I’ll save you a click: yes, of course it was a no bid contract. And: > The procurement did not require the system to clear FedRAMP, the government’s security review for cloud systems handling sensitive data, before deployment. It described no independent audit, congressional notification or outside review of how the system would be used. I don’t know how the US charts a path back from all this. There are going to be…
If we had a software building code that applied to digital infrastructure in general, the way building codes apply to buildings in general, and electrical codes apply to electrical installation in general, this wouldn't be an issue, because you'd need your shit together to make any software product. But nobody seems to mind companies making shit products and leaking all our data.