U.S. SLED · Capabilities & compliance

What we bring, and how we secure it.

The engineering we plug in on day one, the compliance posture your security officer needs, and the architecture behind both.

Core capabilities

Six capabilities, mapped to NAICS and NIGP.

The back-end build behind your brand, under your contract. Each row is work we've shipped, mapped to the codes a prime files against.

Capability
What we do
NAICS / NIGP
Enterprise Application Development
Citizen-service portals, case management, and back-office systems built to agency requirements and delivered under the prime contract.
NAICS 541511 · NIGP 920-29
Systems Modernization & Integration
Legacy modernization within procurement and budget constraints; inter-agency integration that breaks down data silos and meets interoperability requirements.
NAICS 541512 · NIGP 918-46
AI & Process Automation
Automated case routing, document intake, and decision support that reduce manual processing and backlog for understaffed program teams.
NAICS 541511 · NIGP 920-29
GIS & Geospatial Data
Facility and asset inventories, parcel and permitting data, and forecast models for planning, public works, and environmental programs.
NAICS 541519 · NIGP 918-00
Data, Reporting & Grant Compliance
Audit-ready data pipelines, grant and performance reporting, and FOIA-exportable records aligned to oversight and compliance requirements.
NAICS 541512 · NIGP 920-04
Accessibility & Statutory Documents
Section 508 and WCAG 2.2 AA conformance, VPAT preparation, and statutory document and format compliance for public-facing deliverables.
NAICS 541519 · NIGP 918-46
Compliance frameworks

The frameworks a prime compliance officer is looking for.

Specific claims with status, scope, and target dates. We don't list controls we can't substantiate; in-progress frameworks show a target date.

Operational cybersecurity controls. Independent audit of access, change management, monitoring, and incident response over a 6 to 12 month window.

Scope · platform, repos, IdP, deployTarget · Q4 2026Bridge letter on request

Required for law-enforcement, court, and dispatch work. Fingerprinted, background-checked U.S.-citizen personnel on U.S. soil; FIPS 140-2/3 encryption.

Onshore · CJIS-cleared staffOffshore · never touches CJIAttestations to CJIS coordinator

Cloud architectures we design are StateRAMP-aware. We build inside the prime's authorization boundary using controls that map to StateRAMP and TX-RAMP categorization.

Architecture & control mappingSSP narrative drafts3PAO response support

Required for all government digital interfaces. WCAG 2.2 AA validation, screen-reader regression, PDF/UA conversion, plain-language editing.

Signed VPAT 2.5 per surfaceNVDA & VoiceOver testedPrior VPATs under NDA

Standard hygiene for any prime serving federal customers. 110-control baseline across access, audit, configuration, incident response, and media protection.

Self-assessment completeSSP & POAM maintainedCMMC Level 2 alignment

Required for healthcare, eligibility, and tax-data engagements. BAA executed as Subcontracting under the prime BAA; offshore plane never touches FTI or PHI.

Mutual / flow-down BAAFTI onshore-only · Pub 1075 §9.3
Data architecture

Where the data goes. Who touches it.

The one question a prime compliance officer asks before paperwork moves. Live agency data, CJI, PHI, FCI, and CUI are handled only by U.S. personnel on U.S. soil. Lahore engineers work against sanitized, synthetic data behind a documented air-gap.

CONUS · US persons

Onshore plane

U.S.-citizen personnel on U.S. soil. The only environment cleared to handle live agency data, controlled information, and any work touching law-enforcement, judicial, or healthcare systems.

  • Engagement manager & technical liaison: single accountable contact for the prime PM. Status, escalations, and change requests flow here first.

  • Live data handling: any production pull touching CJI, PHI, FCI, CUI, or agency PII is performed onshore inside the prime's authorization boundary.

  • CJIS-cleared operations: fingerprinted, background-checked U.S. personnel on a CJIS-aligned workstation for law-enforcement, court, or dispatch systems.

  • Acceptance, KT, and deployment: final review, agency-facing artifact handoff to the prime, and production deployment gates.

Data classes handled here
CUIFCICJIPHIAgency PIILive production data
Lahore · Engineering

Offshore engineering plane

Senior engineers in Lahore working against sanitized environments, synthetic data sets, and API contracts that do not expose live agency endpoints. Where the bulk of the build happens, never against production data.

  • Codebase development: feature work against mock data and contract tests. Pull requests gated by onshore review before any live-data deployment.

  • Synthetic-data engineering: schema-faithful but content-scrubbed datasets for development and regression testing. Real records never leave the onshore plane.

  • Artifact production: architecture docs, runbooks, statutory-format templates, and dashboards, reviewed onshore before release.

  • Workstation controls: managed devices, disk encryption, DLP egress monitoring, no removable-media write, audit logs forwarded to the onshore SIEM.

Data classes handled here
Synthetic dataMock fixturesPublic-domain artifactsCodebase & configs
State-by-state offshore restrictions

Where we serve directly. Where the prime discloses. Where a waiver is required.

The U.S. landscape on offshore subcontracting is fragmented. Here's our posture, kept current. Always confirm against the live solicitation before bid.

Serve directly

Standard subcontract

Non-PII, non-CJI scopes proceed under standard prime terms.

Most SLED procurements
Permitting, environmental, GIS, public engagement, grant reporting, document production.
Disclose

Subcontract + offshore-handling disclosure

Permitted with explicit disclosure of offshore handling.

CJIS · national
Onshore-only CJI; U.S.-citizen staff vetted by state CJIS coordinators.
15+ states · Medicaid
Offshore rules range from disclosure-only to prohibition; HIPAA BAA layered on top.
Waiver / restructure

Written waiver or restructuring required

Onshore by default; bid-by-bid analysis.

MD
State CISO written waiver for any offshore activity.
CA · Gov't Code §19130
Onshore-only handling of state data.
NJ
Statutory offshore-labor limits; scope varies by agency.
AZ · FL · MO · TX
Medicaid data: disclosures and, in some scopes, restructuring.

// Disclosure pack on request · Updated quarterly · Confirm against live solicitation language

What we don't do

Honest about the lane.

Trust comes from knowing where the work ends. These belong to the prime, a specialist sub, or nobody at all.

Fieldwork

We support remotely; the prime owns the physical room.

Legal drafting

We follow the legal opinion; we don't issue it.

Product replacement

We don't compete with Tyler, Granicus, or OpenGov; we ship the custom piece they don't cover.

Procurement intelligence

We don't sell or resell RFP, tender, or solicitation data.

Engage us

Need the full compliance pack before your next subcontract review?

The capability statement, architecture diagram, control mapping, per-state posture page, and personnel attestation template, sent under NDA within one business day.

Frequently asked questions

SLED Backbone Capabilities

Answers about what Techtiz can plug into on day one of a pursuit or delivery effort.

What technical domains does the SLED backbone cover?

Core competencies include GIS and spatial systems, AI and intelligence (LLM/RAG, agents, ML pipelines), workflow automation, statutory document production, grant and compliance reporting, and platform modernization, each scoped to your subcontract SOW.

Can Techtiz support proposal and orals work pre-award?

Yes, under an executed teaming letter and NDA: technical volumes, compliance matrices, demonstrable prototypes, and past-performance packaging aligned to your capture strategy, not as a separate prime offer.

Which compliance frameworks does delivery align to?

Engagements are wrapped to the frameworks your flow-down requires, commonly NIST SP 800-171, SOC 2, StateRAMP, CJIS, Section 508/VPAT, CMMC, HIPAA, and IRS Pub 1075. Confirm certification versus roadmap status per framework before external claims.

How does insurance and registration route through the prime?

Insurance and liability flow through your master agreement. NAICS 541511 and 541512 and state NIGP 918-46 / 918-00 are listed on our capability materials for subcontract paperwork.

What work is explicitly out of scope?

We do not prime contracts, face agencies, or compete with partners. We do not take ownership of the agency relationship or publish deliverables under the Techtiz brand on active government work.