Voice AI that cleared federal review
Bland is FedRAMP® 20x Class A certified, so federal agencies can run voice AI built for regulated, high-stakes work. The intelligence of every call runs on Bland’s own models, plugged into the telephony your agency already trusts.
FedRAMP 20x Class A certified · Marketplace listing
Independently assessed: SOC 2 Type II, HIPAA, GDPR, PCI DSS
Bland owns the brains of the call
Your agency already runs telephony it trusts. Today those lines end at a human; with Bland, they end at an AI. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models, with no third-party frontier model provider in the call path. Bland doesn’t replace your phone infrastructure. It replaces the seat at the end of the line.
Your calls stay inside the boundary
Audio, transcription, reasoning, and speech synthesis run on Bland’s own models. No frontier model provider enters the authorization boundary.
Plugs into telephony you already trust
Bland connects to the phone infrastructure your agency already operates and has already reviewed, where a human agent used to sit.
One DPA, one incident contact
A single data processing agreement and a single security contact, so review and response stay simple.
FedRAMP public record
FedRAMP requires this information published in both human-readable and machine-readable form. This page and the machine-readable record render from one source, so the values cannot drift. Blank values are not yet assigned.
Certification status
The committed assessment timeline is documented in the assessment statement of work on the Trust Center.
Provider & service
Service properties
Services in scope
The Bland FedRAMP boundary includes Voice agents, SMS, and Chat as part of a single cloud service offering (CSO). Bland is FedRAMP 20x Class A certified for these services, has completed its independent FedRAMP 20x Class C assessment, and submitted its Class C application on 2026-09-08. Class C is not yet certified. Final agency authorization decisions remain agency-specific and use-case dependent.
Everything in the AI path is built and operated by Bland. The models that listen, reason, and speak, along with the prompts, voices, and conversation pathways, are built in-house and run inside Bland’s own container. The only pieces Bland does not build are the telephony connectivity that carries the call and the government cloud infrastructure it runs on, the trusted layers an agency already operates.
Example agency deployments
How agencies put these services to work. These are representative deployments, not a limit on what Bland supports.
One number for an entire agency
An agency routes every incoming call to a single voice agent that answers on the first ring, resolves common questions from an approved knowledge base, and acts on behalf of the caller, from checking the status of a case to scheduling an appointment or capturing an intake form, handing off to a person only when one is genuinely needed.
Benefits and eligibility support at peak volume
During enrollment and renewal periods, agents authenticate callers, walk them through program questions, and start or update applications, holding wait times flat no matter how many constituents call at once.
Proactive outreach and reminders
Agents place outbound calls and send text messages for appointment reminders, renewals, and notifications, with two-way rescheduling and confirmation, so constituents hear from the agency before a deadline passes.
Contacts
Trust Center & documentation
Documentation Catalog
Catalog of all policies and procedures (name, version, date updated, summary). Available on the Trust Center in human-readable and machine-readable format.
Quarterly Certification Progress Report
Detailed quarterly roadmap: completed milestones, current work, upcoming work, and assessment timeline.
Assessment Deadline
Official statement of work from Prescient Security documenting Bland’s commitment to a Class C assessment within the next 24 months.
Vulnerability Reporting
Vulnerability detection and response reporting published as FedRAMP Certification Data: the monthly human-readable report required by VER-TFR-MHR and its machine-readable companions for VER-RPT-VDT and VER-RPT-AVI. Governed by the Bland Vulnerability Management Plan and the Bland VDR Reporting Procedure.
Historical Vulnerability Activity
Machine-readable historical vulnerability evaluation and reporting activity for automated retrieval (VER-TFR-MRH), with the retrieval design, access model, and schedule set out in the Bland Historical Vulnerability Activity Retrieval Statement. Partially implemented; published as a periodic snapshot pending the authenticated retrieval endpoint.
Incident Reporting
Where Bland publishes Initial, Ongoing, and Final Incident Reports for FedRAMP Reportable Incidents (IEC-CSO-IIR, IEC-CSO-OIR, IEC-CSO-FIR) in human-readable and machine-readable form.
Significant Change Notifications
Where Bland publishes Significant Change Notifications and related audit records (SCN-CSO-INF, SCN-CSO-HRM) in human-readable and machine-readable form.
Independent Assessment Results
Results of the Prescient Security FedRAMP 20x Class C independent assessment supplied without inappropriate modification per IVV-CSO-ICP: assessment report, master assessment workbook, machine-readable assessment results, assessor acceptance and completion register, provider responses and assessor dispositions, metrics mechanism inventory, evidence index, supporting artifact date register, and release gate register.
Each repository above is published on the Trust Center at https://trust.bland-gov.com/. Authentication is required for all documents except the secure configuration guide, which is open access. Use the "Request access" button on the Trust Center; access can be reclaimed with "Reclaim access". Questions: fedramp@bland.ai.
Third-party information resources
Third-party information resources that support Bland’s service delivery, customer data path, or security architecture. The intelligence of every call runs on Bland’s own models; these providers support the surrounding infrastructure.
FedRAMP eligibility
Why agencies use Bland
Bland is a voice AI platform for building and operating AI phone agents that conduct natural-language conversations over telephony at scale. Agencies run high-volume telephone channels that face long hold times, inconsistent coverage, and staffing constraints. Agencies use Bland to automate inbound and outbound voice interactions, route or escalate calls to human staff, capture structured outcomes from conversations, and operate these channels continuously without expanding headcount, while maintaining auditable records of each interaction.
Federal use case
Bland is pursuing FedRAMP because the service is intended to support direct agency use and/or indirect use as a third-party information resource within other cloud service offerings used by agency customers.
- Direct Use
- The Bland cloud service offering is used directly by agency customers and integrated into a federal information system, intended to receive an agency Authorization to Operate. Agencies integrate Bland into their own systems to operate constituent-facing voice agents, outbound notification and outreach, and human-in-the-loop escalation, with conversation outcomes written back into agency case-management, scheduling, or CRM systems inside the agency’s authorization boundary.
- Indirect Use
- Bland may also be included as a third-party information resource within other cloud service offerings that are directly used by agency customers (for example, embedded telephony and messaging capabilities).
Independent assessment
FedRAMP requires a provider seeking Class C Certification to publish the overall summary of its independent assessment as supplied by the assessor. This is that summary, published as supplied and carried in the machine-readable record as well. It records adverse determinations and open matters, because that is what the assessor supplied. Bland is not Class C certified.
Timeline
Key Security Indicator determinations (46)
The assessor reports Key Security Indicator outcomes as Supported with Conditions or Partial; the KSI category set contains no unconditional pass.
Provider rule determinations (158)
Automated verification and validation (FRC-CSX-VVK)
Retained findings (20)
Disposition authority: Accountable assessor evaluates; provider/FedRAMP acceptance where applicable; no silent waiver of MUST. Carried in the Bland Security Decision Record per IVV-IAS-SUM and in the assessor's Class C Assessment Report.
| Record | Name | Force | Determination |
|---|---|---|---|
| KSI-CED-RAT | Reviewing All Training | KSI outcome | Supported with Conditions |
| KSI-CNA-EIS | Enforcing Intended State | KSI outcome | Partial |
| KSI-IAM-AAM | Automating Account Management | KSI outcome | Partial |
| KSI-IAM-JIT | Authorizing Just-in-Time | KSI outcome | Partial |
| KSI-MLA-ALA | Authorizing Log Access | KSI outcome | Partial |
| KSI-MLA-OSM | Operating SIEM Capability | KSI outcome | Partial |
| KSI-MLA-RVL | Reviewing Logs | KSI outcome | Partial |
| KSI-PIY-RES | Reviewing Executive Support | KSI outcome | Supported with Conditions |
| KSI-PIY-RIS | Reviewing Investments in Security | KSI outcome | Supported with Conditions |
| KSI-RPL-TRC | Testing Recovery Capabilities | KSI outcome | Partial |
| KSI-SVC-ASM | Automating Secret Management | KSI outcome | Partial |
| FRC-CSO-FCP | FedRAMP Certification Profile | MUST | Satisfied |
| FRC-CSO-JSN | FedRAMP JSON Schemas | MUST | Partial |
| FRC-CSX-MOT | Metrics Over Time for Key Security Indicators | MUST | Partial |
| FRC-CSX-VVK | Automated Verification and Validation of Key Security Indicators | MUST | Partial |
| FRC-CSX-VVR | Automated Verification and Validation of FedRAMP Rules | SHOULD | Partial |
| IEC-CSO-AIR | Automated Incident Reporting | SHOULD | Partial |
| MKT-CSO-MLR | Marketplace Listing Requirements | MUST | Satisfied |
| MKT-CSO-PML | Provider Marketplace Listing Requests | MUST | Pending Application / Submission Gate |
| SDR-CSX-KMT | Key Security Indicator Metrics | MUST | Partial |
Provider responses and assessor dispositions
Areas of dispute and matters requiring disposition
Supplied under IVV-IAS-OSA, which requires the overall summary to include any resulting failures or areas of dispute.
Just-in-time authorization — KSI-IAM-JIT, KSI-MLA-ALA
Privileged and log-access grants remain standing entitlements with no approval-gated, time-bound elevation workflow. Closure requires an implemented JIT mechanism or a FedRAMP-approved alternative interpretation.
Secret and certificate management — KSI-SVC-ASM
An explicit contradiction between two sections of the provider's own source about whether two static edge TLS certificates are auto-renewed must be resolved. No provider exception is represented as assessor accepted.
Two-method qualification — FRC-CSX-VVK, KSI-CED-RAT
Qualification of the second automated method for KSI-CED-RAT is unresolved pending test identity, in-scope population and execution outputs; training-specific tests operating in the commercial Vanta workspace returned no result in the CR26 export. Reconciliation of training populations and dates is outstanding.
Metric history — FRC-CSX-MOT, SDR-CSX-KMT
Elapsed artifact date spans do not establish a complete six-calendar-month KSI metric history or the required 30-day metric summaries and daily series. Initial-certification treatment requires operating mechanisms and documented agreement where historical metrics are unavailable; that agreement is not yet recorded.
Security Decision Record adoption — FRC-CSO-JSN
The original v2.3 Security Decision Record carries an invalid implementation enum on a Rev5-only context row. The prepared Class C derivative excludes all 11 out-of-scope context rules without changing the 158 applicable provider implementation fields. The determination stays Partial until Bland approves or adopts the corrected release and all required formats pass final validation.
Marketplace listing evidence — MKT-CSO-PML
Missing listing transaction evidence is recorded as an explicit substantive limitation and the rule is held at the application and submission gate.
Recommendations retained at SHOULD strength — FRC-CSX-VVR, IEC-CSO-AIR
The unresolved validation-review and incident-reporting automation items are recorded at their official SHOULD strength and are not additional mandates; the absence of a specific scheduler, automatic external-send design or fully automated external communication is not disqualifying. The accountable assessor records any justified alternative and residual risk.
Recovery testing — KSI-RPL-TRC
Full-path service re-point and recovery were explicitly untested; Partial is retained until an in-scope end-to-end recovery test and an actual objective comparison are documented.
Sign-off attribution
Completion of the assessment is attributed to the assessment team as an organization on all 204 records and no named individual assessor sign-off is recorded. Independent quality assurance is attributed to a named senior assessor.
Assessor-stated limitations
- Historical IV&V completion is September 3, 2026; September 4 reconciliations and September 5 corrections are retained.
- Independent QA was completed September 7, 2026. Existing findings and provider/application release gates remain recorded.
- Finalization reconciles the supplied QA workbook and does not represent a new technical test execution.
- ArtifactDateSpanDays = latest - earliest + 1. It is elapsed calendar span, not continuous history days demonstrated. A dated sample, policy age or a query window does not alone establish 30-day KSI metrics or six-calendar-month history. Available longer evidence is retained. Current assessment determinations are preserved.
- Independent QA completed September 7, 2026. Date enrichment prepared September 8, 2026 from retained sources; no new assessor signature, test execution or independent QA execution is asserted.
- Screenshots and passing governance-tool counters alone do not establish effectiveness. Separate Security Assessment Plan and Security Assessment Report documents are not required for 20x, and the per-record acceptance layout used in this delivery is not represented as a mandated FedRAMP template.
Release gates
Gate statuses are as issued by the assessor on 2026-09-08. Bland’s own closure actions are recorded separately below and do not change them.
Historical assessor procedures — Completed 2026-09-03
Completed assessment work and September 4 reconciliations carried forward across all 204 records. Current package corrections remain available for revision review.
Owner: Prescient engagement lead
Qualifications and independence — Completed 2026-09-05
Historical workpapers record organizational independence confirmation. Carry forward the engagement QMS/qualification references under normal release documentation; no individual signature was synthesized.
Owner: Prescient engagement lead
Provider SDR adoption — Pending
Approve the Class C derivative or provide corrected release; preserve original and context exclusions.
Owner: Bland responsible official
Independent QA — Completed 2026-09-07
Independent QA completed for all 204 records in the supplied master workbook. Reviewer and date are recorded in Assessor Acceptance.
Owner: Lynette Shelton - Senior Assessor
Application freshness and findings — Pending
Resolve or obtain authorized dispositions for substantive MUST findings; distinguish SHOULD recommendations. Verify package within seven days of application and independent assessment completion within three months.
Owner: Bland responsible official / Prescient engagement lead
Publication and submission — Pending
Reconcile listing transaction evidence, publish matching current formats and provider submits directly. No submission has been sent.
Owner: Bland responsible official
Bland’s notes on the assessment
Recorded by Bland; not part of the summary supplied by the assessor.
Security Decision Record version not acknowledged — FRC-CSO-JSN
Bland published Security Decision Record v2.4 on 2026-09-04, which passes JSON schema validation, and supplied it to Prescient Security the same day. The final assessment addresses the original v2.3 record and the Class C derivative prepared from it; it does not acknowledge or evaluate v2.4. The FRC-CSO-JSN Partial determination is therefore premised on v2.3. Bland has adopted v2.4 as the Class C release and closed the provider Security Decision Record adoption gate on its own record.
Met / not-met determinations were not delivered
Bland asked Prescient Security to state each outcome as met or not met against the corresponding FedRAMP Practice. The overall summary of assessment supplied by the assessor reports only its own six determination categories - Satisfied, Supported with Conditions, Partial, Optional / Non-Adverse, Pending Application / Submission Gate, and Not Applicable / Not Exercised. No met or not-met determination was delivered.
Bland’s closure record
Remaining open:
- Authorized dispositions for the substantive MUST findings, which require the assessor.
- Reconciliation of FedRAMP Marketplace listing transaction evidence (MKT-CSO-PML).
Assessment artifacts
References are file paths within the Prescient Security final delivery package (edition Bland-C-Final-Delivery-20260908-v2), not public URLs. The documents themselves are supplied to federal agencies and FedRAMP Recognized assessors through the Trust Center under Independent Assessment Results.
Class C Assessment Report
06-independent-assessment/Bland-Class-C-Assessment-Report.pdf
Master assessment workbook (controls the assessment results)
06-independent-assessment/Bland-Class-C-Master-Assessment.xlsx
Machine-readable assessment results
06-independent-assessment/assessment-results.json
Assessor acceptance and completion register
06-independent-assessment/assessor-acceptance-register.json
Provider responses and assessor dispositions
06-independent-assessment/provider-responses-and-dispositions.json
Metrics mechanism inventory
06-independent-assessment/metrics-mechanism-inventory.json
Supporting artifact date register
06-independent-assessment/artifact-date-register.json and .html
Release gate register
06-independent-assessment/application-gates.json
QA-completed master assessment workbook
05-evidence/qa-source/QA-Completed-Master-Assessment-20260907.xlsx
Evidence index
05-evidence/evidence-index.json and .html
Pinned FedRAMP rules source
00-manifest/official-sources/fedramp-consolidated-rules.json
Record metadata
FedRAMP requires the responsible official, version, date of last update, and source of update to be published with the Certification Package Overview, alongside the overall summary of assessment above. The FedRAMP schema defines no field for any of them, so Bland carries them in an x-bland extension in the machine-readable record and publishes them here.
FAQ
Yes. Bland holds FedRAMP 20x Class A Certification, achieved August 25, 2026 and listed on the FedRAMP Marketplace as package FR2628647242. The listing phase is Ongoing Certification. This page is kept in sync with that listing.
Bland is certified at FedRAMP 20x Class A, achieved August 25, 2026. Class C at the Moderate security category is submitted, not certified. Prescient Security, LLC. completed the independent Class C assessment on September 3, 2026, independent quality assurance completed September 7, and the final assessment was issued September 8, 2026; Bland submitted its Class C application the same day. Prescient is engaged for Class C only and did not assess Class A. The assessor’s overall summary of assessment, including its determinations, the twenty retained findings, and the open matters, is published on this page and in the machine-readable record.
Bland runs its own speech and language models. Most vendors wrap third-party frontier models, which pulls those providers into the authorization boundary and onto an agency’s review. With Bland, a call’s audio, transcription, reasoning, and synthesis all happen on Bland’s own models, plugged into the telephony an agency already operates. That means a smaller assessment boundary and no AI subprocessor chain to vet.
Yes. Bland holds FedRAMP 20x Class A Certification, and is also available to commercial and public-sector teams under SOC 2 Type II, HIPAA, GDPR, and PCI DSS. Class C at the Moderate security category has been independently assessed and submitted, and is not yet certified. Final agency authorization decisions remain agency-specific and use-case dependent.
Federal agencies and FedRAMP-recognized assessors can request access with the "Request access" button on the Trust Center at https://trust.bland-gov.com/. Questions can be directed to fedramp@bland.ai.
Bringing voice AI to a federal program?
Talk to our team about deployment options, our security package, and where Bland is in the FedRAMP process.
FedRAMP® is a registered mark of the U.S. General Services Administration. Bland holds FedRAMP 20x Class A Certification; Class C at the Moderate security category has been independently assessed and submitted and is not yet certified. FedRAMP Certification does not imply U.S. government endorsement. Status on this page is intended to match Bland's FedRAMP Marketplace listing.