Scan and evaluate the environment
Run STIG and SCAP-oriented checks, retain results, and connect technical findings to the authorization work they affect.
A fully air-gapped RMF solution.
Cordevan connects scanning, control documentation, findings, and continuous-monitoring records in one fully air-gapped RMF system.
Request a product discussionDemo available v0.48.0
Authorization work often fragments across scanners, spreadsheets, document folders, and manually transferred evidence. Cordevan keeps that work inside one air-gapped operating environment so engineers, security staff, and program leadership can work from the same record.
Run STIG and SCAP-oriented checks, retain results, and connect technical findings to the authorization work they affect.
Support SSP, SAR, and POA&M work without separating the narrative from the evidence and findings behind it.
Keep ownership, remediation activity, validation results, and the supporting record together as work moves across teams.
Use the same system for recurring checks and evidence updates after the immediate authorization milestone has passed.
Cordevan runs on premises inside the protected environment. Updates, vulnerability data, findings, evidence, and authorization records remain within the controlled boundary.
Detailed security design, deployment prerequisites, and product architecture are shared during a vetted technical review. That keeps the public page useful without publishing the protected detail a deployment team actually needs.
Request a technical reviewCordevan is a fully air-gapped RMF and vulnerability management system. It brings scanning, control documentation, authorization tracking, continuous monitoring records, PKI, and offline update handling into one on-premises product.
Yes. Product updates and vulnerability data can be delivered as signed offline packages, verified during import, and applied without an outbound internet connection.
The current framework set includes NIST RMF, NIST SP 800-53 Rev. 5, NIST SP 800-171, CMMC, FedRAMP, CNSSI 1253, DISA STIGs and SRGs, and CycloneDX 1.5 SBOM records.
The evaluation is intended to test core scanning and compliance-monitoring work on a bounded set of targets. We confirm the current limits and the features included before the evaluation begins.
Bring the enclave constraints, current toolchain, and authorization work. We can walk through the available release and decide whether a demonstration or bounded evaluation is useful.
Start a product conversation