Request a demo

NAICOM · AVAILABLE CITADEL · 1.0.0 BEACON · BETA

See it running. Then run it yourself.

NAICOM makes AI-assisted engineering auditable. Citadel turns a host fleet into signed, queryable compliance evidence. Both are released and deployed inside your own boundary — Beacon, our FedRAMP 20x KSI emitter, is in beta alongside them.

A demo is the running system, walked live, against the questions your auditor is going to ask. Pick the product that is most urgent, tell us what your environment looks like, and we will show you the part that matters to you.

The products

Different products, different audiences.

What follows is who each product is actually for. They are not gates — if your situation is close but not exactly this, the conversation is still worth having.

NAICOM

Generally available

The audit trail for AI-assisted engineering. Sessions open against a tracked issue, instructions are versioned prompt files committed beside the code, and a named human approves every merge. It runs against your own repositories and your own tracker, inside your boundary.

NAICOM —What is already true

1,637 dispatches · 825 issues · 8 projects · 12 weeks

Novaprospect runs its own engineering on NAICOM. Those are the figures from our production ledger for the period 27 May – 21 August 2026, covering 718 pull requests.

Who this is for

Engineers already shipping with AI

Coding assistants are in use on production repositories today. NAICOM records work that is already happening — it is not a reason to start.

An issue tracker you actually use

Jira, or a tracker with an equivalent API. The issue is the root of the trace, so a team that opens tickets after the fact has nothing to link to.

A governance question with a date on it

An ISO/IEC 42001 certification, an AI RMF self-assessment, an EU AI Act Article 12 or 14 obligation from 2 August 2026, or a customer security review that has started asking about AI.

Someone who owns the answer

A named engineering or compliance contact who will be asked "which of these changes was AI-written, on whose authority?" — and who can tell us whether our export is what they needed.

Citadel

Version 1.0.0 · generally available

Host-state evidence for regulated fleets. Enrol the Citadel agent across your fleet, distribute compliance-aligned query packs, and get a signed, queryable evidence stream for the CM, SI, and AU control families instead of a folder of quarterly screenshots.

Citadel —What is already true

A host enrolled and reporting, over TLS

Verified 20 August 2026: a Citadel control plane running behind a real certificate chain, with a macOS host enrolled and ONLINE, reporting its scheduled results over TLS.

Who this is for

Hosts whose live state you cannot answer for

Today "what is running right now" comes from a quarterly scan or a CMDB that drifts. Starting from nothing is fine — enrolment is an installer and a config file.

Endpoints to enrol

A real fleet of Linux, macOS, or Windows hosts inside a boundary you control. Tens is enough to be useful; the interesting questions start in the hundreds.

A compliance or asset-inventory driver

CM-2, CM-6, CM-8, SI-4 or SI-7 evidence you currently assemble by hand, a CMDB that drifts from reality, or FedRAMP continuous monitoring you are trying to move off a screenshot cadence.

Somewhere for the results to land

A SIEM, a data warehouse, or a willingness to run the append-only evidence store we ship. Air-gapped deployments are supported natively.

Beacon

Beta

The continuous KSI emitter for FedRAMP 20x. Reads infrastructure state and emits signed, machine-readable Key Security Indicator evidence at the cadence 20x asks for, in the format the Consolidated Rules mandate. Still in beta — see it, and see exactly where it is.

Beacon —What is already true

Reproducible KSI output from the open-source evaluator

The Beacon KSI evaluator emits real, verbatim JSON for KSI-IAM-01 and KSI-CMT-RMV from its own bundled examples — reproducible on your machine, not a rendering of what output might look like.

Who this is for

In or applying to 20x Phase 2 / Phase 3

Your authorization plan includes 20x — Phase 2 cohort participation, the Phase 2 Cohort 2 window, or Phase 3 wide-scale adoption starting Q3 2026.

Cloud-native infrastructure

Production runs on cloud primitives (AWS / Azure / GCP) and IaC (Terraform, Pulumi, Helm) the KSI emitter can read directly. On-prem is workable where the read path is well-defined.

A real authorization timeline

An authorization milestone this calendar year. A beta is worth your time under genuine timeline pressure, and rarely worth it without one.

Tolerance for a beta

Coverage is still expanding KSI by KSI. You should want to see the current output against your own infrastructure before you plan around it.

What the demo covers

The running product, not a deck.

  • A live walkthrough of the running product against a real deployment — not slides, and not a recorded video.
  • The auditor-facing output in front of you: the per-issue AI trail, or a host queried for its state on a date in the past.
  • A straight answer on scope, effort and price for your environment, in the same conversation.
  • A deployment plan for your own boundary — self-hosted, air-gapped where that applies, with the integration points named.
  • A named engineering contact from the team that builds it — not a queue and not a support ticket.

What we need from you

Thirty minutes and a named contact.

  • A named technical contact who can speak for the environment the product would run in.
  • A rough shape of that environment — repositories and tracker for NAICOM, host count and operating systems for Citadel, cloud and IaC for Beacon.
  • The deadline actually driving this: an authorization date, a certification, an audit, or a customer security review.
  • Thirty minutes. A second, deeper session is common; the first one does not need to be long.

Release status

What is released, and what is not.

NAICOM

generally available

In production on our own engineering since 27 May 2026. Deployed in your boundary, against your tracker and your forge.

Citadel

1.0.0 · generally available

Control plane, agent, and compliance query packs, released. Air-gapped and FIPS 140-3 capable deployments supported.

Beacon

beta

KSI coverage is still expanding, and the FedRAMP Management Engine that consumes it is in limited release. Both are demonstrable today.

Customer identities stay confidential unless a customer chooses to publish. We will say plainly which parts of a beta are implemented rather than demoing around them — a demo that oversells is a support problem three months later.

FAQ

What people usually ask first.

Can I see more than one product?

Yes. NAICOM, Citadel, and Beacon are separate deployments with separate audiences, and several organizations want two of them. Pick the most urgent one in the form and say so in the message — we scope them as separate engagements so neither one waits on the other.

What does a NAICOM demo involve?

We walk the running system: an AI session opening against a tracked issue, the instruction landing in the repository as a versioned prompt file, the pull request carrying the session ID, and the export that answers "every AI-driven change to this component last quarter" as a table. Then we look at your tracker and your forge — GitHub, GitLab, Bitbucket or Gitea, resolved per repository — and what deployment inside your boundary would take.

What does a Citadel demo involve?

A control plane with hosts enrolled, live. We show enrolment (an installer and a config file, reporting over TLS), the query packs and the 800-53 controls each one evidences, and a historical query — what a host looked like on a date that has already passed. Air-gapped deployments are supported natively and we will walk that path if it is yours.

Can we run it ourselves after the demo?

That is the normal next step. Both NAICOM and Citadel are deployed inside your own boundary rather than accessed as a hosted service, so an evaluation is a real installation with your data staying where it already is. We scope it in the demo conversation.

What does it cost?

NAICOM list pricing is published on the pricing page — SaaS, PaaS, and on-prem tiers. Citadel and Beacon are quoted per engagement, because fleet size and deployment shape move the number more than anything else does. The price is open in the first conversation; we do not make you sit through a demo to get it.

Is everything generally available?

No, and the difference matters. NAICOM is generally available and has been running our own engineering in production since 27 May 2026. Citadel is at 1.0.0 and generally available. Beacon is still in beta and the FedRAMP Management Engine is in limited release — you can see both, and we will tell you plainly what is and is not implemented rather than demoing around the gaps.

How quickly do you respond?

Every request gets an answer. In practice that is inside a business day, with a session scheduled the same week where the timeline warrants it.

Request a demo.

Pick a product, tell us about your environment and your timeline, and name the technical contact who would lead the work on your side. We answer every request — usually inside a business day.

Which product *

The audit trail for AI-assisted engineering. Sessions open against a tracked issue, instructions are versioned prompt files committed beside the code, and a named human approves every merge. It runs against your own repositories and your own tracker, inside your boundary.

I'm reaching out about *