FAQ

Frequently Asked Questions

Everything you need to know about PolicyCortex, from compliance frameworks to deployment options.

General

What is PolicyCortex?

+
PolicyCortex is an autonomous cloud governance platform that replaces disconnected compliance, security, cost, and AI governance tools with a single system. It continuously monitors your cloud infrastructure, detects misconfigurations and policy violations, and remediates issues automatically — all while collecting compliance evidence in real time.

Who is PolicyCortex built for?

+
PolicyCortex is designed for defense contractors preparing for CMMC assessments, national laboratories and federal agencies managing complex multi-cloud environments, and any organization that needs continuous compliance monitoring across AWS, Azure, and GCP.

How is PolicyCortex different from a traditional GRC tool?

+
Traditional GRC tools manage policies and risk registers but don't connect to your cloud infrastructure. PolicyCortex reads your actual cloud configuration via API, continuously monitors compliance posture, and can automatically remediate issues — closing the gap between documented policies and actual infrastructure state.

What cloud providers does PolicyCortex support?

+
PolicyCortex supports AWS, Microsoft Azure, and Google Cloud Platform. It provides unified governance across all three providers from a single dashboard, with provider-specific policy engines that understand each platform's native services.

Compliance & Frameworks

What compliance frameworks does PolicyCortex support?

+
PolicyCortex supports CMMC (Levels 1-3), NIST 800-171, NIST 800-53, FedRAMP, CIS Benchmarks, SOC 2, HIPAA, PCI-DSS, ISO 27001, DFARS 252.204-7012, and more. Controls are mapped across frameworks so you don't duplicate effort when meeting multiple requirements simultaneously.

How does PolicyCortex help with CMMC preparation?

+
PolicyCortex continuously monitors your cloud environment against all 110 NIST 800-171 practices (CMMC Level 2). It automatically collects evidence for each control, generates System Security Plans (SSPs) and POA&Ms, and alerts you when your compliance posture drifts. This transforms CMMC preparation from a months-long manual process into continuous readiness.

Does PolicyCortex replace my C3PAO assessment?

+
No. You still need a Certified Third-Party Assessor Organization (C3PAO) for your formal CMMC assessment. PolicyCortex helps you prepare by maintaining continuous compliance and assembling the evidence your assessor will need, significantly streamlining the assessment process.

Can PolicyCortex map controls across multiple frameworks?

+
Yes. PolicyCortex maintains a cross-framework control mapping so that a single security implementation can satisfy requirements across CMMC, NIST, FedRAMP, CIS, and other frameworks simultaneously. This eliminates duplicate evidence collection and provides a unified compliance dashboard.

How does evidence collection work?

+
PolicyCortex continuously monitors your cloud configuration and automatically collects evidence as it detects compliant (or non-compliant) states. Each evidence artifact is timestamped, versioned, and mapped to the relevant control. When assessment time comes, your evidence is already assembled and current.

Technical & Deployment

How is PolicyCortex deployed?

+
PolicyCortex offers multiple deployment models: SaaS (multi-tenant), single-tenant cloud, GovCloud (AWS GCC/GCC-High, Azure Government), and on-premises for air-gapped environments. Every deployment model runs the same platform with the same capabilities.

Does PolicyCortex require agents on my servers?

+
No. PolicyCortex operates agentlessly via cloud provider APIs (AWS, Azure, GCP). It reads your configuration, resource state, and event data through standard cloud APIs using read-only access where possible. Remediation actions use scoped write permissions that you control.

How does autonomous remediation work?

+
When PolicyCortex detects a policy violation or misconfiguration, it analyzes the root cause and determines the appropriate remediation action. Depending on your configuration, it can execute the fix automatically or present it for human approval. Every action includes a rollback ID so changes can be reversed if needed.

Can I start with manual approvals before enabling full automation?

+
Yes. Most organizations start in gated mode where every remediation action requires human approval. As confidence builds, you can gradually enable autonomous remediation for specific action types and resource categories while keeping human approval for higher-risk changes.

What data does PolicyCortex access?

+
PolicyCortex accesses cloud configuration data, metadata, and event logs through cloud provider APIs. It does not access the content of your files, databases, or application data. For CUI environments, the platform can be deployed within your own boundary so that metadata never leaves your environment.

Can PolicyCortex work in air-gapped environments?

+
Yes. PolicyCortex supports on-premises deployment for organizations that operate disconnected or air-gapped environments. The platform runs entirely within your infrastructure with no external connectivity required for core functionality.

Security & Trust

How does PolicyCortex handle my data?

+
PolicyCortex processes cloud configuration metadata — not your application data or CUI. Data is encrypted in transit and at rest. For the most sensitive environments, single-tenant and on-premises deployments ensure your data never leaves your boundary.

Is PolicyCortex pursuing FedRAMP authorization?

+
PolicyCortex is designed with FedRAMP-aligned security controls. Contact us for current authorization status and available deployment options for federal customers.

Who can see what in PolicyCortex?

+
PolicyCortex implements role-based access control with scoped visibility. CISOs see organization-wide posture. Cloud architects see infrastructure details. FinOps teams see cost data. Each role sees only what they need — without exposing sensitive information across team boundaries.

Pricing & Getting Started

How is PolicyCortex priced?

+
Pricing depends on your deployment model, cloud footprint size, and the modules you need. We offer flexible models that scale with your infrastructure. Contact us for a tailored quote based on your specific requirements.

Is there a free trial?

+
We offer guided evaluations where you can see PolicyCortex operating against your actual cloud environment. Contact us to schedule a technical evaluation.

How quickly can I get started?

+
SaaS deployments can be connected to your cloud accounts within hours. Initial compliance posture assessment is typically available within the first day. Full policy configuration and remediation setup varies by environment complexity but typically takes days, not weeks.

Still have questions?

Our team is ready to walk you through PolicyCortex and answer any specific questions about your environment.

Contact Us