Active development, demo available
RAVEN
All-in-one RMF. Air-gapped. DoD-ready.
A full-lifecycle Risk Management Framework and vulnerability management platform for DoD program offices, defense contractors, and federal agencies - consolidated into one air-gapped, on-premises product.
Current release: v0.40.1,
NIST RMF 800-53 rev 5 800-171 CMMC 2.0 FedRAMP CNSSI 1253 DISA STIG/SRG FIPS 140-3 CycloneDX 1.5 SBOM
Capabilities
What RAVEN Delivers
Air-gapped operation
STIG / SCAP scanning
SSP, SAR, POA&M generation
Continuous monitoring
Client Portal
Full technical documentation
Architecture, security design, and the product roadmap for RAVEN are available to vetted partners through the client portal.
Request Portal Access FAQ
RAVEN Questions
What is RAVEN?
RAVEN is a full-lifecycle Risk Management Framework and vulnerability management platform for DoD program offices, defense contractors, and federal agencies. It consolidates scanning, compliance authoring, ATO tracking, continuous monitoring, PKI, and signed air-gapped updates into one on-premises product.
Which frameworks does RAVEN support?
NIST RMF (SP 800-37), NIST SP 800-53 rev 5, NIST SP 800-171, the NIST Cybersecurity Framework, CMMC 2.0, FedRAMP, CNSSI 1253, DISA STIG/SRG, FIPS 140-3 (capable via the OpenSSL FIPS provider), and CycloneDX 1.5 SBOM.
Does RAVEN work on an air-gapped network?
Yes. Air-gap operation was part of RAVEN’s design from day one. Updates and threat feeds are delivered as signed offline packages, verified on import and applied without any internet connectivity.
How are licenses activated?
Upload the signed license file through the setup wizard or the Settings page. The license is verified locally - no internet connection or license server is required.
What happens during the evaluation period?
New installations start with a 14-day evaluation that includes core scanning and compliance monitoring with capacity limits (up to 25 targets, 5 agents, 3 users, 1 concurrent scan). Scheduled scans, eMASS export, SBOM generation, and SSP/SAR artifact generation are disabled during evaluation. After 14 days, RAVEN enters a locked read-only state until a license is applied - no data is lost.
How do I request a demo or pilot?
Use the Request a Demo button above or email info@glacierbytetechnology.com. Our team typically responds within one business day and can arrange a pilot on your network.
Deploy RAVEN
RAVEN is in production use today. Contact us to discuss a pilot on your network, or sign up for release updates.
Stay Informed
CMMC and RMF updates, plus the occasional field note from live assessments. No spam.
Release updates only. No spam, ever.