Project Hawk · Compliance, Automated
Compliance that watches itself.
Se ipsum custodit: it guards itself.
Project Hawk turns the slow, manual work of staying compliant into something continuous. It maps your obligations, tracks the evidence, and flags drift before an assessor would. It does all of this without ever touching your controlled content.
That last part is the point. Project Hawk works from pointers and references, never the protected bytes themselves. Your sensitive material stays where it lives. The result is a smaller compliance footprint by design, which means less of your environment falls inside the assessment boundary in the first place.
- Maps obligations to controls and keeps the mapping current.
- Tracks evidence continuously and flags drift before an assessor would.
- Works from pointers and references, never your controlled content.
- Engineered to stay outside your CUI boundary.
Map
It maps your obligations to the controls that satisfy them, and keeps the mapping current as scope changes.
Watch
It tracks the evidence continuously and flags drift early, the way a standing watch catches a problem before it becomes one.
Stay clear
It works from pointers and references, so your controlled content never enters the tool and never leaves your boundary.
Built for CMMC Level 2 · NIST SP 800-171 · NIST SP 800-53 programs.
Project Hawk, answered.
What is Project Hawk?
Continuous compliance automation for defense contractors. It maps your obligations to the controls that satisfy them, tracks the supporting evidence continuously, and flags drift before an assessor would. Built for CMMC Level 2, NIST SP 800-171, and NIST SP 800-53 programs, and engineered to operate entirely outside your CUI boundary.
How does it stay outside the CUI boundary?
It works from pointers and references rather than the protected bytes themselves. It records that a given piece of evidence exists, where it lives, and whether it is current, without ingesting, copying, or transmitting the controlled content. Your sensitive material never enters the tool, which means less of your environment falls inside the assessment boundary in the first place.
Which frameworks does it support?
CMMC Level 2, NIST SP 800-171, and NIST SP 800-53. Project Hawk maps obligations across those frameworks to a single control set, so evidence gathered once satisfies the overlapping requirements rather than being collected separately for each assessment.
What is compliance drift, and why does it matter?
Drift is the gap that opens between the posture you documented and the posture you actually run, as systems change, people leave, and evidence goes stale between assessments. It matters because assessments are point-in-time while environments are not: most findings are not new failures but old controls that quietly stopped being true. Continuous tracking catches drift while it is still cheap to fix.
How does this relate to the Praesidium Suite?
Project Hawk is an affiliated venture rather than a Praesidium Suite product. It demonstrates the same architecture at a different deployment profile: Project Hawk is the CUI-safe on-customer-infrastructure profile, RFI Hawk is the hosted profile, and Legatus is the fully air-gapped profile. One architecture, three deployment profiles.
Built for CMMC and NIST-aligned programs. · Salian Defense · SDVOSB · Capabilities ›