FedRAMP-Compliant DevOps & Monitoring Vendors
DevOps & Monitoring vendors that hold FedRAMP certification
Datadog
17/32Cloud monitoring and analytics platform for infrastructure, applications, and logs.
FedRAMP Moderate authorized, verified on marketplace.fedramp.gov
MongoDB Atlas
17/32Fully managed cloud database service with multi-cloud support.
FedRAMP Moderate authorized for Atlas for Government
ServiceNow
17/32Cloud platform for IT service management, workflow automation, and enterprise operations.
High P-ATO
GitHub
13/32Code hosting platform with version control, CI/CD, and collaboration tools.
GitHub Enterprise Cloud FedRAMP Tailored authorized per government.github.com
Mendix
13/32Low-code application development platform, owned by Siemens.
Freshservice
10/32IT service management (ITSM) platform from Freshworks.
FedRAMP Readiness stage
Google Apigee
10/32API management platform, part of Google Cloud.
JFrog
7/32DevOps platform for artifact management, binary repositories, and software supply chain security.
Referenced elsewhere on site regarding regulatory standards
PagerDuty
6/32Incident management and digital operations platform for IT teams.
FedRAMP Moderate authorized, verified on marketplace.fedramp.gov
New Relic
6/32Observability and application performance monitoring (APM) platform.
MuleSoft
6/32Integration and API management platform (Anypoint Platform), part of Salesforce.
Available via MuleSoft Government Cloud
Bitbucket
5/32Git-based source code repository and CI/CD platform from Atlassian.
FedRAMP-compliant solutions for public sector
LaunchDarkly
5/32Feature management and experimentation platform for software delivery.
Kong
4/32API gateway and AI/API connectivity platform.
Partial per the vendor's trust center; the specific condition is not detailed there.
GitLab
3/32DevSecOps platform for source code management, CI/CD, and software delivery.
GitLab Dedicated for Government achieved FedRAMP Moderate Authorization (2025)
CircleCI
2/32Continuous integration and continuous delivery (CI/CD) platform.
SOC 2 and FedRAMP reports referenced in support documentation
These devops & monitoring vendors do not currently hold FedRAMP certification:
- Supabase
- Travis CI (not documented)
- Jenkins (not documented)
- Postman (not documented)
- Sentry (not documented)
- AppDynamics (not documented)
- Grafana Cloud (not documented)
- Honeycomb (not documented)
- Rollbar (not documented)
- Bugsnag (not documented)
- Zapier (not documented)
- Bubble (not documented)
- Make (not documented)
- n8n (not documented)
- Retool (not documented)
- OutSystems (not documented)
- Betty Blocks (not documented)
- Glide (not documented)
- Softr (not documented)
- SolarWinds (not documented)
- ManageEngine (not documented)
- Datto RMM (not documented)
- ConnectWise (not documented)
- Kaseya (not documented)
- NinjaOne (not documented)
- Tyk (not documented)
- BrowserStack (not documented)
- Sauce Labs (not documented)
- LambdaTest (not documented)
- TestRail (not documented)
- Cypress.io (not documented)
- Applitools (not documented)
- SonarQube (not documented)
Know a vendor we're missing?