THE CONTINUOUS ASSURANCE PLATFORM

Know what is true.Show how you know.

ComplAI turns operational data into one reviewable assurance record for ATO, cATO, and CMMC.

PARTNER ECOSYSTEM

Relationships and availability are confirmed per customer.

  • Carahsoft
  • Amazon Web Services
  • Microsoft Azure
  • Axonius
  • NSF International

ONE CONTROL PLANE

Connect once. Map to every framework in scope.

Bring assets, identities, data, telemetry, and evidence into one context graph. ComplAI maps that context across the catalogs in scope while people retain review and decisions.

Representative assets, devices, identities, data stores, telemetry, and governed artifacts feed one ComplAI data governance control plane, which discovers, classifies, correlates, and maps that context into a single graph. The plane then relates the same facts to requirements in NIST SP 800-53 Rev. 5, NIST SP 800-171 Rev. 3, CMMC Level 2, ISO/IEC 27001:2022, NIST CSF 2.0, and SOC 2, and those catalogs stay crosswalked to each other. Example: one verified multi-factor authentication fact relates to IA-2(1), 03.05.03, IA.L2-3.5.3, A.8.5, PR.AA-03, and CC6.1. The sequence is illustrative; connectors, catalog availability, and mapping depth are confirmed per deployment, and people retain review.

Representative sources and example requirement relationships. Requirements stay distinct per catalog; mapping depth, availability, and connectors are confirmed for each deployment. People retain review and decisions.

WHY CONTINUOUS ASSURANCE

A status is only useful when the evidence behind it is current.

Compliance work breaks down when the dashboard, evidence folder, asset inventory, and system boundary tell different stories.

ComplAI keeps requirements, implementation, evidence, scope, ownership, and review history connected. When one fact changes, teams can see which conclusions and artifacts need attention.

ASSURANCE WORKSPACE VIEWRELATIONSHIP VIEW · EXAMPLE RECORD

See the program state. Inspect the record behind it.

reviewablesignal → context → owner
REVIEW STATEExample record
  • Current58%
  • Review due26%
  • Context gap16%
Latest linked changeIdentity source refreshedTrace affected context
RELATIONSHIP SIGNALSFive checkpoints

Five checkpoints compare linked context with review attention. Hover, tap, or use the arrow keys to inspect each checkpoint.

88%linked context
+36 pts
HUMAN REVIEW PATHAccountability retained
  • Control ownerassigned
  • Evidence reviewerreview due
  • Boundary stewardcontext needed
CHANGE TIMELINENeeds attention
  1. Identity source refreshedEvidence linked · now
    ER
  2. Privileged role changedScope review
    CO
  3. Owner confirmation missingAction required
    ?

Illustrative values and event history · not a customer result, authorization decision, assessment result, or readiness score.

01Detect the changeA source signal shifts02Trace the impactLinked context surfaces03Assign the reviewA person retains the decision
CONNECTOR CONTEXTDEPLOYMENT-SCOPED

Source systems in. Governed outputs out.

Representative cloud accounts, identity directories, operating telemetry, repositories, SaaS systems, and data platforms enter through approved connector or custom-ingestion paths. ComplAI's DSPM capabilities can then discover and classify regulated data in scope before the context resolves into governed assurance records.

An illustrative, deployment-scoped source fabric shows AWS, Microsoft Azure, Microsoft Entra ID, Okta, CrowdStrike, Splunk, ServiceNow, GitHub, SharePoint, Box, Databricks, Salesforce, and approved custom ingestion feeding ComplAI. ComplAI then discovers, classifies, correlates, maps, and preserves review context for evidence, posture, SSP and POA&M artifacts, findings, and drift. Exact connectors and data flows are confirmed for each deployment.INGESTION + ASSURANCE FABRICDEPLOYMENT-SCOPEDSOURCE CONTEXTREPRESENTATIVE SOURCESCLOUD + IDENTITYCLOUD ACCOUNTS + DIRECTORIESSECURITY + OPERATIONSTELEMETRY + TICKETS + CODEDATA SYSTEMSREPOSITORIES + SAAS + LAKEHOUSESCustom ingestionAPI · CSV · FILE · WEBHOOKAPPROVED PATHSGOVERNED OUTPUTSReview recordOWNER + BASIS PRESERVEDEvidenceLinkedPostureMappedSSP + POA&MReview basisFindings + driftChanges visibleHUMAN REVIEW RETAINEDCONNECTORS APPROVED PER DEPLOYMENTRepresentative cloud, identity, security, operations, repository, SaaS, lakehouse, and custom ingestion sources flow through five ComplAI processing stages into a governed review record. Exact connectors are confirmed per deployment.ASSURANCE FABRICDEPLOYMENT-SCOPEDSOURCE CONTEXTREPRESENTATIVECLOUD + IDENTITYCLOUD SOURCESSECURITY + OPSOPERATING SOURCESDATA SYSTEMSDATA SOURCESCustom ingestionAPI · CSV · FILE · WEBHOOKGOVERNED REVIEW RECORDEvidenceLinkedPostureMappedSSP + POA&MReview basisFindings + driftChanges visible
REPRESENTATIVE SOURCE CONTEXT
Cloud + identity
  • AWS
  • Azure
  • Entra ID
  • Okta
Security + operations
  • CrowdStrike
  • Splunk
  • ServiceNow
  • GitHub
Data systems
  • SharePoint
  • Box
  • Databricks
  • Salesforce
DIRECT CONNECTORSAXONIUS CONTEXTSECURE API / FILECUSTOM ADAPTERS
ComplAI
GOVERNED OUTPUTS
  • EvidenceLinked
  • PostureMapped
  • SSP + POA&MPreserved
  • Findings + driftVisible
CATALOG PORTFOLIO30+

Connect the fact once. See every related requirement.

ComplAI preserves a fact's source, scope, and owner, then shows which requirements it supports across the framework catalogs in your environment.

  • One fact, multiple relationships
  • Each requirement keeps its meaning
  • People review every conclusion
Active lens Registered Portfolio
ADDITIONAL CATALOG REFERENCES12 SHOWN · AVAILABILITY VARIES BY DEPLOYMENT
  • CMMC Level 1Active lens
  • NIST AI Risk Management FrameworkRegistered
  • NIST Secure Software Development FrameworkRegistered
  • EU Artificial Intelligence ActRegistered
  • CMMC Level 3Portfolio
  • NIST SP 800-172 Rev. 3Portfolio
  • NIST Privacy FrameworkPortfolio
  • HIPAA Security RulePortfolio
  • General Data Protection RegulationPortfolio
  • NIS2 DirectivePortfolio
  • Digital Operational Resilience ActPortfolio
  • FBI CJIS Security PolicyPortfolio
Active lens · Federal controlsNIST SP 800-53 Rev. 5

Follow this federal catalog through shared controls, evidence, scope, and accountable owners. Its requirements and source context stay distinct in the reviewable record.

NIST

Eighteen representative catalog references are shown across active, registered, and portfolio states. Availability, version, mapping depth, and enabled workflows are confirmed per deployment. ComplAI seals are first-party navigation artwork—not official publisher marks, certifications, authorizations, or endorsements, and not assessment results or compliance guarantees.

THE COMPLAI ASSURANCE GRAPH

Trace every conclusion back to the system.

See how each requirement relates to the assets, identities, regulated data, evidence, and accountable review behind its current state.

CONTROLS & EVIDENCE

One relationship model for the facts behind each control.

01
NIST SP 800-53 · NIST SP 800-171 · control inheritance
02
SCOPE

Assets & identities

Relate devices, workloads, services, users, and vendors to the boundary they actually influence.

Inventory · access paths · accountable owners
03
DATA

CUI & regulated data

Discover where regulated data lives, understand how it moves, and connect handling expectations to its repositories.

Discovery · classification · lineage · protection
04
OUTPUT

Governed artifacts

Maintain SSP, POA&M, assessment evidence, and authorization context from linked sources and review history.

Source · owner · timestamp · decision trace

ONE CHANGE. ONE CLEAR STORY.

Something changes. Your team can see what matters next.

Follow one example from the moment a privileged role changes to the moment a person decides what to do. ComplAI keeps the facts connected so your team can act with context and explain the decision later.

01A change happens

A privileged role changes. Your team sees it clearly.

A privileged role changes in an identity system. ComplAI brings the source and time together in one clear event, so your team begins with what happened—not a spreadsheet hunt.

Where it happened · when it happened · what changed

Illustrative workflow with synthetic records. Source systems and data paths are representative; exact integrations and actions are confirmed for each deployment.

DEPLOYMENT BOUNDARY

Fit the architecture to the data boundary.

ComplAI can be scoped for customer-hosted, commercial-cloud, and government-cloud environments. Before data is connected, the customer and ComplAI document the hosting boundary, approved model provider, ingress and egress, controls, and shared responsibilities. Final architecture and service availability are confirmed for each deployment.

On-premises / customer-hostedCommercial cloudAWS GovCloudAzure Government
Discuss architecture and data flow
CUSTOMER-DEFINED BOUNDARYSCOPED
ACTIVE SOURCEEvidenceFreshness + provenance
COMPLAI WORKFLOW LAYERRetrieval · reasoning · workflow
GOVERNED OUTPUTArtifacts + actions + decision trace
review required

PROCUREMENT & DELIVERY

Move from technical fit to a viable buying path.

ComplAI is available through Carahsoft’s public-sector channel, with direct scoping for deployment and services. Exact vehicle, eligibility, responsibilities, and terms are confirmed for each customer.

CarahsoftPublic-sector channel
Explore partner paths

COMMON QUESTIONS

Clear answers before architecture work begins.

The right answer depends on the boundary, decision authority, and deployment constraints. These are the stable starting points.

Is ComplAI only for CMMC?

No. The platform supports CMMC and ATO / continuous ATO workflows, with a shared model for controls, evidence, assets, identities, regulated data, findings, and artifacts.

Does ComplAI replace the people responsible for authorization or assessment?

No. ComplAI organizes and automates work, but accountable officials, system owners, security teams, assessors, and authorizing stakeholders retain their respective decisions and responsibilities.

Does regulated data have to be sent to a public AI model?

That data flow is deployment-specific. Architecture review determines whether a customer-controlled or government-cloud pattern is appropriate; model providers, ingress and egress, and handling rules are confirmed before regulated data is connected.

Can we start with our existing artifacts and tools?

Yes. A practical rollout starts by inventorying the current boundary, evidence sources, SSP, POA&M, asset records, repositories, and workflows before deciding what to integrate, migrate, or retire.

LET'S TALK

See how ComplAI fits your program.

Tell us what you're working toward. We'll show you how ComplAI can help and where to start.

Don't send CUI, credentials, SSPs, evidence packages, or system diagrams through this form or email.