Legal
Compliance
How Excalibur supports organizations that operate under FedRAMP, GDPR, and other regulatory frameworks.
1. Our Approach
CyberAGI's approach to compliance is architectural. For enterprise customers, Excalibur is deployed entirely on-premises, inside infrastructure that you own and control. Your data never leaves your environment, and CyberAGI does not ingest enterprise customer data into any CyberAGI-operated cloud. Because sensitive data never reaches us, entire categories of regulatory exposure are removed by design rather than managed by policy.
2. Deployment Model
On-premises by default. Enterprise deployments of Excalibur run within your controlled environment. All processing, including storage of sensitive and personal data, occurs on your infrastructure.
No data egress. Enterprise customer data is not transmitted to, stored in, or processed by CyberAGI-operated systems. Telemetry and diagnostic information may be collected solely for troubleshooting and service improvement, and such telemetry does not include personal identifiers.
Your boundary, your controls. Access controls, network segmentation, encryption, and monitoring remain under your authority and are enforced by your existing security stack.
3. FedRAMP and Federal Deployments
CyberAGI is not FedRAMP Authorized, and we do not claim to be. FedRAMP is a U.S. government program that authorizes cloud service offerings operated by vendors. Excalibur is not operated as a CyberAGI-hosted cloud service for enterprise customers; it is software deployed inside your own environment.
For federal agencies and organizations that handle federal data, this deployment model means Excalibur runs within your existing authorization boundary rather than introducing a new external cloud service that would require its own authorization. Your Authorizing Official and your ATO process govern the environment in which Excalibur operates.
Excalibur is architected to support teams working in FedRAMP-regulated environments. The platform includes NIST SP 800-53 framework content and control mapping, which is the control catalog on which FedRAMP baselines are built, and provides artifact and evidence management workflows that support assessment and authorization activities.
4. GDPR
There is no official GDPR certification for software vendors, and CyberAGI does not claim one. GDPR places obligations on data controllers and data processors. For enterprise on-premises deployments, CyberAGI does not receive, store, or process personal data from your environment, which means we do not act as a data processor for those deployments.
Your organization remains the data controller, and personal data stays within infrastructure you control. Because you choose where Excalibur is deployed, data residency requirements, including keeping data within the European Union or within national borders, are satisfied by your deployment decision rather than by trusting a vendor's data handling.
5. Framework Support
Excalibur is framework agnostic. NIST SP 800-53 ships with the platform, and additional governance and compliance frameworks can be added on request. Controls can be mapped across frameworks so that evidence collected for one assessment can support others, reducing duplicated work across overlapping regulatory obligations.
6. What We Do Not Claim
In the interest of accuracy, CyberAGI does not claim the following:
- FedRAMP Authorized, FedRAMP Ready, or any other FedRAMP Marketplace status.
- GDPR certification, since no such certification exists for software vendors.
- That deploying Excalibur makes your organization compliant with any regulation. Compliance obligations remain yours, and Excalibur is a tool that helps your team meet them.
7. Questions
If your security or compliance team would like to discuss deployment architecture, data handling, or framework support in detail, contact us at legal@cyberagi.ai.