Skip to content

Government & Public Sector

Zero Trust Access for Public Sector Systems

Public sector teams carry the largest legacy application estates and the strictest access requirements at the same time. MaskFlare Access publishes those applications individually so a contractor reaches one case management system rather than a network segment, and Radar covers the constituent-facing side where appointment slots and benefits applications get taken by scripts.
MaskFlare is in development · Capabilities below are described as intended, and pilot scope is agreed case by case
access path
  1. 01

    Request

  2. 02

    Policy check

  3. 03

    Approved path

01

Requirements reviewed with your team

02

Technical fit and integrations assessed

03

Pilot scope defined around measurable outcomes

How access actually works in an agency

An agency estate is layered rather than replaced. A benefits case management system from 2009 still runs, because the program it administers still exists. Around it sit a records system, a GIS platform, a document repository, and three integrations built by three different contractors across two decades.

The people reaching those systems are not one population either. Career staff on issued devices, a systems integrator's engineers, a seasonal cohort hired for a filing period, and staff from another agency who need one shared function. Historically all four got the same thing: a VPN account and a network they could see far too much of.

Federal zero trust direction, set out in OMB M-22-09 and the CISA Zero Trust Maturity Model, has been clear for years about where this is meant to go. The hard part was never the target state. It is that the systems in question cannot be rewritten, and that is exactly the constraint per-application access is built for.

Where government & public sector is actually exposed

Five failure modes specific to this environment, not a restatement of general security advice.

01

Legacy applications that cannot be modernised first

The mainframe front end, the case management system, and the records platform all predate every modern authentication standard. They cannot be rewritten on a security timeline, and any control requiring the application to change is a control that will not ship.

02

Contractor and systems integrator access

Integrators need deep access to the systems they maintain, often across multiple agencies, with staff rotating on and off the contract. When that access is a VPN account, offboarding becomes a paperwork exercise, and reach is defined by network topology rather than by the statement of work.

03

Automated abuse of constituent services

Anywhere a public service allocates something scarce, scripts show up. Appointment slots for licensing and immigration services get taken the moment they are released and resold. Benefits and grant portals attract fraudulent applications submitted at machine speed. Neither looks like an attack; both look like citizens filling in forms.

04

Cross-agency and inter-jurisdictional access

One team needs a single function in another agency's system. The clean answer is one published application governed by both sides. The common answer is a site-to-site tunnel and a trust relationship far broader than the requirement, which then outlives the project that created it.

05

Research and monitoring from an attributable range

Investigators, threat analysts, and policy researchers work from address ranges that publicly resolve to a government body. That is a signal to whatever is on the other end, and it changes both what is served and who knows the enquiry happened.

Who this page is for

Agency CISO
Has to show maturity progress against zero trust guidance using systems that cannot be replaced.
Contracting and vendor management
Needs a vendor's access to match the statement of work and end when the contract does.
Program and service delivery
Owns the constituent-facing service and the queue of people who could not get a slot.
Identity and credential management
Runs the authoritative directory and wants applications to consume it rather than route around it.
Network operations
Maintains the VPN concentrators, the tunnels, and the accumulated exceptions nobody has authority to remove.

How a team would actually run this

Publishing a legacy case management system without touching it

  1. 01 Deploy a connector on the network the application already sits on. The application is not modified, moved, or re-hosted.
  2. 02 Publish it as a named resource and bind policy to your existing identity provider, so authorization follows the directory that is already authoritative.
  3. 03 Run it in parallel with VPN access for a defined pilot window and compare outcomes with real users rather than a lab test.
  4. 04 Withdraw VPN reach for that application once it is verified. Reach is now described by a policy you can produce on request.

Giving an integrator access that matches the contract

  1. 01 Map the statement of work to specific applications rather than to network ranges. If the mapping is hard, that difficulty is itself the finding.
  2. 02 Grant per-application access to the integrator's identity group, with time bounds matching the contract period.
  3. 03 Where the work is sensitive, deliver it through an isolated browser session so no data lands on a device you do not control.
  4. 04 Offboarding becomes a directory change rather than a firewall change, which is the difference between it happening on time and happening eventually.

Keeping appointment slots available to people rather than scripts

  1. 01 Score the booking endpoint on interaction behavior, since the scripts taking slots submit well-formed requests that a rule cannot distinguish from a fast citizen.
  2. 02 Challenge on suspicion rather than block outright, because a wrongly blocked constituent has no alternative channel and will escalate.
  3. 03 Keep an accessible path. Any challenge mechanism has to work for assistive technology, or the control has created a different kind of exclusion.
  4. 04 Publish nothing about the detection logic. Public detail on thresholds is a specification for whoever is writing the next script.

Which modules apply, and why

Each links to the module page, where the boundaries and development status are set out in full. Or start at the MaskFlare platform overview.

Regulatory context

Readiness and relevance, not certification. Nothing here is a claim to hold an audit or authorization we do not have.

FedRAMP
MaskFlare is not FedRAMP authorized and is not in process. For US federal workloads requiring authorization today, we are not a fit, and we would rather tell you now than during a procurement.
OMB M-22-09 and CISA Zero Trust Maturity Model
Per-application access and per-request authorization map to the identity and network pillars of that guidance. MaskFlare is a control that supports maturity progress, not an accreditation.
NIST SP 800-207
The zero trust architecture definition MaskFlare Access is designed against. Useful as shared vocabulary in an evaluation.
UK, EU, and state-level equivalents
Requirements vary by jurisdiction and often by program. Tell us which regime applies and we will say plainly whether we meet it today.
See current commitments in the Trust Center

What MaskFlare does not do

  • MaskFlare is pre-launch, is not FedRAMP authorized, and holds no government accreditation in any jurisdiction. That rules us out of some procurements today, and we will say so early.
  • No public sector customers to name and no case studies to point at.
  • MaskFlare does not provide identity proofing, credential issuance, PIV or CAC infrastructure, or records management. It consumes your identity provider rather than replacing it.
  • Data residency for a specific jurisdiction is a scoping conversation, not a checkbox we can currently tick everywhere.

Four questions to ask any vendor here

Including us. If our answer is worse than someone else's, you should know that before a pilot, not during one.

  1. 01Can this publish a 2009 application that cannot be modified, and what exactly gets deployed to do it?
  2. 02When a contractor rolls off, what single action removes their access, and how long does it take to take effect?
  3. 03Is the vendor FedRAMP authorized, in process, or neither? Accept only one of those three words.
  4. 04How does the bot control handle constituents using assistive technology or older devices? A challenge that excludes people is a policy failure, not a tuning issue.

Workflow guides for this industry

How a team applies each of these, including the contrast with the tool it replaces.

Government & Public Sector questions we get asked

Is MaskFlare FedRAMP authorized?

No, and we are not currently in process. If your program requires FedRAMP authorization today, MaskFlare is not a fit, and saying that clearly is more useful to both of us than a roadmap answer.

Can this work with applications we cannot modify?

That is the primary design constraint. A connector is deployed on the network the application already sits on and publishes it as a named resource. The application itself is not changed, re-hosted, or re-authenticated.

How does this map to federal zero trust guidance?

Per-application access and per-request authorization sit in the identity and network pillars of the CISA maturity model, and align with the architecture described in NIST SP 800-207. It supports maturity progress. It is not an accreditation and does not substitute for one.

What stops scripts from taking every appointment slot?

Scoring the booking interaction rather than the request rate, because the scripts submit valid forms from ordinary-looking addresses. The design constraint specific to public services is that a wrongly challenged constituent often has no alternative channel, so the accessible fallback path matters as much as the detection.

Can we keep data within a specific jurisdiction?

It depends on the jurisdiction and the deployment shape, and it is a real scoping conversation rather than a setting. Raise it in the first call, because for some requirements the honest answer today will be no.

How do contractors on their own devices get access?

Through a browser-delivered session, so nothing installs on a device you do not manage and no data is left behind on it. That capability is in development, and which applications it covers first is part of pilot scoping.

Early customer program

We're looking for government & public sector teams with a specific exposure from the list above and a willingness to scope a pilot around one measurable outcome. Bring the constraint that makes it hard, because that is the part worth talking about.

Your next chapter starts here

Make room for possibility.
We'll talk protection.

Tell us what your team needs to protect.
Let's explore where MaskFlare could fit.

Talk to our team