sha3:61cb91e052e7a1248afb5c8bd1a15b60873fe88290c622f15edf541e7bd70ebcIntactNIST SP 800-53 Rev 5 / OSCAL 1.1.2 / air-gap capable
Continuous ATO for federally funded research.
FFRDCs, national laboratories, and university-affiliated research programs run on perpetual authorization cycles. PolicyCortex records every NIST SP 800-53 Rev 5 control implementation in the boundary as hash-chained evidence, generates the SSP, POA&M, and SAR from that record, and exports OSCAL 1.1.2, inside the enclave and, where the enclave is air gapped, on premises.
2899be61bc5c104cdfcdf70c2f5fba942f9e6cae449ea125603076e4bc7f53acprev:94280fee476dWhat a research enclave's authorization asks you to prove
Research computing changes faster than an authorization package can be rewritten: new instruments, new collaborators, new data-use agreements, new hosts inside the boundary. The authorizing official still signs a claim about the system as of a date, and the SAR still has to describe what the assessor found rather than what the program remembers. Between re-authorizations the POA&M has to move with the environment, and every closure needs closure evidence.
Some enclaves are disconnected by design. The obligation does not change: the record has to be produced inside the enclave and carried out through an approved transfer, with its chain intact.
- rd.baseline
- NIST SP 800-53 Rev 5 at Low, Moderate, or High, with program overlays where the control selection is tailored.
- rd.package
- SSP, SAR, and POA&M generated from one implementation record; OSCAL 1.1.2 and eMASS shapes.
- rd.enclave
- Runs inside the enclave. On-premises delivery for air-gapped environments; evidence exported through your approved transfer mechanism.
- rd.people
- The founder holds active DoD Secret and DoE Q clearances and is an active consultant at a DOE national laboratory.
265bbce4a315b011b6951c7126990428518b47c97c55cfc67da7e7295b173108prev:2899be61bc5cThe evidence produced inside the enclave
The package is a projection of three records. Where each proof files under 800-53:
- CA-7 · CA-2 · CA-6
- Proof of state: continuous monitoring and re-authorization grounded in point-in-time records of every control implementation, regenerable to the date the authorizing official names.
- AU-9 · AU-10
- The chain itself: the audit record protected from modification, non-repudiable, retained seven years.
- CM-3 · CM-8
- Proof of change and the system inventory: a new host, instrument, or collaborator account is a row with actor, authority, and timestamp, not a surprise at the next SAR.
- AC-6 · SI-4
- Proof of agency: what autonomous tooling in the enclave was permitted to do before it ran, and what it did.
- SSP · SAR · POA&M
- Generated from one implementation record, exported as OSCAL 1.1.2. Assessors with OSCAL tooling consume it directly; everyone else gets the evidence package.

Exhibit SB-7 · one authorization package from scope to 3PAO assessment: passing controls, family coverage, next action. Illustrative demo data; the interface is real.
2808a0f2e02018750cc8d632d2cd81d19c0f08ee15d454c9ad6c5a4696679611prev:265bbce4a315How the record is verified after transfer
For a disconnected enclave the recomputation happens on the receiving side: the evidence leaves through your approved transfer mechanism with its chain intact, and the assessor recomputes it there without a connection back to the enclave.
Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.
A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.
519ddeb358d6134983157e5daca350276bc25b2938ed072c14a6962290a0f640prev:2808a0f2e020Access and onboarding in a research enclave
We agree on the enclave scope, impact level, overlays, and onboarding before access is granted. Read-only captures run inside the connected or air-gapped enclave and file under the 800-53 families the SAR will cite.
Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.
- eval.mode
- SHADOW. Watch only; nothing executes.
- eval.onboarding
- Access is reviewed. Scope and onboarding are agreed with your team.
- eval.location
- Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
- eval.egress
- None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
- eval.after
- You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
3c8e39a14bcb07f3e3945a0ef42839045d48ec27fe5517d9b2d5701551673f32prev:519ddeb358d6Delivery, if you want the record stood up for you
Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.
Every engagement is delivered by the people who hold the clearances and wrote the code. Delivery inside a cleared or disconnected enclave is scoped with you before work begins.
- engagement.scope
- Thirty days. One agreed primary cloud environment.
- engagement.outcome
- An evidence package built and defended through assessor review.
- engagement.limit
- The independent assessor decides. No certification is guaranteed.
61cb91e052e7a1248afb5c8bd1a15b60873fe88290c622f15edf541e7bd70ebcprev:3c8e39a14bcbQuestions assessors and buyers ask
Can assessors consume the OSCAL output?
Yes. SSP, POA&M, and SAR export in OSCAL 1.1.2. Assessors with OSCAL-aware tooling consume it directly; everyone else receives the evidence package.
Does it run in an air-gapped enclave?
Yes. On-premises delivery for air-gapped environments is available. Evidence is captured locally and exported through your approved transfer mechanism, with the chain intact so the receiving side can recompute it.
What about framework overlays?
NIST SP 800-53 Rev 5 baselines with impact-level tailoring (Low, Moderate, High). Program overlays are supported when the control selection is tailored.
Who operates the platform?
Your team, inside your enclave. Where an engagement is delivered, it is delivered by the people who hold the clearances and wrote the code; there is no sales organization between you and them.
Does PolicyCortex make us compliant?
No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
Re-authorize from the record, not from memory.