Security testing built for government boundaries

Control where Antigen runs, the policies it follows, who can access it, how every action is audited, and how long your data is retained.

Book a demo

Meet the governance requirements public agencies need

Connect agency identity, retention, and audit controls to the evidence your security, procurement, and oversight teams need.

Fine horizontal lines compress toward a tall, empty central aperture, with oxide registration marks and faint calibration ticks.

Identity and access

Connect Antigen to Microsoft Entra ID or Okta for agency sign-on, then use role-based access to control who can view findings, manage policy, or start a run.

Data retention controls

Choose how long pentest data is kept, retain only what your agency needs, or purge it on demand.

Audit trail

Record every run, finding, login, policy change, and data access, then stream those events to your agency's SIEM for centralized monitoring and investigation.

Procurement and compliance

Use Antigen reports for NIST, CJIS, and FERPA reviews and cooperative purchasing.

Choose where Antigen runs.

Use Antigen as a managed service or run the entire stack inside your own infrastructure.

Managed

Use Antigen as a managed SaaS with the same enterprise controls and integrations available in a Dedicated deployment.

  • Isolated infrastructure managed by Antigen
  • SSO, audit logs, API, SDK, and integrations included
  • Customer-defined testing and retention policies
  • Fastest path to production

Dedicated (on-premises)

Run the entire Antigen stack inside infrastructure you control so no testing data leaves your network boundary.

  • Frontend, control plane, and workers run in your environment
  • Delivered as a Helm chart or container image
  • Dashboard, findings, logs, and artifacts stay on your systems
  • Operates entirely within your private network

Security for the systems communities depend on.

Continuous testing for public agencies, water and power providers, and K-12 and higher education.

State and local government

Antigen helps state and local security teams test approved applications, APIs, and connected infrastructure on a recurring basis, with evidence system owners can act on.

  • Test public portals, internal services, and vendor-connected systems within an approved scope.
  • Trace reachable attack paths across cloud, on-premises, and third-party dependencies.
  • Retest fixes after changes and keep findings tied to the affected systems.
Public utilities

Water and power providers can test the public-facing and enterprise systems connected to essential services without treating every environment as the same network.

  • Test customer portals, billing systems, APIs, and remote-access gateways.
  • Identify reachable paths between enterprise IT, vendor access, and operational support systems.
  • Verify remediation after network, application, or access-control changes.
Education

Antigen helps K-12 districts and higher education institutions test open, distributed environments while keeping findings connected to the people who own each system.

  • Test student, family, faculty, and administrative applications across distributed environments.
  • Find exposed identities, APIs, and third-party integrations that create paths deeper into the network.
  • Retest after releases, term changes, and remediation work.

A simpler path to public-sector procurement.

Antigen partners with Pursuit, a public-sector reseller, to help government teams navigate purchasing and contracting requirements.

Build your security program on the Antigen API.

Trigger pentests, automate security workflows, and build internal tools with the API and SDK. Authenticate with an API key or an access token.

CI/CD pipelines

Start a pentest before or after a release from the pipeline you already run.

Software factories

Connect Antigen to your existing software factory so remediation uses its codebase context and produces the PR quality your team already trusts.

Internal observability

Bring run status, findings, and audit events into internal security tools.

API key authentication

Use scoped API keys for machine-to-machine workflows and automation.

Access token authentication

Connect Antigen to your existing identity provider so employee access follows the roles and permissions you already manage.

Custom frontends

Build an Antigen interface in Slack, Retool, or the internal dashboard your team already uses.

Control every run, user, and artifact.

Connect Antigen to the identity, policy, data, and audit systems your organization already uses.

SSO and SCIM

Connect SAML 2.0 or OIDC through Okta, Entra ID, or Google Workspace. SCIM provisions access from your employee directory and removes it when someone leaves.

Audit logs and SIEM

Record every run, finding, access event, and material state change. Stream events into Splunk, Datadog, Elastic, Microsoft Sentinel, or Panther.

Role-based access

Define which employees can view reports, connect repositories, manage findings, or change testing policy.

Data encryption

KMS encryption protects data at rest, encryption protects it in transit, and every customer's data remains isolated.

Data handling and retention

Antigen retains the data needed to run your pentests. You control how long it is kept with a 30-day, 90-day, or custom policy, and can purge it on demand.

Reports and compliance, ready for government review.

Authorization support

Organize technical findings and supporting evidence for customer-led GovRAMP and FISMA reporting and authorization work.

GovRAMP

Reporting and authorization support

FISMA

Customer requirement support

Compliance mapping

Map findings and remediation evidence to the frameworks and reporting requirements your program uses.

NIST

Control mapping

CJIS

Requirement mapping

FERPA

Safeguard mapping

CIRCIA

Reporting requirement mapping

Procurement

Antigen works with Pursuit to help agencies identify direct, reseller, and cooperative purchasing paths. Vehicle availability and eligibility remain program-specific.

DPA

Data processing terms

MSA

Commercial agreement support

Cooperative purchasing

Contract pathway support

Grant eligibility

Program documentation support

Fits into your existing workflows.

Move confirmed findings into the systems your security and engineering teams already use.

Antigen connects to Jira, AuditBoard, Azure DevOps, Microsoft Teams, Splunk, Tenable, Power BI, Metabase, Slack, ServiceNow, GitHub, and Linear.
  • Jira
  • AuditBoard
  • Azure DevOps
  • Microsoft Teams
  • Splunk
  • Tenable
  • Power BI
  • Metabase
  • Slack
  • ServiceNow
  • GitHub
  • Linear

Frequently asked questions

Can CISA State and Local Cybersecurity Grant Program funds cover penetration testing?

CISA lists penetration testing as an eligible assessment and evaluation activity under the State and Local Cybersecurity Grant Program. Funding still depends on the current notice of funding opportunity, the approved state plan, and the award terms, so confirm each proposed project with your grant administrator.

How can Antigen support GovRAMP or FISMA reporting?

Engagements can be scoped to produce findings, retest evidence, and technical detail for a GovRAMP or FISMA authorization package. Required controls and artifacts depend on the agency and system boundary, and this support does not represent a certification or authorization.

Can Antigen run inside our network boundary?

Dedicated deployments run the Antigen frontend, control plane, and workers inside infrastructure you control. The dashboard, findings, logs, and artifacts stay on your systems, so no testing data leaves your private network.

What data residency and retention controls are available?

Deployment determines where credentials, findings, logs, and artifacts are stored. Retention periods and on-demand purging can be set to match agency policy, subject to the agreed deployment and contract terms.

Can testing support CJIS- or FERPA-aligned reviews?

Testing can be limited to systems and control objectives relevant to CJIS or FERPA, with reports that record scope, findings, and verification results. Your agency or assessor determines whether that evidence satisfies a requirement; using Antigen does not by itself establish compliance.

What contracting and purchasing paths are available?

Antigen can review agency DPA and MSA terms and discuss available direct, reseller, or cooperative purchasing paths. Vehicle availability and eligibility vary by jurisdiction, so your procurement team should confirm the applicable route.

What approval is required to test government systems?

The system owner must provide written authorization and an explicit scope before testing begins. That approval should identify targets, testing windows, allowed methods, points of contact, and prohibited actions; testing stays within the approved boundary.

See Antigen test your environment.

Book a 30-minute demo to review your deployment requirements and watch a live pentest.

Get a demo