Built for FedRAMP 20x

Compliance, compiled from infrastructure.

Rookwright reads your infrastructure the way a compiler reads source code and turns it into certification artifacts. Every claim traces back to the configuration or runtime fact that proves it.

Infrastructure sources feed an evidence graph keyed to NIST SP 800-53 controls, which compiles into a verified FedRAMP 20x certification artifact. Sources Evidence graph Artifact terraform kubernetes ci pipeline identity aws api AC-2 IA-2 CM-2 SC-7 AU-6 gate: pass FedRAMP 20x

The problem

Compliance is written alongside systems, not from them.

A security plan describes the environment as someone understood it on the day they wrote it. By the next deploy, the environment has changed and the document has not.

Engineers lose weeks translating infrastructure into prose. Assessors receive narratives they have to take on faith. And a security regression can ship on a Tuesday and go unnoticed until the next audit.

How it works

Source in. Certification out.

Your infrastructure is the source code. Compliance is the compiled output.

01

Read the source

Rookwright parses your infrastructure as code, cluster configuration, CI pipelines, identity provider, and cloud APIs.

02

Build one graph

Every fact lands in a single intermediate representation keyed to NIST SP 800-53, recording where it came from and whether it was declared in configuration or observed at runtime.

03

Compile to the framework

Framework backends generate certification artifacts from that graph, starting with FedRAMP 20x. New frameworks become new outputs, not new projects.

04

Gate every change

Output is deterministic and byte-for-byte reproducible. Rookwright runs in CI, so a security regression fails the build the same way a broken test does.

For assessors and compliance leads

Built for the people who have to sign off.

Evidence you can re-run

Anyone with access can regenerate an artifact from the same inputs and get identical output. Nothing depends on who wrote it or when.

Provenance on every claim

Every statement in an artifact links back to the file, resource, or API response it came from.

Declared versus observed

Rookwright separates what your configuration says from what your environment actually does, and shows you where the two disagree.

Why Rookwright

The tower, the bird, and the maker.

Rook

In chess, the rook is the tower. It moves in straight lines, holds the edges of the board, and draws its strength from the ground it stands on.

Rook

The rook is also a bird, a member of the crow family and one of the sharpest problem solvers in the animal world. Rooks don't use tools in the wild, yet in laboratory studies they have bent wire into hooks and worked in pairs to solve puzzles.

Wright

A maker, as in shipwright or millwright: someone who builds things that have to hold.

Rookwright builds the tower that compliance stands on. The layers are your infrastructure, stacked from the foundation up and compiled into one structure. At the top, the tower becomes the rook, keeping watch. Its brass eye stands for what matters most in an assessment: what is actually there.

Stop writing compliance. Compile it.

Early access is open to teams preparing for FedRAMP 20x.

Request early access