Skip to main content

FedRAMP

Coralogix operates a FedRAMP Authorized observability environment in AWS GovCloud, separate from the commercial Coralogix regions. It is sponsored by the U.S. Department of Education's Federal Student Aid (FSA) office.

This page is the entry point for the environment. Configuration steps live on the same product pages you would use for any other Coralogix region, with the FedRAMP environment (GOV1) selectable in the domain selector.

Authorization status

Impact levelClass C (formerly Moderate)
Current statusAuthorized
Entity nameCoralogix Inc.
Cloud service provider nameUS GovOps
SponsorU.S. Department of Education, Federal Student Aid (FSA)
3PAOA-LIGN
EnvironmentAWS GovCloud, us-gov-west-1
FedRAMP Marketplace listingfedramp.gov/marketplace/products/FR2407275137

What's in scope

The Coralogix FedRAMP environment ingests three signal types:

  • Logs
  • Metrics
  • Traces

The environment runs on gov1.coralogixgov.us in AWS GovCloud us-gov-west-1. Customers access the environment through a tenant-specific URL of the form {tenant}.app.gov1.coralogixgov.us.

How to access

Access to the FedRAMP environment is limited by design. To request access or evaluate Coralogix for a federal workload, contact your account representative or email [email protected].

Connect to the environment

The FedRAMP environment appears in the domain selector as GOV1 (gov1.coralogixgov.us). Select it on any of the pages below and the endpoints, service names, and hostnames update to the FedRAMP values.

To do thisGo to
Find ingest and management endpointsCoralogix endpoints
Set up private connectivityAWS PrivateLink
Configure an S3 archive bucketConnect an S3 archive
Manage resources as codeCoralogix Terraform provider
PrivateLink cannot cross an AWS partition boundary

The FedRAMP environment runs in the aws-us-gov partition. A consumer VPC in AWS GovCloud can reach it over native PrivateLink. A consumer VPC in the commercial partition (aws) cannot, in any region, because AWS provides no cross-partition PrivateLink path.

Workloads outside AWS GovCloud send telemetry to the FedRAMP environment over its public endpoints instead.

Deployment models

Customers connect to the FedRAMP environment in one of two patterns:

  • Direct SaaS on GOV1. Your workloads send telemetry to the public GOV1 endpoints, or through PrivateLink from AWS GovCloud. Your tenant lives on {tenant}.app.gov1.coralogixgov.us. This is the pattern most customers use.
  • BYOC with PrivateLink. You run Coralogix ingest components in your own AWS GovCloud account and forward data to GOV1 over PrivateLink. Use this when the ingest plane has to stay inside your own boundary. Your AWS account must be allowlisted on the Coralogix PrivateLink service.

Customer Responsibility Matrix

FedRAMP authorization rests on a shared responsibility model. Coralogix controls the observability platform and its hosting environment. You control the workloads, data, and identities you connect to it.

The Customer Responsibility Matrix (CRM) is the document that sets out which controls are yours. It is delivered as part of the Coralogix FedRAMP documentation package, which you can obtain in either of two ways:

Review the CRM before you go live. It is the authoritative statement of the controls you are responsible for implementing in your own environment.

Support

The FedRAMP environment has its own support mailbox, staffed by personnel cleared for the environment. Use it instead of the general Coralogix support address for anything that concerns a FedRAMP tenant.

ForContact
Incidents and technical issues in the FedRAMP environment[email protected]
Account, onboarding, and access requestsYour Coralogix account representative

Compliance and data privacy

For the cryptography, data-in-transit, jurisdiction, and change-management commitments that apply to the environment, see FedRAMP data privacy.

Last updated on