Pular para o conteúdo principal

Trust Center

Last updated: 20 September 2026 · FedRAMP 20x Initial Implementation

This page is Toonimo's public Trust Center for the Toonimo Digital Adoption Platform (Toonimo-DAP). It is the human-readable half of the information FedRAMP requires under CDS-CSO-PUB. The machine-readable Certification Package Overview is published at /fedramp/frc-cso-pkg.json.

Cloud service offering

Toonimo Inc. provides a multi-tenant SaaS digital adoption platform: in-application walkthroughs, AI chatbot and voicebot guidance, process intelligence, and analytics that help employees and constituents complete tasks in existing web applications. The runtime is containerized on Kubernetes on commercial cloud (Oracle Cloud Infrastructure and Amazon Web Services).

  • Service model: SaaS
  • Deployment model: Public Cloud
  • Certification path: FedRAMP 20x Class C (Moderate), Program Certification (no agency sponsor)
  • Marketplace phase: Initial Implementation (listing requested)
  • FedRAMP ID: pending assignment (placeholder TOONIMO-DAP)

Federal use case

Direct use. Agencies can deploy Toonimo-DAP into a federal information system (44 U.S.C. § 3506) so employees and members of the public receive in-application guidance on agency portals, benefits applications, HR systems, and case-management tools. The offering is intended to receive an agency Authorization to Operate as part of that system, or to be listed for reuse after Program Certification.

Indirect use (alternate). Toonimo-DAP can also run as a third-party information resource inside another cloud service offering that federal customers already use.

How to access non-public materials

SOC 2 Type II, ISO 27001, the System Security Plan, KSI evidence, and 3PAO materials are shared with agencies, the FedRAMP PMO, and accredited assessors under NDA. Email security@toonimo.com with your agency or company name, role, and the artifacts you need. Public vulnerability reports go to the vulnerability disclosure program.

Continuous progress (quarterly)

FedRAMP Initial Implementation listings must show progress against documented goals at least quarterly (MKT-IIP-DCP). Status below is Toonimo's self-measurement against the Class C 20x plan.

GoalTargetStatus (20 Sep 2026)
Marketplace Initial Implementation listingQ3 2026Packet published; form submission pending FedRAMP.gov access
Public Trust Center + listing JSON + VDPSep 2026In this release
CI security gates (Trivy, OSV, Gitleaks, Semgrep, Checkov, Syft)Oct 2026Workflow added; first evidence artifacts on next CI run
KSI collectors for 24 already-strong KSIs (2 methods each, 3-day cadence)Oct 2026Engine running in repo; cloud/API collectors still to wire
CSPM, SIEM, FIDO2, FIPS cryptoNov 2026–Jan 2027Not started (requires cloud and IdP admin access)
3PAO assessment scheduledBook by Q4 2026 for Feb–Apr 2027RFP drafted; not yet sent
Class C package to FedRAMP PMOMar–May 2027Blocked on persistent validation history + 3PAO

Secure configuration (customer-controlled)

Customers control SSO/IdP federation, which applications Toonimo overlays, author roles, data-retention settings, and whether AI features call customer-hosted or Toonimo-hosted models. Toonimo does not require customers to place federal data in a Toonimo-managed training corpus. Full Secure Configuration Guide pages will be issued with the 20x package.

Existing independent assurance

  • SOC 2 Type II (EY / KFGK, Feb 2025–Jan 2026 period)
  • ISO 27001 information security management system
  • Annual independent penetration test (commercial program; FedRAMP 3PAO pen test still required)

Contacts