CMMC and FedRAMP Webinar Introduction Welcome to today’s webinar. My name is Micheál McGrath and I’m delighted to welcome everyone here today. We got a really interesting webinar and we got some great expertise that joined us here today. Today’s webinar is all about CMMC, FedRAMP, and what you need as a federal contractor to be secure and to know that your content is meeting the regulations that you need to meet. We’re going to talk about VisibleThread, we’re going to talk about FedRAMP, we’re going to talk about CMMC in general, we’re going to demystify some of the conversations, but if we really want the audience to get involved, so if you have direct questions for us today, feel free to get involved in the attendee chat or the Q and A box. If you’re in the attendee chat, let us know where you’re tuning in from. I’m based here in Ireland in Cork and we have lots of people here from the US and we have Andrew from Dublin. So feel free to drop in your questions, let us know where you’re coming from. Just to start off today’s webinar and to help us out understand, know where everybody is in terms of their understanding of CMMC and FedRAMP, we have a poll on screen just to view, are you very familiar? Are you already in the weeds? Are you not familiar at all? Is this an entry level? This will help us gauge the content a little bit more. So you can actually click directly on the slide and that will help, you’ll be able to answer the poll through that. So feel free to answer that poll as we’re just getting started. So what we’ll do while people are kind of figuring that poll out is we’ll do a little bit of introductions. We’ll start with Kyle, Kyle Peterson. Do want to introduce yourself? Sure, thanks Micheál. Hi everyone, I’m Kyle Peterson. I lead our customer success and account strategy team here at VisibleThread, Chicago, Illinois based. Pre VisibleThread, I was a contracts manager in the aerospace industry, so have always been, I should say, affected by some of these cyber security regulations whether they’re new or existing in terms of highly secure aircraft efforts. So, have never been a cyber security practitioner, but I’ve certainly been on the kind of the end user side of things and then certainly hearing a lot from our existing customer base as they work to comply with these very same standards. So, looking forward to the conversation. Fabulous, And Andrew, we also have Andrew here from VisibleThread too. Andrew, would you like to introduce yourself? Yeah. Sure. Hi, Micheál. My name is Andrew Locatelli Woodcock. I work with Micheál and Kyle and also with Martina who you’ll meet in a moment. And I’m CTO with VisibleThread. As you can tell from my beard, I have many, many years experience working in IT. Most of my time was spent working with financial services, particularly Citibank and some of the Irish based banks. So a solid background in financial security and what it takes to make sure that, you know, you’re doing things right in a safe manner. My background initially was software engineering, then architecture, then leadership. I joined three months ago now, and yeah, very excited to be here. Absolutely, and what an impact you’ve made already, Andrew, may I say. So we’re delighted to have you here on this. And also, we are delighted to welcome Christina to this webinar from Ignite. Christina, we’ve been working with you for a number of months now and it’s been a pleasure. So we’re absolutely delighted to partner with you on this webinar. Would you like to introduce yourself and let us know a little bit about Ignite? Yeah, absolutely. Thanks, Micheál. Yeah, I’m Christina Martinson. I’m the lead CCA here and the deputy director of service delivery over here at Ignite. Before Ignite, I’m an Army veteran and I worked mainly with the DoD, so coming directly from your government, well maybe not everyone’s government but the American side. And I don’t have a beard for my time of telling but I do dye my hair to make sure it’s not gray because over here we manage the C3PAO side. So we’re here to let you know exactly what’s acceptable on the audit side and to get you through the audit side in a secure fashion. So very excited to let you guys know what I know. Fabulous and I think it’s a good setting as well because we have a bit of a mix based on the poll that we did at the beginning. It’s a bit of a mixed knowledge. So we’re looking at almost sixty percent of the webinar right in the middle, heard of the terms, understand the basics. That’s where people are kind of lying. There’s some people that are not familiar and then there is some people that are a little bit further down the line. So it is quite broad, but I think most people are kind of sitting right in the middle here where they might’ve heard the terms or understand the basics, but I think that’s a perfect opportunity for this webinar. If you do have direct questions, it’s a great place. Okay, we’d love to move you up the line here on this webinar. So hopefully we can do so. What also might help us to understand, so we have two polls from Ignite. So I would love to know where are you on your compliance journey? So are you at the very beginning? Are you researching? Is that why you’re on this webinar? Are you currently in progress? Are you completed and looking for some validation or is this not relevant to you in terms of where you are? So I’ll let this poll run for just a few seconds. We have about fourteen percent right now, so you can click directly on the slides if you’re just joining us. Okay, so I’ll let it go up a little bit more. So I’ll get over the halfway mark. Okay, fabulous. Okay, so again, nearly half the webinar have completed this journey, but then the other half are in that kind of researching phase, which is great. It’s applicable to everybody, which is good. And most, nearly everyone here who’s filled out the poll have started this journey, which is positive. So that’s great. And our last question, and it’ll help us actually really understand who we’re dealing with and it’ll help direct some of the questions at the end. But does your organization handle FCI, CUI? Are you unsure what you’re actually handling or is it not applicable at all, of those? You can select multiple if you are CUI, CTI and FCI. And if these terms don’t, you don’t get them, I’m sure Christina is going to get us there at some point in this webinar too. So again, you can click directly on the slides. And it feels like we’re on track. It feels like most people are in the same boat, but this will really be interesting to see now. So we have about a third of the webinar have filled this out. Christina, your time in the DOD surely has armed you with all the acronym knowledge one could ever need, right? Absolutely. Yeah. We still speak in acronyms at home for sure. And if we didn’t need more acronyms in GovCon, now we have them. So plenty more, buddy. So we have half the webinar there. Okay, seventy three percent CUI, CTI, fifty percent in the FCI space, and then a couple of people in “not applicable.” So at this point, we’re going to hand over to Christina. Christina is going to give us a basic understanding and demystify a few things and then we’re going to talk at the end about the VisibleThread approach and the collaboration with Ignite. So feel free to drop in your questions as Christina is going, but from this point on, Christina, I’ll let you take over. Chapter Demystifying CMMC and FedRAMP Yeah, thank you, Micheál. Yeah, so again, we’re here with Ignite. We’ve been over fifteen years in business. We have multiple certifications to be able to handle auditing from many compliance platforms. And we are excited to be here as well. Awesome. So first off, there are many common misconceptions when it comes to CMMC and FedRAMP. It’s a lot of terminology running around, a lot of acronyms as you have mentioned, and they’re both really big entities and they do share a relationship, but they’re not the same. So a lot of times organizations will say, oh, we’re CMMC, we need CMMC people. And that doesn’t apply to the organization that they’re trying to work with. They would actually need FedRAMP. And you’re like, well, aren’t they the same thing? Why can’t FedRAMP be equal to CMMC and vice versa? Well, not quite. So CMMC does not equal FedRAMP and FedRAMP doesn’t equal CMMC. And of course, the companies that need FedRAMP are cloud based and they don’t need CMMC. And maybe the companies who need CMMC don’t need FedRAMP because that’s not their compliance genre. So we’re here to maybe separate those two a little clearer for you guys. And then the other thing is that unfortunately compliance is not complacency. We can’t be complacent and compliant at the same time because this is an ever expanding framework in nature that we’re working with. The government can wake up tomorrow and change their mind, as they have before, as we’ve seen currently. So we’re here to remind everybody that we have to stay diligent. So when we’re understanding CMMC at the very high level, why do we do this? For example, we have that nifty clause at the top, 7021, that everyone looks at and says, why do I have to do this? Well, pre-pause for what’s happening in the government at the moment: 7021 was where it said, hey, if you’re working with CUI and you need to be CMMC level two, you need to go get that C3PAO certification and you need it for having that contract. Right now, we understand it’s a little bit of a limbo, but this is where it stems from. And then CUI, for anyone who said they’re unsure, is the controlled unclassified information, and the level below it is FCI. So again, like I said, they’re two different bodies. CMMC, you’re based on your contractor information systems. It’s governed by the DoD. You’re aligning with NIST 800-171, R2 at the moment. We’re not in R3, which is the revision, high level. We’re staying on the R2 side. That’s what everyone’s auditing against. And then again, you’ve got your C3PAOs like Ignite, or the DIBCAC, the heavy arms coming in to say, hey, we’re here, we can audit you. FedRAMP is for your cloud, monitored and developed by the GSA, follows that nifty 800-53. There’s three hundred twenty three controls within 800-53, much more of a robust framework. And again, requires that 3PAO blessing. At a glance, we’re looking at CMMC, making sure we’re getting those federal contracts, applies to the organizations that are handling, processing or storing CUI on or for behalf of the government. And there are multiple levels of CMMC. You can be level one, two or extra special level three. And it can have self assessment as we’ve seen before. Level one can be self assessed to get your SPRS score. Level two, at the moment, currently, you can. That doesn’t mean you can in the future, or could forty five days ago, but it is now. And so that’s where we’re going there. Chapter FedRAMP and Cloud Compliance Moving on to the FedRAMP side of the house, what it’s covering. We’ve got that cloud aspect. So this is your applications that are run out of the cloud. They’re software as a service providers. And that’s where that comes in to saying, well, how are we responsible? How are we providing our customers with compliance? How are we making sure their data is remaining compliant? How are we proving transparency throughout? And FedRAMP said, we got you. We’re going to give you the 3PAO ability to audit against NIST 800-53 and a stamp of approval so that you guys can go forward and show good faith. So why does it all matter? Well, FedRAMP equivalency. This is the honeypot in the sense that not everybody is in cahoots with the government and can easily get an agency to support them or pay for it. So the DoD said, hey, we really need cloud products big time. We rely heavily on them like the rest of the world. And so the DoD said, let’s create the equivalency program. So now organizations who are fully compliant, in my opinion even more compliant than some of the ones that have agency ATOs, because they have to meet even more stringent requirements than a regular ATO would, now they are able to provide their services to the government because they have gone through and got the full FedRAMP equivalency. And that’s the DoD memo in the corner. It’s publicly available if anyone is into some light reading. There are many challenges that these compliance frameworks bring, and we see a lot of barriers in our line of work. A lot of times there are awesome and amazing processes and procedures and there are brilliant engineers and developers doing everything they can in the background, but nothing’s documented. It’s all siloed. It’s all within one person. The other one is resource limitations. Can one person really do it all? I know it’s a good idea. And then there’s the ambiguity of the NIST definitions and the control language. So we’re more than happy to clarify and go through all that ambiguity. And that leads to your third party independent assessment for the stamp of approval, for the 3PAOs to give to those with FedRAMP equivalency and those with full ATOs. We also can assess and audit them. What I’ll do, I know you want to ask this question now, Christina. What I’ll do is prep that question in the background and ask it in a second. If you want to move to your next slide and then we’ll get to that one. Yeah. If that’s okay. Yep. So in reality, you’re like, all of this is great information. A lot of people are saying, which side of the fence do I sit on? There’s a lot of confusion about which side of the fence companies apply to. Do they fall under CMMC? Do they fall under FedRAMP? Do they need it? What about who they’re trying to share information with? Does that company need CMMC or FedRAMP? Chapter Determining CMMC vs FedRAMP Needs So, you know, we’re letting you know that if you’re going to put your own controlled data into a cloud tool, that cloud tool should have FedRAMP moderate equivalency or higher. If you are connecting to another service that your CUI data is going to, it should be FedRAMP moderate equivalent or higher. If you are producing or manufacturing, leveraging information on or for behalf of the government directly, and you have partial on-prem or any type of manufacturing business, you make a product, you’re looking at CMMC. Okay, Christina, thank you so much for that. First of all, I’ll open up to the audience as well. Any questions at this point? Christina has done a really good overview there and thank you for that, Christina. That was super helpful. I think you’ve laid it out really well. You’ve set out the landscape in terms of the general type of topic, the general type of information that people might need on this webinar. Is there a question or a topic that pops up with you the most? Is there something that most organizations struggle with? Yeah, I would say that most organizations struggle with where they sit. We see a lot of organizations come in that thought they needed CMMC because of customers, thinking also that their own customers required CMMC of them. So they spent the time, they spent the money, they did all that due diligence to learn CMMC, and then they went to scope their boundary and they realized, oh no, I’m actually a cloud product. I don’t need CMMC. So now they have to shift gears. They have to re-scope. They have to rethink how they’re going to maintain compliance and provide compliance, because CMMC is not as in-depth as FedRAMP. Makes total sense. This is the question that Christina wanted to ask earlier. So again, I’ll put it up on screen, you can click the slides. What is your concern when it comes to compliance? And Christina, we can roll to this question once we get a few more answers. But is it tooling? Is it timing? Is it knowledge, budget? Is it all of the above? Or is it other elements? If it’s other, feel free to drop it in the chat. But maybe it’s a good time to roll over to VisibleThread and the collaboration with Ignite. Chapter VisibleThread and Ignite Partnership I know, Andrew, from your perspective, you are very much involved in the process and the want to make sure we’re FedRAMP equivalent and make sure that we have a new offering for our customers that meets regulation standards. What was the process there? What was it like working with Ignite? Why did we do this process in the first place? Yeah. So, thanks, Micheál. So I think we, at VisibleThread as a company, tend to view projects like FedRAMP equivalency as a journey, not just a task. So this isn’t a tick-box exercise for us. So when we started on this project, we did, like we do with all of our major projects, start with a simple question. Why are we doing this? What are we doing it for? We view FedRAMP equivalency as something we are, basically. It’s not so much something we have, or something we need to produce a certificate for, but something that reflects who we are and matches the core DNA of what we try to achieve here at VisibleThread. So that led us to look for someone who wasn’t just going to give us a checklist and make sure we ticked things off. We were looking for a 3PAO and a CMMC assessor that would accompany us on the journey and work with us, make sure we were maximizing our opportunities, make sure we could see the entire three-sixty degree view of FedRAMP equivalency and the opportunities it offered. And for me, that’s where Ignite came in. And from the first conversations, it was obvious to all of us, I think, that what we could achieve with Ignite was a true partnership where we had common purpose and a common goal in mind, and an understanding that we were on a journey, not just performing an exercise. I have to say, I think it’s a decision that’s been validated repeatedly during our relationship with Ignite. So I, for one, am very pleased with it. Very good. And Christina, if you have a reaction to that? Absolutely, yes. We treat it, we call it “mom as a service” or “dad as a service,” because we develop relationships with our teams, and it’s forward thinking, right? Because after FedRAMP, there’s ConMon. We’re linked. We care deeply about the product. We know that it’s beneficial to all of your customers, and how amazing you guys did putting it together. So we’re invested. Appreciate that. Yeah. As I said, that’s kind of a succinct way of putting what I was trying to get at, that relationship came across right from the start, and it’s been something that’s made, I wouldn’t claim the journey’s been pleasant, you know, it’s been illuminating, and that attitude that Christina just displayed has been extremely helpful, and it’s why we chose to work with Ignite in the first place, and very, very pleased with it. Very good. Bring Kyle in. Kyle, you’re in the weeds with the customers. You’re speaking to customers, I’m going to say every hour at this point. But who is asking about FedRAMP? Who is asking VisibleThread about questions? What type of organizations, industries? What comes up over and over again? Sure, yeah. So starting broad and then narrowing, just right off the bat, anyone that does work with the DoD, certainly probably the highest density of questions and concerns, and rightfully so. I’d say really, but also organizations that maybe are non-traditional contractors looking to get into the market with just changes to the procurement process. If you’re less familiar with government contracting in general, the cyber security context can be, I’d say, daunting. So we get questions there, and then in terms of who is actually asking the questions, obviously IT, security, ITCO teams, but also leaders whose teams engage with CUI or FCI every day. So program managers looking at an Air Force statement of work, proposal managers who are looking to write a proposal that then generates CUI. So we’re seeing it from the end user standpoint as well. So a pretty wide gamut, but everyone from Fortune 500 organizations all the way down to 8(a) SMBs. So it’s been pretty interesting, but it’s certainly a common topic and I hear it every week, if not every day. Fabulous, and I wonder, does this align with Christina’s poll about what people’s biggest concerns are? It’s not actually the tooling side, it’s more the traditional blockers in terms of timing, knowledge, budget. “Other” is popping up there. I’d love to know what that is if you drop it in the chat. Christina, is this regular, what you see? Is it mostly timing, knowledge, budget? Yeah, I would say that with knowledge comes power, and we’re more than happy to share all of it. So that’s part of the journey, right? And as you mentioned it being daunting, we try to make it a little easier as we go. Timing, I think, is underrated on our side. A lot of organizations will come ready, gung-ho, ready to fight, ready to do all the things, and they’ve got ninety days and here you go. And then I look under the hood, no, sir, you do not have ninety days worth of work. You have a little bit more than that. So I think one of those misconceptions we find often is timing seems like it would be a no-brainer, but when IT’s running around to do what they do, timing gets a little stretched. And budget-wise, everyone has one, and we try to be flexible, that’s the point of having Ignite. You know, if it’s on-prem, if you can think it, you can do it, and the budget can be stretched. Sure. Kyle, any reaction to this? Does this align with stuff that you see too? This does. I’d say the shift I’m seeing is, earlier on in the process, maybe the last year to six months ago, more of a knowledge gap. To Christina’s earlier point, do I need CMMC? Do I need FedRAMP? Which one? I’m throwing the kitchen sink, I need it all. So there was some initial scoping knowledge gap. I think for the most part now, we’re getting into more of the timing and budget. Now we need to execute, whether it’s in ninety days or not, to Christina’s point. So that’s I think been the shift. But yeah, this breakdown aligns with what I’m hearing certainly. Okay, well, moving swiftly on then to the VisibleThread portion of this. I see lots of customers, but I see lots of names that I don’t recognize in the chat as well. Suppose, Kyle, our organizations, our customer base is very vast, very wide, and every organization is different, especially when you get to the more enterprise side. They all have different processes. They have different wants and needs and requirements. We try to be as flexible as possible. We’ve been in the industry over fifteen years. We’ve worked with all organizations, big and small, different industries from healthcare to defense to IT services. So we need to have a plethora of options for our customers. Maybe in a light overview, could you give a sense of the different types of deployment options that we currently have, and maybe what types of customers fit into what box most regularly? Chapter VisibleThread Deployment Options Yeah, absolutely, and as we’ve been discussing, it’s not one-size-fits-all, so we have deployment options that meet our customers where they’re at. So moving left to right: customer-hosted, on-premise, these would be our highest security-conscious customers. We might be doing classified work, maybe not every day, but we have those capabilities and those needs. So in that case, and let me actually take one step back. As you’re looking at these options, what organizations need to be thinking about is where does my controlled information live or reside, and then whose assessment does it fall under. So for a customer-hosted on-premise deployment, I need to have physical control of my CUI, for example, and in that case, we would fall under that organization’s CMMC assessment umbrella. For customers where they might not necessarily need to have physical control of all that information, they would still host, but they’d do so in a private cloud. And in that case, once again, they would still be falling under their own CMMC assessment umbrella. GovCloud single-tenant, that’s a VisibleThread-hosted option where we will do all the updates, manage all the generative AI capabilities on behalf of our customers, where you could upload CUI in this environment as well, but in this case, you’d be falling under VisibleThread’s assessment umbrella. And then finally, that public cloud multi-tenant, this would be the lightest weight option if you’re doing basically zero sensitive type work. This is a great quick option, where VisibleThread would do the hosting, but certainly wouldn’t put CUI into that option. But we do have customers that just don’t do that kind of work, so we need to have an option there too. So long story short, if you’re doing high-security work, you want to be on the left side of this spectrum; over to the right, less secure, maybe smaller. So hopefully that’s a pretty good breakdown. Yeah, there is indeed. And there are variables within each box as well, isn’t there, Kyle? Every organization has different requirements, especially when you get into things like AI and integrations into SharePoint. We have options there which are different. We allow customers to make their own path when we get into an IT discussion. Yeah, exactly. For example, we allow customers to pick their own large language model. So we have LLMs that back a number of our AI-powered features, such as a busy chat and so on. We allow customers to select which one they’re using. And if you’re on-premise, you can have a locally hosted one if you want, or you can pick between the various models that we allow. So, yeah, our view is that AI is always in support of a human, and we aim to give the human as much control and flexibility as we can with that. I appreciate that, and I know it has come up in very recent discussions with bigger enterprises and expansions, so if you have detailed questions there, we’re happy to take them on the webinar, or we’re more than happy to talk about deployments afterwards if it’s a specific use case. Christina referenced this, there was news about the CMMC phase two being suspended, and that caused a little bit of confusion in the market as well. Do we even need this anymore? I know Andrew had some dealings with this as well and answered some questions with customers. Yes, absolutely, yes, you do still need it. The cloud provider requirement was not part of the pause. What was paused was level two C3PAO assessments and level three government assessments. And this is just while the reform task force does its review. DFARS 7012, phase one self-assessments, SPRS submission, annual affirmations and subcontractor flow-down all continue. And as I stated at the start, the cloud provider requirement was never paused anyway. So yes, absolutely. Makes sense. And this is a question for Kyle, because this is the question that we get all the time. And I think it ties into what Andrew said about this being a journey and what Christina said about this being a pattern. There’s always a next step when it comes to this. Where are we today from a VisibleThread perspective? Are we FedRAMP compliant? Could you give a little bit of an overview there? Sure, always a good question to ask a former contracts manager. So where are we at today? We are FedRAMP ready as of July seventh, so now if you go into the FedRAMP marketplace and look for VisibleThread, you’ll find us as a result of that distinction. We’re currently going through our full assessment with Ignite right now, and so if we were to attest today, we’d say that we’re DoD FedRAMP moderate equivalent, and we’re certainly happy to provide that evidence as required to any customers who ask. So exciting times, we’re making good progress, that’s where we’re at today. Fabulous, and this kind of line of questioning is our frequently asked questions from customers and prospects. So I feel like it’s helpful for Andrew and Kyle to answer them here. And actually, Micheál, just one more aside, just to put a bow on that, into what Andrew was mentioning earlier about this being a journey. So this is where we’re at today. If a customer were to ask us a similar question later in the year, it will change as we move through the process, and so you should be asking that of your own vendors for any organization out there that’s engaging other software providers. For sure. Andrew, I’ll move back to you, we’re already in AWS GovCloud. Doesn’t that make us compliant already? That was kind of the thought process with some folks. Yeah, so AWS GovCloud and GCC High cover the infrastructure only. So it’s a bit like saying, “I bought a Ferrari, it can do a hundred and fifty miles an hour, so I can do a hundred and fifty miles an hour.” It’s not quite the same thing. You have the capability, but GCC High only tells us that the infrastructure complies. It says nothing about the services running on top of it, much like someone who’s just stepped into their first Ferrari, we don’t know whether you can actually do that or not. You can’t just assume that because the infrastructure complies, that anything you do on top of that will also comply. The services have to be assessed separately. So as we said earlier, we view FedRAMP equivalency as something we are, not just something we have. We view this as a journey, but also one that’s of high value to ourselves, making sure that we’re delivering the best experience that we can for our clients and customers. We’re setting the stake out there that we really are the leaders, and we want you to know we’re the people you should be choosing to be with. But the simple answer is no, it only covers the infrastructure, and everything built on top of that has to be assessed separately. Makes total sense. So, Christina, I might just pull back to you for a second because I think we see the FedRAMP logo in lots of places, especially when our prospects come to us, there’s a little bit of transparency needed. “Oh, I saw the FedRAMP logo, therefore isn’t everybody FedRAMP equivalent?” You’ve worked with VisibleThread on this journey. Why is ours believable? Why should people trust us? In your words might be helpful. Absolutely. Well, because Ignite is persistent and thorough. We have vetted VisibleThread. We have left no stone unturned. As someone said earlier, it’s daunting. We try our best to make it lighter, but we still take compliance very seriously. With FedRAMP equivalency versus an ATO, the 3PAO accepts the risk on behalf of the organization. So I do believe that any responsible 3PAO out there would want to make sure their risk was a little lighter. So we make sure that everything we’re viewing and approving meets the standard, if not higher than what it would otherwise be. And, for example, on your previous slide, with the cloud options, that’s a very huge misconception that comes through: people say “we’re good” and put the label on there. They’ll say, “yeah, we’re FedRAMP, we sit on top of AWS GovCloud.” Just because I pay for my electric doesn’t mean I turn all my lights on. So I have to be able to configure it. And we’re here to say that VisibleThread is thorough and compliant. Appreciate that. And I know, Kyle, this is kind of a question you might have to bat away every so often. Do you come up against this question a lot as well? I’d say this is maybe more common in the sales cycle. Within our existing customer base, we’ve had some customers with us since 2013, 2014, which predated some of this conversation. So I think it comes down to, if you’re an existing customer that hosts VisibleThread and has always hosted VisibleThread, it’s a question, but it’s a little bit less common and urgent because we’re falling under that umbrella. Now if customers are exploring different hosting options, particularly with the advent of AI features that have usage and token costs, that question can come up if organizations are exploring our GovCloud options, certainly. So we get the question, but generally it’s kind of where they’re at in their deployment history and whether they’re thinking of making a change. Appreciate that. I’ll skip one. And an important one, actually, because I think the introduction of generative AI and this explosion of technology that we’ve all faced over the last maybe three years has raised a lot of questions as well. Chapter Generative AI and Data Security At VisibleThread, we’re very conscious of how we deployed AI into our product and how we advanced some of our own functionality. But rightly so, lots of customers and prospects ask questions around AI and VisibleThread. Andrew, could you cover a little bit of that today, in terms of AI features, where does my content go? Yeah, so it’s important to note that certainly in the GovCloud environment, our capability runs on AWS’s managed AI service within GovCloud. So that is covered by the GCC High boundary that we talked about earlier. These services sit inside the same GovCloud boundary as the rest of the deployment. So your content, your data, your questions and queries do not ever leave our boundary. They don’t go to a third-party model provider. They stay within GovCloud and run on the AWS managed AI service. Makes sense. So you hear that term “training the model” come back a lot. Do you find, Andrew, that people worry about that? Yeah, it’s actually quite a valid concern. If you remember, there was a piece of news a while ago about people writing queries that ended up searchable on Google, it was a temporary glitch, but still a major concern. So the fact that this content never leaves the GovCloud boundary is critical. That data cannot be used to train the models. Now, if you go on something like public ChatGPT and enter questions, they will use that data to train their model. For us, we do AI-agent-powered software development. We use Claude Code. Claude guarantees that your software is not stored and it’s not used. Your prompts are not stored, your software is not stored, none of it is used to train the model. So yeah, it’s something that gets asked a lot, and I understand the worry behind it, because there have been instances in the public sector, and some not public, where data has been leaked. Having said that, AWS’s managed service, as far as I’m aware, has had no issues at all, and everything we do stays within that boundary. So that’s why it’s CUI-safe. It’s safe to put your CUI information in GovCloud because, even if you’re using their AI services, it’s not going beyond the boundary. This is one of the things that Christina and our DevOps team have been all over. We make very sure that we know exactly what our boundaries are, where things are installed, whether we’re changing them. We have a change control board that meets once a week to discuss what changes are going out. And one of the things we always go through is: is this doing anything with our boundaries? If it is, we need to loop in Ignite. We need to plan in advance, they need time to review, and so on. So yeah, I can understand the question certainly, but if you’re using the VisibleThread GovCloud solution, it’s not one you really need to worry about, it’s handled and it stays within the boundary. Fabulous. And Christina, I can see you smiling and nodding along there. Would you add to that? Yeah, I mean, to the extent of knowing your boundary and what the left and right is, after FedRAMP you’re going to wish you’d taken it to dinner first, because we know everything, and we want you to know everything about your boundary, because that’s how you build your relationship with your customers. It’s all about transparency and honesty, and FedRAMP is part of that too. So we come in and make sure that everyone is being accountable, and VisibleThread has done an amazing job of that. Yeah, thanks Christina. And that’s kind of what I meant earlier when I referred to this being part of our DNA and something we are. It’s the idea that we are transparent, we are on the side of our clients, we are doing our best with them, and we are doing everything we can to make sure this works as it should. And that’s the purpose of this webinar really, to show trust and validation and honesty, and, in changing times when there is confusion out in the market, to be transparent and answer these questions and have an open forum for them. That’s really important to us. And hopefully we’ve built that trust. What I’d like to speak a little bit about now is, if you’re on GovCloud with VisibleThread, or if you’re on-premise, why should you upgrade? Why should you get to the latest version? If you’re a new customer, what should you expect? We’ve had an amazing release schedule over the past six months or so since we launched the full platform combining our two products. And very recently, we’ve had a major release with 7.3. I think for customers who are on-premise and maybe don’t have the up-to-date version, or people who are new or unaware of what we do, Kyle, I’d love you to speak about some of the latest functionality in our latest release. It’s quite exciting. Chapter VisibleThread Platform Release 7.3 Yeah, this is my favorite slide here. Bottom line here with 7.3: organizations don’t need to choose between security and the most up-to-date firepower available, and that’s important. We don’t want features to get ahead of the security side. So however you’re choosing to deploy, you have access to 7.3, the most powerful version of the platform. I’m using AI daily just to figure out what’s coming down the pike, because the engineering team is going a little too fast, which is rare for me, I’m pretty quick. So just a couple of things to touch on. Particularly if you’ve been a long-time VisibleThread user, everything you know and love about VisibleThread today is there, improved. But in terms of brand new features and philosophy, big focus on ownership and collaboration. So, I’m generating content, reports, analysis with VisibleThread, but who do I need to look at it, review it, approve it, contribute to it? Whether it’s a shred, a comparison of a statement of work, whatever it is, more ability to comment, to mention, to call out, to tag. Really important. When it comes to process, moving through stage gates, the ability to customize as an opportunity moves from initial assessment, bid/no-bid, into the proposal lifecycle. Users can now customize stage gates. Are certain tasks being completed? Are certain outcomes achieved before we move it along? So beyond just the features of the software, this is allowing organizations to inject their existing processes into it. Really important from an adoption, compliance and governance standpoint. Auditability, when we talk about AI in VisibleThread, where is it coming from? How do I know who’s using it, and doing what? Where is this content coming from? So improved usage reports and dashboards. If I’m moving things through stage gates, we can see why and how that decision was reached. And then finally, rationale traceability, whether I’m using AI technology or a deterministic approach, we can show you exactly where outputs and ideas are derived from. So this ability to trust but verify, maintaining a human in the loop, you’ll see how the product’s been thoughtfully designed to put users in a position to say “yep, I agree with this, and I can prove to myself or to peers where this information came from.” So really, really important, and whether you’re using VisibleThread or any other AI-enabled piece of software, users should be asking: where did this content come from, and how do I know it’s valid? So really excited here about 7.3. I’m an excitable guy, but this is more exciting than normal. Yeah, it was a wonderful release, and if you’re not up to speed, we have office hours running every second week where we run through different elements of the platform, with great user interaction. That’s with Alison Ritz, our Director of Product Marketing, so stay tuned to those updates. Last week she ran through all the updates in 7.3 and demoed it, that’s accessible on the console. I want to pivot a little bit to Andrew at this point. Kyle spoke about what we have now, is there anything you’re excited about that you’re willing to share with the group for the near future? Yeah. So firstly, I mean, 7.3 was, I’m going to take full credit for it, even though it happened right as I joined. So it came in an easier way, joking aside, it really was a very big release. We went very ambitious with it. Chapter Future MCP Server Integration One of the things that didn’t quite make it into the initial release, because we wanted to perfect it, was an MCP server. So what we’re delivering, and will be released in the next couple of weeks pending testing completion, is the ability for your AI tools, such as Claude Desktop, to connect to your VisibleThread instance, and you can ask it questions. We’ve been doing demos where you’ve opened a Word document and realized, “oh, actually I could do with tracking this.” You can add it to an opportunity and then shred it. And the really nice thing is that it feeds straight into the existing auditability trail. We know that it’s been done, and we know it was done by MCP. It’s done under your single sign-on, so it’s done under your authentication and authorization. So the user can’t do anything they’re not allowed to do in the standard product. You can tell who did it, when they did it, why they did it, and it integrates perfectly with the main VisibleThread product. So let’s say I’m traveling, I’ve got my phone, I log into Slack, and I’ve got the connector set up, and I say, “okay, I need you to shred this document in this tracked opportunity using this dictionary.” I would then be able to comment to you, Micheál, and call you out and say, “can you check this? I’ve shredded it for you, can you give it an eye over?” Even though I did that in, say, a Slack instance of an AI agent connected to an MCP server, you’re able to log on to the server or view it via another AI agent, and it’ll show exactly as if I had logged into the full product and done the full task there. That’s just going to be expanded over time. And the really nice thing with MCP, and we’re using it internally ourselves, is the way you can chain MCP servers together. So we’ve done various things where we’re chaining various sources to generate reports, and they’re completely disparate, and we’re asking, “okay, what are we seeing on this topic?” You and Kyle have worked together on Claude skills, Micheál, where we’re able to ask very complex questions across multiple sources. VisibleThread will be one of those sources going forward. And all the things you see here, stage gates, compiling proposals, auditability, ownership, etcetera, all of that will be available via MCP. Not from day one, but we’ll release it on a routine schedule throughout the rest of the year. So that’s one thing we’re very excited about. We have SharePoint integration coming up in 7.4, I think. That’s really interesting. There are some additional features where we can really lock down what site you have access to within SharePoint. That’ll be very interesting to go through. There’s also very interesting work on proposal outlines, I trust you, I can’t really pick my favorite. I think my favorite though is still MCP, largely because I worked on that in a heads-down session with one of our lead engineers shortly after I started, just to say, “can we do this, how does it work?” We sat down and bashed it backwards and forwards for a couple of weeks and had a working prototype at the end. So, yeah, it is genuinely exciting times. No worries. To be here. Yeah. And MCP is almost limitless, it’s up to the imagination of the user. There are a lot of really innovative VisibleThread users out there. For years I’ve asked, “what’s possible?” And I think the MCP server is really going to open that up. Absolutely. Yeah. You can work it into your own workflow. Claude Desktop, for example, gives you scheduled tasks. So you’ve got multiple sources, VisibleThread is one of them. You can run a scheduled report using the VisibleThread MCP server, or whatever it is you want to do. So, yeah, it’s really, really flexible. It allows an enormous amount of flexibility for existing customers. Most importantly of all, it’s fully locked down and secure. You’re not opening up any new routes into the software in terms of risk, because it’s all handled under the existing single sign-on and authentication/authorization. So yeah, it’s going to be a very, very powerful feature. Well, that’ll be a great webinar whenever we get to that point, Andrew. I think there’ll be a lot of interest in that. As you can see, I get very excited about it, so just wind me up and point me in the right direction. For sure. Well, look, we’ll take any questions from the audience, so feel free to drop in questions if you have direct ones. Obviously, if it’s very technical or specific, we’re here afterwards to tackle any questions one-on-one, or you can book a technical meeting with a customer or prospect. Chapter VisibleThread Version Update Outreach I’ll note as well, we’re doing a bit of an outreach campaign to our customers at the moment to make sure they get the benefit of what Kyle went through there. So in the next week or so, if you’re not on the latest version of VisibleThread, expect to be contacted to get on the latest version, or at least be very clear on what you’re missing out on. Those conversations are happening rapidly right now, a lot of interest, a lot of people wanting to get on the latest version. So keep an eye out for those emails and book in time. We’re excited to get people using the new stuff, or maybe make a transfer over to GovCloud, because that might be a more suitable option for them. I have one question here related to our timeline, when exactly will we have equivalency? Andrew, you’re working directly with the leads there who are currently going through the process, would you mind answering that? Yeah, I can’t predict that exactly. We are starting the audit next week. We’re expecting it to take a week or so. Christina might have more information she’s happy to share on that. But it’s one of those tasks that, should it all go smoothly, we should have it by the end of the month. But it may take longer, it may go quicker, may go slower, but we are starting next week. That’s about as accurate a timeline as I can give. Chapter Evidence Submission and Data Processing Thank you, Christina. And a question came in via the chat about the provider’s evidence and workload submission, what do you do with that evidence? Where does it go? How do you process it? So on the auditing front, any evidence that Ignite takes or processes is stored securely for the necessary parameters and retention logs under the C3PAOs and FedRAMP. When we’re looking through evidence, it’s twofold during auditing. Some of it will be part of a discovery experience, where auditing evidence is required ahead of time to show good faith of what everyone has under the hood, and whether they’re ready. And then there’s the second fold, during live audits we require screen sharing and real-time screenshots to support the evidence package, which is hashed. If it’s under the CMMC side, it’s sent up to the government for the eMASS system. And on the FedRAMP side, depending on whether it’s equivalency or a full ATO, it’s kept in-house or moved over to the FedRAMP side. Perfect, that makes a lot of sense. Chapter GovCloud Data Access and Security I might finish with this one, Kyle and Andrew, I’ll let you decide who takes it. If I’m a US GovCloud client, who at VisibleThread can touch our data? Do you have an accurate answer for that? I’ll start, Andrew, and then why don’t you add any additional color I’m missing. So in short, it’s a single-tenant environment. You’re isolated in your own workspace, think of it as a sandbox. And all that infrastructure is managed by US persons. Andrew, anything else to add? But I think those are two important variables to lead with. Yeah, that touches on the important difference between single-tenanted and multi-tenanted. Single-tenanted is equivalent to an on-premise installation in the cloud. And you also mentioned something very important, that US citizens are the only people who can touch anything. For example, even as CTO of VisibleThread, because I’m a British citizen, not a US citizen, I can’t access logs from the VisibleThread product in GovCloud. And that’s by design. We have US citizens based in the US whose roles are to manage and support the GovCloud environment. Yeah, and boundaries are firm. They’re being thoroughly investigated by Ignite. We’re not just saying this, it’s rigidly enforced, and it’s checked, confirmed and audited by very competent and dedicated auditors. So, yeah, your data doesn’t go to any competitor, can’t be reached by anyone, and only US citizens can touch any of the data or logs. Okay. Well, I think that is a great place to leave it. Chapter Webinar Wrap Up and Support Resources I just want to thank Christina, Kyle and Andrew for your time. This was a very technical webinar, a different space than what we would normally do versus best practices and product overviews. It’s a highly specific topic. If you have direct questions for VisibleThread, Kyle has shared some links about working with your customer success manager, every customer has their dedicated person, but we also have a fully-fledged support team, and Andrew noted our US systems working on US GovCloud. So if you have direct questions, feel free to contact us. We’re happy to help. I’d also shout out Ignite, if you have general questions about FedRAMP and CMMC or anything in this space, they’re a fantastic partner. They know their stuff. We trust them heavily. So feel free to reach out to Christina and her team. Any parting words, Christina, Kyle, Andrew? Anything additional to say? No, thank you for having us. You’re very welcome. Well, thank you for your time. I learned a lot. If you have further questions, feel free to bring them to us. Thank you for anyone who joined. Thank you for your time, and happy to answer any questions afterwards. See you soon. Thanks. Thank you.