THE CONTINUOUS ASSURANCE PLATFORM

Know what is true.Show how you know.

Your dashboard, evidence folder, and asset inventory disagree. ComplAI connects them, so ATO, cATO, and CMMC teams can see what is current — and show why.

Five streams of governance, data, inventory, remediation, and deployment coming together into one review record.
FIVE CONNECTED LAYERSWhat you have what it means what to review
PARTNER ECOSYSTEM

Relationships and availability are confirmed per customer.

  • Carahsoft
  • Amazon Web Services
  • Microsoft Azure
  • Axonius
  • NSF International

ONE CONTROL PLANE

Connect once. Map to every framework in scope.

Bring assets, identities, data, and evidence into one place. ComplAI maps them to the catalogs you actually run. Your team still reviews the result.

Example assets, identities, data stores, telemetry, and records feed one ComplAI control plane. That plane finds, classifies, and maps the same facts to requirements in NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC Level 2, ISO/IEC 27001:2022, NIST CSF 2.0, SOC 2, FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, and DORA. Example: one verified multi-factor authentication fact relates to IA-2(1), 03.05.03, IA.L2-3.5.3, A.8.5, PR.AA-03, and CC6.1. The sequence is illustrative. Connectors and mapping depth are confirmed per deployment. Your team still reviews the result.

Example sources and requirement relationships. Each catalog keeps its own meaning. Connectors and mapping depth are confirmed per deployment.

WHY CONTINUOUS ASSURANCE

A status is only useful when the evidence behind it is current.

By the time someone asks how you know, the evidence is a quarter old and nobody remembers which export it came from.

ComplAI keeps the sources attached to the claim. When something changes, you can see what else needs a look.

ASSURANCE WORKSPACE VIEWRELATIONSHIP VIEW · EXAMPLE RECORD

See the program state. Inspect the record behind it.

reviewablesignal → context → owner
REVIEW STATEExample record
  • Current58%
  • Review due26%
  • Context gap16%
Latest linked changeIdentity source refreshedTrace affected context
RELATIONSHIP SIGNALSFive checkpoints

Five checkpoints compare linked context with review attention. Hover, tap, or use the arrow keys to inspect each checkpoint.

88%linked context
+36 pts
HUMAN REVIEW PATHAccountability retained
  • Control ownerassigned
  • Evidence reviewerreview due
  • Boundary stewardcontext needed
CHANGE TIMELINENeeds attention
  1. Identity source refreshedEvidence linked · now
    ER
  2. Privileged role changedScope review
    CO
  3. Owner confirmation missingAction required
    ?

Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.

01Detect the changeA source signal shifts02Trace the impactLinked context surfaces03Assign the reviewA person retains the decision
HOW SOURCES CONNECTCONFIRMED PER DEPLOYMENT

Your systems in. Records you can review out.

Cloud, identity, security, and data systems come in through a path your environment can govern. ComplAI finds and classifies the regulated data in scope, then turns what it finds into records people can review.

An example set of sources feeds ComplAI: AWS, Microsoft Azure, Microsoft Entra ID, Okta, CrowdStrike, Splunk, ServiceNow, GitHub, SharePoint, Box, Databricks, Salesforce, and approved custom feeds. ComplAI then finds, classifies, connects, and maps what it collects into evidence, control status, SSP and POA&M records, findings, and drift, and keeps the review history with each one. Exact connectors and data flows are confirmed for each deployment.SOURCES + ASSURANCE GRAPHCONFIRMED PER DEPLOYMENTSOURCE SYSTEMSEXAMPLESCLOUD + IDENTITYCLOUD ACCOUNTS + DIRECTORIESSECURITY + OPERATIONSTELEMETRY + TICKETS + CODEDATA SYSTEMSREPOSITORIES + SAAS + LAKEHOUSESCustom ingestionAPI · CSV · FILE · WEBHOOKAPPROVED PATHSWHAT COMES OUTReview recordOWNER + BASIS PRESERVEDEvidenceLinkedControl statusMappedSSP + POA&MReview basisFindings + driftChanges visibleHUMAN REVIEW RETAINEDCONNECTORS APPROVED PER DEPLOYMENTExample cloud, identity, security, operations, repository, SaaS, lakehouse, and custom sources flow through five ComplAI stages into one review record. Exact connectors are confirmed per deployment.ASSURANCE GRAPHPER DEPLOYMENTSOURCE SYSTEMSEXAMPLESCLOUD + IDENTITYCLOUD SOURCESSECURITY + OPSOPERATING SOURCESDATA SYSTEMSDATA SOURCESCustom ingestionAPI · CSV · FILE · WEBHOOKREVIEW RECORDEvidenceLinkedControl statusMappedSSP + POA&MReview basisFindings + driftChanges visible
SOURCE SYSTEMS
Cloud + identity
  • AWS
  • Azure
  • Entra ID
  • Okta
Security + operations
  • CrowdStrike
  • Splunk
  • ServiceNow
  • GitHub
Data systems
  • SharePoint
  • Box
  • Databricks
  • Salesforce
DIRECT CONNECTORSAXONIUS CONTEXTSECURE API / FILECUSTOM ADAPTERS
ComplAI
WHAT COMES OUT
  • EvidenceLinked
  • Control statusMapped
  • SSP + POA&MPreserved
  • Findings + driftVisible
FRAMEWORKS SUPPORTED30+

Connect the fact once. See every related requirement.

Keep the source, scope, and owner with the fact. Then see which requirements it supports in the catalogs you run — including FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, DORA, CMMC, and the NIST 800-53 / 800-171 families. Availability and mapping depth are confirmed per deployment.

  • One fact, multiple relationships
  • Each requirement keeps its meaning
  • People review every conclusion
Active lens Registered Portfolio
ADDITIONAL CATALOG REFERENCES13 SHOWN · AVAILABILITY VARIES BY DEPLOYMENT
  • CMMC Level 1Active lens
  • NIST AI Risk Management FrameworkRegistered
  • NIST Secure Software Development FrameworkRegistered
  • EU Artificial Intelligence ActRegistered
  • CMMC Level 3Portfolio
  • NIST SP 800-172 Rev. 3Portfolio
  • NIST Privacy FrameworkPortfolio
  • HIPAA Security RulePortfolio
  • General Data Protection RegulationPortfolio
  • NIS2 DirectivePortfolio
  • Digital Operational Resilience ActPortfolio
  • FBI CJIS Security PolicyPortfolio
  • FedRAMP 20xPortfolio
Active lens · Federal controlsNIST SP 800-53 Rev. 5

Follow this federal catalog through shared controls, evidence, and owners. Its requirements stay distinct.

NIST

Nineteen catalogs are shown here as examples, across active, registered, and portfolio states — including FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, and DORA. Availability, version, mapping depth, and enabled workflows are confirmed per deployment. The seals are ComplAI’s own navigation artwork—not official publisher marks, certifications, authorizations, or endorsements, and not assessment results or compliance guarantees.

THE COMPLAI ASSURANCE GRAPH

Trace every conclusion back to the system.

See the assets, people, data, and evidence behind each requirement — not just a status.

CONTROLS & EVIDENCE

See the facts behind each control.

01
NIST SP 800-53 · NIST SP 800-171 · control inheritance
02
SCOPE

Assets & identities

See which devices, workloads, services, users, and vendors actually sit inside the boundary.

Inventory · access paths · owners
03
DATA

CUI & regulated data

Find where regulated data lives, how it moves, and what handling rules apply.

DSPM · classification · lineage · protection
04
OUTPUT

SSP, POA&M & evidence

Keep every artifact tied to the source it came from and the person who reviewed it.

Source · owner · timestamp · review history

PRODUCT LAYER

Javelin Security Validation

Need to prove the controls work—not just that they exist? Test inside the boundary you approve.

Explore Javelin

ONE CHANGE. ONE CLEAR STORY.

Something changes. Your team can see what matters next.

Follow one example from the moment a privileged role changes to the moment a person decides what to do. ComplAI keeps the facts connected so your team can act with context and explain the decision later.

01A change happens

A privileged role changes. Your team sees it clearly.

A privileged role changes in an identity system. ComplAI brings the source and time together in one clear event, so your team begins with what happened—not a spreadsheet hunt.

Where it happened · when it happened · what changed

Illustrative workflow with synthetic records. Source systems and data paths are examples; exact integrations and actions are confirmed for each deployment.

DEPLOYMENT BOUNDARY

Host it where the data has to live.

Self-hosted, commercial cloud, or government cloud. Bring the AI model you approve. We confirm the boundary, model use, and who owns what before anything regulated is connected.

Self-hosted / customer-hostedCommercial cloudAWS GovCloudAzure Government
Discuss architecture and data flow
CUSTOMER-DEFINED BOUNDARYSCOPED
ACTIVE SOURCEEvidenceFreshness + source
COMPLAI WORKFLOW LAYERRetrieval · reasoning · workflow
WHAT COMES OUTArtifacts + actions + decision trace
review required

PROCUREMENT & DELIVERY

A buying path that matches the program.

Buy through Carahsoft’s public-sector channel, or start with us directly. Vehicle, eligibility, and terms are confirmed for each customer.

CarahsoftPublic-sector channel
Explore partner paths

COMMON QUESTIONS

A few things people ask first.

The details depend on your boundary and who decides. These answers stay the same.

Is ComplAI only for CMMC?

No. It supports CMMC, ATO / continuous ATO, and connected catalogs such as FedRAMP 20x, the EU AI Act, NIST AI RMF, NIS2, and DORA. Coverage and mapping depth are confirmed per deployment.

Does ComplAI replace the people responsible for authorization or assessment?

No. ComplAI organizes and automates the work. System owners, security teams, assessors, and authorizing officials still make the decisions that belong to them.

Does regulated data have to be sent to a public AI model?

No. You bring the model your boundary allows. ComplAI does not require a public model. We confirm hosting, model use, and handling rules before regulated data is connected.

Can we start with our existing artifacts and tools?

Yes. Start with the boundary, evidence, SSP, POA&M, and tools you already have. Then decide what to connect, keep, or retire.

LET'S TALK

See how ComplAI fits your program.

Tell us what you're working toward. We'll show you how ComplAI can help and where to start.

Don't send CUI, credentials, SSPs, evidence packages, or system diagrams through this form or email.