Gomes Security · ATO

Your stack in. Your authorization package out.

Computed, not generated · from the platform's own data · snapshot 2026-09-16

What GS|ATO does

GS|ATO drafts your System Security Plan, policies and procedures from what you run, gives every statement a second review, and hands each one to a named person to approve. Measured on our own FedRAMP High package (Class D under the Consolidated Rules for 2026). Nothing on this page is typed in by hand.

Let's Talk →

Start small — $5,000 · a five-day readiness assessment of the SSP you already have.

Try it on your own scan →

The product's own scanner parsers, run over your own export. Nothing leaves your machine.

The home page is one lens: sixteen incidents and the control that decided each. The same engine can be pointed at your priorities.

What you receive, and how fast

What you receive, and how fast

WhatCountMinutesDate

These times are the slowest we measured, not averages: the clock stops when a scheduled check finds the batch done. That package is our proving ground, not an authorized system. Your reviewers' calendar sets the rest.

What is missing, said plainly

What is missing, said plainly

statements awaiting a named approver
evidence requests open
documents awaiting promotion

Every gap has a name: which control, which evidence item, which approver. Never a percentage without the list behind it.

These are our own package's numbers on the snapshot date.

One control, end to end

AC-12 · Session Termination

Requires

We drafted

{n} characters, drafted from the stack profile

The assessor pass checked

    Evidence
      Approved

      Every statement carries its requirement, its draft, its review, its evidence and its approvals as one record. A person approves by retyping twelve characters of the record's code. It is a confirmation, not a signature. Every later change needs a named approver.

      A living document

      A living document

      1. Your stack changes
      2. The affected controls are found from the change, not guessed
      3. Their statements are flagged
      4. A re-draft batch runs
      5. The same assessor pass
      6. A named person approves the change

      Today a re-draft runs when an operator starts it; a scheduled run is the client's choice.

      Machine-readable, in and out

      Machine-readable, in and out

      NIST's SP 800-53 Rev 5 catalog comes in as OSCAL (version {catalogIn}, catalog release {catalogRelease}); the FedRAMP baselines come from the OSCAL Foundation's fedramp-resources repository. Your package goes out as OSCAL {out}: {exports}. The package is checked before it leaves, and the full FedRAMP schema check runs in our build pipeline. The same inputs produce the same package.

      FedRAMP 20x

      FedRAMP's machine-readable indicators were loaded from FedRAMP's own repository on {corpusAsOf}: {indicators} indicators in {themes} themes, {indicatorControlLinks} links to controls. Your Rev 5 work is mapped onto the indicators ({controlMappings} mappings today), so the move to 20x starts from what you already approved. On our own package as of {evalAsOf}: {evalCount} of {ofIndicators} indicators evaluated — {manualReview} routed to a person, {notMet} not met, {met} met.

      We check that list against FedRAMP's current rules file. On {upstreamRetrievedAt} it listed {upstreamIndicators} indicators in {upstreamThemes} themes. {notInCurrentFile} of the indicators we loaded are no longer in that file.

      Why ATO

      Why ATO

      CategoryWhat you get
      Evidence-collection platformscollect and checklist; you still write
      Package tools and templatesfill a template; you still review
      Consultancies and assessorspeople, months, a fixed report
      GS|ATOdrafts, reviews in a second pass, names the gaps, hands each statement to a named approver, keeps the record

      What we publish that we did not find on the platforms we reviewed on 16 September 2026: timings with dates on a full package; a second review pass separate from the drafter; a named approval on every statement; statements, policies, procedures and fix drafts from one engine.

      Your stack

      Your stack

      Pick your stack. See what you won't have to write.

      Instant, and no AI in it: a deterministic function reads each provider's package and returns every control it speaks to, with the citation and the split. For this stack at {baseline label}: {P+S} of {total}.

      One batch. On the package we keep on our own platform at the High baseline, a 203-statement batch came back drafted in 14 minutes. For this stack: {Y} statements to draft.

      How one statement assembles

      The Fix Engine

      The Fix Engine

      Bring a scanner export. Every real finding gets a cited draft fix; the ones we can check in isolation are checked before you see them; nothing is applied without your approval, and a finding closes only when a later comparable scan confirms it.

      Where these numbers come from

      The baselines are FedRAMP Rev 5 as published in OSCAL by the OSCAL Foundation: 156 controls at Low, 323 at Moderate, 410 at High. Control and family names are the official NIST SP 800-53 Rev 5 titles.

      The cloud underlay is the shared-responsibility split common to AWS GovCloud, Azure Government and Google Cloud: 31 controls the provider owns outright (physical, environmental, maintenance, media, provider personnel, alternate sites) and 37 it shares with you.

      AWS service citations come from AWS's published OSCAL component definitions, joined to the Security Hub → NIST 800-53 mapping AWS publishes with its guard rules. They are shared, never provider-complete.

      cloud.gov rows come from cloud.gov's published control policies. Red Hat OpenShift rows come from the ComplianceAsCode OSCAL component definition at the Moderate baseline — which is why OpenShift stops counting at High.

      Vendor rows are what each vendor's public FedRAMP package or trust documentation asserts, one citation per control, with its reference link where the vendor's page still answers. At FedRAMP High, a vendor we hold at the Moderate baseline does not count until we map its High package. A vendor we have not mapped yet counts as yours to write until we map it — which happens at onboarding, from the vendor's own package.

      A control is provider-covered when at least one of your picks' packages asserts full responsibility for it, shared when they assert a split, and yours when no pick speaks to it.

      The same engine runs inside the platform. This page carries a copy of its data as of the snapshot date in the masthead; the platform recomputes on every change.

      Nothing here is an audit of your configuration, and nothing here is legal, audit or compliance advice.

      The full method, including how each observation above was checked, is on sources.html.