Compliance without the headaches.
Security that's better for it.
Painful compliance produces box-checking, not security. ACTA removes the pain: it provisions the environment, assesses it, trains the people in it, generates the full ATO package, and monitors what it built. Deterministically, start to finish.
It was never just the paperwork
The artifact package was the visible bottleneck, so that's what ACTA automated first. But the actual journey runs longer in both directions: provision the environment, configure it against controls, document all of it, train every human, keep the evidence current, and hand everything off cleanly at the end. That journey is fragmented across roles, tools, and months, and the market's answer is a dashboard that costs $50K to $250K a year, tells you where you're failing, and hands you a checklist.
ACTA owns the journey instead. Empty account to authorized to retired, with every step carried through to the deliverables your ISSM actually needs.
What ACTA Does
Six integrated modules. One deterministic journey: provision, assess, document, train, monitor, retire.
Composable Policy Engine
YAML-based, auditable, and designed for real-world compliance workflows. Policies define rules with configurable thresholds, actions, and per-environment overrides, and the full pack library ships with every license. No vertical add-on pricing.
Built-in Compliance Packs
The complete library ships with every license, because the compliance professional ACTA is built for supports multiple contracts across multiple industries at once. Combine multiple packs per journey.
| Vertical | Packs |
|---|---|
| Federal / Government | NIST RMF, FISMA, NIST 800-53, FedRAMP, CMMC, NIST 800-171, CJIS, IRS 1075, DoD Cloud Computing SRG, StateRAMP |
| Cybersecurity | NIST CSF, ISO/IEC 27001, SOC 2, CIS Controls, COBIT, Cyber Essentials, Essential Eight, CSA STAR, NIST 800-161, MITRE D3FEND |
| Education | FERPA, HECVAT, GLBA, COPPA, CIPA, CoSN, GDPR |
| Healthcare | HIPAA, HITRUST, HITECH, ISO 27799, FDA §524B device cybersecurity, GxP, NHS DSP Toolkit |
| Finance | PCI DSS, GLBA, FFIEC, SOX, DORA, NYDFS 23 NYCRR 500, SEC Cyber Disclosure, SWIFT CSP, Basel III, FINRA |
| Container / Pipeline | DISA CIC, DISA CDE, NIST 800-190, Iron Bank Pipeline, Vulnerability Gates, OMB M-22-18 Procurement |
Environment Overrides
Rules behave differently per deployment target. A critical vulnerability can block production deploys while only warning in development: same policy file, no duplication.
Waivers with Accountability
Temporarily exempt specific CVEs with tracked, expiring waivers tied to ticket numbers. Blast radius analysis shows what a waiver covers. Expiration alerts prevent waivers from going stale. Simulate revoking a waiver before you do it.
Policy Management Tools
Diff two policies before deploying changes. Validate syntax and semantics. Dry-run against historical scans. Generate human-readable explanations of what a policy enforces.
Direct DISA Control Mapping
Every check maps to a specific control from the DISA Container Image Creation and Deployment Guide (V2 R0.6), with CCI identifiers for traceability.
| Check | DISA Control | CCI | What It Enforces |
|---|---|---|---|
| SSH disabled | CM-7a | CCI-000381 | No SSH daemon in container |
| Non-root user | AC-6(10) | CCI-002235 | Must not run as root |
| COPY over ADD | CM-7a | CCI-000381 | Use COPY instead of ADD |
| Non-privileged ports | CM-7(1)(b) | CCI-001762 | Ports above 1024 only |
| HEALTHCHECK required | SC-5 | CCI-002385 | Process health monitoring |
| No embedded secrets | CM-6b | CCI-000366 | No credentials in image layers |
| Approved base image | SC-8(2) | CCI-003782 | DoD-approved registry only |
| Resource limits | SC-5(1) | CCI-002386 | CPU and memory limits set |
| Read-only root FS | CM-5(1) | CCI-001813 | Immutable root filesystem |
| Liveness probe | SC-5 | CCI-002385 | Kubernetes liveness check |
| Readiness probe | SC-5 | CCI-002385 | Kubernetes readiness check |
| No host namespaces | SC-4 | CCI-001090 | No hostPID or hostNetwork |
Reports That Go Where You Need Them
ACTA produces outputs in formats that integrate directly into your existing toolchain, from CI/CD dashboards to compliance management systems.
Human-readable summary
CLIQuick review and terminal output
GitLab SAST JSON
JSONGitLab Security Dashboard integration
SARIF
JSONGitHub Code Scanning and VS Code
CycloneDX 1.5 VDR
XML/JSONVulnerability disclosure reporting
SPDX 2.3
JSON/TAGSoftware supply chain compliance
CSV
CSVSpreadsheet analysis and stakeholder sharing
OpenVEX
JSONVulnerability exploitability exchange
POA&M CSV
CSVeMASS import for Plan of Action & Milestones
STIG CKL XML
XMLSTIG Viewer checklist import
Branded PDF & Markdown
PDF/MDFull artifact package on your letterhead, templates imported at onboarding
Evidence Binder
BUNDLEOne-click evidence package for assessor review
SPRS Package
BUNDLENIST 800-171 scoring submission, tracked live during the journey
Native CI/CD Integration
Native support for GitLab CI and GitHub Actions with exit codes that gate your pipeline. Scans produce machine-readable reports as build artifacts. A single pipeline stage covers image scanning, Dockerfile compliance, and manifest validation.
Built for How Teams Actually Work
Scan History & Baselines
Every scan is persisted to a local SQLite database. Browse past scans, show full details, compare any two scans side-by-side, and track how your security posture changes over time. Baseline resolution is automatic — when you specify a branch, ACTA finds the most recent scan for comparison.
Embedded Dashboard
An embedded dark-themed dashboard for visual scan browsing, vulnerability trends over time, and scan-to-scan comparison. Everything is compiled into the single binary — no npm, no database server, no external dependencies. Works fully offline.
Air-Gapped Support
Offline vulnerability database and feed caches for disconnected environments. Download EPSS, KEV, and NVD feeds when connected, then scan without network access.
Procurement Validation
Evaluate vendor-supplied SBOMs against OMB M-22-18 requirements. Import external SBOMs, run vulnerability matching, assess completeness, and produce APPROVE, CONDITIONAL, or REJECT recommendations.
Threat Intelligence Feeds
Advisory source tracking, remediation SLA enforcement, FIPS readiness checking, and Iron Bank pipeline compliance validation — all driven by regularly updated feed data.
One Docker Image, Full Platform
ACTA ships as a single hardened Docker image under 20 MB that runs on about 100 MB of RAM, fully air-gappable. Dashboard plus CLI, with the command structure organized around workflows, not implementation details.
- Provisioning
Plan and build cloud environments from structured inputs. Bootstrap, clone, and migrate accounts. Strip privileges on journey completion.
- Scanning
Image, Dockerfile, directory, and manifest scanning with combined passes and engine selection.
- Policy
Validate, diff, test, and explain policies. List available compliance packs. Re-evaluate findings against updated policies without re-scanning.
- History
Browse, inspect, compare, and manage scan records in the local database.
- cATO
Set baselines, check posture, generate evidence packages, and gate CI/CD pipelines on continuous compliance status.
- Training
Generate role-based training packs and quizzes per framework, score uploaded results, and track awareness state as evidence.
- Procurement
Validate vendor SBOMs against federal procurement requirements.
- Waivers
Impact analysis, expiration tracking, audit reports, and revocation simulation.
- SBOM
Sign, verify, and import SBOMs with HMAC-SHA256 integrity checking.
- Feeds
Update and check status of offline vulnerability and enrichment data.
- Deprovision
Tear down environments at end of life with proof: deletion evidence, egress history, and the full causal journey packaged for handoff.
- Infrastructure
REST API server, registry monitoring daemon, and Kubernetes admission controller for runtime enforcement.
Built for Federal and Enterprise
ACTA is in production with paying customers and licensed per environment, with deployment, integration, and support tailored to your authorization timeline. Every policy pack ships with every license. The standard build phones home for a license heartbeat and nothing else; the fully air-gapped build is licensed annually and doesn't even do that. From single-node installs to multi-cluster federal enclaves, every engagement starts with a conversation.
Run one deployment through ACTA. Going back to manual won't make sense.
Tell us about your environment and authorization timeline, and we'll put together a quote built around it.