FedRAMP Authorized — High Impact

Palantir Gotham by Palantir. 6 compliance features verified.

Analytics & BI

Palantir Gotham

by Palantir

High ImpactAuthorized

Impact Level

High

Status

Authorized

Pricing

enterprise

Authorization Date: March 10, 2018 | Sponsoring Agency: DoD

Overview

Palantir Gotham is a FedRAMP High authorized data integration and intelligence analysis platform purpose-built for defense and intelligence organizations. It provides entity resolution, link analysis, and geospatial intelligence capabilities. The platform enables analysts to discover hidden patterns across massive disparate datasets.

Key Features

FedRAMP High baseline controls
Entity resolution and link analysis
Geospatial intelligence mapping
Temporal pattern analysis
Multi-source data fusion
Role-based access with need-to-know

Certifications & Authorizations

FedRAMP High Authorization (JAB P-ATO)DoD SRG IL4/IL5 AuthorizationSOC 2 Type IIISO 27001:2013FIPS 140-2 Level 3 cryptographic modulesCommon Criteria EAL4+ evaluationSection 508 accessibility complianceITAR compliance certification

Deployment Options

AWS GovCloud (US-West) — IL4/IL5 authorized environment with FedRAMP High boundary
AWS GovCloud (US-East) — IL4/IL5 authorized environment with dedicated tenant isolation
On-premises deployment via Palantir's hardened appliance infrastructure
Hybrid cloud deployment combining GovCloud and on-premises components
Air-gapped deployment for classified networks up to SECRET//NOFORN
Multi-tenant SaaS deployment within FedRAMP High boundary for IL2/IL4 workloads

NIST 800-171 Compliance Coverage

92% of controls covered

How to Procure Palantir Gotham for Defense Contracts

Palantir Gotham is available through GSA MAS (Contract #47QSWA19D0063) and DoD ESI Encore III contract vehicles. Commercial pricing starts at $2.5M annually for enterprise deployments, while government pricing includes volume discounts and multi-year agreement incentives. The FedRAMP High P-ATO covers the complete authorization boundary including data ingestion, processing, analytics, and visualization components deployed in AWS GovCloud. Contracting officers must approve the government-furnished information (GFI) data classification levels, user access controls implementation, and interconnection agreements for data feeds from existing DoD systems. The SSP inheritance documentation clearly defines customer vs. Palantir security control responsibilities, particularly for AC-2 (Account Management), SC-7 (Boundary Protection), and AU-2 (Event Logging). Typical procurement timeline spans 6-9 months including security review, pilot deployment, and full production authorization. For CMMC Level 2 compliance, include Gotham within your assessment boundary as a cloud service provider, documenting data flow mappings, access control matrices, and incident response procedures. Ensure your CMMC assessment covers the contractor's configuration management of user roles and data classification handling within the platform.

Compliance Cross-References

Palantir Gotham's FedRAMP High authorization directly satisfies DFARS 252.204-7012 requirements for adequate security when processing covered defense information (CDI). The platform's cloud deployment architecture aligns with DFARS 252.239-7010 cloud computing security requirements through inherited AWS GovCloud FedRAMP controls. NIST 800-171 control family compliance includes: Access Control (AC) through role-based permissions and multi-factor authentication; System and Communications Protection (SC) via encryption in transit/at rest and network segmentation; Audit and Accountability (AU) through comprehensive logging and monitoring capabilities. For CMMC Level 2, Gotham addresses Access Control (AC), Audit and Accountability (AU), Configuration Management (CM), Identification and Authentication (IA), and System and Communications Protection (SC) domains. The DoD Cloud Computing SRG IL4/IL5 authorization ensures appropriate security controls for processing Controlled Unclassified Information (CUI) and Secret-level data, with data sovereignty maintained within US boundaries and appropriate personnel security clearances verified.

Defense Contractor Use Case

Defense contractors use Palantir Gotham for intelligence analysis, threat assessment, and operational planning, integrating data from multiple classified and unclassified sources.

Frequently Asked Questions

What is the FedRAMP authorization level for Palantir Gotham?

Palantir Gotham is authorized at the FedRAMP High impact level, with authorization granted on 2018-03-10 sponsored by DoD. The FedRAMP High baseline includes approximately 421 security controls and is the most rigorous authorization level.

Can defense contractors use Palantir Gotham for CUI?

Yes, Palantir Gotham is authorized at the FedRAMP High baseline, which is suitable for protecting CUI. Defense contractors can use this platform for processing, storing, and transmitting CUI in compliance with NIST 800-171 and DFARS 252.204-7012 requirements. The High baseline provides the most comprehensive set of security controls for cloud services.

How does Palantir Gotham pricing compare to commercial?

Palantir Gotham government pricing is typically negotiated on an enterprise basis and may differ from commercial list prices. Government and defense contractor pricing often includes compliance overhead that can make it 15-30% higher than commercial equivalents. However, volume discounts, GSA Schedule pricing, and multi-year commitments can help offset these costs. Contact Palantir directly or check GSA Advantage for current government pricing.

Browse All FedRAMP Authorized Tools

Search and filter 80+ FedRAMP authorized products for your defense contracting needs.

Open FedRAMP Finder

Get a defensible CUI architecture

This Palantir Gotham FedRAMP profile flags the gaps. The next step is a compliance architecture review where we map your data flows to FedRAMP-authorized alternatives and CMMC-aligned controls.

Schedule architecture review

Related: how much CMMC certification costs — DoD’s own priced figures