Voice AI that cleared federal review
Bland is FedRAMP® 20x Class A certified, so federal agencies can run voice AI built for regulated, high-stakes work. The intelligence of every call runs on Bland’s own models, plugged into the telephony your agency already trusts.
FedRAMP 20x Class A certified · Marketplace listing
Independently assessed: SOC 2 Type II, HIPAA, GDPR, PCI DSS
Bland owns the brains of the call
Your agency already runs telephony it trusts. Today those lines end at a human; with Bland, they end at an AI. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models, with no third-party frontier model provider in the call path. Bland doesn’t replace your phone infrastructure. It replaces the seat at the end of the line.
Your calls stay inside the boundary
Audio, transcription, reasoning, and speech synthesis run on Bland’s own models. No frontier model provider enters the authorization boundary.
Plugs into telephony you already trust
Bland connects to the phone infrastructure your agency already operates and has already reviewed, where a human agent used to sit.
One DPA, one incident contact
A single data processing agreement and a single security contact, so review and response stay simple.
FedRAMP public record
FedRAMP requires this information published in both human-readable and machine-readable form. This page and the machine-readable record render from one source, so the values cannot drift. Blank values are not yet assigned.
Certification status
The committed assessment timeline is documented in the assessment statement of work on the Trust Center.
Provider & service
Service properties
Services in scope
The Bland FedRAMP boundary includes Voice agents, SMS, and Chat as part of a single cloud service offering (CSO). Bland is FedRAMP 20x Class A certified for these services and is pursuing Class C. Final agency authorization decisions remain agency-specific and use-case dependent.
Everything in the AI path is built and operated by Bland. The models that listen, reason, and speak, along with the prompts, voices, and conversation pathways, are built in-house and run inside Bland’s own container. The only pieces Bland does not build are the telephony connectivity that carries the call and the government cloud infrastructure it runs on, the trusted layers an agency already operates.
Example agency deployments
How agencies put these services to work. These are representative deployments, not a limit on what Bland supports.
One number for an entire agency
An agency routes every incoming call to a single voice agent that answers on the first ring, resolves common questions from an approved knowledge base, and acts on behalf of the caller, from checking the status of a case to scheduling an appointment or capturing an intake form, handing off to a person only when one is genuinely needed.
Benefits and eligibility support at peak volume
During enrollment and renewal periods, agents authenticate callers, walk them through program questions, and start or update applications, holding wait times flat no matter how many constituents call at once.
Proactive outreach and reminders
Agents place outbound calls and send text messages for appointment reminders, renewals, and notifications, with two-way rescheduling and confirmation, so constituents hear from the agency before a deadline passes.
Contacts
Trust Center & documentation
Documentation Catalog
Catalog of all policies and procedures (name, version, date updated, summary). Available on the Trust Center in human-readable and machine-readable format.
Quarterly Certification Progress Report
Detailed quarterly roadmap: completed milestones, current work, upcoming work, and assessment timeline.
Assessment Deadline
Official statement of work from Prescient Security documenting Bland’s commitment to a Class C assessment within the next 24 months.
Vulnerability Reporting
Vulnerability detection and response reporting published as FedRAMP Certification Data: the monthly human-readable report required by VER-TFR-MHR and its machine-readable companions for VER-RPT-VDT and VER-RPT-AVI. Governed by the Bland Vulnerability Management Plan and the Bland VDR Reporting Procedure.
Historical Vulnerability Activity
Machine-readable historical vulnerability evaluation and reporting activity for automated retrieval (VER-TFR-MRH), with the retrieval design, access model, and schedule set out in the Bland Historical Vulnerability Activity Retrieval Statement. Partially implemented; published as a periodic snapshot pending the authenticated retrieval endpoint.
Incident Reporting
Where Bland publishes Initial, Ongoing, and Final Incident Reports for FedRAMP Reportable Incidents (IEC-CSO-IIR, IEC-CSO-OIR, IEC-CSO-FIR) in human-readable and machine-readable form.
Significant Change Notifications
Where Bland publishes Significant Change Notifications and related audit records (SCN-CSO-INF, SCN-CSO-HRM) in human-readable and machine-readable form.
Each repository above is published on the Trust Center at https://trust.bland-gov.com/. Authentication is required for all documents except the secure configuration guide, which is open access. Use the "Request access" button on the Trust Center; access can be reclaimed with "Reclaim access". Questions: fedramp@bland.ai.
Third-party information resources
Third-party information resources that support Bland’s service delivery, customer data path, or security architecture. The intelligence of every call runs on Bland’s own models; these providers support the surrounding infrastructure.
FedRAMP eligibility
Why agencies use Bland
Bland is a voice AI platform for building and operating AI phone agents that conduct natural-language conversations over telephony at scale. Agencies run high-volume telephone channels that face long hold times, inconsistent coverage, and staffing constraints. Agencies use Bland to automate inbound and outbound voice interactions, route or escalate calls to human staff, capture structured outcomes from conversations, and operate these channels continuously without expanding headcount, while maintaining auditable records of each interaction.
Federal use case
Bland is pursuing FedRAMP because the service is intended to support direct agency use and/or indirect use as a third-party information resource within other cloud service offerings used by agency customers.
- Direct Use
- The Bland cloud service offering is used directly by agency customers and integrated into a federal information system, intended to receive an agency Authorization to Operate. Agencies integrate Bland into their own systems to operate constituent-facing voice agents, outbound notification and outreach, and human-in-the-loop escalation, with conversation outcomes written back into agency case-management, scheduling, or CRM systems inside the agency’s authorization boundary.
- Indirect Use
- Bland may also be included as a third-party information resource within other cloud service offerings that are directly used by agency customers (for example, embedded telephony and messaging capabilities).
Record metadata
FedRAMP requires the responsible official, version, date of last update, and source of update to be published with the Certification Package Overview. The FedRAMP schema defines no field for these, so Bland carries them in an x-bland extension in the machine-readable record and publishes them here.
FAQ
Yes. Bland holds FedRAMP 20x Class A Certification, achieved August 25, 2026 and listed on the FedRAMP Marketplace as package FR2628647242. The listing phase is Ongoing Certification. This page is kept in sync with that listing.
Bland is certified at FedRAMP 20x Class A. Class C at the Moderate security category is in application: Prescient Security, LLC. begins the independent Class C assessment on September 1, 2026, with submission to follow. Prescient is engaged for Class C only and did not assess Class A. The committed assessment timeline is documented in the assessment statement of work published on the Trust Center.
Bland runs its own speech and language models. Most vendors wrap third-party frontier models, which pulls those providers into the authorization boundary and onto an agency’s review. With Bland, a call’s audio, transcription, reasoning, and synthesis all happen on Bland’s own models, plugged into the telephony an agency already operates. That means a smaller assessment boundary and no AI subprocessor chain to vet.
Yes. Bland holds FedRAMP 20x Class A Certification, and is also available to commercial and public-sector teams under SOC 2 Type II, HIPAA, GDPR, and PCI DSS. Class C at the Moderate security category is in application. Final agency authorization decisions remain agency-specific and use-case dependent.
Federal agencies and FedRAMP-recognized assessors can request access with the "Request access" button on the Trust Center at https://trust.bland-gov.com/. Questions can be directed to fedramp@bland.ai.
Bringing voice AI to a federal program?
Talk to our team about deployment options, our security package, and where Bland is in the FedRAMP process.
FedRAMP® is a registered mark of the U.S. General Services Administration. Bland holds FedRAMP 20x Class A Certification; Class C at the Moderate security category is in application and is not yet certified. FedRAMP Certification does not imply U.S. government endorsement. Status on this page is intended to match Bland's FedRAMP Marketplace listing.