sha3:086c076e79a0e4a28dd3b66bac4d33a58d5909121febfee25964502a43395622Intact8130cd09596693e9fb6d3374b9af0e6292cdd0fc4aec3cd99ad27d776978f18fprev:6183bd2d2a60The platform, in plain language.
What is PolicyCortex?
PolicyCortex is a compliance and assurance platform for regulated cloud and AI systems. It connects requirements, control implementation, remediation, and verifiable evidence in your tenant, helping your organization prepare for self-assessment, independent assessment, and authorization review, and maintain readiness as systems change.
Access is reviewed. Scope and onboarding are agreed with your team.
e49e56e7bfdde03028c246aba43b9a946f0c22b34a7c75ce83a622329181299aprev:8130cd095966Who it is for
Security, compliance, and infrastructure teams responsible for regulated systems. You may be establishing your first program, closing gaps in an existing implementation, preparing a review package, or keeping an authorized system ready for its next assessment. PolicyCortex connects that work to the evidence behind it.
- WHO-01Defense contractors pursuing CMMC and managing CUI
- WHO-02National laboratories under DOE and NNSA
- WHO-03Federal agencies
- WHO-04Defense Industrial Base organizations
- WHO-05Regulated commercial environments running autonomous systems
- FOR-01ATO and continuous authorization
- FOR-02CMMC Level 2, the 110 requirements of NIST SP 800-171
- FOR-03FedRAMP 20x
- FOR-04NIST SP 800-53 Rev 5 and NIST SP 800-171
- FOR-05OMB M-25-21 AI use-case inventories and minimum risk management practices
Licensed software with access arranged through our team; fixed-scope delivery engagements are optional. The pricing page describes the license; the engagement page describes the optional delivery work.
aae96b411d1cf0e10c5653328710a0e31917c10e294bff804497df15d9d8d117prev:e49e56e7bfddWhat it produces: three proofs
Everything PolicyCortex exports is a projection of three records, kept on one hash chain inside your tenant. Each is stated here in one paragraph; each has a page of its own.
Proof of state
Proof of state is a point-in-time record of cloud configuration, taken from the cloud provider APIs, content hashed with SHA3-256, chained to the previous record, retained for seven years, and regenerable to any timestamp a second party picks. It answers what was true in the environment on a date somebody else names, not what is true now.
Read the recordPROOF 02 / CHANGEProof of change
Proof of change records who or what altered the environment, under what authority, with before and after state hashes, the hashed delta, the policy gates that ruled, and a rollback identifier, committed to an append-only chain that administrators cannot edit without detection. Changes made around the gates surface at the next capture as drift with no authority attached.
Read the recordPROOF 03 / AGENCYProof of agency
Proof of agency holds three artifacts for every autonomous action: the envelope that permitted it before it ran, the chained record of what it did, and the counterfactual showing what would have blocked it had it been one notch different. Envelope versions are records, so the authority in force at 02:14 comes from the chain, not the current settings page.
Read the record
Exhibit W-1 · the assessor-ready package all three proofs ship in: inventory, validations, POA&M, SSP, SAR. One ZIP, hash chained, AES-256 protected. Illustrative demo data; the interface is real.
eb55c3e28edf31d1969002fcd1a2714eac02b0a0b8a9fc4c93dba512958c0f7eprev:aae96b411d1cWhat it is not
The register states its limits in the same voice as its claims. Four things PolicyCortex is not.
How it compares with Vanta, Drata, Wiz, Prisma Cloud, RegScale and GCC High is answered by the same eight questions on the compare register.
282557b200cdec6f07c4692bfd1d2fef8e53f65f8bfa5bf003fa75fa51b539efprev:eb55c3e28edfHow to get access and verify it
Request access so we can review your environment and agree on scope and onboarding. After access is approved, a read-only connection in SHADOW mode can produce state records and declared gaps inside your tenant. Nothing executes. Verify the chain yourself: export the stream, recompute SHA3-256 over each record plus the digest of the record before it, and compare.
- access
- Read only. We do not need write access to show you something.
- onboarding
- Access is reviewed. Scope and onboarding are agreed with your team.
- trust.mode
- SHADOW. The reasoning layer proposes and publishes confidence; zero actions are executed.
- location
- Your tenant, including AWS GovCloud, Azure Government, and GCC High. On-premises delivery for air-gapped environments is available.
- egress
- None. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.
- you.get
- State records, declared gaps, and a chain you can recompute without a PolicyCortex account or API in the loop.
25ad8ed615c13c65ac2cf62d58b61c92e134c50a1fb07d29917143b688276896prev:282557b200cdThe vocabulary, defined once
Seven terms the register uses without apology. The same definitions are published for machines in llms-full.txt.
- Proof of state
- A point-in-time record of what a cloud environment was, captured from the provider APIs, content hashed, chained to the record before it, regenerable to any date inside retention.
- Proof of change
- Who or what altered the environment, under what authority, with before and after state hashes and a rollback identifier, on a chain that cannot be edited without detection.
- Proof of agency
- What a machine was permitted to do before it acted, what it actually did, and what would have stopped it one notch different.
- Declared gap
- An explicit chained entry, with interval and reason, written whenever a collector is down or a scope is unobserved. Absence is recorded, never inferred from fewer rows.
- Autonomy envelope
- A machine-enforced object read before every autonomous action: allowed and blocked action types, maximum affected resources, minimum published confidence, cost ceiling, excluded environments, change windows, emergency stop. Every evaluation of it is a chained record.
- Trust modes
- SHADOW (watch only, nothing executes), GATED (default; a named human approves each action and becomes part of its record), AUTONOMOUS (narrow, well-tested action classes, every gate still run on every act).
- Register
- A page or evidence stream whose visible copy is the input to its own SHA3-256 hash chain, so a second party can recompute it.
086c076e79a0e4a28dd3b66bac4d33a58d5909121febfee25964502a43395622prev:25ad8ed615c1Five questions, answered plainly
- Q-01
What is PolicyCortex?
PolicyCortex is a compliance and assurance platform for regulated cloud and AI systems. It connects requirements, control implementation, remediation, and verifiable evidence in your tenant, helping your organization prepare for self-assessment, independent assessment, and authorization review, and maintain readiness as systems change.
- Q-02
Does PolicyCortex make us compliant?
No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.
- Q-03
Where does the data live?
In the customer's own tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.
- Q-04
How is evidence verified?
By recomputation. Every record is SHA3-256 hashed over its content plus the digest of the record before it. Export the stream, recompute, compare: intact, or the exact sequence number where integrity fails. No PolicyCortex account or API is needed.
- Q-05
What happens when a collector is down?
The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.
Request access to review your scope and verify the record.
Request Access