United States
US data residency with FedRAMP, HIPAA, and multi-sector compliance
US customers choose from AWS US-EAST, US-EAST-2, or US-WEST-2. Federal agencies deploy in GovCloud. ManySignal supports HIPAA BAA, FedRAMP-aligned controls, CCPA, NIST 800-53, and automated tracking of all 50 state breach notification timelines.
US deployment options
Commercial Cloud (AWS US regions)
AWS US-EAST-1 (N. Virginia), US-EAST-2 (Ohio), or US-WEST-2 (Oregon). HIPAA-eligible infrastructure. SOC 2 Type II certified. Suitable for financial services, healthcare, SaaS, retail, and all commercial sectors.
GovCloud (AWS GovCloud)
AWS GovCloud US-EAST and US-WEST. FedRAMP-eligible infrastructure. ITAR-compliant data handling. CAC/PIV authentication integration. Suitable for federal agencies, DoD contractors, and regulated government suppliers.
US regulatory frameworks supported
NIST CSF 2.0
NIST SP 800-53 Rev 5 (FedRAMP / FISMA)
NIST SP 800-171 Rev 2 (CMMC / DFARS)
HIPAA Security Rule & Breach Notification Rule
GLBA Safeguards Rule
PCI DSS v4.0
SOX IT Controls
SEC Regulation S-P
FFIEC Cybersecurity Assessment Tool
NERC CIP
CCPA / CPRA
All 50 State Breach Notification Laws
US breach notification — 50 state compliance
ManySignal tracks breach notification deadlines for all 50 US state breach notification laws. When an incident is confirmed, the case management system automatically identifies the applicable state laws based on affected individual residency and starts the notification countdown for each jurisdiction.
California (CCPA/CPRA)
30 days — notification to affected residents
New York (SHIELD Act)
Most expedient time without unreasonable delay
Texas (TDPSA)
30 days — notification to AG if 500+ Texans affected
US sales and support
US commercial sales: [email protected]
US government sales: [email protected]
Support: 24x7 US-based SOC team available for GovCloud customers
US deployment — common questions
What AWS regions are available for US customers?
US customers can deploy ManySignal in AWS US-EAST-1 (N. Virginia), AWS US-EAST-2 (Ohio), or AWS US-WEST-2 (Oregon). GovCloud customers use AWS GovCloud US-EAST or US-WEST. The deployment region is selected during onboarding and specified in the customer agreement. Multi-region deployments with DR replication are available for enterprise customers.
Does ManySignal support FedRAMP for federal agency deployments?
ManySignal is pursuing FedRAMP authorization. Federal agencies may deploy ManySignal in FedRAMP-eligible AWS GovCloud infrastructure under an Agency ATO while marketplace authorization is in progress. The system security package, including the SSP and control implementation summary, is available to federal agencies under NDA. Contact your ManySignal government account team.
How does ManySignal support CCPA and state privacy law compliance?
ManySignal acts as a Service Provider under CCPA — processing personal data only for the purposes specified in the contract, not selling or sharing data with third parties for cross-context advertising. For organizations with California employees whose data is processed by ManySignal (e.g., identity and access logs), ManySignal's DPA covers CCPA/CPRA obligations. Multi-state privacy law compliance (Virginia CDPA, Colorado CPA, Texas TDPSA) is addressed in the DPA as well.
Does ManySignal support HIPAA for US healthcare customers?
Yes. ManySignal executes Business Associate Agreements (BAAs) with US healthcare customers. All PHI is processed in HIPAA-eligible AWS infrastructure with AES-256 encryption, TLS 1.3, and restricted staff access. ManySignal's BAA is available at /legal/baa. For federal health agencies, HIPAA compliance is maintained alongside FedRAMP controls in GovCloud deployments.
What US-specific compliance frameworks does ManySignal support?
ManySignal supports: NIST CSF 2.0, NIST SP 800-53 Rev 5 (for FedRAMP/FISMA), NIST SP 800-171 (for CMMC/DFARS), GLBA Safeguards Rule, HIPAA Security Rule, PCI DSS v4.0, SOX IT Controls, SEC Regulation S-P, FFIEC CAT, NERC CIP, and all 50 state breach notification laws with automated notification timeline tracking.
Start your US deployment
Choose commercial or GovCloud, configure your HIPAA or FedRAMP requirements, and have the platform ingesting data within days.