Products Authorization and vulnerability management

Cordevan

A fully air-gapped RMF solution.

Cordevan connects scanning, control documentation, findings, and continuous-monitoring records in one fully air-gapped RMF system.

Request a product discussion

Demo available v0.48.0

Why it exists

Keep the authorization record beside the system it describes.

Authorization work often fragments across scanners, spreadsheets, document folders, and manually transferred evidence. Cordevan keeps that work inside one air-gapped operating environment so engineers, security staff, and program leadership can work from the same record.

Product scope

The work Cordevan brings together.

Scan and evaluate the environment

Run STIG and SCAP-oriented checks, retain results, and connect technical findings to the authorization work they affect.

Maintain authorization documents

Support SSP, SAR, and POA&M work without separating the narrative from the evidence and findings behind it.

Track findings through closure

Keep ownership, remediation activity, validation results, and the supporting record together as work moves across teams.

Carry the record into monitoring

Use the same system for recurring checks and evidence updates after the immediate authorization milestone has passed.

Deployment model

RMF operation without an internet dependency.

Cordevan runs on premises inside the protected environment. Updates, vulnerability data, findings, evidence, and authorization records remain within the controlled boundary.

  • Signed offline product and vulnerability-data packages
  • On-premises storage for findings and authorization records
  • Local administration with no hosted control plane
  • Evidence and system data remain inside the boundary
Framework coverage

The records Cordevan is built to support.

  • NIST RMF
  • NIST SP 800-53 Rev. 5
  • NIST SP 800-171
  • CMMC
  • FedRAMP
  • CNSSI 1253
  • DISA STIGs and SRGs
  • CycloneDX 1.5 SBOM
Technical review

Architecture belongs in the technical conversation.

Detailed security design, deployment prerequisites, and product architecture are shared during a vetted technical review. That keeps the public page useful without publishing the protected detail a deployment team actually needs.

Request a technical review
Product questions

Before an evaluation.

What does Cordevan handle?

Cordevan is a fully air-gapped RMF and vulnerability management system. It brings scanning, control documentation, authorization tracking, continuous monitoring records, PKI, and offline update handling into one on-premises product.

Can Cordevan operate without an internet connection?

Yes. Product updates and vulnerability data can be delivered as signed offline packages, verified during import, and applied without an outbound internet connection.

Which frameworks does Cordevan support?

The current framework set includes NIST RMF, NIST SP 800-53 Rev. 5, NIST SP 800-171, CMMC, FedRAMP, CNSSI 1253, DISA STIGs and SRGs, and CycloneDX 1.5 SBOM records.

What is included in an evaluation?

The evaluation is intended to test core scanning and compliance-monitoring work on a bounded set of targets. We confirm the current limits and the features included before the evaluation begins.

Product discussion

Put Cordevan against a real system boundary.

Bring the enclave constraints, current toolchain, and authorization work. We can walk through the available release and decide whether a demonstration or bounded evaluation is useful.

Start a product conversation