OneVizion’s governance and authorization maintenance activities.
Last Reviewed: [Month Day, Year] Next Scheduled Review: [Month Day, Year] Page Owner: OneVizion Security and Compliance
Disclaimer
The information on this page is provided for public transparency regarding the OneVizion GovCloud Platform and OneVizion’s FedRAMP authorization activities.
This page applies only to the OneVizion GovCloud FedRAMP authorization boundary. It does not describe OneVizion commercial cloud services, commercial customer environments, or non-FedRAMP deployments.
Security-sensitive details, including internal tools, vendor names, architecture diagrams, detection logic, network configurations, and implementation-specific control details, are intentionally excluded from this public page. Such information may be provided through controlled channels to authorized parties with a need to know.