sha3:e8f3df8547131ce5ba39c5f874d8546b7fa1329e1e9108e358d078212ef7c26cIntactRegister / Mechanism / Monitoring
Monitoring that leaves a record, not a green light.
PolicyCortex monitors your cloud against NIST 800-53, NIST 800-171 and CMMC Level 2, and CIS benchmarks, and writes every observation as evidence: content hashed with SHA3-256, timestamped, appended to the chain in your tenant, retained seven years. The control mapping is stored on the record. A control that stopped being observed produces a declared gap, not a stale green.

Exhibit G-2 · every control in one of five states, with permitted automatic fixes flagged per control. Illustrative demo data; the interface is real.
d20f97ae9ea8a2e42a0d092933bc80264b8ba52e78d56935a696050f1daa4e6aprev:7e2b4914b287One observation, one record.
One record per resource, per capture, whether the capture ran on schedule or a change triggered it. The claim is not a sentence about the resource; it is the raw provider response underneath, hashed. The fields that make an observation file as compliance evidence are these.
- resource.id
- The full provider path of the resource this record is about: the identifier the cloud API resolves, not a friendly name someone typed into a spreadsheet.
- control.mapping
- The control statements this state bears on, stored on the record. One encryption setting can evidence NIST 800-171 3.13.16 and 800-53 SC-28 at once, and the mapping is written down, not implied.
- asset.scope
- The declared boundary the resource sits in: CUI enclave, environment, production class. Scoping arguments get settled by this field instead of by the meeting.
- state.proof
- The raw cloud API response that grounds the claim, stored verbatim. If a narrative and this payload ever disagree, the payload wins.
- content.hash
- SHA3-256 digest of the record content. Anyone holding the record can recompute it; a matching digest means unaltered content.
- captured.at
- UTC timestamp of the capture. Every claim in the evidence base reads as of this field, not as of whenever someone last looked.

Exhibit G-1 · the 110-requirement table where observations file, control by control. Illustrative demo data; the interface is real.
See alsoProof of state, the full recordWhere the collectors run
a086572fd780a19a4f4aaaee4d2686add7de6e9a9174068f1b19e1a5d9795d23prev:d20f97ae9ea8Drift is a finding, not a dashboard color.
Changes made around the system, in the portal, through a direct API call, from a pipeline that never met a gate, surface at the next state capture as drift records with no authority attached. A change with no authority is not a blind spot. It is a finding, and it is recorded as one.
Configuration tampering becomes detectable for the same reason: expected state is on record, so an unexplained delta from the last capture anchors the detection. Every control sits in one of five honest states, and permitted automatic fixes are flagged per control; a fix, when one runs, is approval gated and arrives with its own record.
See alsoProof of change, where drift is recordedProof of agency, how a fix is gated
45143d6b2e8eb61a5cd2315090e348576c07c4be4cad37e12d5c9d496a808820prev:a086572fd780What is written when nothing was watching.
A collector down for six hours does not produce six hours of silence. It produces a gap record: which stream, from when to when, why, and when the gap was declared. Evidence with fewer rows and no explanation is indistinguishable from evidence that was trimmed, so the register declares the gap and lets you hold us to it.
{
"record_type": "declared_gap",
"stream": "aws.iam.role_state",
"from": "2026-07-03T09:12:44Z",
"to": "2026-07-03T15:12:44Z",
"reason": "collector_unreachable: credential rotation failed, retries exhausted",
"declared_at": "2026-07-03T15:13:02Z"
}
# hashed and chained like any other recordWhy absence is a record and not a smaller number is argued in full in the architecture.
2bc01802ea50adc88444109c44c1a5f1a8d4714b948238743057ced3f03f83b2prev:45143d6b2e8eWhere the observations file.
Monitoring files under continuous monitoring, with the audit family governing how the records themselves are protected. The mapping is quiet on purpose: the record is the product, and the rows below are where monitoring evidence files. The full list of supported frameworks follows them.
- NIST 800-53
- CA-7 continuous monitoring grounded in point-in-time records, with the AU family covering how those records are protected, retained, and reviewed.
- NIST 800-171 / CMMC Level 2
- One evidence base for the 110 requirements: state records handed to your assessor as generated evidence with the raw payload attached.
- CIS Benchmarks
- Benchmark observations written as evidence on the same chain, hashed and timestamped like every other record.
- FedRAMP 20x
- Machine-readable by construction. State and control mappings export as OSCAL 1.1.2.
- MITRE ATT&CK
- Configuration tampering becomes detectable because expected state is on record: an unexplained delta from the last capture anchors the detection.
Supported frameworksCMMC Levels 1 to 3NIST SP 800-171 Rev 2/3NIST SP 800-53 Rev 5DFARS 252.204-7012FedRAMP Low, Moderate, HighFISMAITAR/EARHIPAASOXPCI DSSCIS Benchmarks for AWS, Azure, and GCPSOC 2 Type IINIST AI RMFMITRE ATT&CK and ATLAS
e8f3df8547131ce5ba39c5f874d8546b7fa1329e1e9108e358d078212ef7c26cprev:2bc01802ea50What this layer does not do.
See your controls as records, not as a score.
Request verification