C1BERTITANS//THE FRINGE//UNCLASSIFIEDMETHODOLOGY OVER MYSTIQUE

Home · Trust

Mapped to published guidance · not an ATO

Mapped to published NIST, not a seal

GRC can map us. No agency verified us. No ATO is claimed here.

What maps

  • NIST CSF — Identify / Protect / Detect / Respond / Recover as the operator loop language.
  • NIST SP 800-53 — control-family vocabulary so your GRC sheet does not invent a taxonomy.
  • NIST SP 800-207 — Ikaros is the policy engine (PE); AEGIS is the policy administrator (PA); Edge PEPs sit on the data plane. Dual-plane admission is two PEP classes, not a Wi‑Fi SKU.
  • CISA CPG + NSA CSI — continuous verification, least privilege, residual risk from published text.

What you can inspect

  • Public Docs allowlist vs operator library (LAN only).
  • CEP-Rank kind card: rules + scored join; LLM narrates, does not rank.
  • AEGIS: guide on this origin; kernel is HUMAN_ONLY inside Ikaros.
  • Decision journal shape — not a live API on this origin.
  • ENGINE PATH on Architecture: five stages, one diagram, Play. This origin is not a PEP.

What this is not

  • Not FedRAMP, CMMC, SOC 2, or an ATO package.
  • Not NSA, CISA, FBI, CIA, DHS endorsement, use, or accreditation.
  • Not this origin actuating PEPs. Not measured MTTD. Not a certification wall.
  • Not edge WAF (Cloudflare/Akamai) — app-layer headers on shared hosting only.

How to use it

  • Counsel: map families, then NDA for the enclave.
  • Operator: Briefing tape, then Architecture, then Ikaros, then Mandate stages.
  • Disclosure: security.txt + briefing form.

Security disclosure

If you believe you have found a vulnerability in a C1BERTITANS public property, contact us via the briefing form with a responsible disclosure summary. See also security.txt.

What this page is not

This is not a FedRAMP authorization package and not a substitute for your own risk assessment. Enterprise deployments are scoped under NDA and architecture review.