How we architected a FedRAMP Moderate boundary on AWS GovCloud for an AI SaaS
A redacted engineering write-up: draw the authorization boundary first, then write Terraform. Account topology, Bedrock under a BAA, KMS, OPA gates, and an SSP generated from modules.