Frequently Asked Questions.
FAQ
Answers to common questions about the platform, compliance frameworks, DevSecOps capabilities, and AI guidance. Search or filter by category.
FAQ
Everything you need to know.
Questions organized by topic. Click any question to see the answer.
54 items
Redoubt Forge is a compliance control plane: the layer that holds defenses as desired state, reconciles the running system against it, and reports divergence as a diff. Security posture comes first; compliance proof is a property of that posture, computed from the running system instead of assembled apart from it. The design covers CMMC, FedRAMP, NIST 800-53, SOC 2, ISO 27001, HIPAA, PCI-DSS, and more. See the full list at Frameworks and Overlays. Nine capability domains stand on one computed posture, sharing data, findings, evidence, and context across the estate.
Defense contractors pursuing CMMC certification. Federal vendors and cloud service providers seeking FedRAMP authorization. Healthcare organizations managing HIPAA compliance. Financial institutions navigating SOC 2 and PCI-DSS. SaaS companies proving ISO 27001 to enterprise customers. State agencies implementing StateRAMP. AI companies building under NIST AI RMF. Any organization that needs to prove its security posture to assessors, partners, regulators, or customers. Redoubt Forge is for any industry that takes compliance seriously enough to build it from actual security.
The design scales from individual developers to enterprise programs. Subscription tiers span solo practitioners building secure from day one through organizations with dedicated security programs and custom framework requirements. The intended progression: start with scanning and security posture, then add compliance when the requirement arrives. Nobody should need a framework to get value.
Platforms like Drata and Vanta have expanded their framework coverage significantly. Both now support CMMC, FedRAMP, NIST 800-53, and NIST 800-171 alongside SOC 2 and ISO 27001. The framework overlap is real. The difference is what happens beyond framework mapping. Redoubt Forge is designed around the full compliance lifecycle: infrastructure built compliant through native scanning and hardened Terraform modules, posture held through event-driven monitoring, proof carried in assessor-ready packages. Three specific gaps remain in commercial platforms. First, no native scanning: they aggregate third-party tools rather than running SAST, DAST, SCA, STIG validation, or CIS Benchmark scanning natively. Second, no overlay composition: DISA STIGs, CIS Benchmarks, DoD Impact Levels, ITAR, and DFARS are not supported. Third, no GovCloud deployment and no designed path for air-gapped estates.
No. Artificer, the AI guidance layer, is designed to lead with targeted questions: context-aware, drawing on what Sentinel discovery has already established about the environment. You do not need to be a framework expert to start; scoping, assessment, and evidence collection are guided, conversational workflows in the design. Technical depth is there for teams that want it: raw scan results, a platform CLI, a public API, and IaC modules. The entry point is built for compliance officers, security managers, and business owners who need results without reading 800 pages of NIST documentation first.
A compliance control plane is the layer that holds desired state, reconciles the world against it, and reports divergence as a diff. A control plane is never a system's mission; it is how the system stays true. That is the break from traditional GRC tools, which start at the checklist: a compliance control plane starts at the threat, holds defenses as desired state, and computes posture from the running system. In the Redoubt Forge design, discovery and collection are Sentinel's ground; Garrison is the passive estate record that discovery populates; Rampart interprets observed posture against framework controls. The result is infrastructure as evidence: proof computed from the running system, not assembled by a compliance team.
Framework coverage spans CMMC, NIST 800-53, FedRAMP, SOC 2, ISO 27001, HIPAA, PCI-DSS, and more; the full list lives at Frameworks and Overlays. Custom frameworks are an Enterprise-tier capability.
GRC tools start with checklists and work backward to evidence. Redoubt Forge starts with security posture: defenses held as desired state, posture computed from the running system, proof projected from what is actually there. The assessor artifact is an immutable chain of evidence, not a binder of narratives. The design also bridges DevSecOps and compliance: findings born in Vanguard scans enter Rampart and drive control posture. No traditional GRC tool bridges that gap.
Where GRC platforms rely on manual uploads and periodic collection cycles, the Sentinel design is continuous: change events re-evaluate posture, so drift surfaces as a diff instead of accumulating between audits. Garrison holds the temporal record of the estate, so the boundary in the documentation is the boundary that exists. Evidence decay is the failure the evidence fabric is designed against: evidence carries freshness and provenance, not a file date.
Posture-first compliance inverts the traditional model. Instead of starting at the checklist and working backward to security, you start at the threat: hardened infrastructure, enforced controls, continuous monitoring. Posture is computed from the running system, and every framework is a projection of that one defended implementation; compliance proofs are what the projection emits. For the assessor, that means immutable evidence from running systems, not narratives from spreadsheets. Proof stays current because it is computed, and trusted because it is traceable.
The framework you need depends on who you sell to and what data you handle. Defense contractors working with Controlled Unclassified Information need CMMC Level 2. Cloud service providers selling to federal agencies need FedRAMP. Healthcare organizations handling protected health information need HIPAA. SaaS companies with enterprise customers typically need SOC 2 or ISO 27001. Financial institutions face PCI-DSS requirements. Many organizations need multiple frameworks simultaneously.
Artificer is designed to guide that determination through questions about your customers, contracts, data types, and regulatory environment. You can also browse the full framework catalog to understand what each standard requires before committing to an assessment.
A small defense contractor typically starts with CMMC Level 1 (Federal Contract Information) and works toward CMMC Level 2 (110 practices for Controlled Unclassified Information) as contract requirements demand it. The first step is understanding your data flows: what CUI you handle, where it lives, and who has access. From there, you define your system boundary and begin implementing controls.
Redoubt Forge is designed to make this practical for a small team: a security baseline from Vanguard scanning, an estate record populated by Sentinel discovery, and Artificer guidance through scoping, from identifying which practices apply to drafting the narratives an assessor needs. The design assumes no dedicated compliance team; the work is structured so a small team makes steady progress toward certification.
Not yet: Redoubt Forge is in design, so there is no onboarding to time. What the design commits to is a short path to value. An engineer scans on day one with no framework in sight. Connected accounts feed Sentinel discovery, which populates the estate record in Garrison; Vanguard establishes the scan baseline; assessment begins when a framework pack activates in Rampart, with Artificer guiding scoping so a team does not stall on where to begin. For organizations migrating from spreadsheets or existing GRC tools, the collection design includes an import path for artifacts the platform never collected.
Redoubt Forge is in design and has not reached general availability. No launch date is announced.
The framework catalog holds 18 frameworks: NIST 800-53 rev5 (Low/Moderate/High baselines), CMMC Level 1/2/3, FedRAMP, NIST 800-171 rev2/rev3, RMF/FISMA, CNSSI 1253, StateRAMP/TX-RAMP, SOC 2 Type I/II, ISO 27001:2022, PCI-DSS v4.0, HIPAA Security Rule, NIST CSF 2.0, CIS Controls v8, NIST 800-207 Zero Trust, CISA Zero Trust Maturity Model, NIST AI RMF, and NIST IR 8596, plus custom frameworks at the Enterprise tier, whose AI-suggested mappings require human confirmation before activation.
The overlay catalog holds 18 overlays, including DISA STIGs (200+, the complete library), six DISA SRGs, 26 CIS Benchmarks, DoD Impact Levels IL2, IL4, IL5, and IL6, CNSSI 1253 overlays, ITAR, DFARS, and sector overlays for healthcare, financial services, education, and critical infrastructure. Full lists: Frameworks and Overlays.
Frameworks are independent control structures. Each defines its own controls, assessment criteria, and certification requirements. NIST 800-53 rev5 defines a catalog of security and privacy controls. CMMC defines maturity levels for the defense industrial base. FedRAMP defines baseline selections for cloud service providers. SOC 2 defines trust service criteria for service organizations. Each stands alone with its own assessment methodology and certification authority.
Overlays modify or extend a base framework. DISA STIGs add platform-specific implementation guidance mapped onto NIST 800-53 controls. CIS Benchmarks define hardening configurations for operating systems, cloud platforms, and databases. DoD Impact Levels (IL2, IL4, IL5, and IL6) add controls based on data sensitivity. ITAR and DFARS layer regulatory requirements on top. In Rampart's design, overlays activate against a base framework: overlay rows add or modify controls, baseline resolution produces the combined control set, and authoritative removal stays framework-intrinsic, so an overlay never silently drops a requirement. See the regulatory compliance guide for overlay application patterns.
The derivation chain is the structural relationship between compliance frameworks. CMMC Level 2 IS NIST 800-171 rev2. NIST 800-171 derives from the NIST 800-53 Moderate baseline. FedRAMP baselines are specific control selections from the same NIST 800-53 catalog. SOC 2 Trust Service Criteria map to 800-53 control families through published cross-walks. ISO 27001:2022 Annex A controls have NIST-published mappings through the NIST Cybersecurity Framework. These relationships are deterministic and auditable. Work done for one framework simultaneously satisfies controls in every framework that traces back to the same NIST lineage.
Rampart's mapping engine is designed around five strategies: native control mapping, NIST 800-53 derivation-chain tracing, NIST CSF 2.0 bridging, published cross-walks from authoritative sources, and AI-suggested mappings that require human confirmation. Coverage recomputes across every framework in the catalog as controls change, so satisfying a control in one framework moves readiness in every framework that shares its lineage. The marginal effort to add each subsequent framework decreases because control overlap compounds through the derivation chain. One security posture. Every framework computed.
Yes, at the Enterprise tier. A custom framework is customer-defined: you supply the control structure through in-product authoring or import, and it lives in your tenant space, never in the shared reference catalog. Custom frameworks ride the same mapping machinery as built-in ones: Rampart's fifth mapping strategy pairs custom controls with existing NIST 800-53 controls through AI-suggested mappings, and no suggested mapping activates until a human confirms it. That places custom frameworks in the same derivation chain as the published catalog, so cross-framework leverage applies from the first activation.
Both are overlays. ITAR (International Traffic in Arms Regulations) adds and modifies controls for export-controlled technical data. DFARS 252.204-7012 layers Controlled Unclassified Information handling onto DoD contracts: it requires contractors to implement NIST 800-171 and report compliance through the Supplier Performance Risk System. Both are carried as registry rows ingested from the regulation text itself, so overlay content traces to the authoritative source.
Overlay activation in Rampart resolves the combined control set: CMMC Level 2 plus DFARS plus ITAR produces the full set of controls a specific contract demands. Regulatory floors reach into the design itself; the audit retention model carries DFARS 7012's 90-day readily-available window as a floor for defense-contractor tenants. See the regulatory compliance guide for implementation patterns across regulated sectors.
Yes. Every framework is a projection of one defended implementation: posture computes once and projects across every active framework. A single control implementation can satisfy requirements in CMMC, NIST 800-53, FedRAMP, and SOC 2 at the same time, because the derivation chain traces every requirement back to its source. When a control changes, coverage recomputes across every framework that references it, and evidence mapped for one framework counts wherever the same control applies. Organizations operating under multiple frameworks are not doing the same work twice.
Overlays modify or extend a base framework for specific environments, sectors, or regulatory requirements. The overlay catalog includes DISA STIGs (200+, the complete library), six DISA SRGs, 26 CIS Benchmarks spanning OS, cloud, container, database, and web server, DoD Impact Levels IL2, IL4, IL5, and IL6, CNSSI 1253 overlays, privacy overlays (NIST 800-53B, NIST 800-122 PII), AI governance (NIST AI 600-1), and sector overlays for healthcare, financial services, education, and critical infrastructure. See the full list at Overlays.
CMMC Level 2 and NIST 800-171 rev2 share the same 110 security practices. The difference is the assessment model. NIST 800-171 relies on self-assessment with a SPRS score submitted to the DoD. CMMC Level 2 requires a third-party assessment by a certified C3PAO for contracts involving prioritized acquisitions. Both protect Controlled Unclassified Information (CUI). Organizations that have implemented NIST 800-171 are already implementing the CMMC Level 2 practices; the remaining step is the formal C3PAO assessment and any gaps the assessor identifies.
In Rampart's registry, the published CMMC-to-800-171 cross-walk is identity: work on one is work on the other, and readiness for each renders as a projection of the same computed posture. Self-assessment readiness and C3PAO readiness are two views of one control set, not two workstreams.
Yes. The HIPAA Security Rule is one framework; healthcare organizations often face more. The overlay catalog carries a healthcare sector overlay with HIPAA technical-safeguard emphasis, plus privacy overlays (NIST 800-53B Privacy Baseline, NIST 800-122 PII protections) for the data privacy dimensions of healthcare compliance. Organizations handling both clinical and research data can layer multiple overlays over one base framework.
Healthcare organizations selling to government agencies may also need FedRAMP or StateRAMP authorization. The derivation chain means HIPAA controls that overlap with NIST 800-53 satisfy both at once, and Rampart's baseline resolution produces one combined control set across active frameworks and overlays: one security posture rather than parallel compliance programs.
Yes, by design. Alliance treats cross-org trust as proof-exchange, not document-exchange. External assessors, auditors, and C3PAOs participate as scoped, time-boxed actors with read-only, as-of views of evidence: control status, evidence chains, and posture for exactly what you grant, nothing more, with every assessor action landing in the audit record.
The evidence itself is built to be verified rather than trusted. It rides an append-only, hash-chained log with signed checkpoints, so an assessor can check integrity cryptographically instead of taking screenshots on faith. Rampart's assessment packages regenerate from living data in the structure assessors expect, mapped to framework requirements. That is what replaces the binder and the evidence walkthrough.
Framework change is a designed-for event. Framework catalogs ingest from their authoritative sources into canonical form, and when a revision publishes, the diff engine computes what changed: which controls moved, which requirements are new, and which existing evidence still satisfies the updated criteria. Affected controls and customer deltas are known on release day, with generated migration plans. Existing assessment data is preserved; Rampart re-derives posture against the new revision rather than starting over.
NIST 800-171 shows why this matters: rev2 is withdrawn yet remains the CMMC Level 2 assessment basis, while rev3 restructured the control families. The registry carries both as distinct rows, and the computed diff identifies the delta, so the work is the net-new requirements, not a rebuild of everything already documented.
Yes. Most organizations start with one framework and expand as contracts, customers, or regulations demand more, and the design is built for that progression. Start with CMMC for defense contracts; add SOC 2 when an enterprise customer asks; add FedRAMP when a federal agency requires authorization. Activating a new framework computes a starting readiness position from work already completed, because Rampart's derivation chain carries satisfied controls across framework boundaries.
Subsequent frameworks cost less marginal effort. Controls satisfied for NIST 800-53 Moderate under CMMC already cover a significant portion of FedRAMP Moderate and SOC 2 requirements. The starting position for each new framework is computed before the assessment begins, so the actual scope of remaining work is visible up front.
Several categories: configuration evidence from connected infrastructure, scan results from Vanguard, inventory records from Garrison, monitoring evidence collected by Sentinel, and control narratives drafted through Artificer and confirmed by a named human. Every evidence event lands on an append-only log with a SHA-256 hash chain and signed checkpoints, and every observation carries its provenance, so an assessor can verify that evidence has not been modified after collection.
In Rampart's design, evidence is organized the way assessors expect: grouped by control family, mapped to specific requirements, with status carried on each. Because collection is continuous by design, evidence shows that a control has held over time, not just at the moment someone took a screenshot.
Substantial overlap, because these frameworks share ancestry. CMMC Level 2 implements 110 NIST 800-171 practices, which derive from the NIST 800-53 Moderate baseline. FedRAMP Moderate selects from the same NIST 800-53 catalog. SOC 2 Trust Service Criteria map to NIST 800-53 control families through published cross-walks. The exact share depends on your implementation, which is why the design computes it instead of estimating it: activating a new framework in Rampart computes a starting readiness score from actual control status, so remaining work is scoped from the real gap, and controls that close gaps across multiple frameworks at once can be prioritized first.
An existing program is not discarded. The design carries an import path for artifacts the platform never collected: third-party and air-gapped scan results enter through an authenticated import surface with a digest taken at receipt, and customer-defined framework structures import at the Enterprise tier. Imported artifacts enter the same evidence machinery as collected evidence, where freshness and expiration are tracked per artifact rather than assumed.
From there the intent is convergence: once Sentinel connections are collecting, computed posture stands on live observations, and imported records settle into history rather than serving as the proof. You do not start from zero, and you do not stay on manual evidence.
Yes, by design. The framework registry carries FedRAMP under the consolidated rules alongside the rev5 baselines derived from NIST 800-53 rev5, ingested from the program's machine-readable content. OSCAL (Open Security Controls Assessment Language) is native in both directions: framework catalogs ingest as OSCAL JSON, and posture attestation is OSCAL-native on emit, so authorization documentation is machine-readable rather than transcribed.
Documents are computation in Rampart: the SSP, POA&M reports, and assessment packages regenerate from living data instead of being edited by hand. Artificer drafts the narrative portions that remain human-readable, and nothing it drafts publishes without human confirmation. The direction FedRAMP 20x points toward, continuous authorization with indicators validated against running systems, is the ground this platform is designed on.
Yes, as part of the commercial terms: a Business Associate Agreement (BAA) for organizations that handle Protected Health Information and require HIPAA compliance. It covers the platform's business-associate role for compliance data that includes or references PHI: permitted uses, disclosure restrictions, breach notification obligations, and subcontractor requirements. No commercial terms are open while the platform is in design. Questions: [email protected].
Sentinel owns evidence collection. In the architecture, every evidence requirement arrives as a declared question: can this control be shown satisfied? A resolver binds that question to the connectors and collection profiles able to answer it, and the answer lands as an artifact observation bound to the control requirement, not a screenshot in a folder. Freshness horizons are declared per evidence class; when one passes, the stale record is demoted and a re-observation task fires. Evidence decay is a failure mode the design removes, not a risk to manage.
Every compliance event is written once to an append-only, timestamped record carrying actor identity, trace correlation, and a SHA-256 chain hash, with Merkle checkpoints sealing the log. An assessor can verify that nothing changed after collection; the proof is cryptographic, not asserted. Vanguard scan results return through the same pipeline, and discovery populates the estate record in Garrison, so the boundary Rampart's scoring reads is the one that actually exists.
Yes, through a designed import path. The connector set includes a scan-artifact import class built for exactly this case: the customer supplies results the platform never collected, over an authenticated upload that records an artifact digest at receipt. Scan artifacts produced inside the enclave, whether from the platform CLI running Vanguard scans or from third-party tools, travel out under the customer's own transfer process and import as evidence with full standing.
Interpretation never depends on how evidence arrived. Imported results ride the same mapping in Rampart as connected ones, so DoD Impact Level and DISA STIG requirements resolve identically for a disconnected estate. Hardened Armory modules are distributable artifacts and can be carried across the boundary the same way. This serves defense contractors and any network where a live connection is not an option.
Desired-state convergence is the platform's constitutional model. You declare what should be true: this system holds CMMC Level 2 on AWS across its declared environments. The reconciliation loop is observe, compare, act within policy, record, escalate, learn; reality is converged toward the declaration, and divergence is reported as a diff. The mechanical belongs to the platform. Judgment belongs to humans: intent, risk acceptance, exceptions, policy. That boundary is itself a human-governed policy, enforced by the system.
Change observations from Sentinel re-evaluate posture in Rampart, and Citadel renders the resulting action queue. Remediation is bounded by automation policy: AUTO, APPROVAL, or MANUAL per resource, within declared change windows, with autonomy earned from verified outcomes and always revocable. The loop is continuous by design, not quarterly by habit.
Drift is a compliance event, not just an operations event. A configuration change, a new resource, a modified policy: any of these can invalidate a control that was satisfied yesterday. Monitoring in the architecture asks one question of the world, what changed, and every answer carries a compliance consequence: change events from Sentinel re-evaluate posture in Rampart, and affected control scores recompute across every active framework at once. Nothing decays silently.
This is the difference between continuous compliance and periodic assessment. Scheduled collection leaves windows where evidence decays and drift accumulates unseen. Here, discovery populates a temporal estate in Garrison that holds what existed at any point in time, so a resource appearing outside the declared boundary registers like any other change: as a recorded observation with a posture consequence in CMMC, FedRAMP, NIST 800-53, SOC 2, or any other active framework.
Vanguard is the DevSecOps workbench, built on a signed FIPS scanner fleet spanning eight scanner classes: code, IaC, secrets, SBOM, vulnerability, DAST, antivirus, and cloud posture. The fleet extends to the AI estate; models, prompts, agent definitions, tool manifests, and RAG corpora are scannable surfaces too, and compliance scanning against STIG and CIS Benchmark baselines rides the same fleet. Three scan surfaces are specified: the local CLI, GitHub Action or GitLab CI, and Sentinel-scheduled. Targets not yet connected to a system live in Outpost and graduate into Garrison when promoted.
The point of the architecture is the bridge between scan results and compliance. Findings return into the posture pipeline: scan results become trends in Sentinel, and the mapping engine in Rampart is designed to carry each finding onto the controls it implicates, across every active framework. A secret in a repository is not a ticket; it is a control status with a consequence.
AI informs every layer of the design, and none of it is trusted on arrival. Artificer is the intelligence capability: a context-aware assistant over the platform's retrieval pipeline, designed to guide scoping with targeted questions, draft narratives and gap analyses, and assemble convergence plans grounded in what Sentinel observation has already recorded about the environment. The mechanical belongs to the platform; the judgment stays human.
The authority rules are architectural, not aspirational. Nothing a model infers counts as evidence until a named human confirms it. Drafts are presented for review, never auto-published; proposed actions land in the Citadel action queue as proposals. Externally influenced input carries a taint mark that informs but never authorizes, and every consequential inference is recorded as a reasoning transaction with the model versions and confidence behind it, so an assessor reading the package in Rampart sees what was machine-drafted and who confirmed it.
Yes. GovCloud is the platform's home ground, not an add-on: the architecture is FedRAMP-High-targeted and designed on AWS GovCloud from its founding commit, with FIPS-validated cryptography as a boundary condition on every technology choice. Customer AWS accounts in Commercial or GovCloud regions connect through cross-account roles with short-lived credentials and no stored long-lived secrets. For organizations under ITAR, FedRAMP High, or DoD Impact Level obligations, the overlay catalog carries those requirements natively, and a managed dedicated-account shape is part of the deployment design through the Armory.
The deployment design is a spectrum of sovereignty shapes. First, SaaS multi-tenant: the platform's own account, with tenant isolation enforced by row-level security and each tenant's events sealed in its own hash chain. Second, a managed dedicated account: platform-owned but dedicated to one customer, converged by the same automation, with a no-touch boundary enforced by policy at the AWS organization level. A third shape, deployment into a customer-owned account, is documented as a pattern whose integrity model is attestation rather than prevention: every unauthorized touch is evidenced, not silently possible. The first two shapes define the initial scope. Air-gapped estates participate through the scan-artifact import path rather than a resident deployment. The capability set is the same platform in every shape; see Capabilities.
Monitoring is a standing question, not a scheduled visit: what changed? Sentinel owns the observation layer, and its output class is observations, never conclusions. Collection profiles declare what must be observed; a resolver binds each declaration to the connectors able to answer it; scheduling is derived from the declaration, never hand-set. The AWS connector set covers resource configuration capture, the provider's own security-service findings, configuration-rule evaluation state, and account event streams. Collection is self-healing: failures are classified and adapted around, not silently skipped.
Downstream, observations become consequences: change events re-evaluate posture in Rampart, Vanguard scan results return as trends, and evidence freshness runs on declared horizons, with expiry triggering re-observation instead of leaving a gap. Citadel renders alerts and monitoring status in one command view. What an assessor gets is posture maintained continuously, not reconstructed for the visit.
The architecture sorts compliance work into reconciliation tiers. Tier 1 is automated: evidence collection and drift detection on the Sentinel side, scan scheduling for Vanguard, freshness tracking, and control scoring with cross-framework coverage recomputation in Rampart, where documents are computed from living data rather than written. Tier 2 is AI-assisted: drafting belongs to Artificer, approval to a human. Tier 3 is human-only and never delegable by architecture: risk acceptance, control N/A justification, authorization-boundary changes, and policy decisions.
Every state change rides an action contract, and per-action approval is the floor of human authority, not its model. POA&M items advance as controls change status; coverage percentages recompute whenever underlying controls do. The boundary between automated and human is itself a human-governed policy, enforced by the system.
The pipeline is a first-class scan surface. Three surfaces are specified for Vanguard scans: the local CLI, GitHub Action or GitLab CI, and Sentinel-scheduled runs. Scheduling and triggering belong to Sentinel; execution belongs to Vanguard; results return as trends. Gating is the intent of the pipeline surface: a scan that fails its checks is designed to stop the pipeline, not just file a ticket. Findings land as compliance consequences, so a vulnerability found in CI moves posture, not only the build status. The CLI and API are first-class consumption channels for human and agent actors alike.
AWS, Commercial and GovCloud, is the provider surface the architecture specifies. Connection is by cross-account role assumption with short-lived session credentials and no stored long-lived secret. The Sentinel connector set covers resource enumeration and configuration capture, the provider's own security-service findings, configuration-rule evaluation state, account event streams, customer SIEM connections, and a resident edge agent for host-level collection. Azure and Google Cloud sit in the connector registry as coming-soon rows against the same universal interface: adding a provider is implementing the interface, not rebuilding the platform. Vanguard scanning spans the eight scanner classes, and DISA STIG and CIS Benchmark overlays carry hardening assessment across operating systems, containers, databases, web servers, and cloud foundations. See Capabilities for the full scope.
The boundary is drawn in the design: compliance data only. Evidence artifacts, scan results, control assessments, and posture scores live in the platform; your operational workloads, databases, and business data stay in your environment. Compliance data is encrypted at rest and in transit over TLS 1.3+, on FIPS-validated cryptographic modules. Tenant isolation is structural, not procedural: row-level security scopes every read to your organization, a cross-tenant query returns zero rows, and operator access has no unaudited path. No tenant's data is shared with another or used for model training. See our security policy for vulnerability reporting.
In AWS: Commercial regions or GovCloud (US), depending on tenancy. Only compliance artifacts are stored; your operational data stays in your own environment. Two deployment shapes are in GA scope: multi-tenant SaaS in the platform account, and a managed dedicated account scoped to a single customer. The design also includes a per-tenant election for sovereign archive delivery: compliance archives written to a bucket you own, with custody transfer recorded as evidence. See our security policy for details.
No. No certification predates a running system. The commitment is structural: a platform that cannot prove its own integrity has no business proving anyone else's, so the architecture makes Redoubt Forge its own first tenant, assessed with the same machinery it offers customers. SOC 2 Type II certification follows a running, provable posture. Status updates are published on the Changelog.
Report vulnerabilities to [email protected]. Include a description of the issue, steps to reproduce, and potential impact. We acknowledge receipt within 48 hours, triage within 5 business days, and coordinate disclosure after remediation. Good-faith research is authorized and protected under our security policy. Researchers who responsibly disclose verified vulnerabilities are recognized on our acknowledgments page.
A Data Processing Agreement is part of the commercial terms for organizations that require one under GDPR, CCPA, or other privacy regulations, settled before any customer signs. It covers data handling, processing purposes, subprocessors, breach notification, and data subject rights. Commercial terms are not open while the platform is in design; when they open, the DPA and subprocessor list take a public home under /policies/. Questions: [email protected].
Not yet. Penetration testing needs a running target, and the platform is still in design. The bar is set in the charter: this platform will pass the audits it administers. The design also replaces the periodic report with standing verification: every exported evidence bundle verifies fully offline, with no platform access required, and a resident edge agent is designed in as the customer's independent auditor of the platform, running that verification continuously against the customer's own records. Status updates on testing and certifications are published on the Changelog.
Incident response is designed as a discipline, not a binder: detection, containment, eradication, recovery, and post-incident analysis, with incident artifacts captured as replayable evidence windows exported with proofs rather than reconstructed after the fact. Breach notification obligations to affected customers, including timelines, belong to the Data Processing Agreement that precedes any customer signature. See our security policy for the responsible disclosure program.
The design answers with structure, not policy alone. Row-level security scopes every read to your organization, and operator access has no unaudited path: an internal read of tenant data is itself a logged, auditable event. Identity is passkeys-first, and elevated access requires phishing-resistant step-up: WebAuthn or PIV, never SMS. Personnel access follows need-to-know; sales and marketing have no path to tenant data. See our security policy for details.
Not yet. Nothing operates yet, and there is no customer data to insure. Cyber liability coverage is bound before commercial terms open, and certificates of insurance become available to customers in procurement at that point.
Key management is designed around AWS KMS. Keys are non-exportable, held behind a signer seam; every use is logged, and every rotation is recorded as an evidence-visible event. Per-tenant key custody is a designed option, up to CloudHSM-held or customer-held keys. Keys you manage in your own AWS accounts stay in your custody; the design never takes possession of them.
The architecture stands on AWS infrastructure (Commercial and GovCloud). The AI layer is designed around Anthropic's Claude models for Artificer guidance, reached in-boundary through AWS Bedrock with no new external interconnection, and no compliance data is used for model training. The full subprocessor list ships with the Data Processing Agreement when commercial terms open; until then, this answer is the list.
Yes. Export is a design invariant, not a feature. Posture is exportable as machine-verifiable attestation (OSCAL-native), and every exported evidence bundle verifies fully offline, with no platform access required. Evidence artifacts, control assessments, posture scores, documents, and audit trails are all covered, and a per-tenant election delivers compliance archives to a bucket you own, with custody transfer recorded as evidence. You own your compliance data.
No. Redoubt Forge is not FedRAMP authorized; no authorization predates a running system. The platform's purpose is your authorization: FedRAMP baselines, controls, evidence, and assessment workflow carried in Rampart. For its own bar, the architecture sets the platform's self-assessment frame at FedRAMP High on the NIST 800-53 rev5 High baseline. Organizations that need the authorization boundary under their own control have a documented customer-account deployment pattern: the customer owns the root account, and platform integrity is proven by attestation.