Register:What-Is7 recordsSHA3-256 chainedSealed Amended head sha3:086c076e79a0e4a28dd3b66bac4d33a58d5909121febfee25964502a43395622Intact
REC 0000Genesissha3-2568130cd09596693e9fb6d3374b9af0e6292cdd0fc4aec3cd99ad27d776978f18fprev:6183bd2d2a60

The platform, in plain language.

What is PolicyCortex?

PolicyCortex is a compliance and assurance platform for regulated cloud and AI systems. It connects requirements, control implementation, remediation, and verifiable evidence in your tenant, helping your organization prepare for self-assessment, independent assessment, and authorization review, and maintain readiness as systems change.

Access is reviewed. Scope and onboarding are agreed with your team.

REC 0001WHO IT IS FORsha3-256e49e56e7bfdde03028c246aba43b9a946f0c22b34a7c75ce83a622329181299aprev:8130cd095966

Who it is for

Security, compliance, and infrastructure teams responsible for regulated systems. You may be establishing your first program, closing gaps in an existing implementation, preparing a review package, or keeping an authorized system ready for its next assessment. PolicyCortex connects that work to the evidence behind it.

  1. WHO-01
    Defense contractors pursuing CMMC and managing CUI
  2. WHO-02
    National laboratories under DOE and NNSA
  3. WHO-03
    Federal agencies
  4. WHO-04
    Defense Industrial Base organizations
  5. WHO-05
    Regulated commercial environments running autonomous systems
  1. FOR-01
    ATO and continuous authorization
  2. FOR-02
    CMMC Level 2, the 110 requirements of NIST SP 800-171
  3. FOR-03
    FedRAMP 20x
  4. FOR-04
    NIST SP 800-53 Rev 5 and NIST SP 800-171
  5. FOR-05
    OMB M-25-21 AI use-case inventories and minimum risk management practices

Licensed software with access arranged through our team; fixed-scope delivery engagements are optional. The pricing page describes the license; the engagement page describes the optional delivery work.

REC 0002WHAT IT PRODUCESsha3-256aae96b411d1cf0e10c5653328710a0e31917c10e294bff804497df15d9d8d117prev:e49e56e7bfdd

What it produces: three proofs

Everything PolicyCortex exports is a projection of three records, kept on one hash chain inside your tenant. Each is stated here in one paragraph; each has a page of its own.

Exhibit W-1the evidence envelope, as shipped
The PolicyCortex evidence package export: assessor-ready ZIP with complete evidence inventory, validation results, POA&M items, SSP, SAR, OSCAL and eMASS formats, and AES-256 protection

Exhibit W-1 · the assessor-ready package all three proofs ship in: inventory, validations, POA&M, SSP, SAR. One ZIP, hash chained, AES-256 protected. Illustrative demo data; the interface is real.

REC 0003WHAT IT IS NOTsha3-256eb55c3e28edf31d1969002fcd1a2714eac02b0a0b8a9fc4c93dba512958c0f7eprev:aae96b411d1c

What it is not

The register states its limits in the same voice as its claims. Four things PolicyCortex is not.

How it compares with Vanta, Drata, Wiz, Prisma Cloud, RegScale and GCC High is answered by the same eight questions on the compare register.

REC 0004HOW YOU EVALUATE ITsha3-256282557b200cdec6f07c4692bfd1d2fef8e53f65f8bfa5bf003fa75fa51b539efprev:eb55c3e28edf

How to get access and verify it

Request access so we can review your environment and agree on scope and onboarding. After access is approved, a read-only connection in SHADOW mode can produce state records and declared gaps inside your tenant. Nothing executes. Verify the chain yourself: export the stream, recompute SHA3-256 over each record plus the digest of the record before it, and compare.

access
Read only. We do not need write access to show you something.
onboarding
Access is reviewed. Scope and onboarding are agreed with your team.
trust.mode
SHADOW. The reasoning layer proposes and publishes confidence; zero actions are executed.
location
Your tenant, including AWS GovCloud, Azure Government, and GCC High. On-premises delivery for air-gapped environments is available.
egress
None. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.
you.get
State records, declared gaps, and a chain you can recompute without a PolicyCortex account or API in the loop.
REC 0005GLOSSARYsha3-25625ad8ed615c13c65ac2cf62d58b61c92e134c50a1fb07d29917143b688276896prev:282557b200cd

The vocabulary, defined once

Seven terms the register uses without apology. The same definitions are published for machines in llms-full.txt.

Proof of state
A point-in-time record of what a cloud environment was, captured from the provider APIs, content hashed, chained to the record before it, regenerable to any date inside retention.
Proof of change
Who or what altered the environment, under what authority, with before and after state hashes and a rollback identifier, on a chain that cannot be edited without detection.
Proof of agency
What a machine was permitted to do before it acted, what it actually did, and what would have stopped it one notch different.
Declared gap
An explicit chained entry, with interval and reason, written whenever a collector is down or a scope is unobserved. Absence is recorded, never inferred from fewer rows.
Autonomy envelope
A machine-enforced object read before every autonomous action: allowed and blocked action types, maximum affected resources, minimum published confidence, cost ceiling, excluded environments, change windows, emergency stop. Every evaluation of it is a chained record.
Trust modes
SHADOW (watch only, nothing executes), GATED (default; a named human approves each action and becomes part of its record), AUTONOMOUS (narrow, well-tested action classes, every gate still run on every act).
Register
A page or evidence stream whose visible copy is the input to its own SHA3-256 hash chain, so a second party can recompute it.
REC 0006FIVE QUESTIONSsha3-256086c076e79a0e4a28dd3b66bac4d33a58d5909121febfee25964502a43395622prev:25ad8ed615c1

Five questions, answered plainly

  1. Q-01

    What is PolicyCortex?

    PolicyCortex is a compliance and assurance platform for regulated cloud and AI systems. It connects requirements, control implementation, remediation, and verifiable evidence in your tenant, helping your organization prepare for self-assessment, independent assessment, and authorization review, and maintain readiness as systems change.

  2. Q-02

    Does PolicyCortex make us compliant?

    No. It produces the records compliance decisions rest on. The authorizing official, the C3PAO, or the accountable official makes the determination; PolicyCortex hands them evidence they can recompute instead of a narrative they have to believe.

  3. Q-03

    Where does the data live?

    In the customer's own tenant. There is no telemetry pipeline to PolicyCortex servers and no egress of evidence.

  4. Q-04

    How is evidence verified?

    By recomputation. Every record is SHA3-256 hashed over its content plus the digest of the record before it. Export the stream, recompute, compare: intact, or the exact sequence number where integrity fails. No PolicyCortex account or API is needed.

  5. Q-05

    What happens when a collector is down?

    The chain carries a declared gap: the stream, the interval, the reason, and when it was declared. Evidence never silently has fewer rows.

Request access to review your scope and verify the record.

Request Access
Register colophonRecomputable by a second party
SeqLabelSHA3-256Prev
REC 0000Genesis8130cd0959666183bd2d2a60
REC 0001WHO IT IS FORe49e56e7bfdd8130cd095966
REC 0002WHAT IT PRODUCESaae96b411d1ce49e56e7bfdd
REC 0003WHAT IT IS NOTeb55c3e28edfaae96b411d1c
REC 0004HOW YOU EVALUATE IT282557b200cdeb55c3e28edf
REC 0005GLOSSARY25ad8ed615c1282557b200cd
REC 0006FIVE QUESTIONS086c076e79a025ad8ed615c1

The record headers on this page are SHA3-256 digests of this page's own copy, chained in sequence from a fixed genesis value. Edit one word of any record's copy above and every digest after it changes. Head of chain: sha3:086c076e79a0. The product does the same thing to your evidence.

Photograph: NASA/JPL-Caltech, Public domain (NASA, 17 U.S.C. 105). Source