Bland becomes FedRAMP certified, clearing the highest security standards.

Voice AI that cleared federal review

Bland is FedRAMP® 20x Class A certified, so federal agencies can run voice AI built for regulated, high-stakes work. The intelligence of every call runs on Bland’s own models, plugged into the telephony your agency already trusts.

FedRAMP 20x Class A certified · Marketplace listing

Independently assessed: SOC 2 Type II, HIPAA, GDPR, PCI DSS

OWNED AND OPERATEDVoiceSTTLLMTTS

Bland owns the brains of the call

Your agency already runs telephony it trusts. Today those lines end at a human; with Bland, they end at an AI. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models, with no third-party frontier model provider in the call path. Bland doesn’t replace your phone infrastructure. It replaces the seat at the end of the line.

Your calls stay inside the boundary

Audio, transcription, reasoning, and speech synthesis run on Bland’s own models. No frontier model provider enters the authorization boundary.

Plugs into telephony you already trust

Bland connects to the phone infrastructure your agency already operates and has already reviewed, where a human agent used to sit.

One DPA, one incident contact

A single data processing agreement and a single security contact, so review and response stay simple.

FedRAMP public record

FedRAMP requires this information published in both human-readable and machine-readable form. This page and the machine-readable record render from one source, so the values cannot drift. Blank values are not yet assigned.

Certification status

FedRAMP statusOngoing Certification
Certification heldFedRAMP 20x Class A, achieved 2026-08-25
Marketplace listingFR2628647242
Certification pathClass C at Moderate, in application
Class C assessorPrescient Security, LLC. Assessment begins 2026-09-01. Did not assess Class A.
Next milestoneClass C submission, Q3 2026
Next ongoing certification report date2026-10-30

The committed assessment timeline is documented in the assessment statement of work on the Trust Center.

Provider & service

Provider nameBland AI
Service nameBland
Service acronymBland
Service descriptionBland is an enterprise voice AI platform for building, deploying, and operating AI phone agents at scale. Bland runs its own speech and language models, so customer calls are not sent to third-party frontier model providers. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models within Bland’s boundary.
Certification type20x
FedRAMP IDFR2628647242
UEI numberBlank, not yet assigned

Service properties

Service modelPaaS
Deployment modelGovernment-Only Cloud
Digital identity levelIAL: customer/agency-managed or not performed by Bland; AAL2 for Bland-managed administrative authentication where MFA is enforced; FAL2 where federated SSO is configured
Business categoryArtificial Intelligence (AI), Contact Center

Services in scope

The Bland FedRAMP boundary includes Voice agents, SMS, and Chat as part of a single cloud service offering (CSO). Bland is FedRAMP 20x Class A certified for these services and is pursuing Class C. Final agency authorization decisions remain agency-specific and use-case dependent.

Everything in the AI path is built and operated by Bland. The models that listen, reason, and speak, along with the prompts, voices, and conversation pathways, are built in-house and run inside Bland’s own container. The only pieces Bland does not build are the telephony connectivity that carries the call and the government cloud infrastructure it runs on, the trusted layers an agency already operates.

Voice agentsAI phone agents that answer inbound calls and place outbound calls, hold natural spoken conversations, and act on what the caller needs. Each agent follows a configurable conversation pathway, a decision tree that interprets the caller’s intent and then routes the call or takes an action such as scheduling, sending follow-ups, taking payments, answering questions from an approved knowledge base, or escalating to a person. Speech-to-text, reasoning, and text-to-speech all run on Bland’s own models inside Bland’s boundary.Recommended security category: Moderate, targeted under FedRAMP 20x Class C. Generally available 2026-07-13.
SMSProgrammatic two-way text messaging driven by the same pathway logic as voice agents. Agents send and respond to messages for notifications, reminders, status updates, and structured question-and-answer flows, triggering the same actions as a voice agent, such as scheduling, follow-ups, and record updates, over text rather than a call.Recommended security category: Moderate, targeted under FedRAMP 20x Class C. Generally available 2026-07-13.
ChatWeb and in-app chat agents that run on the same conversation pathways and actions as voice and SMS, embedded in an agency’s web properties for self-service. Chat shares the rule sets, knowledge, and integrations of the other channels, so a constituent gets the same answers and outcomes no matter how they reach out.Recommended security category: Moderate, targeted under FedRAMP 20x Class C. Generally available 2026-07-13.

Example agency deployments

How agencies put these services to work. These are representative deployments, not a limit on what Bland supports.

One number for an entire agency

An agency routes every incoming call to a single voice agent that answers on the first ring, resolves common questions from an approved knowledge base, and acts on behalf of the caller, from checking the status of a case to scheduling an appointment or capturing an intake form, handing off to a person only when one is genuinely needed.

Benefits and eligibility support at peak volume

During enrollment and renewal periods, agents authenticate callers, walk them through program questions, and start or update applications, holding wait times flat no matter how many constituents call at once.

Proactive outreach and reminders

Agents place outbound calls and send text messages for appointment reminders, renewals, and notifications, with two-way rescheduling and confirmation, so constituents hear from the agency before a deadline passes.

Contacts

Security contactBland FedRAMP, fedramp@bland.ai
Sales contactBland Federal Sales, sales@bland.ai

Trust Center & documentation

Trust Center descriptionBland FedRAMP Trust Center. FedRAMP package and security documentation for federal agencies and recognized assessors.
Authentication requiredtrue
Access instructionsUse the "Request access" button on the Trust Center; access can be reclaimed with "Reclaim access". Questions: fedramp@bland.ai.
Secure configuration guidanceBland AI secure configuration guide: hardening and configuration guidance for operating Bland securely (SCG-CSO-RSC). Open access; no authentication required. https://trust.bland-gov.com/resources?s=8udmre29tx8im63a7l6bhw&name=bland-ai-secure-configuration-guide.pdf

Documentation Catalog

Catalog of all policies and procedures (name, version, date updated, summary). Available on the Trust Center in human-readable and machine-readable format.

Quarterly Certification Progress Report

Detailed quarterly roadmap: completed milestones, current work, upcoming work, and assessment timeline.

Assessment Deadline

Official statement of work from Prescient Security documenting Bland’s commitment to a Class C assessment within the next 24 months.

Vulnerability Reporting

Vulnerability detection and response reporting published as FedRAMP Certification Data: the monthly human-readable report required by VER-TFR-MHR and its machine-readable companions for VER-RPT-VDT and VER-RPT-AVI. Governed by the Bland Vulnerability Management Plan and the Bland VDR Reporting Procedure.

Historical Vulnerability Activity

Machine-readable historical vulnerability evaluation and reporting activity for automated retrieval (VER-TFR-MRH), with the retrieval design, access model, and schedule set out in the Bland Historical Vulnerability Activity Retrieval Statement. Partially implemented; published as a periodic snapshot pending the authenticated retrieval endpoint.

Incident Reporting

Where Bland publishes Initial, Ongoing, and Final Incident Reports for FedRAMP Reportable Incidents (IEC-CSO-IIR, IEC-CSO-OIR, IEC-CSO-FIR) in human-readable and machine-readable form.

Significant Change Notifications

Where Bland publishes Significant Change Notifications and related audit records (SCN-CSO-INF, SCN-CSO-HRM) in human-readable and machine-readable form.

Each repository above is published on the Trust Center at https://trust.bland-gov.com/. Authentication is required for all documents except the secure configuration guide, which is open access. Use the "Request access" button on the Trust Center; access can be reclaimed with "Reclaim access". Questions: fedramp@bland.ai.

Third-party information resources

Third-party information resources that support Bland’s service delivery, customer data path, or security architecture. The intelligence of every call runs on Bland’s own models; these providers support the surrounding infrastructure.

AWS GovCloudCloud infrastructure hosting the Bland service. FedRAMP Certified, ID: F1603047866
OktaIdentity provider for Bland-managed administrative authentication. Provider: Okta, https://www.okta.com
TwilioTelephony carrier connectivity (PSTN) for voice calls. Provider: Twilio, https://www.twilio.com

FedRAMP eligibility

Why agencies use Bland

Bland is a voice AI platform for building and operating AI phone agents that conduct natural-language conversations over telephony at scale. Agencies run high-volume telephone channels that face long hold times, inconsistent coverage, and staffing constraints. Agencies use Bland to automate inbound and outbound voice interactions, route or escalate calls to human staff, capture structured outcomes from conversations, and operate these channels continuously without expanding headcount, while maintaining auditable records of each interaction.

Federal use case

Bland is pursuing FedRAMP because the service is intended to support direct agency use and/or indirect use as a third-party information resource within other cloud service offerings used by agency customers.

Direct Use
The Bland cloud service offering is used directly by agency customers and integrated into a federal information system, intended to receive an agency Authorization to Operate. Agencies integrate Bland into their own systems to operate constituent-facing voice agents, outbound notification and outreach, and human-in-the-loop escalation, with conversation outcomes written back into agency case-management, scheduling, or CRM systems inside the agency’s authorization boundary.
Indirect Use
Bland may also be included as a third-party information resource within other cloud service offerings that are directly used by agency customers (for example, embedded telephony and messaging capabilities).

Record metadata

FedRAMP requires the responsible official, version, date of last update, and source of update to be published with the Certification Package Overview. The FedRAMP schema defines no field for these, so Bland carries them in an x-bland extension in the machine-readable record and publishes them here.

Responsible officialJuan Riojas, Chief Information Officer, fedramp@bland.ai
Record version1.3
Last updated2026-08-31T00:00:00Z
Source of updateRecorded 20x Class A Certification received 2026-08-25 (FedRAMP Marketplace FR2628647242; Type 20x, Path Program, Class A Pilot, phase Ongoing Certification) and the move to a Class C application, with the Prescient Security Class C assessment beginning 2026-09-01 and submission to follow in Q3. Corrected the next Ongoing Certification Report date to 2026-10-30. Removed Cloudflare from third-party information resources. Aligned the service description with the human-readable overview, cleared ueiNumber to blank per the schema’s guidance for an unassigned UEI, and added Trust Center repositories for vulnerability reporting (VER-TFR-MHR, VER-RPT-VDT, VER-RPT-AVI), historical vulnerability activity (VER-TFR-MRH), incident reporting (IEC-CSO-IIR/OIR/FIR), and significant change notifications (SCN-CSO-INF, SCN-CSO-HRM).

FAQ

Yes. Bland holds FedRAMP 20x Class A Certification, achieved August 25, 2026 and listed on the FedRAMP Marketplace as package FR2628647242. The listing phase is Ongoing Certification. This page is kept in sync with that listing.

Bland is certified at FedRAMP 20x Class A. Class C at the Moderate security category is in application: Prescient Security, LLC. begins the independent Class C assessment on September 1, 2026, with submission to follow. Prescient is engaged for Class C only and did not assess Class A. The committed assessment timeline is documented in the assessment statement of work published on the Trust Center.

Bland runs its own speech and language models. Most vendors wrap third-party frontier models, which pulls those providers into the authorization boundary and onto an agency’s review. With Bland, a call’s audio, transcription, reasoning, and synthesis all happen on Bland’s own models, plugged into the telephony an agency already operates. That means a smaller assessment boundary and no AI subprocessor chain to vet.

Yes. Bland holds FedRAMP 20x Class A Certification, and is also available to commercial and public-sector teams under SOC 2 Type II, HIPAA, GDPR, and PCI DSS. Class C at the Moderate security category is in application. Final agency authorization decisions remain agency-specific and use-case dependent.

Federal agencies and FedRAMP-recognized assessors can request access with the "Request access" button on the Trust Center at https://trust.bland-gov.com/. Questions can be directed to fedramp@bland.ai.

Bringing voice AI to a federal program?

Talk to our team about deployment options, our security package, and where Bland is in the FedRAMP process.

FedRAMP® is a registered mark of the U.S. General Services Administration. Bland holds FedRAMP 20x Class A Certification; Class C at the Moderate security category is in application and is not yet certified. FedRAMP Certification does not imply U.S. government endorsement. Status on this page is intended to match Bland's FedRAMP Marketplace listing.