Home · Trust
Mapped to published guidance · not an ATO
Mapped to published NIST, not a seal
GRC can map us. No agency verified us. No ATO is claimed here.
What maps
- NIST CSF — Identify / Protect / Detect / Respond / Recover as the operator loop language.
- NIST SP 800-53 — control-family vocabulary so your GRC sheet does not invent a taxonomy.
- NIST SP 800-207 — dual-plane admission as a PEP pattern, not a Wi‑Fi SKU.
- CISA CPG + NSA CSI — continuous verification, least privilege, residual risk from published text.
What you can inspect
- Public Docs allowlist vs operator library (LAN only).
- CEP-Rank kind card: rules + scored join; LLM narrates, does not rank.
- AEGIS dual-facet: guide on this site; kernel gates inside Ikaros.
- Decision journal shape — illustrative, not a live API.
- Architecture diagram: brochure plane vs operator plane. No RFC1918.
What this is not
- Not FedRAMP, CMMC, SOC 2, or an ATO package.
- Not NSA, CISA, FBI, CIA, DHS endorsement, use, or accreditation.
- Not a live ranker, not measured MTTD, not a certification wall.
- Not edge WAF (Cloudflare/Akamai) — app-layer headers on shared hosting only.
How to use it
- Counsel: map families, then NDA for the enclave.
- Operator: Briefing tape, then Architecture, then Ikaros, then Mandate stages.
- Disclosure: security.txt + briefing form.
Security disclosure
If you believe you have found a vulnerability in a C1BERTITANS public property, contact us via the
briefing form with a responsible disclosure summary.
See also security.txt.
What this page is not
This is not a FedRAMP authorization package and not a substitute for your own risk assessment.
Enterprise deployments are scoped under NDA and architecture review.