Skip to main content

Who it's for

Built for every seat that carries the package.

Roles come from your directory, and there is no limit on them. Each seat sees the systems it is cleared for and the work that is its own. Which seat holds which step of the authorization workflow is set for your agency, not fixed by us.

The seats in our demo environment, and yours

These eight are how the demo environment is configured. Your agency defines its own roles from its own directory; the authorization workflow is being built so you can assign your own people to your own steps.

AO

Authorizing Official

Scope

All systems

Ask for the demo in this seat

What this seat gets

  • A short queue of the decisions your agency assigns to this seat, by default authorization, reauthorization and risk acceptance

  • An opening dashboard pinned to the seat, and Ask Alloy for the rest

  • Nothing routine

Three assistants, every seat

An advisor for the control, an answer from the data, a board from a sentence.

AVISSAA tells an ISSO or ISSE what a control requires before they go collect evidence. Ask Alloy and GenAI Dashboards give every seat the picture it needs and the next thing to do.

AVISSAA

Avint ISSO Advisory Assistant

For the ISSO

Ask what a control means at your baseline, what the assessor will expect, and which tasks are mandatory at each RMF step, with the NIST publication cited. Export the session for the package.

At the upload

The same advice sits beside the evidence upload, so what you are about to prove is never a guess. Advisory only: your evidence and system data stay out of it.

Explore AVISSAA

ASK ALLOY

Ask Alloy

For leadership

Which vulnerabilities are affecting my systems? Which of my ISSOs is behind? Real figures from the database, ranked in code, phrased by a local model.

For the ISSO

What do I have to work on today? Who owns this CVE? What should I prioritize? One drawer, on every page.

Explore Ask Alloy

GENAI DASHBOARDS

GenAI Dashboards

For leadership

Type a sentence, get a board of KPI tiles, charts and tables from your data. Pin one as the opening view for a role, share it, save it.

For the ISSO

Ask for exploited findings by system before a stand up, then send a tile's filters straight into the table you will work from.

Explore GenAI Dashboards

Separation of duties

Whoever fixes it does not attest that it is fixed.

The evidence chain is enforced by permissions, not by policy documents. By default an ISSO offers proof, the model analyzes it, an independent assessor validates it, and the Authorizing Official accepts the risk. Each hand-off is a ledger entry. Which seat holds each step is being made configurable, because the same people are not involved at every agency.

01

ISSO uploads

Evidence goes in against the control or the whole control family it is meant to satisfy.

Artifact on record

02

AI analyzes

A local model reads the artifact against the requirement and returns a determination with its reasoning.

Determination

03

SCA validates

An independent assessor ratifies or overrides. The override is recorded. The assessor cannot close the item.

Ratified finding

04

Decision

Authorization, reauthorization and risk acceptance are decided by the seat your agency assigns, by default the Authorizing Official.

Decision on the ledger

What every seat shares

Server enforced scope

You see the systems you are cleared for. The restriction is applied before a page renders, not by the page.

Configurable workflow

The ATO workflow is being built to follow your agency's practice: which seats approve, which phases apply. RMF is flexible in the field, and the platform is meant to follow yours rather than dictate it.

NIST SP 800-53 today

Control content, baselines and assessment guidance from the NIST corpus. Further frameworks as they are added.

Federal and commercial

Built around the RMF, usable by any team that has to prove control of a system to someone else.

A record, if you want one

Consequential actions and approvals are written to an activity ledger that exports to the SIEM you already run.

Ask for the demo in your seat.

Tell us your role and we will run the demo from that seat, on synthetic data, so you see exactly what your day looks like.