How it works
How CREED turns a binder into a decision.
Five steps, each with its digest. CREED does not shorten the reading of evidence — it removes the work around it.
Compose the requirement set
Frameworks, profiles, overlays. Versioned, digested, published immutably. The template package exports the set, the vocabulary version, the claim ceiling, the extractor manifest, and the validator digest.
Validate before submission
The offline validator reproduces the server byte for byte. Binders arrive already passing — or arrive with the submitter knowing exactly what is unmet.
Submit
Drag-and-drop or API. The occurrence number is assigned, the manifest written, and the classification checked against the system's authorized level. Over-classified binders are refused; nothing is stored; a spillage record is written.
Evaluate and drift
Witnesses for passes, violations for failures, the waiver overlay kept separate. Drift against the last decision and the prior submission: artifact, claim, extractor, and coverage deltas, plus the untouched list.
Decide and retain
Returned, accepted for review, risk decision recorded — the last by the AO only. Returns render from a fixed template; the AO note is appended verbatim in a delimited block. Prior evaluations stay addressable by digest.
ACTA Cyber
Built to meet ACTA Cyber halfway.
ACTA Cyber captures cloud infrastructure, applications, and logging deterministically. CREED reads what ACTA emits — assessment, POA&M, and results shapes plus the ACTA+ CMMC binder — by JSON shape and manifest, never by file extension.
Per-run serials and namespaces are ignored so identical evidence yields identical claims. CREED is the AO side; ACTA is the submitter side. The validator closes the loop between them.
Built by Beautiful Majestic Dolphin, the company behind ACTA Cyber.
Operated like infrastructure.
One statically linked binary. CAC/PIV identity from the fronting proxy. Roles and delegation from a digested roster. TLS required outside dev mode.
The role matrix is enforced in one place and tested for every endpoint. Stable error codes — unsupported_input, manifest_mismatch, classification_exceeds_system, waiver_unauthorized, replay_mismatch — and no silent partial storage.