Find what is wrong,
and prove how you run it.
The AI cybersecurity and GRC platform — and the interesting part is where the AI works: prose only. Connect a cloud account or a GitHub organization once and a scanner runs every night, reporting what is actually wrong. Answer a plain-English questionnaire and get a score computed by rules alone, then the evidence documents where the AI drafts the prose and a named person approves every page of it. A finding and an answer are the same record, in one ledger, because an unchecked questionnaire is a set of claims left untested.
Demonstrable end to end, deployed into your environment, so a demonstration is the way in.
Intake to a signed export, on one record.
MiraShield is an AI cybersecurity and GRC platform, and the interesting part is where the AI works: prose only. Rules compute the score, rules decide whether a requirement is met, and a document is reached through one function that requires a named reviewer. The AI drafts prose and answers questions about a corpus. Everything a buyer would be uncomfortable handing a model is arithmetic held in a table.
It does two things, and the point is that it does both. It SCANS: connect a cloud account or a GitHub organization once, and every night a scanner runs and reports what is actually wrong — a bucket open to the internet, an organization missing two-factor, a branch anyone can force-push. The scanner runs itself. It PROVES: answer a guided questionnaire, get a score computed by rules alone, and generate the evidence documents from the answers you gave.
The two are one record, and that is the part worth having. A finding maps to the requirements it bears on; an answer is evidence for a control; both land in the same hash-chained ledger. A scanner that only reported what a framework asks about would throw away most of what it saw, and a questionnaire left unchecked is a set of claims untested.
It is built for more than one industry. A clinic under HIPAA, a SaaS company being asked for ISO/IEC 27001:2022 by an enterprise customer, and a defense supplier under CMMC are the same problem wearing three different framework names. It is built for whoever is actually doing the work: the owner of a small business who arrived here by obligation, and the consultant they hired.
The division of labor is unchanged and still the point. Scoring is deterministic and rules alone decide. The AI writes prose and only prose, and reaches a document through one function that requires the reviewer role. The scanning roles are read-only and reach configuration alone: it reads configuration and holds compliance metadata, and the regulated data itself stays out of reach. That boundary is what keeps its own authorization scope small.
-
Assessment
Sixty-five plain-English questions for 800-171, saved and resumed, fewer once the scope gates rule some out, and more where a framework asks something beyond the crosswalk’s reach. Knowing what 3.13.11 means is optional: they are asked whether their encryption is FIPS-validated, which the person who set up the laptops can answer.
-
Scoring
Statuses computed from the organization’s own answers by rules held in a table, across all eighteen frameworks. Deterministic, and rules alone decide.
-
Documents
SSP and POA&M assembled complete. The generation tool schema requires a citations array, so an uncited claim is an invalid call rather than a style problem, and every citation is validated against the material the model was given.
-
Review
Drafts land in a proposals table and reach a document through exactly one function, which requires the reviewer role. The hash-chained ledger separates what the model drafted from what the human decided, and verifies on screen.
It scans, as well as asks.
Connect a cloud account or a GitHub organization once — a read-only role you grant, or an app you install — and every night a scanner runs and reports what is actually wrong. The scanner runs itself, and the only credential of yours involved is a role you can revoke.
-
We run the scanner
Connecting used to mean naming your account and running the scanner yourself. Storing the credential and doing the work is the product. One install, then a container runs here every night.
Install once -
Configuration only
The roles are read-only and grant access to configuration alone. A bucket open to the internet is a finding; what is in the bucket stays out of this system’s view.
Read-only -
Findings outlive frameworks
A finding is recorded as a problem on a resource, true regardless of what any standard says about it. A scanner that only reported what a framework asks about would throw away most of what it saw.
Resource-first -
One record with the answers
A finding maps to the requirements it bears on, and an answer is evidence for a control. Both land in the same hash-chained ledger, so the questionnaire is checked rather than merely asserted.
Scan meets assessment
Connects to
A role you grant and can revoke, scanned across all regions
Somebody installs the app on the organization once, and the install stands in for a token
Consent to an application — the closest thing to the GitHub App any cloud offers
Two steps, because the directory and a subscription are two systems
A service account you grant, impersonated for the run
All five have been scanned against real accounts. The Microsoft 365 run is what found a scope bug in our own ingest — the provider reports a tenant by its default domain rather than its id — which is the argument for connecting a real account before claiming one works.
Two numbers, and a list in the order you should work it.
The page above is the process; this is the output. A score a contracting officer can look up, a readiness figure for the revision coming, and a gap list whose first line is the right first thing.
The SPRS score, on Rev 2
110 minus the DoD Assessment Methodology weight of every unmet requirement, on a scale from −203 to 110. Rev 2 is the baseline because DFARS and CMMC are keyed to it. An unanswered requirement counts against the score: to an assessor unknown counts as unimplemented.
Rev 3 readiness, alongside it
Met over total, where partial counts as unmet, exactly how an assessor scores it. One questionnaire feeds both: a question maps to control rows in each catalog, and scoring runs twice over the same answers.
A gap list you can work top-down
Open findings ordered by risk descending, then effort ascending, then SPRS weight. Fix what is dangerous; among equally dangerous things, fix what is cheap. Each line names the requirement, the status, the points at stake and an effort rating.
A POA&M whose dates are reproducible
Scheduled completion derives from the effort rating rather than case-by-case estimation, 30 days for effort 1–2, 90 for 3, 180 for 4–5. Any date recomputes from the rating printed beside it, a check only a derived date allows.
When a number is unavailable, it says so
An SPRS score needs a DoD Assessment Methodology weight on every scored requirement, and it needs Rev 2 in the assessment’s scope. When either is missing the API returns available: false and the reason, in place of an approximation that would look like a score and get used like one. Rev 3 readiness still reports. Guessing a number a contracting officer will look up is worse than declining to: the platform’s abstention rule, applied to arithmetic.
Eighteen frameworks, one questionnaire.
The answers are given once. Each framework is scored from the same set, either directly or across the crosswalk between them, so covering a second standard is a setting rather than a second project.
Twenty rows, eighteen frameworks: CMMC appears three times because its levels carry different control counts, and it is one standard assessed at three depths.
NIST
Directly, by the questionnaire
18 directly, the rest across the Rev 2 crosswalk
Directly, gated behind the Rev 2 question each one hardens
132 directly, 155 inherited along the 800-171 crosswalk
19 across the crosswalk, 87 by 41 questions of its own
Defense and export
FAR 52.204-21, answered by the Rev 2 questions it draws from
It is Rev 2 under other ids, so the Rev 2 answers cover it
24 by questions of its own, plus the 110 Level 2 requires
All of it by 25 questions of its own; the rows are sections of law
Government cloud and data
287 exactly as 800-53 is, 36 by 29 questions of its own
All of it exactly as 800-53 is, so the 800-53 answers cover it
291 exactly as 800-53 is, 4 by 4 questions of its own
326 exactly as 800-53 is, 49 by 20 questions of its own
Industry and international
26 across the crosswalk, the rest by 17 of its own and three from 800-53
155 by questions already asked, 121 by 50 questions of its own
34 by questions already asked, 27 by 20 questions of its own
90 by questions already asked, 30 by 17 of its own, 3 by the risk register
All of it by 75 questions of its own, all written for it
Privacy
5 by questions already asked, 2 by its own
10 by questions already asked, 5 by its own
Two of them produce documents of their own alongside the package the others produce: ISO adds the Statement of Applicability and the Risk Treatment Plan, and CSF 2.0 adds the Organizational Profile, current and target. Every crosswalk edge records where it came from. The NIST ones are read out of the catalogs themselves; the HIPAA, CSF and ISO mappings are written out in the repo, and ingest fails if any of them names a control absent from the catalog. Every inferred edge says so and carries a confidence below 1.0.
The AI writes prose, and only prose.
The model writes prose. Rules and reference data decide all of this:
Remove the model and every one of these still produces; each section would read “assessed, description pending”.
-
The catalog is authoritative
Control text is loaded from NIST’s own OSCAL files as immutable reference data. The catalog answers what a control requires: the model is handed the text.
Reference data -
The score is arithmetic
Computed from the answers by rule. Explainable by pointing at them, and identical on a re-run.
Deterministic -
The draft is a proposal
Narrative is drafted only where a requirement asserts something, grouped so one claim is one decision, and queued in the order most likely to need attention.
Propose -
A person decides
Approve, edit, or reject, edits recorded distinctly from approvals. Every code path from the model to a document passes through a reviewer.
Approve → export
What a reviewer gets
Inside your boundary, scoped to metadata.
Compliance metadata only. Every record it stores or processes is metadata, which is what keeps its own authorization scope small.
Scoped to the compliance layer alone.
The approval contract and the audit ledger MiraShield runs on are the same ones running in production commercially today.