GS|ATO drafts your System Security Plan, policies and procedures from what you run, gives every statement a second review, and hands each one to a named person to approve. Measured on our own FedRAMP High package (Class D under the Consolidated Rules for 2026). Nothing on this page is typed in by hand.
Start small — $5,000 · a five-day readiness assessment of the SSP you already have.
The product's own scanner parsers, run over your own export. Nothing leaves your machine.
The home page is one lens: sixteen incidents and the control that decided each. The same engine can be pointed at your priorities.
| What | Count | Minutes | Date |
|---|
These times are the slowest we measured, not averages: the clock stops when a scheduled check finds the batch done. That package is our proving ground, not an authorized system. Your reviewers' calendar sets the rest.
Every gap has a name: which control, which evidence item, which approver. Never a percentage without the list behind it.
These are our own package's numbers on the snapshot date.
{n} characters, drafted from the stack profile
Every statement carries its requirement, its draft, its review, its evidence and its approvals as one record. A person approves by retyping twelve characters of the record's code. It is a confirmation, not a signature. Every later change needs a named approver.
Today a re-draft runs when an operator starts it; a scheduled run is the client's choice.
NIST's SP 800-53 Rev 5 catalog comes in as OSCAL (version {catalogIn}, catalog release {catalogRelease}); the FedRAMP baselines come from the OSCAL Foundation's fedramp-resources repository. Your package goes out as OSCAL {out}: {exports}. The package is checked before it leaves, and the full FedRAMP schema check runs in our build pipeline. The same inputs produce the same package.
FedRAMP's machine-readable indicators were loaded from FedRAMP's own repository on {corpusAsOf}: {indicators} indicators in {themes} themes, {indicatorControlLinks} links to controls. Your Rev 5 work is mapped onto the indicators ({controlMappings} mappings today), so the move to 20x starts from what you already approved. On our own package as of {evalAsOf}: {evalCount} of {ofIndicators} indicators evaluated — {manualReview} routed to a person, {notMet} not met, {met} met.
We check that list against FedRAMP's current rules file. On {upstreamRetrievedAt} it listed {upstreamIndicators} indicators in {upstreamThemes} themes. {notInCurrentFile} of the indicators we loaded are no longer in that file.
| Category | What you get |
|---|---|
| Evidence-collection platforms | collect and checklist; you still write |
| Package tools and templates | fill a template; you still review |
| Consultancies and assessors | people, months, a fixed report |
| GS|ATO | drafts, reviews in a second pass, names the gaps, hands each statement to a named approver, keeps the record |
What we publish that we did not find on the platforms we reviewed on 16 September 2026: timings with dates on a full package; a second review pass separate from the drafter; a named approval on every statement; statements, policies, procedures and fix drafts from one engine.
Pick your stack. See what you won't have to write.
Instant, and no AI in it: a deterministic function reads each provider's package and returns every control it speaks to, with the citation and the split. For this stack at {baseline label}: {P+S} of {total}.
One batch. On the package we keep on our own platform at the High baseline, a 203-statement batch came back drafted in 14 minutes. For this stack: {Y} statements to draft.
Bring a scanner export. Every real finding gets a cited draft fix; the ones we can check in isolation are checked before you see them; nothing is applied without your approval, and a finding closes only when a later comparable scan confirms it.
The baselines are FedRAMP Rev 5 as published in OSCAL by the OSCAL Foundation: 156 controls at Low, 323 at Moderate, 410 at High. Control and family names are the official NIST SP 800-53 Rev 5 titles.
The cloud underlay is the shared-responsibility split common to AWS GovCloud, Azure Government and Google Cloud: 31 controls the provider owns outright (physical, environmental, maintenance, media, provider personnel, alternate sites) and 37 it shares with you.
AWS service citations come from AWS's published OSCAL component definitions, joined to the Security Hub → NIST 800-53 mapping AWS publishes with its guard rules. They are shared, never provider-complete.
cloud.gov rows come from cloud.gov's published control policies. Red Hat OpenShift rows come from the ComplianceAsCode OSCAL component definition at the Moderate baseline — which is why OpenShift stops counting at High.
Vendor rows are what each vendor's public FedRAMP package or trust documentation asserts, one citation per control, with its reference link where the vendor's page still answers. At FedRAMP High, a vendor we hold at the Moderate baseline does not count until we map its High package. A vendor we have not mapped yet counts as yours to write until we map it — which happens at onboarding, from the vendor's own package.
A control is provider-covered when at least one of your picks' packages asserts full responsibility for it, shared when they assert a split, and yours when no pick speaks to it.
The same engine runs inside the platform. This page carries a copy of its data as of the snapshot date in the masthead; the platform recomputes on every change.
Nothing here is an audit of your configuration, and nothing here is legal, audit or compliance advice.
The full method, including how each observation above was checked, is on sources.html.