NIST AI RMF · ISO/IEC 42001 · EU AI Act · NIST 800-53

  • The NAICOM sessions view: a counter strip reading total and active sessions, an active-sessions panel listing code, QA and research runs each against an issue key, a 90-day activity heatmap, and a recent-sessions table.
    Generally available

    NAICOM

    The audit trail for AI-assisted engineering.

    NAICOM sits between your engineers and the models they work with, and writes down what happened. Every session opens against a tracked issue. Every instruction is a versioned prompt file committed beside the code it produced. Every commit carries the session ID, the issue key, and the human who approved the merge — so "which of these changes was AI-written, and on whose authority?" is a query. It runs against the forge you already use — GitHub, GitLab, Bitbucket or Gitea, resolved per repository — so nothing about the existing workflow has to move.

    The screen above is a demo tenant; the customer and its sessions are invented.

  • The Citadel hosts view: a table of twelve enrolled hosts with per-row status dot, hostname, platform tag, operating system, osquery version, address, uptime and last-seen time; a scope panel counting 12 all hosts, 10 online, 2 offline, 0 mia, and the built-in macOS, Ubuntu, CentOS and Windows labels.
    Version 1.0.0 · generally available

    Citadel

    Live host-state evidence for regulated fleets.

    Citadel is a host-state evidence platform for regulated environments. It enrols and configures the Citadel agent across a host fleet, distributes compliance-aligned query packs, and turns their results into a signed, append-only evidence stream — so "what is actually running on every host, and what was running on the day of the finding" is a SQL question with a timestamped answer.

    Built for fleet-scale collection over mutually authenticated TLS, with packs distributed per platform and every result signed at the agent. Air-gap and FIPS 140-3 capable.

    The screen above is the control plane running against an example fleet, not a customer's.

  • Diagram: cloud and infrastructure-as-code inputs read into the Beacon evaluator, which emits signed KSI evidence — KSI-IAM, KSI-CNA, KSI-CMT — on a repeating three-day cadence timeline.
    Beta

    Beacon

    The continuous KSI emitter for FedRAMP 20x.

    Beacon reads infrastructure state continuously and emits signed, machine-readable Key Security Indicator evidence — at the three-day cadence 20x asks for and in the format the Consolidated Rules 2026 mandate. It plugs into the FedRAMP Management Engine or stands alone against your own package.

    Designed to emit KSI evidence at the three-day 20x cadence from cloud primitives and IaC it reads directly. The open-source evaluator produces verbatim, reproducible output today.

  • Diagram: two authorization pathways — FedRAMP 20x KSI emissions and the Rev 5 OSCAL baseline — converging on one record, which issues the OSCAL SSP, the POA&M lifecycle and the evidence ledger.
    Limited release

    FedRAMP Management Engine

    The system of record for authorization, in both directions.

    The Engine holds Beacon's 20x KSI emissions as the authoritative package, and generates Rev 5 OSCAL artifacts and POA&M lifecycle for organizations still on the traditional path through the Consolidated Rules transition window. One record, whichever pathway an authorization is on.

    Designed to carry a full Rev 5 Moderate baseline as OSCAL, with POA&M lifecycle and evidence origin references sourced from Beacon and Citadel rather than re-keyed.

Page 1 of 2 — NAICOM, Citadel

The platform

Four products, one authorization boundary.

Each product runs on its own. Run together, they compose one evidence pipeline: host state, the AI-assisted change that ships the code, the KSI emission that lands in the 20x package, and the OSCAL artifact your 3PAO reads.

One evidence pipeline

Every event inside the boundary lands in the same OSCAL record. Auditors query one surface.

Control coverage by design

AC, SC, AU, CM, SA, SI, and AI-RMF families are covered natively by the stack. No manual attestation pass.

Signed, tamper-evident

Every event is signed at its source. The evidence ledger is verifiable end-to-end without trusting Novaprospect.

Deploys in your boundary

The entire stack runs inside your authorization boundary. Customer data and audit records never leave your environment.

The corrections record

AI spend is billed as usage. Much of it is likely a defect bill.

A model that reads a stale branch, or reports work delivered that never landed, produces a re-run billed at the same rate as the work. Every mistake made building the products above is recorded against a fixed class, with the check that would have caught it — and that check is composed into the next operator's instructions before it starts.

Measured, and fed back in

A fixed classification, held in source rather than editable at record time, each correction carrying what was claimed and what was actually true. The classes recorded most often against a role are injected into that role's instructions at dispatch time, with the command that falsifies each one.

Inferred, and next to build

That closing the loop moves the bill is an inference. The join that would measure it — token cost attached to each correction and to the re-run it caused, then spend reported by failure class — is intended, not shipped. No percentage of spend recovered is claimed anywhere.

Counts move daily, so here are the commands rather than the numbers

$ novaicom corrections classes
$ novaicom corrections stats --by week
How the record works, screen by screen → What it is worth to a buyer

About

About Novaprospect

Novaprospect, LLC is a New Mexico limited liability company. It builds authorization software for organizations operating in regulated environments, on a path to FedRAMP and DoD IL authorization.

The company is open to acquisition, with investment as the alternative outcome. What exists, what a buyer inherits, and where each codebase came from is set out on the acquisition page. Financials are open under NDA and appear nowhere on this site.

The ask

Ask for the beta.

Every product above is in closed beta and runs in production here. In your hands it runs on a machine you control, against data that stays there. Nothing reports back, so nothing about your evaluation is visible to the company that wrote it.

Closed beta · running in production at Novaprospect

Request beta access →

Acquisition conversations are open.

Acquisition

The conversation is the acquisition of a product and the team that keeps building it. Investment is the alternative outcome and the same conversation. Financials open under NDA.