For federal teams
For vendors that sell to government
Government-cloud tiers often run on their own release schedules, with features that arrive later or behave differently than in the commercial release. Admins in those environments post in public: exact error strings, the tier and sign-in method they use, the release they are on, and which workarounds held. That information rarely arrives in one place or in a form an engineering team can act on.
Thread Witness tags each report with the environment the reporter names, so every issue carries an affected-environment matrix: commercial and government tiers, sign-in method, and how many reporters did not name their environment. A timeline annotated with releases and status-page incidents shows when reports started and whether they eased after a fix.
Product, support-engineering and quality teams get a weekly cited report on what users on each tier report, which workarounds other admins said worked, and whether reports fell after the last fix. Each topic keeps the same ID from week to week, so the ID in your ticket can be followed release to release.
Example (fictional product, invented data). The affected-environment matrix for one Northwind Cloud issue:
| Tier | Reporters | SSO (SAML) | Smart card | Password | Unknown method |
|---|---|---|---|---|---|
| Commercial | 3 | 3 | 0 | 0 | 0 |
| Gov 1 | 11 | 8 | 2 | 0 | 1 |
| Gov 2 | 6 | 4 | 2 | 0 | 0 |
| Gov 3 | 0 | 0 | 0 | 0 | 0 |
| Unknown tier | 3 | 1 | 0 | 0 | 2 |
For agency program offices
Teams that run public-facing systems see what users say in public about those systems: the steps users say they get stuck on, the error messages they quote, the help-center advice they relay (shown as Secondhand), and whether reports fall after a change. The same evidence rules apply: pseudonymized authors, short linked quotes, and counts of public discussion rather than failure rates. Findings are not published as rankings or scorecards.
Example (fictional system, invented data). For a fictional benefits portal, 12 reporters describe the identity-verification step rejecting a photo of a valid ID, and 5 of them relay help-desk advice to retry from a desktop browser, shown as Secondhand. Reports fell from 6 a week to 2 in the three weeks after a change to the upload page.
The Community Issue Audit
The audit is $14,500 fixed. The federal micro-purchase threshold is $15,000; your contracting office makes its own determination of the purchasing path. The audit is a complete, stand-alone deliverable. Any later subscription is a separate purchase and is not required.
- One product and one environment family, for example one government-cloud tier
- 90 days of public reports
- A verified report with an evidence file, human review of any safety- or security-class topic, a 60-minute readout and written answers to three questions
- Payment by invoice or purchase order; ask whether card payment is available at quote
We are scheduling the first early-access audits now. Typical delivery is 15 business days from kickoff, and the delivery date is confirmed in writing at kickoff.
Full audit details on the pricing page
No login needed
If your security office prefers that staff not sign in to a new service: during early access, every customer receives the report, PDF and evidence file by email, with nothing installed and no account needed. Once the dashboard opens, report-only delivery remains available on the audit and on Enterprise plans; for Team and Business, ask at quote.
Public data only
Thread Witness reads only public sources. It reads no agency systems, internal tickets or telemetry. It holds the contact and contract details needed to deliver the service and, if you use the dashboard or integrations, your users’ work email addresses and the statuses, notes, alert rules and integration credentials you enter, with credentials stored encrypted. With ticket sync it creates and updates issues in your tracker using credentials you provide. With report-only delivery it holds only the distribution list and contract details. Logins are never bypassed. How we source data
Authorizations
Thread Witness does not hold a FedRAMP authorization and makes no claim to one. Whether FedRAMP or other requirements apply to your use is a determination for your agency. We can describe our data flows in writing for your security office.
Questions we are asked
We already see this in support tickets. Then the issues you already know are a check on our accuracy, and the ones you do not recognize are the value. Public reports sometimes precede tickets, and they include what administrators told each other worked. The walkthrough shows whether that is true for your product.
Is reading these sites allowed? Each source is read under a recorded basis, with its terms reviewed at least every 180 days. Sources we do not read are listed as known gaps in every report. How we source data
Where is Reddit? Reddit requires a license for commercial use, which we do not hold, so it is excluded and listed as a gap.
Our community’s terms restrict this. Then we either do not read it, and the report lists it as a gap, or we read only the RSS or Atom feed it publishes. Written permission from you adds your community as a source for your reports.
Can we get it without staff logging in? Yes. Reports, PDFs and evidence files are delivered by email.
Many of these posters are federal employees. How is their privacy protected? Author names are replaced with pseudonyms, no profiles of individuals are built, quotes are short and linked, and an author can ask us to erase their posts. Corrections and takedowns
Book a 30-minute walkthroughhello@threadwitness.com