Self-hosted compliance SIEM · CMMC Level 2 · NIST SP 800-171
Practitioner-led security programs, and the software that proves them.
Attestor runs inside your own network, automatically maps your security events to the CMMC / 800-171 controls they satisfy, and generates signed, assessor-ready evidence. Deploy with Docker in minutes.
Self-hosted · Docker · Your enclave, your data
Built for the Defense Industrial Base and the MSPs who serve it.
The deadline is real
Phase 2 is here. Your evidence has to be too.
As of November 10, 2026, third-party C3PAO assessments become the standard for many CUI contracts. Audit & Accountability is where small contractors most often lose points — because it's the one control family you can't satisfy with a policy document. Assessors want to see the logs and the evidence.
How Attestor works
From raw logs to signed evidence — inside your enclave.
Ingest — in your enclave
Point your systems' security logs at Attestor, running self-hosted via Docker. Attestor never sends your data to Phaethon — no telemetry, no analytics, no licence check-in. The only outbound connections it makes are the alert webhooks and SMTP email destinations you configure.
Auto-map to controls
Finish the browser setup and Attestor loads the starter NIST 800-171 / CMMC control set. From then on every event that arrives is tagged automatically to the control(s) it provides evidence for (Access Control, Audit & Accountability, Identification & Authentication).
Produce signed evidence
Generate cryptographically signed, independently verifiable evidence bundles for a framework and date range — built for a C3PAO to review.
Why self-hosted matters
Keep your CUI where it belongs.
Attestor never sends your data to Phaethon. No telemetry, no analytics, no licence check-in. It runs entirely inside your network and verifies its licence offline.
The only outbound connections Attestor makes are the ones you configure: alert webhooks and SMTP email. If you point an alert channel at an external service, the alert — including its context — goes there. You choose whether to configure them, and where they point.
Who it's for
Two audiences. One evidence pipeline.
Defense contractors
Small-to-midsize DIB companies handling CUI and preparing for a Level 2 assessment. Get assessor-ready evidence without standing up Splunk.
Start free evaluationMSPs & MSSPs
Build or expand a CMMC managed offering, deploy Attestor per client, and keep each client's data in their own enclave.
Explore partneringBuilt like security software should be
Architecture and trust — up front, not in an appendix.
Runs entirely self-hosted via Docker, with a PostgreSQL backend.
Password + mandatory TOTP multi-factor authentication (scrypt password hashing).
PostgreSQL Row-Level Security enforces storage-layer data isolation; data encrypted at rest.
Evidence bundles are cryptographically signed and independently re-verifiable.
Honest scope note: Attestor covers the audit logging, monitoring, and evidence side of CMMC — pair it with your other controls (and your GRC tool, if you use one) for full coverage.