Console
GOVCLOUD
Close

External Connections

Outbound links to SaaS and the web, reached only through a customer-owned egress broker. Each connection is a documented, risk-accepted object — distinct from a Tool — so every interconnection has an auditable record.

Interconnection register
4 connections3 accepted1 proposed

Every accepted connection is a row in the CA-3 / SA-9 interconnection inventory, attributed to a named risk owner and a review date.

Egress topology

An agent never reaches an external service directly. The path always runs Agent → Tool → egress broker → service. Solid = accepted; dashed = proposed.

Agent
in-VPC runtime
Tool
servicenow-incident
Egress broker
egress-broker-7741
ServiceNow GovCloud
vpce-0a91…servicenow (PrivateLink)
accepted
Agent
in-VPC runtime
Tool
tenable-scan-read
Egress broker
egress-broker-7741
Tenable.io
vpce-0b22…tenable (PrivateLink)
accepted
Agent
in-VPC runtime
Tool
gov-web-search
Egress broker
egress-broker-7741
USA.gov / data.gov Search
egress-broker → public-internet (bounded)
accepted

ServiceNow GovCloud

acceptedCUI
conn-servicenow-govcloud
per-end-user delegation
Authorization status
FedRAMP-High · F1607057513
Owning party
VDS IT
Egress account
egress-broker-7741
Broker target
vpce-0a91…servicenow (PrivateLink)
Acceptance ledger
acceptedDana Liu (Platform Admin)acc-0001
Review by 2026-11-02

FedRAMP-High far end over PrivateLink, CUI permitted under existing ATO boundary. Per-end-user delegation only; no service-wide token.

Tenable.io

acceptedFOUO
conn-tenable-io
service identity
Authorization status
FedRAMP-Moderate · F1419031923
Owning party
VDS Security Eng
Egress account
egress-broker-7741
Broker target
vpce-0b22…tenable (PrivateLink)
Acceptance ledger
acceptedDana Liu (Platform Admin)acc-0002
Review by 2026-11-04

Read-only scan results, FOUO. Service identity acceptable — no end-user data crosses the boundary.

USA.gov / data.gov Search

acceptedPUBLICweb search
conn-gov-search
service identity
Authorization status
none
Owning party
VDS Platform Admin
Egress account
egress-broker-7741
Broker target
egress-broker → public-internet (bounded)
Accepted scope — domain allowlist
data.govsearch.govusa.gov

The broker resolves only these domains. Every response is labelled untrusted — downstream egress/mutating tools require a Safe-Sink declaration.

Recent queries
QueryResolved domainLabelWhen
SAM.gov entity registration status lookupsearch.govuntrusted6d ago
FAR clause text by reference numberdata.govuntrusted6d ago
GSA schedule contract status lookupusa.govuntrusted7d ago
Acceptance ledger
acceptedDana Liu (Platform Admin)acc-0003
Review by 2026-08-21

Bounded web search, public sources only, domain allowlist enforced at the broker. Every response labelled untrusted; downstream egress/mutating tools require Safe-Sink declaration.

NWS Weather API

proposedPUBLIC
conn-nws-weather
service identity
Authorization status
none
Owning party
VDS Platform Admin
Egress account
egress-broker-7741
Broker target
egress-broker → api.weather.gov
Platform Admin — document & decide
proposed
  • Traffic to NWS Weather API will leave the platform boundary via the egress broker (egress-broker-7741).
  • Authorization status on file: none.
  • Accepting records you as the named risk owner in the CA-3 / SA-9 inventory.
Check the box to record your acceptance — never pre-checked.

Document + risk-accept. An external connection is not FedRAMP-required — but it is the auditable record of every external interconnection: what crosses the boundary, who owns it, who accepted the residual risk, and when it is next reviewed.