State, local & education

AI your organization
can actually approve.

Public-sector teams are being handed AI faster than they can govern it. Optimal stands up governed access to the frontier models already sitting inside the cloud you license — one authenticated gateway, guardrails that fail closed, and an audit trail your auditor and your records officer can both read. Then we secure the cloud underneath it.

Governed AI / Cloud security / Data protection / Risk advisory

Runs in your cloud No new procurement SDVOSB-certified
Why now

The AI is already in your organization.

Someone in your agency has already pasted a case file, a student record, or a draft procurement into a consumer chatbot. Not maliciously — because it was the fastest way to get the work done. Banning the capability does not fix that; it just moves it somewhere you cannot see. The answer is to make the governed path the fast one.

Bring your own cloud

Already licensed with Azure, AWS, or Google Cloud?
The models are already there.

You don't need a new vendor to reach frontier models safely. Optimal builds governed, audited access to the models in the cloud you already pay for — inside your own tenant, on contracts you already hold.

Or self-host the models entirely. Either way, every call runs through one governed boundary with a defensible audit trail. See the architecture →

What we do

Four ways we help public-sector teams.

Scoped to a public-sector budget cycle and to the team you actually have — not to the security organization a vendor wishes you had.

01

AI security & governance

An honest read on the AI already running in your organization — the sanctioned deployments and the ones nobody approved. We assess what is exposed, threat-model what is planned, and write acceptable-use guardrails your staff will actually follow instead of route around.

02

Governed access to frontier models

One authenticated gateway to the models already available in the cloud you license. Per-key identity and rate limits, fail-closed prompt and response guardrails, default-deny egress, and a request-ID-joined audit trail. No new vendor, no new procurement, no SDK rewrite.

03

Cloud security

Review and hardening of the cloud you already run — identity and access, logging, network egress, and the quiet misconfigurations that turn into a public-records incident. Findings come with the fix and a retest, not a spreadsheet.

04

IT risk advisory

Where the risk actually is, in priority order, written for a council, a board, or a cabinet — not for a security team. Engineering-grounded, tied to real attack paths, and scoped to a public-sector budget cycle.

Data protection

The rules don't stop applying because it went to a model.

Criminal justice data, patient records, cardholder data, student records — the regimes that already govern how you hold them govern how a model may see them. Most AI incidents in the public sector are not exotic attacks. They are ordinary data leaving a boundary nobody had drawn yet.

So we draw it. Prompt and response inspection, PII and secret detection, and default-deny egress all run inside your boundary before anything leaves it, and every call is logged with a request ID you can join to the records you already keep. The controls get scoped to the data you actually hold.

CJISHIPAAPCI DSSFERPAState privacy statutesPublic records law
Who it's for

Built for the teams doing this with the staff they have.

  • State agencies Health and human services, transportation, revenue, and the enterprise IT shops that serve all of them.
  • Counties & cities Where one team runs everything from the 911 center to the permit portal, and the AI questions arrive faster than headcount.
  • K-12 districts Student data under FERPA, staff adopting AI tools independently, and a security team that is often one person.
  • Higher education Research data, health systems, and a user population that will find the ungoverned path if the governed one is slower.
SDVOSB — Service-Disabled Veteran-Owned Small Business, SBA VetCert certified

Optimal, LLC is an SBA-certified Service-Disabled Veteran-Owned Small Business — eligible for SDVOSB and VOSB set-asides, and available to team with an incumbent prime.

FAQ

Questions public-sector teams ask first.

Do we have to buy a new AI platform?

No — and that is usually the point. If you already license Microsoft Azure, Amazon Web Services, or Google Cloud, the frontier models are already available to you through Azure OpenAI Service, Amazon Bedrock, or Google Vertex AI. Optimal builds the governed, audited access layer on top of the cloud you already pay for, inside your own tenant. No new vendor, no new procurement cycle.

Our staff are already using AI tools we never approved. Where do we start?

That is the normal starting condition, and banning the capability does not work — people who have a real reason to use it will find an ungoverned path. We start by finding what is actually in use and what data is reaching it, then make the governed path the fastest one: one authenticated gateway, guardrails that catch sensitive data before a request leaves your boundary, and an audit trail you can produce when someone asks.

How does this work with CJIS, HIPAA, PCI, or FERPA data?

Those regimes do not stop applying because the request went to a model. The gateway sits between your users and the model, so prompt and response inspection, PII and secret detection, and default-deny egress all happen inside your boundary before anything leaves it — and every call is logged with a request ID you can join to your existing records. We scope the controls to the data you actually hold rather than to a generic checklist.

Can you work with our existing cloud and security team?

Yes. Everything we build is self-hostable and yours to operate — the reference architecture is open source, so your engineers can read exactly what we are standing up before we stand it up, and keep running it after we leave. We are not trying to become a dependency you cannot remove.

Is Optimal eligible for set-aside or small-business contracting?

Optimal, LLC is an SBA-certified Service-Disabled Veteran-Owned Small Business (SDVOSB) and Veteran-Owned Small Business (VOSB), listed on the SBA certification registry, and eligible for SDVOSB and VOSB set-aside contracts. Many state and local programs recognize veteran-owned status in their own procurement preferences — we are happy to work through your specific vehicle or to team with an existing prime.

Let's govern
the AI you already have.

Tell us which cloud you run, what data you hold, and what your staff are already doing with AI. We'll scope the work — assessment, governed access, cloud security, or advisory.

Book a scoping call →