Voice AI that cleared federal review

Bland is FedRAMP® 20x Class A certified, so federal agencies can run voice AI built for regulated, high-stakes work. The intelligence of every call runs on Bland’s own models, plugged into the telephony your agency already trusts.

FedRAMP 20x Class A certified · Marketplace listing

Independently assessed: SOC 2 Type II, HIPAA, GDPR, PCI DSS

OWNED AND OPERATEDVoiceSTTLLMTTS

Bland owns the brains of the call

Your agency already runs telephony it trusts. Today those lines end at a human; with Bland, they end at an AI. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models, with no third-party frontier model provider in the call path. Bland doesn’t replace your phone infrastructure. It replaces the seat at the end of the line.

Your calls stay inside the boundary

Audio, transcription, reasoning, and speech synthesis run on Bland’s own models. No frontier model provider enters the authorization boundary.

Plugs into telephony you already trust

Bland connects to the phone infrastructure your agency already operates and has already reviewed, where a human agent used to sit.

One DPA, one incident contact

A single data processing agreement and a single security contact, so review and response stay simple.

FedRAMP public record

FedRAMP requires this information published in both human-readable and machine-readable form. This page and the machine-readable record render from one source, so the values cannot drift. Blank values are not yet assigned.

Certification status

FedRAMP statusOngoing Certification
Certification heldFedRAMP 20x Class A, achieved 2026-08-25
Marketplace listingFR2628647242
Certification pathClass C at Moderate. Application submitted 2026-09-08; not yet certified.
Class C assessorPrescient Security, LLC. (FedRAMP Recognized, assessor ID 202040). Engaged for Class C only; did not assess Class A.
Class C assessmentIndependent assessment completed 2026-09-03, independent quality assurance completed 2026-09-07, final assessment issued 2026-09-08. See the overall summary of assessment below.
Next milestoneFedRAMP review of the Class C application, and authorized dispositions for the retained findings
Next ongoing certification report date2026-10-30

The committed assessment timeline is documented in the assessment statement of work on the Trust Center.

Provider & service

Provider nameBland AI
Service nameBland
Service acronymBland
Service descriptionBland is an enterprise voice AI platform for building, deploying, and operating AI phone agents at scale. Bland runs its own speech and language models, so customer calls are not sent to third-party frontier model providers. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models within Bland’s boundary.
Certification type20x
FedRAMP IDFR2628647242
UEI numberBlank, not yet assigned

Service properties

Service modelPaaS
Deployment modelGovernment-Only Cloud
Digital identity levelIAL: customer/agency-managed or not performed by Bland; AAL2 for Bland-managed administrative authentication where MFA is enforced; FAL2 where federated SSO is configured
Business categoryArtificial Intelligence (AI), Contact Center

Services in scope

The Bland FedRAMP boundary includes Voice agents, SMS, and Chat as part of a single cloud service offering (CSO). Bland is FedRAMP 20x Class A certified for these services, has completed its independent FedRAMP 20x Class C assessment, and submitted its Class C application on 2026-09-08. Class C is not yet certified. Final agency authorization decisions remain agency-specific and use-case dependent.

Everything in the AI path is built and operated by Bland. The models that listen, reason, and speak, along with the prompts, voices, and conversation pathways, are built in-house and run inside Bland’s own container. The only pieces Bland does not build are the telephony connectivity that carries the call and the government cloud infrastructure it runs on, the trusted layers an agency already operates.

Voice agentsAI phone agents that answer inbound calls and place outbound calls, hold natural spoken conversations, and act on what the caller needs. Each agent follows a configurable conversation pathway, a decision tree that interprets the caller’s intent and then routes the call or takes an action such as scheduling, sending follow-ups, taking payments, answering questions from an approved knowledge base, or escalating to a person. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models inside Bland’s boundary.Recommended security category: Moderate, targeted under FedRAMP 20x Class C. Generally available 2026-07-13.
SMSProgrammatic two-way text messaging driven by the same pathway logic as voice agents. Agents send and respond to messages for notifications, reminders, status updates, and structured question-and-answer flows, triggering the same actions as a voice agent, such as scheduling, follow-ups, and record updates, over text rather than a call.Recommended security category: Moderate, targeted under FedRAMP 20x Class C. Generally available 2026-07-13.
ChatWeb and in-app chat agents that run on the same conversation pathways and actions as voice and SMS, embedded in an agency’s web properties for self-service. Chat shares the rule sets, knowledge, and integrations of the other channels, so a constituent gets the same answers and outcomes no matter how they reach out.Recommended security category: Moderate, targeted under FedRAMP 20x Class C. Generally available 2026-07-13.

Example agency deployments

How agencies put these services to work. These are representative deployments, not a limit on what Bland supports.

One number for an entire agency

An agency routes every incoming call to a single voice agent that answers on the first ring, resolves common questions from an approved knowledge base, and acts on behalf of the caller, from checking the status of a case to scheduling an appointment or capturing an intake form, handing off to a person only when one is genuinely needed.

Benefits and eligibility support at peak volume

During enrollment and renewal periods, agents authenticate callers, walk them through program questions, and start or update applications, holding wait times flat no matter how many constituents call at once.

Proactive outreach and reminders

Agents place outbound calls and send text messages for appointment reminders, renewals, and notifications, with two-way rescheduling and confirmation, so constituents hear from the agency before a deadline passes.

Contacts

Security contactBland FedRAMP, fedramp@bland.ai
Sales contactBland Federal Sales, sales@bland.ai

Trust Center & documentation

Trust Center descriptionBland FedRAMP Trust Center. FedRAMP package and security documentation for federal agencies and recognized assessors.
Authentication requiredtrue
Access instructionsUse the "Request access" button on the Trust Center; access can be reclaimed with "Reclaim access". Questions: fedramp@bland.ai.
Secure configuration guidanceBland AI secure configuration guide: hardening and configuration guidance for operating Bland securely (SCG-CSO-RSC). Open access; no authentication required. https://trust.bland-gov.com/resources?s=8udmre29tx8im63a7l6bhw&name=bland-ai-secure-configuration-guide.pdf

Documentation Catalog

Catalog of all policies and procedures (name, version, date updated, summary). Available on the Trust Center in human-readable and machine-readable format.

Quarterly Certification Progress Report

Detailed quarterly roadmap: completed milestones, current work, upcoming work, and assessment timeline.

Assessment Deadline

Official statement of work from Prescient Security documenting Bland’s commitment to a Class C assessment within the next 24 months.

Vulnerability Reporting

Vulnerability detection and response reporting published as FedRAMP Certification Data: the monthly human-readable report required by VER-TFR-MHR and its machine-readable companions for VER-RPT-VDT and VER-RPT-AVI. Governed by the Bland Vulnerability Management Plan and the Bland VDR Reporting Procedure.

Historical Vulnerability Activity

Machine-readable historical vulnerability evaluation and reporting activity for automated retrieval (VER-TFR-MRH), with the retrieval design, access model, and schedule set out in the Bland Historical Vulnerability Activity Retrieval Statement. Partially implemented; published as a periodic snapshot pending the authenticated retrieval endpoint.

Incident Reporting

Where Bland publishes Initial, Ongoing, and Final Incident Reports for FedRAMP Reportable Incidents (IEC-CSO-IIR, IEC-CSO-OIR, IEC-CSO-FIR) in human-readable and machine-readable form.

Significant Change Notifications

Where Bland publishes Significant Change Notifications and related audit records (SCN-CSO-INF, SCN-CSO-HRM) in human-readable and machine-readable form.

Independent Assessment Results

Results of the Prescient Security FedRAMP 20x Class C independent assessment supplied without inappropriate modification per IVV-CSO-ICP: assessment report, master assessment workbook, machine-readable assessment results, assessor acceptance and completion register, provider responses and assessor dispositions, metrics mechanism inventory, evidence index, supporting artifact date register, and release gate register.

Each repository above is published on the Trust Center at https://trust.bland-gov.com/. Authentication is required for all documents except the secure configuration guide, which is open access. Use the "Request access" button on the Trust Center; access can be reclaimed with "Reclaim access". Questions: fedramp@bland.ai.

Third-party information resources

Third-party information resources that support Bland’s service delivery, customer data path, or security architecture. The intelligence of every call runs on Bland’s own models; these providers support the surrounding infrastructure.

AWS GovCloudCloud infrastructure hosting the Bland service. FedRAMP Certified, ID: F1603047866
OktaIdentity provider for Bland-managed administrative authentication. Provider: Okta, https://www.okta.com
TwilioTelephony carrier connectivity (PSTN) for voice calls. Provider: Twilio, https://www.twilio.com

FedRAMP eligibility

Why agencies use Bland

Bland is a voice AI platform for building and operating AI phone agents that conduct natural-language conversations over telephony at scale. Agencies run high-volume telephone channels that face long hold times, inconsistent coverage, and staffing constraints. Agencies use Bland to automate inbound and outbound voice interactions, route or escalate calls to human staff, capture structured outcomes from conversations, and operate these channels continuously without expanding headcount, while maintaining auditable records of each interaction.

Federal use case

Bland is pursuing FedRAMP because the service is intended to support direct agency use and/or indirect use as a third-party information resource within other cloud service offerings used by agency customers.

Direct Use
The Bland cloud service offering is used directly by agency customers and integrated into a federal information system, intended to receive an agency Authorization to Operate. Agencies integrate Bland into their own systems to operate constituent-facing voice agents, outbound notification and outreach, and human-in-the-loop escalation, with conversation outcomes written back into agency case-management, scheduling, or CRM systems inside the agency’s authorization boundary.
Indirect Use
Bland may also be included as a third-party information resource within other cloud service offerings that are directly used by agency customers (for example, embedded telephony and messaging capabilities).

Independent assessment

FedRAMP requires a provider seeking Class C Certification to publish the overall summary of its independent assessment as supplied by the assessor. This is that summary, published as supplied and carried in the machine-readable record as well. It records adverse determinations and open matters, because that is what the assessor supplied. Bland is not Class C certified.

AssessorPrescient Security, LLC. (FedRAMP Recognized, assessor ID 202040).
Package stateFINAL ASSESSMENT - INDEPENDENT QA COMPLETED
Delivery editionBland-C-Final-Delivery-20260908-v2
ScopeFedRAMP 20x Class C at the Moderate security category; all 46 Key Security Indicators and all 158 applicable provider rules (IVV-CSX-AIA). A further 11 rules are carried as out-of-scope context and receive no determination.
MethodsCompleted source examinations, automated validation results, offline evidence reviews, interviews, demonstrations and walkthroughs, recorded as 45 Key Security Indicator discussion notes and 121 provider-rule discussion notes. Rule and KSI determinations are final; implementation status reconciliation is complete.
Rules sourceVersion 2026.07.14.01, last updated 2026-07-14.
Source documentsClass C Assessment Report, issued 2026-09-08, Machine-readable assessment results (final independently reviewed assessment results, generated 2026-09-08), Assessor acceptance and completion register (204 records), Provider responses and assessor dispositions register (101 records, 2026-09-04), Metrics mechanism inventory (46 Key Security Indicators), Supporting artifact date register, Release gate register

Timeline

Assessment start2026-09-01
Assessment completion2026-09-03
Response reconciliation2026-09-04
Corrections2026-09-05 (KSI-MLA-OSM, KSI-MLA-RVL)
Qualifications and independence2026-09-05
Independent quality assurance2026-09-07, Lynette Shelton, Senior Assessor. 204 records reviewed; 0 determinations changed.
Final assessment issued2026-09-08
Completion attributionPrescient Security Assessment Team (IV&V); 204 records. No named individual assessor sign-off is recorded; completion is attributed to the assessment team as an organization.

Key Security Indicator determinations (46)

Supported with Conditions38
Partial8

The assessor reports Key Security Indicator outcomes as Supported with Conditions or Partial; the KSI category set contains no unconditional pass.

Provider rule determinations (158)

Supported with Conditions88
Satisfied54
Optional / Non-Adverse5
Pending Application / Submission Gate4
Partial6
Not Applicable / Not Exercised1

Automated verification and validation (FRC-CSX-VVK)

Meets two-method count33
Below two methods12
Unresolved second method1 (KSI-CED-RAT)
DeterminationPartial
Assessor noteArithmetic pairing is not technical qualification: actual evaluated conditions, identities and configuration, population, outputs and recurring execution must be recorded for each method. Same-tool methods may qualify; duplicate presentations of a single evaluation do not.

Retained findings (20)

Disposition authority: Accountable assessor evaluates; provider/FedRAMP acceptance where applicable; no silent waiver of MUST. Carried in the Bland Security Decision Record per IVV-IAS-SUM and in the assessor's Class C Assessment Report.

RecordNameForceDetermination
KSI-CED-RATReviewing All TrainingKSI outcomeSupported with Conditions
KSI-CNA-EISEnforcing Intended StateKSI outcomePartial
KSI-IAM-AAMAutomating Account ManagementKSI outcomePartial
KSI-IAM-JITAuthorizing Just-in-TimeKSI outcomePartial
KSI-MLA-ALAAuthorizing Log AccessKSI outcomePartial
KSI-MLA-OSMOperating SIEM CapabilityKSI outcomePartial
KSI-MLA-RVLReviewing LogsKSI outcomePartial
KSI-PIY-RESReviewing Executive SupportKSI outcomeSupported with Conditions
KSI-PIY-RISReviewing Investments in SecurityKSI outcomeSupported with Conditions
KSI-RPL-TRCTesting Recovery CapabilitiesKSI outcomePartial
KSI-SVC-ASMAutomating Secret ManagementKSI outcomePartial
FRC-CSO-FCPFedRAMP Certification ProfileMUSTSatisfied
FRC-CSO-JSNFedRAMP JSON SchemasMUSTPartial
FRC-CSX-MOTMetrics Over Time for Key Security IndicatorsMUSTPartial
FRC-CSX-VVKAutomated Verification and Validation of Key Security IndicatorsMUSTPartial
FRC-CSX-VVRAutomated Verification and Validation of FedRAMP RulesSHOULDPartial
IEC-CSO-AIRAutomated Incident ReportingSHOULDPartial
MKT-CSO-MLRMarketplace Listing RequirementsMUSTSatisfied
MKT-CSO-PMLProvider Marketplace Listing RequestsMUSTPending Application / Submission Gate
SDR-CSX-KMTKey Security Indicator MetricsMUSTPartial

Provider responses and assessor dispositions

Response date2026-09-04
Records responded101
Adverse determinations or gaps withdrawn53
Assessor record corrections8
Prior status retained with concurrence4
Responded records currently Partial13
Revised after reconciliation: KSI-MLA-RVLSupported with Conditions on 2026-09-04; now Partial.
Revised after reconciliation: KSI-MLA-OSMSupported with Conditions on 2026-09-04; now Partial.
InterpretationThe dated exchange is preserved. The QA-completed current determination controls where later reconciliation changed the result.

Areas of dispute and matters requiring disposition

Supplied under IVV-IAS-OSA, which requires the overall summary to include any resulting failures or areas of dispute.

Just-in-time authorizationKSI-IAM-JIT, KSI-MLA-ALA

Privileged and log-access grants remain standing entitlements with no approval-gated, time-bound elevation workflow. Closure requires an implemented JIT mechanism or a FedRAMP-approved alternative interpretation.

Secret and certificate managementKSI-SVC-ASM

An explicit contradiction between two sections of the provider's own source about whether two static edge TLS certificates are auto-renewed must be resolved. No provider exception is represented as assessor accepted.

Two-method qualificationFRC-CSX-VVK, KSI-CED-RAT

Qualification of the second automated method for KSI-CED-RAT is unresolved pending test identity, in-scope population and execution outputs; training-specific tests operating in the commercial Vanta workspace returned no result in the CR26 export. Reconciliation of training populations and dates is outstanding.

Metric historyFRC-CSX-MOT, SDR-CSX-KMT

Elapsed artifact date spans do not establish a complete six-calendar-month KSI metric history or the required 30-day metric summaries and daily series. Initial-certification treatment requires operating mechanisms and documented agreement where historical metrics are unavailable; that agreement is not yet recorded.

Security Decision Record adoptionFRC-CSO-JSN

The original v2.3 Security Decision Record carries an invalid implementation enum on a Rev5-only context row. The prepared Class C derivative excludes all 11 out-of-scope context rules without changing the 158 applicable provider implementation fields. The determination stays Partial until Bland approves or adopts the corrected release and all required formats pass final validation.

Marketplace listing evidenceMKT-CSO-PML

Missing listing transaction evidence is recorded as an explicit substantive limitation and the rule is held at the application and submission gate.

Recommendations retained at SHOULD strengthFRC-CSX-VVR, IEC-CSO-AIR

The unresolved validation-review and incident-reporting automation items are recorded at their official SHOULD strength and are not additional mandates; the absence of a specific scheduler, automatic external-send design or fully automated external communication is not disqualifying. The accountable assessor records any justified alternative and residual risk.

Recovery testingKSI-RPL-TRC

Full-path service re-point and recovery were explicitly untested; Partial is retained until an in-scope end-to-end recovery test and an actual objective comparison are documented.

Sign-off attribution

Completion of the assessment is attributed to the assessment team as an organization on all 204 records and no named individual assessor sign-off is recorded. Independent quality assurance is attributed to a named senior assessor.

Assessor-stated limitations

  • Historical IV&V completion is September 3, 2026; September 4 reconciliations and September 5 corrections are retained.
  • Independent QA was completed September 7, 2026. Existing findings and provider/application release gates remain recorded.
  • Finalization reconciles the supplied QA workbook and does not represent a new technical test execution.
  • ArtifactDateSpanDays = latest - earliest + 1. It is elapsed calendar span, not continuous history days demonstrated. A dated sample, policy age or a query window does not alone establish 30-day KSI metrics or six-calendar-month history. Available longer evidence is retained. Current assessment determinations are preserved.
  • Independent QA completed September 7, 2026. Date enrichment prepared September 8, 2026 from retained sources; no new assessor signature, test execution or independent QA execution is asserted.
  • Screenshots and passing governance-tool counters alone do not establish effectiveness. Separate Security Assessment Plan and Security Assessment Report documents are not required for 20x, and the per-record acceptance layout used in this delivery is not represented as a mandated FedRAMP template.

Release gates

Gate statuses are as issued by the assessor on 2026-09-08. Bland’s own closure actions are recorded separately below and do not change them.

Historical assessor proceduresCompleted 2026-09-03

Completed assessment work and September 4 reconciliations carried forward across all 204 records. Current package corrections remain available for revision review.

Owner: Prescient engagement lead

Qualifications and independenceCompleted 2026-09-05

Historical workpapers record organizational independence confirmation. Carry forward the engagement QMS/qualification references under normal release documentation; no individual signature was synthesized.

Owner: Prescient engagement lead

Provider SDR adoptionPending

Approve the Class C derivative or provide corrected release; preserve original and context exclusions.

Owner: Bland responsible official

Independent QACompleted 2026-09-07

Independent QA completed for all 204 records in the supplied master workbook. Reviewer and date are recorded in Assessor Acceptance.

Owner: Lynette Shelton - Senior Assessor

Application freshness and findingsPending

Resolve or obtain authorized dispositions for substantive MUST findings; distinguish SHOULD recommendations. Verify package within seven days of application and independent assessment completion within three months.

Owner: Bland responsible official / Prescient engagement lead

Publication and submissionPending

Reconcile listing transaction evidence, publish matching current formats and provider submits directly. No submission has been sent.

Owner: Bland responsible official

Bland’s notes on the assessment

Recorded by Bland; not part of the summary supplied by the assessor.

Security Decision Record version not acknowledgedFRC-CSO-JSN

Bland published Security Decision Record v2.4 on 2026-09-04, which passes JSON schema validation, and supplied it to Prescient Security the same day. The final assessment addresses the original v2.3 record and the Class C derivative prepared from it; it does not acknowledge or evaluate v2.4. The FRC-CSO-JSN Partial determination is therefore premised on v2.3. Bland has adopted v2.4 as the Class C release and closed the provider Security Decision Record adoption gate on its own record.

Met / not-met determinations were not delivered

Bland asked Prescient Security to state each outcome as met or not met against the corresponding FedRAMP Practice. The overall summary of assessment supplied by the assessor reports only its own six determination categories - Satisfied, Supported with Conditions, Partial, Optional / Non-Adverse, Pending Application / Submission Gate, and Not Applicable / Not Exercised. No met or not-met determination was delivered.

Bland’s closure record

As of2026-09-08
Security Decision Record adoptionClosed on Bland's record. Bland adopted Security Decision Record v2.4 as the Class C release; v2.4 passes JSON schema validation and preserves the original record and the out-of-scope context exclusions.
Application submittedBland verified the Certification Package and submitted its FedRAMP 20x Class C application on 2026-09-08, five days after assessment completion, satisfying the application freshness conditions.

Remaining open:

  • Authorized dispositions for the substantive MUST findings, which require the assessor.
  • Reconciliation of FedRAMP Marketplace listing transaction evidence (MKT-CSO-PML).

Assessment artifacts

References are file paths within the Prescient Security final delivery package (edition Bland-C-Final-Delivery-20260908-v2), not public URLs. The documents themselves are supplied to federal agencies and FedRAMP Recognized assessors through the Trust Center under Independent Assessment Results.

Class C Assessment Report

06-independent-assessment/Bland-Class-C-Assessment-Report.pdf

Master assessment workbook (controls the assessment results)

06-independent-assessment/Bland-Class-C-Master-Assessment.xlsx

Machine-readable assessment results

06-independent-assessment/assessment-results.json

Assessor acceptance and completion register

06-independent-assessment/assessor-acceptance-register.json

Provider responses and assessor dispositions

06-independent-assessment/provider-responses-and-dispositions.json

Metrics mechanism inventory

06-independent-assessment/metrics-mechanism-inventory.json

Supporting artifact date register

06-independent-assessment/artifact-date-register.json and .html

Release gate register

06-independent-assessment/application-gates.json

QA-completed master assessment workbook

05-evidence/qa-source/QA-Completed-Master-Assessment-20260907.xlsx

Evidence index

05-evidence/evidence-index.json and .html

Pinned FedRAMP rules source

00-manifest/official-sources/fedramp-consolidated-rules.json

Record metadata

FedRAMP requires the responsible official, version, date of last update, and source of update to be published with the Certification Package Overview, alongside the overall summary of assessment above. The FedRAMP schema defines no field for any of them, so Bland carries them in an x-bland extension in the machine-readable record and publishes them here.

Responsible officialJuan Riojas, Chief Information Officer, fedramp@bland.ai
Record version1.4
Last updated2026-09-08T00:00:00Z
Source of updateIncorporated the overall summary of assessment required by CPO-CSO-OSA from the final assessment supplied by Prescient Security, LLC. under IVV-IAS-OSA: the Class C Assessment Report issued 2026-09-08, the machine-readable assessment results, the assessor acceptance and completion register, the provider responses and assessor dispositions register, the metrics mechanism inventory, the supporting artifact date register, and the release gate register (delivery edition Bland-C-Final-Delivery-20260908-v2). Recorded the assessment timeline (completion 2026-09-03, reconciliation 2026-09-04, corrections 2026-09-05, independent quality assurance 2026-09-07 across all 204 records), determinations for 46 Key Security Indicators and 158 provider rules, the FRC-CSX-VVK continuous validation method counts, the 20 retained findings, the areas of dispute and matters requiring disposition or interpretation, the assessor-stated limitations, and the release gates. Recorded Bland's own notes that the assessment does not acknowledge Security Decision Record v2.4 published 2026-09-04, and that no met or not-met determinations were delivered. Recorded Bland's adoption of Security Decision Record v2.4 as the Class C release and the submission of Bland's 20x Class C application on 2026-09-08. Added the assessor record to the machine-readable overview and a Trust Center repository for independent assessment results, and updated the certification status and the Independent Verification and Validation section for a completed Class C assessment pending provider adoption, findings dispositions, and submission.

FAQ

Yes. Bland holds FedRAMP 20x Class A Certification, achieved August 25, 2026 and listed on the FedRAMP Marketplace as package FR2628647242. The listing phase is Ongoing Certification. This page is kept in sync with that listing.

Bland is certified at FedRAMP 20x Class A, achieved August 25, 2026. Class C at the Moderate security category is submitted, not certified. Prescient Security, LLC. completed the independent Class C assessment on September 3, 2026, independent quality assurance completed September 7, and the final assessment was issued September 8, 2026; Bland submitted its Class C application the same day. Prescient is engaged for Class C only and did not assess Class A. The assessor’s overall summary of assessment, including its determinations, the twenty retained findings, and the open matters, is published on this page and in the machine-readable record.

Bland runs its own speech and language models. Most vendors wrap third-party frontier models, which pulls those providers into the authorization boundary and onto an agency’s review. With Bland, a call’s audio, transcription, reasoning, and synthesis all happen on Bland’s own models, plugged into the telephony an agency already operates. That means a smaller assessment boundary and no AI subprocessor chain to vet.

Yes. Bland holds FedRAMP 20x Class A Certification, and is also available to commercial and public-sector teams under SOC 2 Type II, HIPAA, GDPR, and PCI DSS. Class C at the Moderate security category has been independently assessed and submitted, and is not yet certified. Final agency authorization decisions remain agency-specific and use-case dependent.

Federal agencies and FedRAMP-recognized assessors can request access with the "Request access" button on the Trust Center at https://trust.bland-gov.com/. Questions can be directed to fedramp@bland.ai.

Bringing voice AI to a federal program?

Talk to our team about deployment options, our security package, and where Bland is in the FedRAMP process.

FedRAMP® is a registered mark of the U.S. General Services Administration. Bland holds FedRAMP 20x Class A Certification; Class C at the Moderate security category has been independently assessed and submitted and is not yet certified. FedRAMP Certification does not imply U.S. government endorsement. Status on this page is intended to match Bland's FedRAMP Marketplace listing.