Technical Summary · for review teams

govFMP: prompt quality assurance and governance, inside your boundary

Model Single-tenant, self-hosted Data path to vendor None Integration One base-URL change

Staff already use AI. govFMP puts a measurable, logged control between them and whatever model your agency has approved, so every prompt is scored, cleared, and recorded before its output is trusted. It runs entirely within your network. The vendor never sees a prompt.

How it sits in your network

Staff tools
ChatGPT, Copilot,
agency chatbot, IDE
same API
govFMP gate
score · clear · log
pass / review
Your model
Azure OpenAI Gov,
Bedrock, or local
▲  block (enforce mode) → a clear refusal, logged with its reason, and it never reaches the model
Agency network

Everything above lives here. govFMP holds the only network route and the only model credential, so a prompt cannot reach a model except through the gate.

🔒 Enforced by your controls: egress rule makes the raw model endpoint unreachable except from govFMP · model key held only inside govFMP
No outbound connection leaves the boundary except to your approved model. The vendor has no telemetry, no console, no access.

What it does per prompt

Deployment and control

Runs where you say

OCI container in your VPC / GovCloud subscription or on-prem. Air-gap capable, offline license, no phone-home.

Your identity, your logs

SSO/SAML/OIDC, PIV/CAC where required. Scores and audit records write to your datastore. The vendor has no read path.

Your rules, versioned

Mode, thresholds, prohibited data categories, role exceptions, and rubric "packs" are declarative config under your change control. The vendor cannot alter them remotely.

Monitored in your stack

/metrics for Prometheus, decisions streamed to your SIEM (Splunk, Sentinel), plus a governance dashboard with an over-block watch.

Compliance posture

Adopting it