Skip to content
ActaCyber
ACTA // THE ACTA+ RELEASE

Compliance without the headaches.
Security that's better for it.

Painful compliance produces box-checking, not security. ACTA removes the pain: it provisions the environment, assesses it, trains the people in it, generates the full ATO package, and monitors what it built. Deterministically, start to finish.

Provisions the full environment as code in about 25 minutes, on AWS, GovCloud, GCC High, Azure, Google Cloud, or bare metal
Every policy pack ships with every license: NIST, FedRAMP, CMMC, HIPAA, PCI DSS, and the rest
Full artifact package plus continuous monitoring, refreshed to current in two clicks
ENGINES: GRYPE // TRIVY
Scroll to brief
SITUATION REPORT

It was never just the paperwork

The artifact package was the visible bottleneck, so that's what ACTA automated first. But the actual journey runs longer in both directions: provision the environment, configure it against controls, document all of it, train every human, keep the evidence current, and hand everything off cleanly at the end. That journey is fragmented across roles, tools, and months, and the market's answer is a dashboard that costs $50K to $250K a year, tells you where you're failing, and hands you a checklist.

ACTA owns the journey instead. Empty account to authorized to retired, with every step carried through to the deliverables your ISSM actually needs.

MOSTCOMPLIANCEPLATFORMSFOCUSON:TELLINGYOUWHEREYOU'REFAILING.
WE FOCUS ON: GETTING YOU TO AUTHORIZATION.
A checklist is not a journey. ACTA provisions, documents, trains, monitors, and retires. The loop is closed.
CAPABILITY BRIEF

What ACTA Does

Six integrated modules. One deterministic journey: provision, assess, document, train, monitor, retire.

CAP-01 // CLOUD PROVISIONING

Provisions the Environment From Point One

Give ACTA a handful of inputs (users, roles, devices) and it plans and provisions the entire environment: VPCs, subnets, S3, KMS, CloudTrail, Security Hub, GuardDuty, EKS clusters, IAM roles. All of it as code, Terraform and CloudFormation, on AWS commercial, GovCloud, GCC High, Azure, Google Cloud, or bare metal. A small environment takes about 25 minutes, gated by AWS provisioning speed, not by ACTA. It runs on temporary admin credentials and strips its own privileges when the journey completes.

TERRAFORMCLOUDFORMATIONGOVCLOUDAZUREGCP
CAP-02 // POLICY PACKS

Every Policy Pack, With Every License

NIST 800-53 and 800-171, FedRAMP, CMMC, StateRAMP, CJIS. Also HIPAA, HITRUST, PCI DSS, SOX, FERPA, SOC 2, GDPR, and the rest of a library spanning federal, cybersecurity, education, healthcare, and finance. Every pack ships with every license, because the person ACTA is built for runs a DoD enclave, a CMS contract, and a hospital client in the same week. Packs are editable YAML; an agency-specific directive is a two-line change, not a support ticket.

NISTFEDRAMPCMMCHIPAAPCI DSS
CAP-03 // DETERMINISTIC ENGINE

Deterministic All the Way Down

No LLMs, no agents, no probabilistic components anywhere in the compliance path. ACTA runs on goRapide, BMD's deterministic causal engine. Run the same journey a hundred times and get identical artifacts, identical scores, identical evidence, with every decision carrying a causal chain an assessor can inspect. The whole product is a single Docker image under 20 MB, and evidence never leaves your boundary: the standard build phones home for a license heartbeat and nothing else; the air-gapped build doesn't even do that.

GORAPIDEREPLAYABLEAIR-GAPUNDER 20 MB
CAP-04 // SCANNING & SBOM

Multi-Engine Scanning and SBOMs

Powered by Grype and Trivy with automatic cross-engine deduplication. Every finding is enriched with EPSS exploit probability scores and CISA KEV flags, then ranked by a composite risk score so your team triages what matters first. Syft-powered CycloneDX SBOMs with license extraction support FAR/DFARS-aware procurement decisions, and vendor SBOMs can be imported, vulnerability-matched, and evaluated for completeness.

GRYPETRIVYEPSSKEVCYCLONEDX
CAP-05 // ARTIFACTS & EVIDENCE

Artifacts in Whatever Format Your Assessor Reads

System Security Plan, Security Assessment Report, POA&M, Risk Assessment Report, control narratives, the evidence binder, the SPRS package. Generated in YAML, JSON, Markdown, and PDF, on your letterhead, so the assessor picks a format and nobody regenerates anything. eMASS-importable POA&M CSVs and STIG CKL checklists included. Machine-readable by default, because two hundred screenshots in an email was never actually a standard.

SSPPOA&MSPRSeMASSPDF
CAP-06 // MONITOR & RETIRE

Monitors What It Built. Retires It With Proof.

An ATO package is a snapshot; ACTA keeps taking the picture. Scheduled or on-demand sync tracks credential health, evidence freshness, endpoint posture, and drift from previously passing controls. A six-month-old posture is two clicks from current. Role-based training packs and quizzes are generated, scored, and tracked as evidence. At end of contract, ACTA deprovisions with proof: deletion evidence, egress history, the full causal journey, packaged for whoever inherits the system.

cATODRIFTTRAININGTEARDOWN
PHASE 01 // PROVISION

From Empty Account to Built Environment

One bootstrap role connects ACTA under a temporary admin policy. From your inputs it plans and builds the environment as code, or clones a commercial account into GovCloud item per item with controls enabled.

PHASE 02 // ASSESS

Controls, Scans, and the Human Layer

Controls are assessed against your selected policy packs. Grype and Trivy scan the workloads, endpoints report through your MDM, and role-based training packs go out to the humans. Anything ACTA can't fix is flagged into a POA&M, never deleted.

PHASE 03 // AUTHORIZE & MONITOR

Package, Strip Privileges, Keep Current

The full package generates in YAML, JSON, Markdown, and PDF on your letterhead. ACTA then strips its own admin privileges and stays in monitoring-only mode: refresh posture on a schedule or in two clicks, and hand off or tear down with proof at end of contract.

POLICY ENGINE

Composable Policy Engine

YAML-based, auditable, and designed for real-world compliance workflows. Policies define rules with configurable thresholds, actions, and per-environment overrides, and the full pack library ships with every license. No vertical add-on pricing.

Built-in Compliance Packs

The complete library ships with every license, because the compliance professional ACTA is built for supports multiple contracts across multiple industries at once. Combine multiple packs per journey.

VerticalPacks
Federal / GovernmentNIST RMF, FISMA, NIST 800-53, FedRAMP, CMMC, NIST 800-171, CJIS, IRS 1075, DoD Cloud Computing SRG, StateRAMP
CybersecurityNIST CSF, ISO/IEC 27001, SOC 2, CIS Controls, COBIT, Cyber Essentials, Essential Eight, CSA STAR, NIST 800-161, MITRE D3FEND
EducationFERPA, HECVAT, GLBA, COPPA, CIPA, CoSN, GDPR
HealthcareHIPAA, HITRUST, HITECH, ISO 27799, FDA §524B device cybersecurity, GxP, NHS DSP Toolkit
FinancePCI DSS, GLBA, FFIEC, SOX, DORA, NYDFS 23 NYCRR 500, SEC Cyber Disclosure, SWIFT CSP, Basel III, FINRA
Container / PipelineDISA CIC, DISA CDE, NIST 800-190, Iron Bank Pipeline, Vulnerability Gates, OMB M-22-18 Procurement

Environment Overrides

Rules behave differently per deployment target. A critical vulnerability can block production deploys while only warning in development: same policy file, no duplication.

Waivers with Accountability

Temporarily exempt specific CVEs with tracked, expiring waivers tied to ticket numbers. Blast radius analysis shows what a waiver covers. Expiration alerts prevent waivers from going stale. Simulate revoking a waiver before you do it.

Policy Management Tools

Diff two policies before deploying changes. Validate syntax and semantics. Dry-run against historical scans. Generate human-readable explanations of what a policy enforces.

# policy/prod.yaml
$api_version: v1
$kind: Policy
$metadata:
$ name: production-gate
$spec:
$ # Enforce DISA Container Image Creation requirements
$ require_packs:
$ - disa-cic-v2
$ - vulnerability-gates

$ # Environment overrides
$ overrides:
$ - threshold: CRITICAL
$ action: BLOCK_DEPLOYMENT # Fails CI/CD

$ - threshold: HIGH
$ has_fix: true
$ action: BLOCK_DEPLOYMENT # Block only if fixable

$ - package: "curl"
$ # Legacy dependency exception
$ waiver_id: "JIRA-9412"
$ expires: "2025-06-01"
$ action: WARN

CONTROL MAPPING

Direct DISA Control Mapping

Every check maps to a specific control from the DISA Container Image Creation and Deployment Guide (V2 R0.6), with CCI identifiers for traceability.

CheckDISA ControlCCIWhat It Enforces
SSH disabledCM-7aCCI-000381No SSH daemon in container
Non-root userAC-6(10)CCI-002235Must not run as root
COPY over ADDCM-7aCCI-000381Use COPY instead of ADD
Non-privileged portsCM-7(1)(b)CCI-001762Ports above 1024 only
HEALTHCHECK requiredSC-5CCI-002385Process health monitoring
No embedded secretsCM-6bCCI-000366No credentials in image layers
Approved base imageSC-8(2)CCI-003782DoD-approved registry only
Resource limitsSC-5(1)CCI-002386CPU and memory limits set
Read-only root FSCM-5(1)CCI-001813Immutable root filesystem
Liveness probeSC-5CCI-002385Kubernetes liveness check
Readiness probeSC-5CCI-002385Kubernetes readiness check
No host namespacesSC-4CCI-001090No hostPID or hostNetwork
OUTPUT FORMATS

Reports That Go Where You Need Them

ACTA produces outputs in formats that integrate directly into your existing toolchain, from CI/CD dashboards to compliance management systems.

Human-readable summary

CLI

Quick review and terminal output

GitLab SAST JSON

JSON

GitLab Security Dashboard integration

SARIF

JSON

GitHub Code Scanning and VS Code

CycloneDX 1.5 VDR

XML/JSON

Vulnerability disclosure reporting

SPDX 2.3

JSON/TAG

Software supply chain compliance

CSV

CSV

Spreadsheet analysis and stakeholder sharing

OpenVEX

JSON

Vulnerability exploitability exchange

POA&M CSV

CSV

eMASS import for Plan of Action & Milestones

STIG CKL XML

XML

STIG Viewer checklist import

Branded PDF & Markdown

PDF/MD

Full artifact package on your letterhead, templates imported at onboarding

Evidence Binder

BUNDLE

One-click evidence package for assessor review

SPRS Package

BUNDLE

NIST 800-171 scoring submission, tracked live during the journey

1 PIPELINE STAGE
3 SCAN TYPES
MACHINE-READABLE ARTIFACTS

Native CI/CD Integration

Native support for GitLab CI and GitHub Actions with exit codes that gate your pipeline. Scans produce machine-readable reports as build artifacts. A single pipeline stage covers image scanning, Dockerfile compliance, and manifest validation.

OPERATIONS

Built for How Teams Actually Work

Scan History & Baselines

Every scan is persisted to a local SQLite database. Browse past scans, show full details, compare any two scans side-by-side, and track how your security posture changes over time. Baseline resolution is automatic — when you specify a branch, ACTA finds the most recent scan for comparison.

$$ acta history list
$ID DATE TARGET ENGINE FINDINGS STATUS
$0xA7F3 2025-03-15T08:42:00Z nginx:latest Trivy 0 CRIT COMPLIANT
$0xA7F2 2025-03-14T10:15:33Z api-server:v2 Grype 2 CRIT FAILED
$0xA7F1 2025-03-14T09:00:12Z postgres:15-alp Trivy 0 CRIT COMPLIANT

$> Showing 3 of 142 records.

Embedded Dashboard

An embedded dark-themed dashboard for visual scan browsing, vulnerability trends over time, and scan-to-scan comparison. Everything is compiled into the single binary — no npm, no database server, no external dependencies. Works fully offline.

Dash // Posture Overview

Air-Gapped Support

Offline vulnerability database and feed caches for disconnected environments. Download EPSS, KEV, and NVD feeds when connected, then scan without network access.

FEEDS: CACHEDOFFLINE MODE: ACTIVE

Procurement Validation

Evaluate vendor-supplied SBOMs against OMB M-22-18 requirements. Import external SBOMs, run vulnerability matching, assess completeness, and produce APPROVE, CONDITIONAL, or REJECT recommendations.

$$ acta vendor evaluate ./vendor-sbom.json
$[+] Parsing CycloneDX 1.5 document...
$[+] Analyzing dependencies (142 components)...
$[!] Missing NTIA minimum elements: Author missing for 3 components.
$[+] Vulnerability correlation (offline database)...

$RECOMMENDATION: CONDITIONAL
$Reason: 2 HIGH vulnerabilities found (non-KEV). Remediation required within 30 days.

Threat Intelligence Feeds

Advisory source tracking, remediation SLA enforcement, FIPS readiness checking, and Iron Bank pipeline compliance validation — all driven by regularly updated feed data.

ARCHITECTURE

One Docker Image, Full Platform

ACTA ships as a single hardened Docker image under 20 MB that runs on about 100 MB of RAM, fully air-gappable. Dashboard plus CLI, with the command structure organized around workflows, not implementation details.

  • Provisioning

    Plan and build cloud environments from structured inputs. Bootstrap, clone, and migrate accounts. Strip privileges on journey completion.

  • Scanning

    Image, Dockerfile, directory, and manifest scanning with combined passes and engine selection.

  • Policy

    Validate, diff, test, and explain policies. List available compliance packs. Re-evaluate findings against updated policies without re-scanning.

  • History

    Browse, inspect, compare, and manage scan records in the local database.

  • cATO

    Set baselines, check posture, generate evidence packages, and gate CI/CD pipelines on continuous compliance status.

  • Training

    Generate role-based training packs and quizzes per framework, score uploaded results, and track awareness state as evidence.

  • Procurement

    Validate vendor SBOMs against federal procurement requirements.

  • Waivers

    Impact analysis, expiration tracking, audit reports, and revocation simulation.

  • SBOM

    Sign, verify, and import SBOMs with HMAC-SHA256 integrity checking.

  • Feeds

    Update and check status of offline vulnerability and enrichment data.

  • Deprovision

    Tear down environments at end of life with proof: deletion evidence, egress history, and the full causal journey packaged for handoff.

  • Infrastructure

    REST API server, registry monitoring daemon, and Kubernetes admission controller for runtime enforcement.

LICENSING

Built for Federal and Enterprise

ACTA is in production with paying customers and licensed per environment, with deployment, integration, and support tailored to your authorization timeline. Every policy pack ships with every license. The standard build phones home for a license heartbeat and nothing else; the fully air-gapped build is licensed annually and doesn't even do that. From single-node installs to multi-cluster federal enclaves, every engagement starts with a conversation.

Run one deployment through ACTA. Going back to manual won't make sense.

Tell us about your environment and authorization timeline, and we'll put together a quote built around it.

SELF-HOSTED//AIR-GAP READY//MULTI-CLOUD//FEDERAL DEPLOYMENT//ENTERPRISE LICENSING