Trust Center
Last updated: 20 September 2026 · FedRAMP 20x Initial Implementation
This page is Toonimo's public Trust Center for the Toonimo Digital Adoption Platform (Toonimo-DAP). It is the human-readable half of the information FedRAMP requires under CDS-CSO-PUB. The machine-readable Certification Package Overview is published at /fedramp/frc-cso-pkg.json.
Cloud service offering
Toonimo Inc. provides a multi-tenant SaaS digital adoption platform: in-application walkthroughs, AI chatbot and voicebot guidance, process intelligence, and analytics that help employees and constituents complete tasks in existing web applications. The runtime is containerized on Kubernetes on commercial cloud (Oracle Cloud Infrastructure and Amazon Web Services).
- Service model: SaaS
- Deployment model: Public Cloud
- Certification path: FedRAMP 20x Class C (Moderate), Program Certification (no agency sponsor)
- Marketplace phase: Initial Implementation (listing requested)
- FedRAMP ID: pending assignment (placeholder TOONIMO-DAP)
Federal use case
Direct use. Agencies can deploy Toonimo-DAP into a federal information system (44 U.S.C. § 3506) so employees and members of the public receive in-application guidance on agency portals, benefits applications, HR systems, and case-management tools. The offering is intended to receive an agency Authorization to Operate as part of that system, or to be listed for reuse after Program Certification.
Indirect use (alternate). Toonimo-DAP can also run as a third-party information resource inside another cloud service offering that federal customers already use.
How to access non-public materials
SOC 2 Type II, ISO 27001, the System Security Plan, KSI evidence, and 3PAO materials are shared with agencies, the FedRAMP PMO, and accredited assessors under NDA. Email security@toonimo.com with your agency or company name, role, and the artifacts you need. Public vulnerability reports go to the vulnerability disclosure program.
Continuous progress (quarterly)
FedRAMP Initial Implementation listings must show progress against documented goals at least quarterly (MKT-IIP-DCP). Status below is Toonimo's self-measurement against the Class C 20x plan.
| Goal | Target | Status (20 Sep 2026) |
|---|---|---|
| Marketplace Initial Implementation listing | Q3 2026 | Packet published; form submission pending FedRAMP.gov access |
| Public Trust Center + listing JSON + VDP | Sep 2026 | In this release |
| CI security gates (Trivy, OSV, Gitleaks, Semgrep, Checkov, Syft) | Oct 2026 | Workflow added; first evidence artifacts on next CI run |
| KSI collectors for 24 already-strong KSIs (2 methods each, 3-day cadence) | Oct 2026 | Engine running in repo; cloud/API collectors still to wire |
| CSPM, SIEM, FIDO2, FIPS crypto | Nov 2026–Jan 2027 | Not started (requires cloud and IdP admin access) |
| 3PAO assessment scheduled | Book by Q4 2026 for Feb–Apr 2027 | RFP drafted; not yet sent |
| Class C package to FedRAMP PMO | Mar–May 2027 | Blocked on persistent validation history + 3PAO |
Secure configuration (customer-controlled)
Customers control SSO/IdP federation, which applications Toonimo overlays, author roles, data-retention settings, and whether AI features call customer-hosted or Toonimo-hosted models. Toonimo does not require customers to place federal data in a Toonimo-managed training corpus. Full Secure Configuration Guide pages will be issued with the 20x package.
Existing independent assurance
- SOC 2 Type II (EY / KFGK, Feb 2025–Jan 2026 period)
- ISO 27001 information security management system
- Annual independent penetration test (commercial program; FedRAMP 3PAO pen test still required)
Contacts
- Security / FedRAMP: security@toonimo.com
- Sales: sales@toonimo.com