THE CONTINUOUS ASSURANCE PLATFORM

Know what is true.Show how you know.

ComplAI turns operational data into one reviewable assurance record for ATO, cATO, and CMMC.

PARTNER ECOSYSTEM

Relationships and availability are confirmed per customer.

  • Carahsoft
  • Amazon Web Services
  • Microsoft Azure
  • Axonius
  • NSF International

ONE CONTROL PLANE

Connect once. Map to every framework in scope.

Bring assets, identities, data, telemetry, and evidence into one context graph. ComplAI maps that context across the catalogs in scope while people retain review and decisions.

Representative assets, devices, identities, data stores, telemetry, and governed artifacts feed one ComplAI data governance control plane, which discovers, classifies, correlates, and maps that context into a single graph. The plane then relates the same facts to requirements in NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC Level 2, ISO/IEC 27001:2022, NIST CSF 2.0, and SOC 2, and those catalogs stay crosswalked to each other. Example: one verified multi-factor authentication fact relates to IA-2(1), 03.05.03, IA.L2-3.5.3, A.8.5, PR.AA-03, and CC6.1. The sequence is illustrative; connectors, catalog availability, and mapping depth are confirmed per deployment, and people retain review.

Illustrative sequence with representative sources and related requirements. Requirements stay distinct per catalog; mapping depth, availability, and connectors are confirmed for each deployment. People retain review and decisions.

WHY CONTINUOUS ASSURANCE

A status is only useful when the evidence behind it is current.

Compliance work breaks down when the dashboard, evidence folder, asset inventory, and system boundary tell different stories.

ComplAI keeps requirements, implementation, evidence, scope, ownership, and review history connected. When one fact changes, teams can see which conclusions and artifacts need attention.

ILLUSTRATIVE ASSURANCE WORKSPACERELATIONSHIP VIEW · EXAMPLE RECORD

See the program state. Inspect the record behind it.

reviewablesignal → context → owner
REVIEW STATEExample record
  • Current58%
  • Review due26%
  • Context gap16%
Latest linked changeIdentity source refreshedTrace affected context
RELATIONSHIP SIGNALSFive checkpoints
HUMAN REVIEW PATHAccountability retained
  • Control ownerassigned
  • Evidence reviewerreview due
  • Boundary stewardcontext needed
CHANGE TIMELINENeeds attention
  1. Identity source refreshedEvidence linked · now
    ER
  2. Privileged role changedScope review
    CO
  3. Owner confirmation missingAction required
    ?

Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.

01Detect the changeA source signal shifts02Trace the impactLinked context surfaces03Assign the reviewA person retains the decision
CONNECTOR CONTEXTDEPLOYMENT-SCOPED

Source systems in. Governed outputs out.

Representative cloud accounts, identity directories, operating telemetry, repositories, SaaS systems, and data platforms enter through approved connector or custom-ingestion paths. ComplAI's DSPM capabilities can then discover and classify regulated data in scope before the context resolves into governed assurance records.

An illustrative, deployment-scoped source fabric shows AWS, Microsoft Azure, Microsoft Entra ID, Okta, CrowdStrike, Splunk, ServiceNow, GitHub, SharePoint, Box, Databricks, Salesforce, and approved custom ingestion feeding ComplAI. ComplAI then discovers, classifies, correlates, maps, and preserves review context for evidence, posture, SSP and POA&M artifacts, findings, and drift. Exact connectors and data flows are confirmed for each deployment.INGESTION + ASSURANCE FABRICILLUSTRATIVE · DEPLOYMENT-SCOPEDSOURCE CONTEXTREPRESENTATIVE SOURCESCLOUD + IDENTITYCLOUD ACCOUNTS + DIRECTORIESSECURITY + OPERATIONSTELEMETRY + TICKETS + CODEDATA SYSTEMSREPOSITORIES + SAAS + LAKEHOUSESCustom ingestionAPI · CSV · FILE · WEBHOOKAPPROVED PATHSGOVERNED OUTPUTSReview recordOWNER + BASIS PRESERVEDEvidenceLinkedPostureMappedSSP + POA&MReview basisFindings + driftChanges visibleHUMAN REVIEW RETAINEDCONNECTORS APPROVED PER DEPLOYMENTRepresentative cloud, identity, security, operations, repository, SaaS, lakehouse, and custom ingestion sources flow through five ComplAI processing stages into a governed review record. Exact connectors are confirmed per deployment.ASSURANCE FABRICILLUSTRATIVESOURCE CONTEXTREPRESENTATIVECLOUD + IDENTITYCLOUD SOURCESSECURITY + OPSOPERATING SOURCESDATA SYSTEMSDATA SOURCESCustom ingestionAPI · CSV · FILE · WEBHOOKGOVERNED REVIEW RECORDEvidenceLinkedPostureMappedSSP + POA&MReview basisFindings + driftChanges visible
REPRESENTATIVE SOURCE CONTEXT
Cloud + identity
  • AWS
  • Azure
  • Entra ID
  • Okta
Security + operations
  • CrowdStrike
  • Splunk
  • ServiceNow
  • GitHub
Data systems
  • SharePoint
  • Box
  • Databricks
  • Salesforce
DIRECT CONNECTORSAXONIUS CONTEXTSECURE API / FILECUSTOM ADAPTERS
ComplAI
GOVERNED OUTPUTS
  • EvidenceLinked
  • PostureMapped
  • SSP + POA&MPreserved
  • Findings + driftVisible
CATALOG PORTFOLIO30+

One assurance graph. A 30+ catalog portfolio.

Relate applicable requirements to the same controls, evidence, systems, identities, and owners while keeping each catalog's maturity and deployment scope visible.

  • Requirements stay distinct
  • Evidence can be reused with context
  • Catalog maturity stays visible
Active lens Registered Portfolio
ADDITIONAL CATALOG REFERENCES12 SHOWN · AVAILABILITY VARIES BY DEPLOYMENT
  • CMMC Level 1Active lens
  • NIST AI Risk Management FrameworkRegistered
  • NIST Secure Software Development FrameworkRegistered
  • EU Artificial Intelligence ActRegistered
  • CMMC Level 3Portfolio
  • NIST SP 800-172 Rev. 3Portfolio
  • NIST Privacy FrameworkPortfolio
  • HIPAA Security RulePortfolio
  • General Data Protection RegulationPortfolio
  • NIS2 DirectivePortfolio
  • Digital Operational Resilience ActPortfolio
  • FBI CJIS Security PolicyPortfolio
Active lens · Federal controlsNIST SP 800-53 Rev. 5

Requirements in this federal catalog stay related to shared controls, evidence, scope, and accountable owners. Availability and mapping depth remain deployment-scoped.

NIST

Eighteen representative catalog references are shown across active, registered, and portfolio states. Availability, version, mapping depth, and enabled workflows are confirmed per deployment. ComplAI seals are first-party navigation artwork—not official publisher marks, certifications, authorizations, or endorsements, and not assessment results or compliance guarantees.

THE COMPLAI ASSURANCE GRAPH

Trace every conclusion back to the system.

See how each requirement relates to the assets, identities, regulated data, evidence, and accountable review behind its current state.

CONTROLS & EVIDENCE

One relationship model for the facts behind each control.

01
NIST SP 800-53 · NIST SP 800-171 · control inheritance
02
SCOPE

Assets & identities

Relate devices, workloads, services, users, and vendors to the boundary they actually influence.

Inventory · access paths · accountable owners
03
DATA

CUI & regulated data

Discover where regulated data lives, understand how it moves, and connect handling expectations to its repositories.

Discovery · classification · lineage · protection
04
OUTPUT

Governed artifacts

Maintain SSP, POA&M, assessment evidence, and authorization context from linked sources and review history.

Source · owner · timestamp · decision trace

HOW THE SYSTEM WORKS

Connect the facts. Keep the decision reviewable.

Follow one synthetic account change from question to evidence, human review, and a durable decision record.

01Ask the environment

Questions run against the live boundary.

Ask in plain language. ComplAI investigates connected sources and returns an answer with the evidence attached — never a bare status.

Scoped questionsThe boundary shapes the answer.

Questions resolve against the systems, identities, and data actually in scope — not a generic index.

Answer anatomyEvery answer keeps its basis.

Source, collection time, and accountable owner ride along with the response.

02Trace live evidence

Every fact keeps its source.

Evidence stays connected to where it came from, when it was collected, and the requirement it supports — freshness and provenance resolve in view.

Freshness resolvesCurrent is a fact, not a feeling.

Each record carries its own collection time and review cadence, so stale context is visible before it misleads.

Provenance chainLineage survives the pipeline.

From source system to requirement, every hop is recorded and reviewable.

03Review what changed

Change surfaces as a proposal, not a surprise.

When the environment drifts, only the affected relationships light up. ComplAI prepares the review — and stops at the person who owns it.

Impact scopeOnly what changed demands attention.

The relationship graph bounds the blast radius, so review effort follows actual impact.

Owned queueNothing waits without a name.

Every prepared review lands with an accountable owner and a due date.

04Authorize the action

A person approves. The record shows why.

Scope, impact, and rollback sit in front of the decision owner before anything proceeds. Authority stays human; context stays complete.

Decision recordApproval is an artifact.

Who decided, when, and on what basis — preserved in the same graph as the evidence.

Rollback visibleEvery approval knows its exit.

The reverse path is part of the proposal, not an afterthought.

05Preserve the decision

Approved once. Precedent afterward.

Each decision joins a chronological trace. The next time a similar change appears, the prior decision is already there.

ContinuityThe record outlasts the moment.

Decisions, evidence, and ownership stay reviewable across cycles, staff changes, and assessments.

Precedent recallInstitutional memory, on demand.

Prior decisions resurface beside similar changes instead of living in someone's inbox.

Illustrative product choreography with synthetic records · not a customer result, authorization decision, assessment result, or readiness score.

DEPLOYMENT BOUNDARY

Fit the architecture to the data boundary.

ComplAI can be scoped for customer-hosted, commercial-cloud, and government-cloud environments. Before data is connected, the customer and ComplAI document the hosting boundary, approved model provider, ingress and egress, controls, and shared responsibilities. Final architecture and service availability are confirmed for each deployment.

On-premises / customer-hostedCommercial cloudAWS GovCloudAzure Government
Discuss architecture and data flow
CUSTOMER-DEFINED BOUNDARYSCOPED
ACTIVE SOURCEEvidenceFreshness + provenance
COMPLAI WORKFLOW LAYERRetrieval · reasoning · workflow
GOVERNED OUTPUTArtifacts + actions + decision trace
review required

PROCUREMENT & DELIVERY

Move from technical fit to a viable buying path.

ComplAI is available through Carahsoft’s public-sector channel, with direct scoping for deployment and services. Exact vehicle, eligibility, responsibilities, and terms are confirmed for each customer.

CarahsoftPublic-sector channel
Explore partner paths

COMMON QUESTIONS

Clear answers before architecture work begins.

The right answer depends on the boundary, decision authority, and deployment constraints. These are the stable starting points.

Is ComplAI only for CMMC?

No. The platform supports CMMC and ATO / continuous ATO workflows, with a shared model for controls, evidence, assets, identities, regulated data, findings, and artifacts.

Does ComplAI replace the people responsible for authorization or assessment?

No. ComplAI organizes and automates work, but accountable officials, system owners, security teams, assessors, and authorizing stakeholders retain their respective decisions and responsibilities.

Does regulated data have to be sent to a public AI model?

That data flow is deployment-specific. Architecture review determines whether a customer-controlled or government-cloud pattern is appropriate; model providers, ingress and egress, and handling rules are confirmed before regulated data is connected.

Can we start with our existing artifacts and tools?

Yes. A practical rollout starts by inventorying the current boundary, evidence sources, SSP, POA&M, asset records, repositories, and workflows before deciding what to integrate, migrate, or retire.

LET'S TALK

See how ComplAI fits your program.

Tell us what you're working toward. We'll show you how ComplAI can help and where to start.

Don't send CUI, credentials, SSPs, evidence packages, or system diagrams through this form or email.