Register:Federal R&D6 recordsSHA3-256 chainedSealed Amended head sha3:61cb91e052e7a1248afb5c8bd1a15b60873fe88290c622f15edf541e7bd70ebcIntact

NIST SP 800-53 Rev 5 / OSCAL 1.1.2 / air-gap capable

Continuous ATO for federally funded research.

FFRDCs, national laboratories, and university-affiliated research programs run on perpetual authorization cycles. PolicyCortex records every NIST SP 800-53 Rev 5 control implementation in the boundary as hash-chained evidence, generates the SSP, POA&M, and SAR from that record, and exports OSCAL 1.1.2, inside the enclave and, where the enclave is air gapped, on premises.

Request AccessBook a call

Access is reviewed. Scope and onboarding are agreed with your team.

REC 0000OBLIGATIONsha3-2562899be61bc5c104cdfcdf70c2f5fba942f9e6cae449ea125603076e4bc7f53acprev:94280fee476d

What a research enclave's authorization asks you to prove

Research computing changes faster than an authorization package can be rewritten: new instruments, new collaborators, new data-use agreements, new hosts inside the boundary. The authorizing official still signs a claim about the system as of a date, and the SAR still has to describe what the assessor found rather than what the program remembers. Between re-authorizations the POA&M has to move with the environment, and every closure needs closure evidence.

Some enclaves are disconnected by design. The obligation does not change: the record has to be produced inside the enclave and carried out through an approved transfer, with its chain intact.

rd.baseline
NIST SP 800-53 Rev 5 at Low, Moderate, or High, with program overlays where the control selection is tailored.
rd.package
SSP, SAR, and POA&M generated from one implementation record; OSCAL 1.1.2 and eMASS shapes.
rd.enclave
Runs inside the enclave. On-premises delivery for air-gapped environments; evidence exported through your approved transfer mechanism.
rd.people
The founder holds active DoD Secret and DoE Q clearances and is an active consultant at a DOE national laboratory.
REC 0001EVIDENCEsha3-256265bbce4a315b011b6951c7126990428518b47c97c55cfc67da7e7295b173108prev:2899be61bc5c

The evidence produced inside the enclave

The package is a projection of three records. Where each proof files under 800-53:

CA-7 · CA-2 · CA-6
Proof of state: continuous monitoring and re-authorization grounded in point-in-time records of every control implementation, regenerable to the date the authorizing official names.
AU-9 · AU-10
The chain itself: the audit record protected from modification, non-repudiable, retained seven years.
CM-3 · CM-8
Proof of change and the system inventory: a new host, instrument, or collaborator account is a row with actor, authority, and timestamp, not a surprise at the next SAR.
AC-6 · SI-4
Proof of agency: what autonomous tooling in the enclave was permitted to do before it ran, and what it did.
SSP · SAR · POA&M
Generated from one implementation record, exported as OSCAL 1.1.2. Assessors with OSCAL tooling consume it directly; everyone else gets the evidence package.
Exhibit SB-7ato collection, as shipped
A PolicyCortex ATO collection overview: passing controls, six-stage lifecycle from scope to 3PAO assessment, control family coverage, and package readiness

Exhibit SB-7 · one authorization package from scope to 3PAO assessment: passing controls, family coverage, next action. Illustrative demo data; the interface is real.

REC 0002VERIFICATIONsha3-2562808a0f2e02018750cc8d632d2cd81d19c0f08ee15d454c9ad6c5a4696679611prev:265bbce4a315

How the record is verified after transfer

For a disconnected enclave the recomputation happens on the receiving side: the evidence leaves through your approved transfer mechanism with its chain intact, and the assessor recomputes it there without a connection back to the enclave.

Every record PolicyCortex writes for this obligation is content hashed with SHA3-256 and carries the digest of the record before it, so each line commits to the entire history above it. The log is append only: a correction is a new record, never an edit. Verification is a recomputation, not an assertion. Run the chain from the first record forward and it returns one of two answers: intact, or the sequence number of the first record that breaks.

A second party can do that recomputation without our help. The records, the digests, and the chain rule are everything required: no PolicyCortex account, no API of ours in the loop. When a collector was down or a scope was unobserved, the chain carries a declared gap with the interval and the reason, never silently fewer rows. Absence is declared, not inferred.

REC 0003EVALUATIONsha3-256519ddeb358d6134983157e5daca350276bc25b2938ed072c14a6962290a0f640prev:2808a0f2e020

Access and onboarding in a research enclave

We agree on the enclave scope, impact level, overlays, and onboarding before access is granted. Read-only captures run inside the connected or air-gapped enclave and file under the 800-53 families the SAR will cite.

Request access so we can review your environment, evidence needs, and onboarding scope. After access is approved, read-only onboarding uses SHADOW mode inside your own tenant. Nothing executes. Policy evaluation, evidence collection, and action gating run where your data already is; there is no telemetry pipeline to PolicyCortex servers and no egress of evidence. You hold the records and can recompute the chain yourself.

eval.mode
SHADOW. Watch only; nothing executes.
eval.onboarding
Access is reviewed. Scope and onboarding are agreed with your team.
eval.location
Your tenant. Azure, AWS, and GCP are observed clouds, including AWS GovCloud, Azure Government, and GCC High.
eval.egress
None. No telemetry pipeline to PolicyCortex servers; no evidence leaves the tenant.
eval.after
You keep the records. Licensing is annual and the tenant owns the evidence; a delivery engagement is optional.
REC 0004DELIVERYsha3-2563c8e39a14bcb07f3e3945a0ef42839045d48ec27fe5517d9b2d5701551673f32prev:519ddeb358d6

Delivery, if you want the record stood up for you

Licensing does not depend on it, but a fixed-scope delivery engagement is available: thirty days, one agreed primary cloud environment, an evidence package built and defended through assessor review. The independent assessor makes the certification decision. No certification is guaranteed.

Every engagement is delivered by the people who hold the clearances and wrote the code. Delivery inside a cleared or disconnected enclave is scoped with you before work begins.

engagement.scope
Thirty days. One agreed primary cloud environment.
engagement.outcome
An evidence package built and defended through assessor review.
engagement.limit
The independent assessor decides. No certification is guaranteed.

Every term of the engagement, on its own page.

REC 0005QUESTIONSsha3-25661cb91e052e7a1248afb5c8bd1a15b60873fe88290c622f15edf541e7bd70ebcprev:3c8e39a14bcb

Questions assessors and buyers ask

Can assessors consume the OSCAL output?

Yes. SSP, POA&M, and SAR export in OSCAL 1.1.2. Assessors with OSCAL-aware tooling consume it directly; everyone else receives the evidence package.

Does it run in an air-gapped enclave?

Yes. On-premises delivery for air-gapped environments is available. Evidence is captured locally and exported through your approved transfer mechanism, with the chain intact so the receiving side can recompute it.

What about framework overlays?

NIST SP 800-53 Rev 5 baselines with impact-level tailoring (Low, Moderate, High). Program overlays are supported when the control selection is tailored.

Who operates the platform?

Your team, inside your enclave. Where an engagement is delivered, it is delivered by the people who hold the clearances and wrote the code; there is no sales organization between you and them.

Does PolicyCortex make us compliant?

No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

What happens when a collector is down?

The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Re-authorize from the record, not from memory.

Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000OBLIGATION2899be61bc5c94280fee476d
REC 0001EVIDENCE265bbce4a3152899be61bc5c
REC 0002VERIFICATION2808a0f2e020265bbce4a315
REC 0003EVALUATION519ddeb358d62808a0f2e020
REC 0004DELIVERY3c8e39a14bcb519ddeb358d6
REC 0005QUESTIONS61cb91e052e73c8e39a14bcb

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:61cb91e052e7. The product does the same thing to your evidence.

Photograph: Chief Photographer's Mate Johnny Bivera, U.S. Navy, Public domain (U.S. Navy, 17 U.S.C. 105). Source