Palette VerteX achieves GovRAMP Authorized status at the Moderate impact level
Government buyers can now draw on a verified security assessment of Palette VerteX’s SaaS offering when evaluating the platform.
We’re proud to announce an important addition to our (long) list of security accreditations. Spectro Cloud’s Palette VerteX has achieved GovRAMP Authorized status at the Moderate impact level. For state agencies, local governments and educational institutions, this provides independently assessed evidence of the service’s security controls to support procurement and risk decisions.
A security assessment public-sector buyers can reuse
GovRAMP, formerly StateRAMP, is a nonprofit that helps public-sector organizations assess the security of cloud services. Its requirements are based on NIST SP 800-53 Revision 5, the security control framework also used by FedRAMP.
GovRAMP gives participating organizations a way to share the work of assessing a cloud service’s security. Your reviewers can draw on evidence that has already been independently checked, then focus on the requirements specific to your organization.
Authorized status requires an independent assessment by an accredited third-party assessment organization, verification by GovRAMP’s Program Management Office, and approval by a government sponsor or the GovRAMP Approvals Committee. Palette VerteX’s assessment was conducted by Schellman & Company, with the Approvals Committee serving as its sponsor.
The security package provides evidence about how controls are implemented, alongside the assessor’s findings. Your reviewers can use it to evaluate the service against your own policies and data requirements, and identify any additional checks needed.
Our SaaS, your workload
The authorization covers Palette VerteX’s SaaS offering. The security package documents the assessed system boundary, which your team should review alongside the responsibilities that apply to your intended deployment.
That distinction matters when a management platform connects to infrastructure you operate. The applications you deploy, the data they process and the access you grant still need to be assessed within your own environment. A platform authorization doesn’t automatically authorize every workload managed through it.
VerteX is available for self-hosted and air-gapped deployments as well, in which case our underlying controls can assist you in meeting your own FedRAMP or other compliance needs.
Security assurance continues after authorization
Maintaining GovRAMP Authorized status requires continuous monitoring. The program calls for regular vulnerability scanning, reporting and remediation, monthly submissions to the Program Management Office, and an annual assessment by an independent Third Party Assessment Organization (3PAO).
That gives your security team ongoing assurance during the life of the service to inform its ongoing risk decisions.
Managing security across your Kubernetes estate
We’re not just proud of VerteX’s own security credentials — we’re proud of how it helps you maintain a better security posture, too. Primarily it equips your teams to apply consistent configurations across clusters through reusable cluster profiles, which define the software stack from the operating system through Kubernetes and its add-ons. Role-based access control and security scans support the day-to-day work of managing that estate.
VerteX also incorporates FIPS 140-3 validated cryptography and we ship security hardened images. Our earlier FedRAMP and FIPS announcement explains those milestones; the VerteX documentation covers supported components and configuration requirements in case you need to go deeper.
Use the authorization in your evaluation
If you’re planning an evaluation, start with Palette VerteX’s entry on the GovRAMP Authorized Product List. Government members can request access to the security package and continuous monitoring reports through GovRAMP’s Government Engagement Team; access requires provider approval.
If your organization isn’t currently participating in GovRAMP, government membership is free. The program also provides procurement resources and sample language that your team can adapt to its own policies.
Talk to our government team to discuss the authorized service, review your deployment requirements and see Palette VerteX in action.

