Aeion Auth for GovTech
Identity architecture aligned to NIST SP 800-53 access controls (AC family) + FedRAMP audit requirements + native DoD CAC / federal PIV smart-card authentication + air-gapped operation with no internet egress — all included at no extra cost. For federal civilian, defense, state, and local government deployments.
What Government Authentication Actually Requires
GovTech identity is the most regulated of the verticals covered here. Three frameworks dominate:
NIST 800-53 AC Family Mapping
| NIST SP 800-53 control | Aeion Auth evidence |
PIV / CAC Smart Card Support
PIV (federal) and CAC (DoD) smart cards are X.509 certificates issued by federally-trusted CAs, presented via browser-side client-cert mutual TLS or a PKCS#11 / PC/SC reader. Aeion supports both paths natively — staff sign in with the card they already carry.
Air-Gapped Deployment
Federal high-impact + classified systems often forbid internet egress entirely. Aeion supports fully air-gapped deployment out of the box, at no extra cost:
Audit Log — FedRAMP AU Controls
FedRAMP AU-2 + AU-6 + AU-9 + AU-11 map directly to Aeion's audit log:
GovTech-Specific FAQ
Aeion is a software platform, not a cloud service provider — it isn't authorized as a CSP itself. Government deployments typically run Aeion ON a FedRAMP-authorized cloud (AWS GovCloud, Azure Government). The CSP carries the authorization; Aeion's architecture provides the AC + AU controls needed for inheriting that authorization.
Aeion's encryption uses AES-256-GCM, which is a FIPS-approved algorithm, and password hashing uses Argon2id (via the Bun runtime), which is not yet a FIPS-140-validated primitive. Aeion doesn't currently ship a dedicated FIPS-mode toggle or an alternate FIPS-validated password-hashing path — for FIPS-strict deployments, run Aeion on a FIPS-mode OS (RHEL FIPS, Ubuntu FIPS) for the OpenSSL/TLS layer and talk to your account team about the application-layer gap.
Yes, natively. Staff present their PIV/CAC card via mutual-TLS client-cert auth (the standard federal web pattern) or a PC/SC reader through the Bridge agent; Aeion verifies the certificate chains to your configured agency CA bundle, checks validity, and maps the cert identity to the user and role. Configure the trusted CA bundle to the federal PIV root, DoD CAC root, or a PIV-I anchor. Login.gov / ID.me federation via the generic OIDC provider remains available as an alternative.
Yes — air-gapped deployment (embedded license, on-prem dependencies, self-hosted AI via BYOM) is included with every Aeion deployment, at no extra cost. Plan a one-time provisioning session with your account team to package the deployment manifest.
CJIS Security Policy Section 5.6 (Identification and Authentication) requirements are met by the same MFA + audit log architecture used for HIPAA / PCI. The harder CJIS requirement is the per-record access logging for CJI (Criminal Justice Information) — which the Aeion Health module's per-record audit pattern can be reused for.
The technical architecture is the same. StateRAMP recognizes FedRAMP-equivalent posture; states like Texas (TX-RAMP) similarly inherit. Most state-level frameworks are subsets of NIST 800-53 + FedRAMP requirements.