Home · Trust
Mapped to published guidance · not an ATO
Mapped to published NIST, not a seal
GRC can map us. No agency verified us. No ATO is claimed here.
What maps
- NIST CSF — Identify / Protect / Detect / Respond / Recover as the operator loop language.
- NIST SP 800-53 — control-family vocabulary so your GRC sheet does not invent a taxonomy.
- NIST SP 800-207 — Ikaros is the policy engine (PE); AEGIS is the policy administrator (PA); Edge PEPs sit on the data plane. Dual-plane admission is two PEP classes, not a Wi‑Fi SKU.
- CISA CPG + NSA CSI — continuous verification, least privilege, residual risk from published text.
What you can inspect
- Public Docs allowlist vs operator library (LAN only).
- CEP-Rank kind card: rules + scored join; LLM narrates, does not rank.
- AEGIS: guide on this origin; kernel is HUMAN_ONLY inside Ikaros.
- Decision journal shape — not a live API on this origin.
- ENGINE PATH on Architecture: five stages, one diagram, Play. This origin is not a PEP.
What this is not
- Not FedRAMP, CMMC, SOC 2, or an ATO package.
- Not NSA, CISA, FBI, CIA, DHS endorsement, use, or accreditation.
- Not this origin actuating PEPs. Not measured MTTD. Not a certification wall.
- Not edge WAF (Cloudflare/Akamai) — app-layer headers on shared hosting only.
How to use it
- Counsel: map families, then NDA for the enclave.
- Operator: Briefing tape, then Architecture, then Ikaros, then Mandate stages.
- Disclosure: security.txt + briefing form.
Security disclosure
If you believe you have found a vulnerability in a C1BERTITANS public property, contact us via the
briefing form with a responsible disclosure summary.
See also security.txt.
What this page is not
This is not a FedRAMP authorization package and not a substitute for your own risk assessment.
Enterprise deployments are scoped under NDA and architecture review.