Solutions · Government

AI Security for Government & the Public Sector

Public agencies are adopting AI to serve constituents faster — and inheriting a new class of risk that traditional controls were never built to see. This guide explains the threats to government AI, the federal policy landscape driving post-quantum migration, and how Deflected secures the AI layer and the cryptography beneath it, with truthful alignment to the frameworks that govern public-sector systems.

Executive summary

Government is deploying artificial intelligence into the machinery of public service — benefits eligibility, document processing, constituent support, fraud detection, case management — at the same moment that two structural risks are converging: a new attack surface at the AI layer, and a cryptographic deadline set by the arrival of quantum computing. Deflected secures both. We protect the models, prompts, agents, and retrieval pipelines that power government AI, and we encrypt the data beneath them with post-quantum cryptography aligned to the standards federal policy is already steering agencies toward.

This page is written for the people accountable for these decisions in the public sector: agency CISOs and CIOs, authorizing officials, chief data and AI officers, program leaders, and the risk, privacy, and procurement staff who have to stand behind them. It is deliberately detailed and deliberately conservative. Where we describe alignment with a framework or policy, we name it accurately and we are explicit about the line between what a vendor can do — support readiness, map controls, produce evidence — and what only the government can do: grant an authorization to operate.

The one-paragraph version

Deflected gives public-sector organizations AI-specific defense — prompt-injection and data-leakage protection, governance and evidence, adversarial testing, supply-chain vetting, incident response — and post-quantum cryptography by default. It aligns to NIST SP 800-53, FISMA, FedRAMP readiness, and the NIST AI RMF, and supports the post-quantum migration directed by CNSA 2.0, NSM-10, and OMB M-23-02. Deflected supports readiness and alignment; it is not an accredited assessor or an authorization body.

AI in the public sector — opportunity and mission risk

Few sectors stand to gain more from AI than government, and few carry higher stakes when it goes wrong. Public agencies operate at enormous scale, hold some of the most sensitive data in existence, and are held to a standard of accountability that private companies rarely face. The same capabilities that make AI attractive — summarizing dense records, answering constituents in natural language, extracting structure from unstructured forms, taking action across systems — are precisely the capabilities that create new avenues for harm when they are not secured.

Where AI is landing in government

Across federal, state, local, and tribal government, a recognizable set of use cases has emerged:

  • Citizen-facing services. Chatbots and virtual assistants that answer questions about programs, deadlines, forms, and status — often the first point of contact a constituent has with an agency, and increasingly the interface through which sensitive interactions begin.
  • Benefits and eligibility. AI systems that help caseworkers assess eligibility, flag missing documentation, or triage applications for programs where an error can deny someone housing, food assistance, healthcare, or unemployment support.
  • Document processing. Extraction and classification of information from the immense volume of forms, filings, correspondence, and records that agencies process — from tax documents to permit applications to public comments.
  • Retrieval over records (RAG). Retrieval-augmented generation systems that let staff query internal knowledge — policy manuals, statutes, prior determinations, case files — in plain language, pulling relevant passages into a model's context to ground its answers.
  • Agentic workflows. AI agents granted tools and limited autonomy to act across systems — updating records, routing cases, drafting correspondence, or orchestrating multi-step processes that once required manual handoffs.

Each of these delivers real value: shorter wait times, faster determinations, staff freed from rote work, and services that are more responsive to the people who depend on them. None of them is safe by default.

Why the stakes and the scrutiny are higher in government

A commercial company that mishandles data faces reputational and financial consequences. A government agency that mishandles data can fail its statutory duty, violate the privacy rights of people who had no choice but to hand over their information, and erode public trust in institutions themselves. Several factors compound the risk:

  • The data is uniquely sensitive and often involuntary. Citizens do not opt in to giving an agency their Social Security number, their medical history, their immigration status, or their criminal record. That non-consensual, comprehensive nature raises the duty of care.
  • The data is long-lived. Government records frequently must be retained for years or decades, and their sensitivity does not expire on a convenient schedule. This is the single most important reason the quantum threat is acute for the public sector, as the next sections explain.
  • Decisions carry the force of the state. When an AI system informs a benefits denial, a fraud referral, or a security determination, an adversary who can manipulate that system can cause real, individualized harm — and the agency, not a vendor, is accountable for it.
  • Scrutiny is structural, not optional. Public agencies answer to inspectors general, auditors, legislatures, oversight bodies, the courts, journalists, and the public through mechanisms like the Freedom of Information Act. A security failure is not a private matter; it is a matter of record.
  • Nation-state adversaries are in scope. Government systems are targeted not only by opportunistic criminals but by well-resourced, patient, state-sponsored actors — the exact profile of attacker most capable of executing a harvest-now, decrypt-later campaign.

The conclusion is not that agencies should slow down on AI. It is that the security of government AI has to be engineered to a public-sector standard from the outset — and that standard now includes defending against threats, like cryptographically relevant quantum computing, that have not fully arrived but are already being prepared for in federal policy.

Regulatory, policy & framework landscape

Public-sector AI security does not exist in a vacuum. It sits inside a dense, evolving body of federal standards, statutes, and policy memoranda. Deflected is designed to help agencies and their vendors align with these instruments accurately. The list below names the ones most relevant to securing government AI and its cryptography, described as they actually are.

Baseline security: NIST SP 800-53 and FISMA

NIST Special Publication 800-53Security and Privacy Controls for Information Systems and Organizations — is the catalog of controls that federal information systems are assessed against. It is the backbone of federal cybersecurity: controls for access, audit and accountability, system and communications protection, incident response, supply chain, and more. The Federal Information Security Modernization Act (FISMA) is the statute that requires federal agencies to develop, document, and implement information security programs, and it operationalizes the NIST Risk Management Framework (RMF) described in NIST SP 800-37, under which systems are categorized (per FIPS 199 and NIST SP 800-60), have controls selected and implemented, and are authorized to operate. Deflected maps its controls and the evidence it produces to the relevant 800-53 control families so that an agency's AI layer fits cleanly into an existing authorization boundary rather than sitting outside it.

Cloud authorization: the FedRAMP program

The Federal Risk and Authorization Management Program (FedRAMP) provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. FedRAMP baselines are built on NIST SP 800-53 controls. It is important to be precise here: a FedRAMP authorization is achieved through assessment by an accredited Third Party Assessment Organization (3PAO) and a decision by a government authorizing official or the FedRAMP program — not by a vendor's self-declaration. Deflected does not claim FedRAMP authorization on this page. What Deflected can do is support FedRAMP readiness: aligning to the applicable baseline, helping assemble the control implementation evidence a package requires, and reducing the friction of bringing an AI-layer capability into an authorization effort. Any authorization status should always be verified through official government channels, never inferred from marketing.

AI risk management: the NIST AI RMF and OMB guidance

The NIST AI Risk Management Framework (AI RMF 1.0) is the leading voluntary framework for identifying, measuring, and managing AI-specific risk across the lifecycle, organized around its Govern, Map, Measure, and Manage functions and complemented by NIST's Generative AI Profile. On the policy side, the Office of Management and Budget has issued guidance governing federal agencies' use of AI — memoranda that direct agencies on responsible acquisition, governance, risk management, and oversight of AI systems, including expectations around safeguards for rights- and safety-impacting uses. These OMB memos on AI use in government set the governance context that agency AI programs are expected to operate within; Deflected's governance and evidence capabilities are built to slot into that context rather than duplicate it.

Post-quantum migration: CNSA 2.0, NSM-10, and OMB M-23-02

This cluster is central to the government story and deserves emphasis. Three federal instruments direct the migration to quantum-resistant cryptography:

  • NSA's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) specifies the quantum-resistant algorithms — including ML-KEM and ML-DSA, along with approved symmetric and hash-based options — that national security systems are to adopt, with a phased timeline pushing toward exclusive use of quantum-resistant algorithms.
  • National Security Memorandum 10 (NSM-10) establishes the national policy for maintaining U.S. leadership in quantum computing while mitigating the risk quantum computers pose to cryptographic systems, directing agencies to prepare for migration to quantum-resistant cryptography.
  • OMB Memorandum M-23-02 directs federal agencies to inventory their cryptographic systems and prioritize the migration to post-quantum cryptography, operationalizing the transition inside the executive branch.

Taken together, these establish that post-quantum migration is not a speculative future concern for government — it is current federal direction. Deflected implements the NIST-standardized algorithms these policies point toward, so an agency's move to quantum-safe cryptography at the AI and data layer is consistent with the guidance it already has to follow.

Criminal-justice data: the CJIS Security Policy

Where AI systems touch criminal-justice information — for example in law-enforcement, courts, or corrections contexts — the FBI Criminal Justice Information Services (CJIS) Security Policy applies, setting requirements for the protection of Criminal Justice Information (CJI), including access control, auditing, encryption, and personnel security. Any AI capability that ingests, retrieves over, or generates from CJI has to respect those requirements, and the cryptographic protections have to meet the policy's encryption expectations. Deflected accounts for CJIS where criminal-justice data is in scope, treating it as a hard constraint on how AI-layer data is handled.

A note on accuracy

Framework and policy names change and mature over time, and authorization status is specific to a system and boundary. Deflected states alignment and readiness support only. We do not assert that Deflected — or an agency's system — holds any authorization, accreditation, or certification unless that status has been formally granted by the appropriate government authority.

The post-quantum imperative for government

Of every argument in this guide, this is the one most specific to the public sector, and the one most likely to be underestimated. The reason is a single, unforgiving property of government data: much of it stays sensitive for a very long time.

Harvest now, decrypt later

Most of the confidentiality on the internet today rests on public-key cryptography — algorithms like RSA and elliptic-curve schemes — whose security depends on math problems that classical computers cannot solve efficiently. A sufficiently large, fault-tolerant quantum computer running Shor's algorithm could solve those problems and break that cryptography. Such a machine does not need to exist yet for the threat to be live, because of a strategy known as harvest now, decrypt later (sometimes called "store now, decrypt later"): an adversary captures encrypted traffic and data today, stores it, and simply waits. When a cryptographically relevant quantum computer becomes available, everything harvested is retroactively exposed.

For a consumer service, much intercepted data would be stale by then. For government, it often is not. Consider what an agency holds that will still be sensitive in ten or twenty years: personal identifiers that never change, intelligence and law-enforcement records, health and immigration data, security-clearance investigations, diplomatic communications, and the personal information of millions of constituents who cannot simply "rotate" their identity. An adversary who harvests that traffic now is making a rational, patient bet — and the well-resourced nation-state actors who target government are exactly the parties with the motive and the means to make it.

Why federal guidance is already moving

The federal government has not treated this as hypothetical. As the previous section detailed, NSM-10, OMB M-23-02, and NSA's CNSA 2.0 collectively direct agencies to take inventory of vulnerable cryptography and migrate to quantum-resistant algorithms on a defined path. In parallel, NIST finalized the first post-quantum cryptographic standards in 2024 — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — giving agencies concrete, standardized algorithms to migrate to rather than research prototypes. The direction of travel is clear: cryptographic inventory, prioritization of the most sensitive and long-lived data, and phased migration to the NIST standards.

The practical implication for AI programs is that any new AI system handling long-lived sensitive data should be built quantum-safe from the start, not retrofitted later. Retrofitting is more expensive, and every day a system runs on classical-only cryptography is another day of data an adversary can harvest against the future. This is why Deflected treats post-quantum cryptography as a default rather than an option, and why we place Quantum-Safe Migration first among the capabilities we bring to government.

AI-era threats specific to government

The AI layer introduces threats that behave nothing like the vulnerabilities traditional government security programs were built around. The attacks are frequently written in natural language, target model behavior rather than infrastructure, and slip past controls that inspect packets and files but cannot read intent. Below are the categories that matter most for public-sector systems.

Prompt injection in citizen-service systems

When an AI application inserts untrusted input — from a constituent, or from a document it retrieved — into a model's prompt, an attacker can hide instructions inside that input to hijack the model's behavior. This is prompt injection, and it is the defining AI-layer vulnerability, analogous to what SQL injection was for databases. In a citizen-facing chatbot or a case-work assistant, a crafted message or a poisoned document could instruct the model to ignore its guardrails, reveal information from its context, or misuse a connected tool. Because agencies expose these systems to the public by design, they are exposed to prompt injection by design unless something inspects that traffic for it.

Leakage of citizen PII and sensitive records through model output

An AI system can disclose sensitive information simply by generating it. A model connected to citizen records, case files, or internal knowledge can be led — deliberately or accidentally — into emitting personally identifiable information, protected records, or confidential determinations in its response. Traditional data-loss prevention watches files and network flows; it does not read a model's natural-language output for a Social Security number, a medical detail, or a sealed record leaving in plain prose. In government, a single such leak can constitute a reportable privacy incident affecting real people.

Manipulation of decision-support models

Where AI informs consequential decisions — eligibility triage, fraud scoring, risk flags, resource prioritization — an adversary who can shape the model's inputs can shape its outputs. Adversarial input crafted to nudge a decision-support model toward a wrong determination can, at scale, systematically approve fraudulent claims, suppress legitimate ones, or bias a triage queue. Unlike a crude system intrusion, this manipulation can be quiet and statistical, showing up as a drift in outcomes rather than an alarm — which is exactly why it demands continuous adversarial testing rather than a one-time review.

Model and dataset supply-chain risk

Government AI systems are assembled from third-party models, open-source components, pre-trained weights, and external datasets. Any of these can carry poisoning, backdoors, or hidden triggers introduced upstream — a model that behaves normally until a specific trigger phrase appears, or a dataset seeded to bias a downstream system. For an agency, an unvetted model is an unvetted dependency with the authority of the state behind its outputs. Supply-chain provenance and vetting are therefore first-class security concerns, not procurement afterthoughts.

Deepfakes and impersonation

Generative AI has made convincing voice clones and synthetic media inexpensive. In a government context this cuts two ways: adversaries can impersonate officials to authorize actions or extract information, and they can impersonate constituents to defraud programs or manipulate staff. Voice-clone-enabled social engineering against a benefits line, a help desk, or an approval workflow is a direct extension of long-standing fraud, now automated and scaled. Synthetic media also threatens the information environment agencies operate in, from forged notices to fabricated official communications.

The quantum threat

Finally, the cryptographic threat described above is itself an AI-era and public-sector threat vector: the data flowing through AI systems — prompts, retrieved records, model outputs, and the stores behind them — is exactly the long-lived sensitive data most attractive to harvest-now, decrypt-later collection. Securing the AI layer without securing its cryptography leaves the most valuable material exposed to the patient adversary. Deflected treats the two as one problem.

How Deflected protects government

Deflected addresses these threats with a coordinated set of always-on products and expert engagements, each applied here in a public-sector context. For government, we lead with the cryptographic migration, because it is both federally directed and time-sensitive, and then layer the AI-specific defenses on top.

Quantum-Safe Migration

Engagement

A cryptographic inventory and phased migration to post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) aligned to CNSA 2.0, NSM-10, and OMB M-23-02 — closing the harvest-now, decrypt-later window on your agency's most long-lived, most sensitive data first, with NIST FIPS 203–205 alignment.

Read the full breakdown →

Prompt Firewall

Recurring

An inline AI gateway that inspects every prompt and response in real time — blocking prompt injection, jailbreaks, and citizen-PII leakage before it reaches a model or a constituent. Every decision is logged, giving an agency the immutable audit trail its accountability regime demands.

Read the full breakdown →

AI Governance & Compliance

Engagement

Policy, controls, and evidence mapped to the NIST AI RMF and to the NIST SP 800-53 control families behind FISMA and FedRAMP — so an agency's AI program fits its authorization boundary and answers oversight with documentation, not assurances. Supports readiness; it is not an accredited assessment.

Read the full breakdown →

Continuous AI Red Team

Recurring

Always-on adversarial testing that attacks your models the way a real threat actor would — probing decision-support systems for manipulation and citizen-service bots for injection — and returns a prioritized, fixable report, so weaknesses are found before an adversary finds them.

Read the full breakdown →

Model Supply-Chain Security

Engagement

Vetting of third-party models, datasets, and dependencies for poisoning, backdoors, and hidden triggers before they enter a government pipeline — with a documented supply-chain sign-off that maps to the supply-chain risk controls agencies are assessed against.

Read the full breakdown →

Shadow AI Discovery

Recurring

Continuously surfaces the unsanctioned AI tools staff use — the quiet pasting of sensitive records into public models — quantifies the exposure, and brings that hidden risk back under an enforceable usage policy, closing a gap that oversight bodies increasingly ask about.

Read the full breakdown →

AI Incident Response

Engagement

On-call expert response when an AI system is breached, manipulated, or leaking — containment, forensic root-cause analysis, and recovery — available on a standing retainer so response capability is in place before an incident, supporting the reporting timelines agencies are held to.

Read the full breakdown →

Compliance & assurance

In government, security that cannot be demonstrated does not count. Systems are authorized, assessed, and continuously monitored against documented controls, and an AI capability that cannot produce that documentation becomes an obstacle to an authorization to operate rather than a contributor to the mission. Deflected is built to produce assurance, not just protection.

How Deflected maps to the frameworks

  • NIST SP 800-53. Deflected maps its controls and generated evidence to the relevant 800-53 control families — access control, audit and accountability, system and communications protection, incident response, and supply-chain risk management — so the AI layer fits inside an existing control baseline.
  • FISMA. By aligning to the NIST RMF process (categorize, select, implement, assess, authorize, monitor) that FISMA operationalizes, Deflected supports an agency's readiness to bring AI systems through authorization rather than around it.
  • FedRAMP readiness. Because FedRAMP baselines derive from 800-53, the same control mappings support FedRAMP readiness. Deflected supports readiness and evidence assembly; it does not assert an authorization, which is a government decision reached through an accredited 3PAO.
  • NIST AI RMF. Deflected's governance capability aligns AI-specific controls and evidence to the Govern, Map, Measure, and Manage functions, addressing the risks that general security controls do not fully cover.
  • Post-quantum guidance. The cryptographic migration aligns to CNSA 2.0, NSM-10, and OMB M-23-02, implementing the NIST FIPS 203–205 standards those policies point toward.

For a fuller treatment of how Deflected approaches control mapping and evidence across frameworks, see our compliance overview. And to be unambiguous about scope: Deflected supports readiness and alignment. It is not an accredited auditor, a 3PAO, or an authorization body. The value we add is making an agency's AI program provable — the accreditation and authorization decisions remain with the government and its accredited assessors.

Real-world scenarios

The following scenarios are illustrative composites drawn from well-understood attack patterns. They are not accounts of specific customers or events. Each shows how an AI-layer or cryptographic weakness turns into a public-sector harm — and where Deflected intervenes.

Scenario one — a benefits chatbot leaks citizen data

An agency deploys a constituent-facing assistant to answer questions about a benefits program. To be helpful, it is connected to case status and eligibility information. A constituent — or an attacker posing as one — submits a message crafted as a prompt injection: text that instructs the model to disregard its instructions and return the underlying records it can see. The model, having no way to distinguish a legitimate question from an embedded command, complies, and personally identifiable information about applicants is disclosed in the chat. What began as a convenience feature has become a reportable privacy incident, complete with notification obligations and oversight interest. With Prompt Firewall inline, the injected instruction and the PII in the drafted response are inspected in real time; the malicious pattern is blocked and the sensitive output is prevented from leaving, with the whole decision logged for the record. Continuous AI Red Team would have surfaced the weakness proactively, before it was ever exposed to the public.

Scenario two — an unmigrated records system exposed to harvest-now, decrypt-later

A records system holds citizen data that must be retained for decades, protected in transit and at rest by classical public-key cryptography. Nothing appears wrong: there is no breach alert, no visible compromise. But a nation-state adversary is quietly capturing the encrypted traffic and archiving it. The bet is patient and rational — when a cryptographically relevant quantum computer becomes available, the harvested archive, still sensitive years later, can be decrypted in bulk. The vulnerability is invisible precisely because the "attack" today is only collection. Deflected's Quantum-Safe Migration addresses this at the root: a cryptographic inventory identifies where classical algorithms protect long-lived data, the most sensitive systems are prioritized, and cryptography is migrated to NIST-standardized post-quantum algorithms — ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures — in a hybrid configuration aligned to CNSA 2.0, NSM-10, and OMB M-23-02. The harvested archive becomes far less useful, and future collection is defeated.

Scenario three — a decision-support model manipulated by adversarial input

A fraud-detection or eligibility-triage model helps caseworkers prioritize their queue. An adversary studies the system's behavior and learns to shape submissions with adversarial input designed to push the model's score in a chosen direction — for instance, dressing fraudulent claims so they read as low-risk, or nudging legitimate applicants into a high-scrutiny bucket. There is no crash and no alert; the harm shows up only as a slow drift in outcomes that a spot check might never catch. Continuous AI Red Team attacks the model the way this adversary would, on an ongoing basis, and returns a prioritized report of the manipulation techniques it succumbs to — so the model can be hardened before the drift becomes a headline. Where the manipulation stems from a compromised upstream model or dataset, Model Supply-Chain Security catches the poisoning before the component ever enters the pipeline.

Scenario four — a voice-clone impersonation targets an approval workflow

An attacker uses an inexpensive voice clone of a senior official to call a help desk or an approvals line, applying pressure to authorize an unusual action or release information. The request sounds authentic because the voice is authentic — synthetically. Deflected's approach pairs deepfake and voice-clone detection with the governance and training that make high-trust workflows resistant to social engineering, so an urgent-sounding voice on the line is not, by itself, sufficient to move money or data. Coupled with AI Incident Response on retainer, an agency has both prevention and a rehearsed path to contain and report if an attempt gets through.

Why Deflected for government

Two commitments distinguish Deflected for public-sector work, and both map directly to the risks this page describes.

Post-quantum by default

Deflected treats post-quantum cryptography as the baseline, not a premium upgrade. Everything the platform protects is designed to be defended with the NIST-standardized algorithms federal guidance points toward — ML-KEM-1024 (FIPS 203) for key encapsulation at a 256-bit quantum security level, ML-DSA-87 (FIPS 204) and SLH-DSA (FIPS 205) for signatures, a hybrid X25519 + ML-KEM key exchange that runs a proven classical algorithm alongside the post-quantum one so protection holds even if either scheme is later weakened, and AES-256 for symmetric encryption at rest and in transit. For an agency working under CNSA 2.0, NSM-10, and OMB M-23-02, this means the AI and data layer is aligned with the migration it is already required to make.

FIPS 203
ML-KEM key encapsulation
FIPS 204/205
Post-quantum signatures
Hybrid
X25519 + ML-KEM together
AES-256
Symmetric at rest & transit

Purpose-built for the AI layer

Deflected is not a repackaged network appliance. It is built specifically for the model, prompt, agent, and retrieval layer where AI risk actually lives — inspecting natural-language traffic for injection and leakage, testing models adversarially, vetting the AI supply chain, and governing it all with evidence. It complements, rather than replaces, an agency's existing network, endpoint, identity, and cloud controls, adding the AI-specific and post-quantum defenses those tools were never designed to provide. That focus is what lets a public-sector team adopt AI at mission speed without opening a security gap it cannot see.

Getting started / first engagement

A first engagement with Deflected is scoped to produce clarity quickly and to fit an agency's authorization and reporting reality. A typical path:

  1. Scoping session. We map where AI touches the mission — the citizen-facing services, decision-support systems, document pipelines, and agentic workflows in play — and where long-lived sensitive data lives. This defines the AI layer and the data that most needs quantum-safe protection.
  2. Cryptographic inventory. We size the post-quantum migration by inventorying where classical cryptography protects data that will still be sensitive years from now, prioritizing the systems most exposed to harvest-now, decrypt-later collection — the approach CNSA 2.0, NSM-10, and OMB M-23-02 call for.
  3. AI-layer assessment. We evaluate the AI systems for prompt-injection and data-leakage exposure, decision-support manipulation, and supply-chain risk, producing a prioritized, fixable picture rather than a generic checklist.
  4. Phased plan. We turn the findings into a sequenced plan aligned to the agency's authorization boundary, 800-53 control baseline, and oversight obligations — leading with the highest-impact, most time-sensitive work, which for most agencies is the cryptographic migration.
  5. Operate and monitor. Always-on products run inline with logging and continuous monitoring; expert services stand ready on retainer for the moments that need a human.
Where to begin

If you take one action, make it the cryptographic inventory. It is federally directed, it is time-sensitive because every day of classical-only encryption is another day of harvestable data, and it produces a concrete, defensible plan you can put in front of leadership and oversight.

Frequently asked questions

Is Deflected FedRAMP authorized?
Deflected does not claim FedRAMP authorization on this page. We help agencies and their vendors prepare for and align with federal requirements — supporting FedRAMP readiness, mapping controls to the NIST SP 800-53 baselines FedRAMP is built on, and producing the evidence an assessment needs. Authorization decisions rest with the government; a FedRAMP authorization is granted through an accredited Third Party Assessment Organization (3PAO) and an authorizing official, not by a vendor's assertion. Always verify any authorization status through official government channels.
Why does post-quantum cryptography matter for government right now?
Government data often stays sensitive for decades, which makes it the prime target for harvest-now, decrypt-later attacks: an adversary captures encrypted traffic today and decrypts it once a cryptographically relevant quantum computer exists. Federal guidance already anticipates this. National Security Memorandum NSM-10, OMB Memorandum M-23-02, and NSA's CNSA 2.0 suite direct agencies to inventory vulnerable cryptography and migrate to quantum-resistant algorithms. Deflected implements the NIST standards those policies point toward — ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205).
What AI-specific threats are most relevant to public-sector systems?
The most pressing are prompt injection in citizen-facing chatbots and case-work assistants, leakage of citizen PII or sensitive records through model output, manipulation of decision-support models by adversarial input, model and dataset supply-chain compromise, and deepfake or voice-clone impersonation used against officials and constituents. These target model behavior in natural language, which traditional network and application controls were not designed to inspect.
Which frameworks and policies does Deflected align to for government?
Deflected maps its controls and evidence to NIST SP 800-53, FISMA, the FedRAMP program's baselines, and the NIST AI Risk Management Framework, and supports the post-quantum migration called for by CNSA 2.0, NSM-10, and OMB M-23-02. Where criminal-justice data is in scope, we account for the FBI CJIS Security Policy. Deflected supports readiness and alignment; it is not an accredited auditor or an authorization body.
Does Deflected replace an agency's existing security stack?
No. Deflected secures the AI layer — the models, prompts, agents, retrieval pipelines, and the cryptography protecting the data underneath — and works alongside existing network, endpoint, identity, and cloud controls. It adds the AI-specific and post-quantum defenses those tools were never designed to provide, rather than replacing them.
How does a first engagement with Deflected typically begin?
Most agencies begin with a scoping session that inventories where AI touches the mission and where long-lived sensitive data lives, followed by a cryptographic inventory to size the post-quantum migration and an assessment of the AI layer for prompt-injection and data-leakage exposure. From there we prioritize a phased plan aligned to the agency's authorization boundary and reporting obligations.

Secure your agency's AI — and its future

Book a working session with our team. We'll map Deflected to your mission, size your post-quantum migration, and show exactly where each layer of protection fits.