Your dashboard, evidence folder, and asset inventory disagree. ComplAI connects them, so ATO, cATO, and CMMC teams can see what is current — and show why.
ONE FACT · RELATED REQUIREMENTSMFA enforced — verified once→
NIST 800-53 · IA-2(1)
NIST 800-171 · 03.05.03
CMMC L2 · IA.L2-3.5.3
ISO 27001 · A.8.5
CSF 2.0 · PR.AA-03
SOC 2 · CC6.1
Example assets, identities, data stores, telemetry, and records feed one ComplAI control plane. That plane finds, classifies, and maps the same facts to requirements in NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC Level 2, ISO/IEC 27001:2022, NIST CSF 2.0, SOC 2, FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, and DORA. Example: one verified multi-factor authentication fact relates to IA-2(1), 03.05.03, IA.L2-3.5.3, A.8.5, PR.AA-03, and CC6.1. The sequence is illustrative. Connectors and mapping depth are confirmed per deployment. Your team still reviews the result.
Example sources and requirement relationships. Each catalog keeps its own meaning. Connectors and mapping depth are confirmed per deployment.
WHY CONTINUOUS ASSURANCE
A status is only useful when the evidence behind it is current.
By the time someone asks how you know, the evidence is a quarter old and nobody remembers which export it came from.
ComplAI keeps the sources attached to the claim. When something changes, you can see what else needs a look.
ASSURANCE WORKSPACE VIEWRELATIONSHIP VIEW · EXAMPLE RECORD
See the program state. Inspect the record behind it.
Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.
01Detect the changeA source signal shifts02Trace the impactLinked context surfaces03Assign the reviewA person retains the decision
HOW SOURCES CONNECTCONFIRMED PER DEPLOYMENT
Your systems in. Records you can review out.
Cloud, identity, security, and data systems come in through a path your environment can govern. ComplAI finds and classifies the regulated data in scope, then turns what it finds into records people can review.
SOURCE SYSTEMS
Cloud + identity
AWS
Azure
Entra ID
Okta
Security + operations
CrowdStrike
Splunk
ServiceNow
GitHub
Data systems
SharePoint
Box
Databricks
Salesforce
DIRECT CONNECTORSAXONIUS CONTEXTSECURE API / FILECUSTOM ADAPTERS
ComplAI
→
WHAT COMES OUT
EvidenceLinked
Control statusMapped
SSP + POA&MPreserved
Findings + driftVisible
FRAMEWORKS SUPPORTED30+
Connect the fact once. See every related requirement.
Keep the source, scope, and owner with the fact. Then see which requirements it supports in the catalogs you run — including FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, DORA, CMMC, and the NIST 800-53 / 800-171 families. Availability and mapping depth are confirmed per deployment.
One fact, multiple relationships
Each requirement keeps its meaning
People review every conclusion
ONE FACT · MANY RELATIONSHIPS6 FEATURED REFERENCES · SELECT ONE
Active lens Registered Portfolio
Controls
Identity
Assets
Evidence
Owner
Scope
ComplAIASSURANCE RECORD
ADDITIONAL CATALOG REFERENCES13 SHOWN · AVAILABILITY VARIES BY DEPLOYMENT
C1CMMC Level 1Active lens
AIRNIST AI Risk Management FrameworkRegistered
SDFNIST Secure Software Development FrameworkRegistered
EAIEU Artificial Intelligence ActRegistered
C3CMMC Level 3Portfolio
172NIST SP 800-172 Rev. 3Portfolio
NPFNIST Privacy FrameworkPortfolio
HIPHIPAA Security RulePortfolio
GDGeneral Data Protection RegulationPortfolio
N2NIS2 DirectivePortfolio
DORDigital Operational Resilience ActPortfolio
CJIFBI CJIS Security PolicyPortfolio
20XFedRAMP 20xPortfolio
Active lens · Federal controlsNIST SP 800-53 Rev. 5
Follow this federal catalog through shared controls, evidence, and owners. Its requirements stay distinct.
NIST
Nineteen catalogs are shown here as examples, across active, registered, and portfolio states — including FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, and DORA. Availability, version, mapping depth, and enabled workflows are confirmed per deployment. The seals are ComplAI’s own navigation artwork—not official publisher marks, certifications, authorizations, or endorsements, and not assessment results or compliance guarantees.
THE COMPLAI ASSURANCE GRAPH
Trace every conclusion back to the system.
See the assets, people, data, and evidence behind each requirement — not just a status.
CONTROLS & EVIDENCE
See the facts behind each control.
01
RequirementAC-2 account management
ImplementationLifecycle owner assigned
EvidenceIdentity source linked
Decision recordReview basis preserved
AC-2CONTROL RECORD
NIST SP 800-53 · NIST SP 800-171 · control inheritance
02
SCOPE
Assets & identities
See which devices, workloads, services, users, and vendors actually sit inside the boundary.
Inventory · access paths · owners
03
DATA
CUI & regulated data
Find where regulated data lives, how it moves, and what handling rules apply.
DSPM · classification · lineage · protection
04
OUTPUT
SSP, POA&M & evidence
Keep every artifact tied to the source it came from and the person who reviewed it.
Source · owner · timestamp · review history
ONE CONNECTED PLATFORM
Five layers. One place to look.
Governance, DSPM, inventory, ITSM, and the host and model you choose. Each layer stays visible. Your team still makes the call.
ATO teams authorize systems. CMMC assessors evaluate implementation. Those are different jobs. ComplAI keeps them separate and still gives both current evidence.
Something changes. Your team can see what matters next.
Follow one example from the moment a privileged role changes to the moment a person decides what to do. ComplAI keeps the facts connected so your team can act with context and explain the decision later.
01A change happens
A privileged role changes. Your team sees it clearly.
A privileged role changes in an identity system. ComplAI brings the source and time together in one clear event, so your team begins with what happened—not a spreadsheet hunt.
Where it happened · when it happened · what changed
Entra IDIdentity source
AWSCloud source
CrowdStrikeSecurity source
ServiceNowWorkflow source
ComplAI
What happenedA privileged role changed
The source and time stay attached
Entra IDSeen 2m ago
Illustrative workflow with synthetic records. Source systems and data paths are examples; exact integrations and actions are confirmed for each deployment.
DEPLOYMENT BOUNDARY
Host it where the data has to live.
Self-hosted, commercial cloud, or government cloud. Bring the AI model you approve. We confirm the boundary, model use, and who owns what before anything regulated is connected.
Self-hosted / customer-hostedCommercial cloudAWS GovCloudAzure Government
The details depend on your boundary and who decides. These answers stay the same.
Is ComplAI only for CMMC?+
No. It supports CMMC, ATO / continuous ATO, and connected catalogs such as FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, and DORA. Coverage and mapping depth are confirmed per deployment.
Does ComplAI replace the people responsible for authorization or assessment?+
No. ComplAI organizes and automates the work. System owners, security teams, assessors, and authorizing officials still make the decisions that belong to them.
Does regulated data have to be sent to a public AI model?+
No. You bring the model your boundary allows. ComplAI does not require a public model. We confirm hosting, model use, and handling rules before regulated data is connected.
Can we start with our existing artifacts and tools?+
Yes. Start with the boundary, evidence, SSP, POA&M, and tools you already have. Then decide what to connect, keep, or retire.
LET'S TALK
See how ComplAI fits your program.
Tell us what you're working toward. We'll show you how ComplAI can help and where to start.