# TestifySec > TestifySec documents technical compliance and validates it on every commit. The TestifySec Platform turns every CI/CD build into cryptographic, audit-ready evidence — automatically mapped to NIST 800-53, FedRAMP, SOC 2, DoD Impact Levels, and other frameworks. Built on the in-toto framework. Frederick Kautz (co-founder) is a co-author of NIST SP 800-204D; both founders contributed to the CNCF Software Supply Chain Best Practices whitepaper. The product is the **TestifySec Platform** (sometimes called "Judge" internally). It is delivered three ways: - **Security Essentials** — self-service SaaS at $65 per user per month, billed annually. Includes a 14-day free trial. A "user" is a committer in the last 90 days (soft limit) plus any added seats. Auditor seats are free. Setting up the trial requires logging in via GitHub and a GitHub organization admin installing the TestifySec GitHub App. - **TestifySec Platform** — hosted SaaS for teams that need full compliance automation at scale. Talk to sales for volume pricing. - **Enterprise (self-hosted)** — runs in your VPC or air-gapped on-prem. Supports BYO LLM provider (AWS Bedrock, Azure OpenAI, GCP Vertex AI, or your own API keys), BYO KMS, BYO storage (S3 / MinIO, Postgres), Helm chart, and EKS reference architecture. ## Core platform primitives - **Products** — every repo or system you ship is a Product the platform tracks over time. - **Frameworks** — attach any framework to a Product; controls are mapped automatically. - **Security Plans** — AI-generated SSPs stay in sync with what your pipelines actually do. - **Reports** — custom auditor-ready packages, versioned, with cryptographic provenance. ## Frameworks (with annual fees, charged per organization) - **NIST 800-53** — Included in every plan. The spine: every other framework maps back to it. Security Essentials includes 5 NIST 800-53 controls free; the full baseline ships with the Platform. - **SOC 2 Type II** — $2,500 / year. - **FedRAMP Low** — $5,000 / year. - **FedRAMP Moderate** — $10,000 / year. - **FedRAMP High** — $15,000 / year. - **DoD Impact Levels (IL2–IL6)** — Starting at $15,000 / year. TestifySec provides cleared support up to IL6. - **FedRAMP 20x** — Coming June 2026. Accelerated authorization pathway. - **CMMC 2.0** — Private Beta. - **ISO 27001** — Coming soon. - **EU Cyber Resilience Act (CRA)** — Coming soon. - **Custom frameworks** — Enterprise. Built to your internal control catalog. ## What the platform observes TestifySec maps four classes of evidence to controls: **pipeline evidence, production scans, IaC, and application code**. It wraps any tool that has a CLI, a webhook, or writes a file. Common ingest: - CI/CD pipelines: GitHub Actions, GitLab CI, Jenkins, Buildkite - Production / runtime scans: Snyk, Semgrep, Trivy, cloud configuration scans - Infrastructure-as-Code: Terraform, CloudFormation, Helm, Kubernetes manifests - Application source code (verified git provenance) - Policy documents (Markdown / PDF, indexed and mapped to controls) - Any custom CLI tool, webhook, or file output ## Where signed evidence exports to - GRC platforms: Vanta, Drata, Secureframe - OSCAL export for assessors - Auditor PDF packages - POA&M JSON for remediation feeds ## Standards authored / contributed-to - **NIST SP 800-204D** — Strategies for the Integration of Software Supply Chain Security in DevSecOps CI/CD Pipelines. **Frederick Kautz** (TestifySec co-founder) is a co-author. - **CNCF Software Supply Chain Best Practices Whitepaper** — Both TestifySec founders (Cole Kennedy and Frederick Kautz) contributed. - **in-toto framework** — TestifySec maintains Witness and Archivista, the production tooling adopted by Autodesk and others for FedRAMP-ready attestation. ## AI assistant The TestifySec Platform includes an AI assistant with read-only access to your evidence base. It answers compliance questions in plain English, drafts POA&Ms, and generates diagrams of control coverage. Token quota is included with every seat; overage is pay-as-you-go or prepay packs. ## Customer story - **Autodesk** — integrated Witness and Archivista into production CI/CD pipelines to achieve FedRAMP-ready evidence on every commit. See https://www.testifysec.com/case-studies/autodesk. ## Key URLs - Product tour: https://www.testifysec.com/product - Pricing (with framework fee table): https://www.testifysec.com/pricing - Compliance frameworks: https://www.testifysec.com/compliance-frameworks - Autodesk case study: https://www.testifysec.com/case-studies/autodesk - Partners: https://www.testifysec.com/partners - Blog: https://www.testifysec.com/blog - Contact / book onboarding: https://www.testifysec.com/contact ## How to evaluate or buy - **Self-service trial**: book an onboarding call from the pricing page. Trial requires GitHub login and a GitHub admin to install the TestifySec App. - **Enterprise / classified / sovereign environments**: contact sales for a custom quote. - **Coming-soon frameworks**: the pricing page has an "Add to wait list" action that opens the contact form pre-filled.