sha3:65e092e60d48571699d38b4c8f56ed3ac50dea587773a3ea7a4237027fc806e4Type to change the copy; digests recompute as you type. Escape or Restore puts it back. Nothing you type is saved.Intact268f6dae680fb58face3879d5394d31f254c67a6753360597715cd7282a97edcprev:a32090232926Compliance evidence for cloud and AI systems, kept in your tenant.
An evidence locker for systems that act without you.
PolicyCortex records what your cloud was, what changed it, and what your machines were allowed to do. Inside your tenant. Hash chained. Gaps declared, not hidden.
Chain headsha3:65e092e60d48intact
Read only. Fourteen days. No sales call.
sha3:2d3ca00b2964sha3:fa6d1aa66e92sha3:0dc7038ed6dehead sha3:0dc7038ed6deChain intactBuilt for
- ATO and continuous authorization
- CMMC Level 2
- FedRAMP 20x
- NIST 800-53 and 800-171
- OMB M-25-21 AI inventories
e6108b6e82fe3a17923dc5c7cdf241ed43b5a0c9322cb3fd3d827d0ac0409371prev:268f6dae680fThree things you will be asked to prove.
Proof of state
What was true in your environment, as of a date somebody else picks. Not what is true now. Not a dashboard. A record of a moment, assembled from the environment itself, that a second person can check without your help.
Read the layerPROOF 02 / CHANGEProof of change
Who or what changed it, under what authority, and whether the record of that change can be edited after the fact. Most organizations can answer the first part. Almost none can answer the third.
Read the layerPROOF 03 / AGENCYProof of agency
What the machine was permitted to do, what it actually did, and what would have stopped it. When an agent acts at two in the morning, the log line saying it happened is not the answer to the question you will be asked.
Read the layer
Exhibit H-1 · the assessor-ready package all three proofs ship in: inventory, validations, POA&M, SSP, SAR. One ZIP, hash chained, AES-256 protected. Illustrative demo data; the interface is real.
bd6acb74e0df0cd6a4f968728fe08dfb735210d1b47e7eaf3acf6d9c6dbedc04prev:e6108b6e82feFive questions the evidence must answer.
- Q-01
Your assessor asks for the configuration as of a date three months back. Can you produce it, or can you only produce today?
Your answerGap declared · no answer on file
- Q-02
An agent took an action overnight. Can you show the policy decision that permitted it, or only the record that it happened?
Your answerGap declared · no answer on file
- Q-03
Your collector was down for six hours. Does your evidence say so, or does it just have fewer rows?
Your answerGap declared · no answer on file
- Q-04
Someone with administrator rights can edit your audit table. What in your architecture makes that detectable?
Your answerGap declared · no answer on file
- Q-05
You are asked whether an AI system in your environment is in scope. Who answers, and from what data?
Your answerGap declared · no answer on file
bdbb0e47b6fe5bb1e28ef1e15c04321bb88afd61dc20abbbf451fc5c37dbb5e3prev:bd6acb74e0dfIt runs where your data already is.
PolicyCortex evaluates policy, collects evidence and gates autonomous action inside your tenant. Nothing about your environment leaves it for us to work. There is no telemetry pipeline pointed at our servers, because a company whose product is proof should not be asking you to trust an outbound connection.
Live readout: policy, evidence, and gating stay inside the wall. Illustrative records; the shape is real.
3baca74297d590056132989a3a4016bfbe8accd241c335ce92d31934bc955077prev:bdbb0e47b6feFive questions with answers on record.
What is PolicyCortex?
PolicyCortex is an evidence locker for cloud and AI systems in regulated environments: it records what the environment was, what changed it, and what machines were allowed to do, hash chained inside the customer's tenant, so an assessor can verify it without trusting the vendor.
Does PolicyCortex make us compliant?
No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.
Where does the data live?
In your own tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.
How is evidence verified?
By recomputation. Every record is SHA3-256 hashed over its content plus the digest of the record before it. Export the stream, recompute, compare: intact, or the exact sequence number where integrity fails. No PolicyCortex account or API is needed.
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
65e092e60d48571699d38b4c8f56ed3ac50dea587773a3ea7a4237027fc806e4prev:3baca74297d5We are not for everyone.
If you need a checklist and a score, there are good products for that and we will point you at them. If you are accountable for what an autonomous system does in a regulated environment, and you have already worked out that logs and evidence are different words, request verification access.