Security Overlays.

Overlay Coverage

50+ overlays that modify, extend, and harden base frameworks. DISA STIGs, SRGs, CIS Benchmarks, DoD Impact Levels, regulatory requirements, privacy baselines, AI governance controls, and sector-specific overlays. Composable layers that stack on any framework.

Composable security layers. Stacked on any framework.

Overlays add technology-specific requirements, regulatory obligations, and sector standards on top of base framework baselines. The overlay composition engine applies ADD, MODIFY, REMOVE, and PARAMETER operations with deterministic precedence and conflict resolution.

18 items

DISA STIGs DoD & Hardening

Automated STIG compliance for RHEL, Ubuntu, Windows, Docker, Kubernetes, PostgreSQL, and 10+ platforms.

DISA SRGs DoD & Hardening

Security Requirements Guides for GP OS, Application, Network, Web Server, Database, and Container platforms.

CIS Benchmarks DoD & Hardening

Configuration baselines for OS, Cloud Foundations, Container, Database, and Web Server platforms.

DoD Impact Levels DoD & Hardening

IL2, IL4, IL5, and IL6 cloud requirements from the DoD Cloud SRG. CUI through classified workloads.

CNSSI 1253 Overlays DoD & Hardening

Classified, Cross Domain, Intelligence, Space Platform, and ICS overlays for National Security Systems.

NIST 800-53B Privacy Baseline Privacy

PT control family: Notice, Consent, Data Minimization, Use Limitation. Privacy overlay on security baselines.

NIST 800-122 PII Protection Privacy

PII identification methodology, confidentiality impact levels, and de-identification strategies.

GDPR Privacy

EU data protection mapped to NIST 800-53. Lawful basis, data subject rights, DPO, DPIA, and breach notification.

NIST AI 600-1 GenAI Profile AI Governance

Twelve GenAI risk categories. Content provenance, training data governance, and model security controls.

COSAiS AI Governance

AI-specific security controls as NIST 800-53 modifications. Model security and AI supply chain hardening.

EU AI Act AI Governance

European AI regulation mapped to security controls. Risk classification and high-risk AI system obligations.

ITAR Regulatory

International Traffic in Arms Regulations. USML categories, US Person access, and Technology Control Plans.

DFARS 252.204-7012 Regulatory

CUI protection, 72-hour incident reporting to DC3, and subcontractor flow-down for defense contracts.

EAR Regulatory

Export Administration Regulations for dual-use technology. Commerce Control List and license requirements.

Healthcare Sector

HIPAA technical safeguards as NIST 800-53 modifications. ePHI access controls, audit logging, and encryption.

Financial Sector

FFIEC examination standards and GLBA Safeguards Rule as NIST 800-53 control modifications.

Education Sector

FERPA student record protection as NIST 800-53 modifications. Student data access and consent management.

Critical Infrastructure Sector

NIST CSF sector profiles for energy, water, transportation, and communications with OT/ICS controls.

No matches. Try a different search or category.

Something is being forged.

The full platform is under active development. Reach out to learn more or get early access.