Identity and access
Connect Antigen to Microsoft Entra ID or Okta for agency sign-on, then use role-based access to control who can view findings, manage policy, or start a run.
Control where Antigen runs, the policies it follows, who can access it, how every action is audited, and how long your data is retained.
Book a demoConnect agency identity, retention, and audit controls to the evidence your security, procurement, and oversight teams need.
Connect Antigen to Microsoft Entra ID or Okta for agency sign-on, then use role-based access to control who can view findings, manage policy, or start a run.
Choose how long pentest data is kept, retain only what your agency needs, or purge it on demand.
Record every run, finding, login, policy change, and data access, then stream those events to your agency's SIEM for centralized monitoring and investigation.
Use Antigen reports for NIST, CJIS, and FERPA reviews and cooperative purchasing.
Use Antigen as a managed service or run the entire stack inside your own infrastructure.
Use Antigen as a managed SaaS with the same enterprise controls and integrations available in a Dedicated deployment.
Run the entire Antigen stack inside infrastructure you control so no testing data leaves your network boundary.
Continuous testing for public agencies, water and power providers, and K-12 and higher education.
Antigen helps state and local security teams test approved applications, APIs, and connected infrastructure on a recurring basis, with evidence system owners can act on.
Water and power providers can test the public-facing and enterprise systems connected to essential services without treating every environment as the same network.
Antigen helps K-12 districts and higher education institutions test open, distributed environments while keeping findings connected to the people who own each system.
Antigen partners with Pursuit, a public-sector reseller, to help government teams navigate purchasing and contracting requirements.
Trigger pentests, automate security workflows, and build internal tools with the API and SDK. Authenticate with an API key or an access token.
Start a pentest before or after a release from the pipeline you already run.
Connect Antigen to your existing software factory so remediation uses its codebase context and produces the PR quality your team already trusts.
Bring run status, findings, and audit events into internal security tools.
Use scoped API keys for machine-to-machine workflows and automation.
Connect Antigen to your existing identity provider so employee access follows the roles and permissions you already manage.
Build an Antigen interface in Slack, Retool, or the internal dashboard your team already uses.
Connect Antigen to the identity, policy, data, and audit systems your organization already uses.
Connect SAML 2.0 or OIDC through Okta, Entra ID, or Google Workspace. SCIM provisions access from your employee directory and removes it when someone leaves.
Record every run, finding, access event, and material state change. Stream events into Splunk, Datadog, Elastic, Microsoft Sentinel, or Panther.
Define which employees can view reports, connect repositories, manage findings, or change testing policy.
KMS encryption protects data at rest, encryption protects it in transit, and every customer's data remains isolated.
Antigen retains the data needed to run your pentests. You control how long it is kept with a 30-day, 90-day, or custom policy, and can purge it on demand.
Organize technical findings and supporting evidence for customer-led GovRAMP and FISMA reporting and authorization work.
Reporting and authorization support
Customer requirement support
Map findings and remediation evidence to the frameworks and reporting requirements your program uses.
Control mapping
Requirement mapping
Safeguard mapping
Reporting requirement mapping
Antigen works with Pursuit to help agencies identify direct, reseller, and cooperative purchasing paths. Vehicle availability and eligibility remain program-specific.
Data processing terms
Commercial agreement support
Contract pathway support
Program documentation support
Move confirmed findings into the systems your security and engineering teams already use.
CISA lists penetration testing as an eligible assessment and evaluation activity under the State and Local Cybersecurity Grant Program. Funding still depends on the current notice of funding opportunity, the approved state plan, and the award terms, so confirm each proposed project with your grant administrator.
Engagements can be scoped to produce findings, retest evidence, and technical detail for a GovRAMP or FISMA authorization package. Required controls and artifacts depend on the agency and system boundary, and this support does not represent a certification or authorization.
Dedicated deployments run the Antigen frontend, control plane, and workers inside infrastructure you control. The dashboard, findings, logs, and artifacts stay on your systems, so no testing data leaves your private network.
Deployment determines where credentials, findings, logs, and artifacts are stored. Retention periods and on-demand purging can be set to match agency policy, subject to the agreed deployment and contract terms.
Testing can be limited to systems and control objectives relevant to CJIS or FERPA, with reports that record scope, findings, and verification results. Your agency or assessor determines whether that evidence satisfies a requirement; using Antigen does not by itself establish compliance.
Antigen can review agency DPA and MSA terms and discuss available direct, reseller, or cooperative purchasing paths. Vehicle availability and eligibility vary by jurisdiction, so your procurement team should confirm the applicable route.
The system owner must provide written authorization and an explicit scope before testing begins. That approval should identify targets, testing windows, allowed methods, points of contact, and prohibited actions; testing stays within the approved boundary.
Book a 30-minute demo to review your deployment requirements and watch a live pentest.