Self-hosted compliance SIEM · CMMC Level 2 · NIST SP 800-171

Practitioner-led security programs, and the software that proves them.

Attestor runs inside your own network, automatically maps your security events to the CMMC / 800-171 controls they satisfy, and generates signed, assessor-ready evidence. Deploy with Docker in minutes.

Self-hosted · Docker · Your enclave, your data

NIST 800-171CMMC L2SOC 2ISO 27001CUI-READY

Built for the Defense Industrial Base and the MSPs who serve it.

Your LogoYour LogoYour LogoYour Logo

The deadline is real

Phase 2 is here. Your evidence has to be too.

As of November 10, 2026, third-party C3PAO assessments become the standard for many CUI contracts. Audit & Accountability is where small contractors most often lose points — because it's the one control family you can't satisfy with a policy document. Assessors want to see the logs and the evidence.

How Attestor works

From raw logs to signed evidence — inside your enclave.

01

Ingest — in your enclave

Point your systems' security logs at Attestor, running self-hosted via Docker. Attestor never sends your data to Phaethon — no telemetry, no analytics, no licence check-in. The only outbound connections it makes are the alert webhooks and SMTP email destinations you configure.

02

Auto-map to controls

Finish the browser setup and Attestor loads the starter NIST 800-171 / CMMC control set. From then on every event that arrives is tagged automatically to the control(s) it provides evidence for (Access Control, Audit & Accountability, Identification & Authentication).

03

Produce signed evidence

Generate cryptographically signed, independently verifiable evidence bundles for a framework and date range — built for a C3PAO to review.

Why self-hosted matters

Keep your CUI where it belongs.

Attestor never sends your data to Phaethon. No telemetry, no analytics, no licence check-in. It runs entirely inside your network and verifies its licence offline.

The only outbound connections Attestor makes are the ones you configure: alert webhooks and SMTP email. If you point an alert channel at an external service, the alert — including its context — goes there. You choose whether to configure them, and where they point.

Who it's for

Two audiences. One evidence pipeline.

Defense contractors

Small-to-midsize DIB companies handling CUI and preparing for a Level 2 assessment. Get assessor-ready evidence without standing up Splunk.

Start free evaluation

MSPs & MSSPs

Build or expand a CMMC managed offering, deploy Attestor per client, and keep each client's data in their own enclave.

Explore partnering

Built like security software should be

Architecture and trust — up front, not in an appendix.

Runs entirely self-hosted via Docker, with a PostgreSQL backend.

Password + mandatory TOTP multi-factor authentication (scrypt password hashing).

PostgreSQL Row-Level Security enforces storage-layer data isolation; data encrypted at rest.

Evidence bundles are cryptographically signed and independently re-verifiable.

Honest scope note: Attestor covers the audit logging, monitoring, and evidence side of CMMC — pair it with your other controls (and your GRC tool, if you use one) for full coverage.

See your own events mapped to CMMC controls in minutes.