Containerized workloads
Each site in its own container with scoped credentials. A compromise in one tenant can’t reach another.
Services →Consumer hosting fails the audit. YesGov runs every government site on hardware we control — isolated containers, segmented networks, monitored endpoints. RPKI keeps your IP space from being silently re-announced; IPv6 keeps you reachable for the residents whose ISPs already cut over.
No third-party shared hosting, no “cloud reseller,” no opaque control plane. We run the boxes; we know the patch level.
Each site in its own container with scoped credentials. A compromise in one tenant can’t reach another.
Services →Cryptographic proof of which AS is allowed to announce your prefix. Hostile re-announcement is rejected by validating networks.
RPKI guide →AAAA records, dual-stack reachability. Residents on IPv6-first ISPs reach the site without v4 fallback.
IPv6 guide →Three copies, two media, one off-site. Daily snapshots, weekly point-in-time, monthly cold-storage. Restore drills documented.
Backups & DR →Humans on call every day. Automated containment, escalation runbooks, every incident logged for the audit trail.
Services →Sender IPs monitored against blocklists. Mail flow watched for delivery anomalies before they impact residents.
IP reputation →Another network announces your IP space. Traffic meant for your .gov gets silently diverted through a hostile transit provider.
Shared-hosting neighbor gets compromised. Without container isolation the attacker can pivot to your filesystem and database.
Ransomware encrypts everything — you find out at the worst moment that backups can’t actually restore.
Resident on T-Mobile or another v6-only network can’t reach your v4-only site. Quiet failure, no error visible to you.
How ROAs sign your prefixes and why validating networks reject hostile announcements.
AAAA records, dual-stack reachability, and the residents who can’t reach you without it.
What blocklists watch, why your mail starts bouncing, and how to recover.
Three copies, two media types, one off-site — and how to actually test the restore.
Same annual fee covers the migration, the hardware, the monitoring, and the documented restore procedure your insurer needs.