Early access, FedRAMP Rev 5 baseline

FedRAMP authorization, managed as one lifecycle

SecurITPosture takes a cloud system from onboarding and boundary definition through evidence, scanning, the System Security Plan, assessment, and the POA&M in a single governed record. AI drafts. People approve.

No cloud credentials are stored. AWS is reached through an IAM role assumed with STS, scoped to read, and only encrypted connection metadata is kept.

Example systemExample data
74

SecurITPosture score

Lifecycle progress, out of 100

Assessment progress

4 of 6

Lifecycle areas complete

Evidence readiness

48 of 71

23 items outstanding

Open findings

63

Latest vulnerability scan

  • Critical 2
  • High 7
  • Medium 19
  • Low 31
  • Informational 4

Package status

Draft

SSP regenerated 2 days ago

  • SystemComplete
  • Pre assessmentComplete
  • ScanningIn progress
  • AdvisoryIn progress
  • AssessmentNot started
  • ReportsNot started

Built to

  • FedRAMP Rev 5
  • NIST SP 800-53
  • NIST SP 800-60
  • FIPS 199

Platform

One record, from questionnaire to authorization package

Data entered once propagates to every downstream document. The questionnaire feeds the SSP, the SSP feeds the SAP and SAR, and findings feed the POA&M.

Evidence to control correlation
Uploaded evidence and discovered resources are mapped to the controls they satisfy, with a confidence score a reviewer can see.
  • Incident response plan v4IR-1IR-4IR-8
    92%
  • Boundary diagram, 2026-08PL-2SC-7
    78%
  • Access review export, Q3AC-2(3)AC-6
    61%

AI generated mappings stay tagged until a person approves them.

Example data

Scan ingestion and drift
Each Tenable export is compared with the inventory and the previous run.
12
New
7
Resolved
31
Persistent

Example data

SSP and control statements
Implementation statements and narrative are drafted from correlated evidence and regenerate when inputs change.
AI GeneratedUnder reviewHuman Approved

Regeneration returns a statement to AI Generated.

Example data

Assessment package
Every assessment document lives on the same record.
  • SAP
  • Test cases
  • SAR
  • RET
  • POA&M
  • SRTM
  • SSP appendices

Example data

Audit trail
Actor, action, target, and UTC time on every change.
  • 14:02Zssp.regenerated
  • 13:47Zevidence.linked
  • 11:20Zgate.4.passed

Example data

01

In development with launch partners

SecurITPosture is in early access. We are building it with a small number of organizations preparing Rev 5 packages, and we would rather tell you where we are than imply otherwise.

Read about the firm on the company page.

To addA quote from a named launch partner or design partner, with their title and organization. One or two sentences about a specific outcome.
To addOne anonymised but specific case: the category of CSP or agency, the baseline, and a measured change such as SSP drafting time before and after.
To addNamed advisors or a named 3PAO partnership, with permission to publish.

Lifecycle

The lifecycle, and what each level hands to the next

Click through the lifecycle. Each level consumes the validated output of the one before it, so the package is traceable from the first record to the last signature.

Customer onboardingExample data
  • Access control policy
  • Incident response plan
  • Configuration management plan
  • Rules of behavior

The customer profile, a dedicated tenant, organization and cloud account registration, and the policies that govern the rest.

01 of 06

Next: continuous monitoring, re-assessment cycles, archival, and the final authorization package. Planned for a later release.

02

Drafting is automated. Approval is not

The tool drafts and correlates. Authority stays with the reviewer, the assessor, and the approving official.

  • AI output stays AI Generated until reviewed

    Every drafted statement, narrative, and correlation carries an AI Generated tag. Only Human Approved content is consumed downstream, and it returns to AI Generated if regenerated.

  • Roles separate creator from approver

    Customer users, compliance analysts, assessors, administrators, executives, and approving officials each see what their role permits. Whoever creates a record does not approve it.

  • Every change is audit logged

    Actor, action, target, and UTC time for each mutation, integration event, and approval. Audit history is retained after the record it describes is removed.

Fourteen questions, scored by lifecycle area

A short self check across the boundary, inventory, evidence, scanning, and documentation, one question at a time. The score is computed in your browser. No account, nothing stored.

Start the readiness check

Example result

Bring your boundary diagram and your last SAR

A 45-minute walkthrough with the team that builds the product, on a system shaped like yours. No slides.