# What happened Everlaw announced it received FedRAMP authorization for the third consecutive year, with the company publishing the notice on October 28, 2022. The announcement frames the authorization as validation that Everlaw meets FedRAMP's security requirements for cloud services used by federal and public-sector customers.
# What FedRAMP authorization means FedRAMP (Federal Risk and Authorization Management Program) defines the security requirements and processes cloud service providers must meet for U.S. government use. Authorization requires a formal security assessment, multiple layers of checks, audits, and ongoing monitoring. For a cloud provider, achieving FedRAMP authorization signals that the platform has completed a set of standardized security procedures and controls required by federal agencies.
# How Everlaw completed the process Everlaw outlined the specific activities completed as part of its FedRAMP authorization:
- Implementation and successful operation of required security controls on the Everlaw Federal platform.
- Completion of an annual penetration test of the Everlaw Federal platform.
- Regular vulnerability scans across the Everlaw platform.
- Submission and review of the Everlaw Platform System Security Plan and associated risk exposure tables.
Those elements form the backbone of a FedRAMP authorization package and help demonstrate how the platform protects data and responds to identified risks.
# What this changes for federal and commercial users For federal users: any division or agency within the federal government can adopt Everlaw's litigation platform with the assurance that it meets FedRAMP's prescribed standards. That removes a common procurement barrier where agencies need to validate a provider's security posture before deployment.
# Why the company highlights this now The announcement positions the authorization in the context of eDiscovery's migration to the cloud. Everlaw frames the FedRAMP authorization as part of its commitment to protect sensitive documents and data as legal teams and public-sector organizations increasingly rely on cloud platforms for litigation and investigations.
# About the announcement The blog post was authored by Vivan Marwaha of Everlaw's marketing team. The post is written as a short public update describing the achievement, the work completed to obtain the authorization, and implications for users.
# Practical takeaway If you work for a federal agency evaluating cloud litigation or eDiscovery platforms, Everlaw's FedRAMP authorization removes a key security and compliance unknown. Private-sector teams evaluating Everlaw should expect several FedRAMP-derived controls to be present in non-federal deployments, offering stronger security practices than some non-validated vendors.