Monitoring Level I
$199 / month
- Up to 3 active BOMs / 500 total lines.
- Daily regulatory screening and monthly reporting.
- Billed monthly under a recurring service agreement. Annual agreements include a two-month discount.
Compliance & Engineering Services
Procure individual BOM audits, scope custom advisory services, or deploy continuous lifecycle monitoring for your product family. Initial system evaluations provide up to five compliance flags at no cost to validate engine capabilities.
One-Time BOM Audit
$600 / BOM Audit
A comprehensive, one-time regulatory cross-reference. No payment is required at upload; orders are confirmed upon delivery of the findings to your secure workspace.
Custom Scope
Project parameters and delivery requirements are defined prior to pricing.
Active BOM Monitoring
Regulatory lists change, and suppliers undergo acquisitions. Active monitoring provides daily checks against the Consolidated Screening List and FCC Covered List, delivering a documented monthly record of supplier ownership changes and lifecycle events where supported data is available.
Monitoring Level I
Monitoring Level II
Portfolio Monitoring
For product families exceeding 10 BOMs or 2,500 lines, we establish dedicated coverage, API capacity, and a firm-fixed price in a written agreement.
Request a Portfolio Quote ↗Monitoring is an optional add-on to completed audits. Coverage is confirmed before service activation. An organization owner must explicitly authorize a logged retention extension. Monitored BOMs are retained while the agreement is active and securely deleted 30 days after it terminates. Recurring charges are disclosed alongside any one-time audit purchase before checkout.
Enterprise Deployment · In Your Environment
The matching engine is deployed directly inside your secure boundary. Processing and reporting remain inside your environment; catalog connections and outbound lookups are controlled by your organization.
From $50,000 / year
A self-assessment is not C3PAO certification. Review the assessment and controls.
The core matching engine operates across two distinct data boundaries. You must select your deployment model prior to submitting materials.
| Capability | Cloud Deployment | Enterprise (On-Premises) |
|---|---|---|
| Processing Location | Blue Ridge Federal managed cloud service. | Engine deployed locally inside your controlled infrastructure. |
| Document Contents | Uploaded to the secure cloud. Support access requires explicit, time-limited owner authorization. | Remains entirely inside your boundary. Blue Ridge Federal never receives document contents. |
| Encryption | AES-256-GCM (isolated keys per organization); HTTPS in transit. | Storage, keys, and access controls governed by your internal requirements. |
| Data Retention | Standard files purged 30 days post-completion. Active monitoring requires an explicit, logged owner retention extension; monitored BOMs are kept while the subscription is active and deleted 30 days after it ends. Purchased archive terms apply separately. | You maintain complete control over data retention. Cloud 30-day deletion policies do not apply. |
| External Lookups | Defaults to U.S. distributors (part numbers/supplier codes only). LCSC requires explicit opt-in. | Only utilizes internal catalog connections and outbound routing authorized by your network. |
| Model Assistance | Disabled by default. Activation requires explicit owner consent (handling details in Security Policy). | Providers and outbound data transmission must be explicitly approved in your deployment agreement. |
| CUI / ITAR Data | Not Accepted. Strictly for unclassified commercial data. | Accepted. Requires an enterprise agreement and internal verification of required controls prior to use. |
Neither deployment tier constitutes a FedRAMP authorization or a substitute for your program’s internal security approvals. Review full security protocols.