BetaQuick Compliance

Compliance Hub

One page for procurement, legal, and CISO teams evaluating BetaQuick for a government AI deployment. Every framework we build against, every identifier you need for vendor onboarding, and the request mechanism for full documentation.

Business Identifiers

UEI
MDBYCN83MT69
CAGE
86Y32
SAM.gov
Active
8(a)
Pending
GSA MAS
Pending
Business Type
Small Business
NAICS Codes

541511 · 541512 · 541519 · 518210 · 541330 · 561422 · 611420

FEDERAL

FedRAMP Moderate (aligned)

BetaQuick's architecture is built against the FedRAMP Moderate control baseline - NIST 800-53 controls covering confidentiality, integrity, and availability for federal systems handling PII, PHI, and sensitive-but-unclassified data. Built on FedRAMP-authorized AWS and Azure. Contact center via Amazon Connect (FedRAMP High). LLM inference via Azure OpenAI Service (FedRAMP High). Transcription via AWS Transcribe and Azure Speech Services (both FedRAMP).

STATE / LOCAL / EDU

StateRAMP / GovRAMP Ready

StateRAMP is the SLED-government equivalent of FedRAMP, rebranding to GovRAMP. BetaQuick's FedRAMP Moderate alignment qualifies for StateRAMP Fast Track reciprocity. SOC 2 Type II practices layered on top.

HEALTHCARE

HIPAA (BAA executed)

Business Associate Agreement in place with customers, plus downstream BAAs with cloud, LLM, transcription, SMS, and payment sub-processors. End-to-end encryption of PHI at rest and in transit. Role-based access control with full audit logging. Aligned with NIST 800-53 and FedRAMP security controls.

MEDICAID

CMS MARS-E 2.2

Minimum Acceptable Risk Standards for Exchanges - CMS's flavor of NIST 800-53 for state Medicaid and exchange systems. Moderate controls for Medicaid member services deployments.

VA / VETERAN

VA Directive 6500

VA's information security framework layered on NIST 800-53. AI deployments on VA workloads pursue Authority to Operate (ATO) through VA channels. Full call recording and decision logging retained per VA records management requirements. Crisis routing to Veterans Crisis Line (988) built into escalation protocols.

PUBLIC SAFETY

CJIS Security Policy

For deployments touching criminal justice information - non-emergency dispatch triage, agency records interaction - CJIS Security Policy controls for data handling, access, personnel screening, and audit.

UNEMPLOYMENT

20 CFR Part 603 (UI Confidentiality)

USDOL's confidentiality rule for unemployment insurance data. Claimant data handling, use limitations, disclosure controls, and state-specific confidentiality statutes supported.

BEHAVIORAL HEALTH

42 CFR Part 2 (SUD Records)

Federal confidentiality rule for substance use disorder records. Required for state and tribal behavioral health programs. Consent-based disclosure, re-disclosure prohibition, and auditing.

FEDERAL TAX

IRS Publication 1075

For UI and benefit programs handling federal tax information. Additional safeguards, background checks, and audit requirements on top of NIST 800-53.

ACCESSIBILITY

Section 508 + ADA

AI voice agents accessible to citizens with hearing, speech, and cognitive differences. TTY routing, video relay support, slowed-speech mode, extended response timing. Past performance: SSA DCPS Modernization Section 508-compliant UI components (2016–2021).

LANGUAGE ACCESS

Section 1557

ACA language access satisfied through native multilingual coverage - English, Spanish, and 60+ languages. No language-line vendor handoff. Every interaction logged in source language and English.

TRIBAL

Tribal Data Sovereignty

For IHS and 638 tribal deployments, adaptation to tribe-specific data governance - on-reservation residency, tribe-specific consent, custom retention and audit rights.

AI-SPECIFIC

NIST AI RMF

NIST AI Risk Management Framework - Map, Measure, Manage, Govern functions. Controls for AI impact assessments, model supply-chain disclosure, human-in-the-loop oversight, decision explainability.

FEDERAL AI POLICY

OMB M-24-10 & AI Guidance

OMB guidance on federal AI use - AI impact assessments, risk categorization, pre-deployment review. Documentation prepared alongside FedRAMP authorization package.

DATA RESIDENCY

US-Only Inference & Storage

All call content, transcripts, customer records, and AI inference processed and stored inside US-based FedRAMP-authorized cloud regions. No offshore handoff.

CONTINUOUS

Continuous Monitoring (ConMon)

Monthly vulnerability scans, quarterly reporting, annual 3PAO reassessment cadence. POA&M tracking. Incident response SLA. Breach notification per state-specific and federal requirements.

Need compliance documentation for an RFP?

Capability statement, sub-processor list, BAA templates, authorization package references, past performance write-ups - all available on request.

Schedule a Call Request Documentation