# Redoubt Forge > Redoubt Forge is a compliance control plane, in design. A control plane holds desired state, reconciles the running system against it, and reports divergence as a diff; compliance proof is computed from that posture rather than assembled alongside it. The architecture is written as machine-checked source and gated before any product code. The platform is not yet released and nothing is for sale. Built by Redoubt LLC, a Pennsylvania company; registered office Philadelphia, PA. The design covers CMMC Level 1-3, FedRAMP (Low/Moderate/High/LI-SaaS), NIST 800-53 rev5, NIST 800-171, SOC 2, ISO 27001, HIPAA, PCI-DSS, RMF/FISMA, CNSSI 1253, StateRAMP, NIST CSF 2.0, NIST AI RMF, Zero Trust (NIST 800-207 + CISA ZTMM), CIS Controls v8. Overlays for DISA STIGs, DISA SRGs, CIS Benchmarks, DoD Impact Levels (IL2, IL4, IL5, and IL6), DFARS, ITAR, GDPR, EU AI Act, healthcare/financial/education sector controls. ## Core thesis Security posture generates compliance proofs, not the other way around. The platform is an event-driven desired-state convergence engine: every infrastructure change fires a posture re-evaluation, every artifact is timestamped and SHA-256 hashed, every CI/CD deploy queries posture before it ships, every framework cadence is mapped to a collection profile. The audit becomes a query against living evidence, not a binder of snapshots. ## Platform capabilities - [Citadel](https://redoubtforge.com/capabilities/citadel/): Central command dashboard with aggregated posture, action queue, role-based lenses - [Rampart](https://redoubtforge.com/capabilities/rampart/): Compliance engine. Assessments, controls, scoring, POA&Ms, evidence mapping across every framework - [Vanguard](https://redoubtforge.com/capabilities/vanguard/): DevSecOps workbench. Scanner types: SAST, DAST, SCA, secrets, containers, STIG validation, CIS Benchmark scanning, fuzzing, API security - [Outpost](https://redoubtforge.com/capabilities/outpost/): Lightweight scan targets registered with Vanguard but not connected to a system or environment - [Sentinel](https://redoubtforge.com/capabilities/sentinel/): Continuous monitoring engine. Discovery, evidence collection, compliance scanning, real-time drift detection, CI/CD pipeline gates, FedRAMP ConMon - [Garrison](https://redoubtforge.com/capabilities/garrison/): Connected estate inventory. Repositories, cloud accounts, on-premises, hybrid, air-gapped - [Alliance](https://redoubtforge.com/capabilities/alliance/): Trust networks. Supply chain compliance, partner posture verification, cryptographically signed attestations - [Armory](https://redoubtforge.com/capabilities/armory/): Product catalog. Framework packs, hardened Terraform modules, capability packs, managed infrastructure, professional services - [Artificer](https://redoubtforge.com/capabilities/artificer/): Domain-specific AI intelligence layer. Queries live data, generates narratives, maps findings across frameworks, every write action requires human confirmation ## Frameworks - [CMMC Level 2](https://redoubtforge.com/frameworks/cmmc/): Cybersecurity Maturity Model Certification for defense contractors handling CUI - [FedRAMP](https://redoubtforge.com/frameworks/fedramp/): Federal authorization for cloud services. Low, Moderate, High, LI-SaaS baselines - [NIST 800-53 rev5](https://redoubtforge.com/frameworks/nist-800-53/): Federal security and privacy controls catalog - [NIST 800-171](https://redoubtforge.com/frameworks/nist-800-171/): CUI protection requirements for non-federal systems - [SOC 2 Type II](https://redoubtforge.com/frameworks/soc-2/): Trust service criteria for service organizations - [ISO 27001:2022](https://redoubtforge.com/frameworks/iso-27001/): International information security management standard - [HIPAA Security Rule](https://redoubtforge.com/frameworks/hipaa/): Protected health information safeguards - [PCI-DSS v4.0](https://redoubtforge.com/frameworks/pci-dss/): Payment card industry data security standard - [NIST CSF 2.0](https://redoubtforge.com/frameworks/nist-csf/): Cybersecurity Framework for organizational risk management - [RMF/FISMA](https://redoubtforge.com/frameworks/rmf/): Federal risk management framework for FISMA compliance - [CNSSI 1253](https://redoubtforge.com/frameworks/cnssi-1253/): National security systems controls - [StateRAMP](https://redoubtforge.com/frameworks/stateramp/): State and local government cloud authorization - [NIST AI RMF](https://redoubtforge.com/frameworks/ai-rmf/): AI risk management framework - [NIST IR 8596](https://redoubtforge.com/frameworks/nist-ir-8596/): Cybersecurity considerations for AI - [Zero Trust (NIST 800-207)](https://redoubtforge.com/frameworks/zero-trust/): Zero trust architecture - [CISA Zero Trust Maturity Model](https://redoubtforge.com/frameworks/cisa-ztmm/): Five-pillar zero trust maturity model - [CIS Controls v8](https://redoubtforge.com/frameworks/cis-controls/): Center for Internet Security top controls - [Custom Frameworks](https://redoubtforge.com/frameworks/custom/): Customer-defined frameworks with AI-suggested mappings (Enterprise tier) ## Overlays - [DISA STIGs](https://redoubtforge.com/overlays/disa-stig/): Product-specific hardening guides from the Defense Information Systems Agency - [DISA SRGs](https://redoubtforge.com/overlays/disa-srg/): Security Requirements Guides for technology categories - [CIS Benchmarks](https://redoubtforge.com/overlays/cis-benchmarks/): OS, cloud, container, database, web server hardening benchmarks - [DoD Impact Levels](https://redoubtforge.com/overlays/dod-impact-levels/): IL2, IL4, IL5, and IL6 cloud authorization tiers - [CNSSI 1253 overlays](https://redoubtforge.com/overlays/cnssi-1253/): Classified, cross domain, intelligence, space platform, ICS overlays - [DFARS 252.204-7012](https://redoubtforge.com/overlays/dfars/): CUI safeguarding requirements for defense contractors - [ITAR](https://redoubtforge.com/overlays/itar/): International Traffic in Arms Regulations - [EAR](https://redoubtforge.com/overlays/ear/): Export Administration Regulations - [NIST 800-53B Privacy](https://redoubtforge.com/overlays/nist-800-53b/): Privacy baseline overlay - [NIST 800-122](https://redoubtforge.com/overlays/nist-800-122/): Protecting personally identifiable information - [NIST AI 600-1](https://redoubtforge.com/overlays/nist-ai-600-1/): Generative AI profile - [COSAiS](https://redoubtforge.com/overlays/cosais/): Cybersecurity overlay for AI systems - [EU AI Act](https://redoubtforge.com/overlays/eu-ai-act/): European Union AI regulation - [GDPR](https://redoubtforge.com/overlays/gdpr/): General Data Protection Regulation - [Healthcare](https://redoubtforge.com/overlays/healthcare/): Healthcare sector controls overlay - [Financial](https://redoubtforge.com/overlays/financial/): Financial sector controls overlay - [Education](https://redoubtforge.com/overlays/education/): Education sector (FERPA) controls overlay - [Critical Infrastructure](https://redoubtforge.com/overlays/critical-infrastructure/): Sixteen critical infrastructure sectors ## Articles (deep dives) - [Evidence Decay](https://redoubtforge.com/articles/evidence-decay/): Why compliance artifacts age past usefulness and how continuous evidence streams prevent it - [The ATO Bottleneck](https://redoubtforge.com/articles/ato-bottleneck/): Why federal authorization takes 12-24 months and how continuous ATO compresses it - [The GRC Tool Gap](https://redoubtforge.com/articles/grc-tool-gap/): Where commercial GRC platforms stop and what filling the gap requires - [Human in the Loop](https://redoubtforge.com/articles/human-in-the-loop/): Three response modes for compliance automation: detect, fix, learn - [Infrastructure as Evidence](https://redoubtforge.com/articles/infrastructure-as-evidence/): Why evidence generated from running systems beats evidence collected from screenshots - [Multi-Framework Overhead](https://redoubtforge.com/articles/multi-framework-overhead/): Why organizations pay 3x for compliance and how single-source-of-truth eliminates duplication - [Scan Results vs Compliance Gap](https://redoubtforge.com/articles/scan-results-compliance-gap/): Why vulnerability scan output does not become compliance evidence on its own - [AI-Guided Compliance](https://redoubtforge.com/articles/ai-guided-compliance/): How domain-trained AI accelerates compliance work without removing human judgment ## Guides - [RMF Process](https://redoubtforge.com/guides/rmf-process/): NIST SP 800-37 Rev 2 authorization lifecycle walkthrough - [AI Governance](https://redoubtforge.com/guides/ai-governance/): AI risk management across NIST AI RMF, NIST IR 8596, NIST AI 600-1, EU AI Act - [Privacy Controls](https://redoubtforge.com/guides/privacy/): Privacy controls across NIST 800-53B, NIST 800-122, GDPR, sector regulations - [Regulatory Compliance](https://redoubtforge.com/guides/regulatory/): Regulatory compliance across DFARS, ITAR, EAR, sector-specific requirements - [Compliance Framework Comparison](https://redoubtforge.com/guides/framework-overview/): CMMC vs FedRAMP vs SOC 2 vs ISO 27001 side by side - [CMMC vs FedRAMP](https://redoubtforge.com/guides/cmmc-vs-fedramp/): Two federal authorization paths compared ## Business - [FAQ](https://redoubtforge.com/faq/): Common questions about the platform, frameworks, technical capabilities, security - [Glossary](https://redoubtforge.com/glossary/): Terminology across security, compliance, frameworks, overlays, DevSecOps, AI, platform - [About](https://redoubtforge.com/about/): Company background, founder, mission - [Security Policy](https://redoubtforge.com/policies/security/): Responsible disclosure policy ## Optional - [Sitemap](https://redoubtforge.com/sitemap.xml): Full URL index with last-modified dates - [Robots](https://redoubtforge.com/robots.txt): Crawler access policy (AI bots explicitly permitted)