ZTI Solutions ZTI SOLUTIONS
Building & Securing IT Visions
ZTI CirraCore — Compliance-by-Construction Infrastructure-as-Code
HomeProducts › CirraCore 2.0
CDAO Tradewinds — Awardable
Compliance-by-Construction Infrastructure-as-Code

ZTI CirraCore

Generates cloud infrastructure-as-code, pre-checked against DoW security standards before it ships.

ZTI CirraCore generates DoW IL5-compliant AWS Terraform with the audit evidence chain baked into a signed deployment bundle.

A 916-rule pre-pass — spanning NIST 800-53, the DISA Cloud SRG, FedRAMP, and FIPS 140-2 — mutates the configuration to satisfy every rule before a single line of HCL is emitted. A plan-based scanner then validates the actual Terraform plan JSON, catching semantic AWS-API errors that static HCL parsers sign off on.

Conventional tooling scans infrastructure code after it is written and hands you a findings report. CirraCore inverts the order: compliance is a property of the artifact at the moment of its construction, and the evidence travels with it.

916
rules in the pre-pass library
39
IL5-hardened AWS services
6mo → days
IL5 ATO cycle time
30+
live AWS cycles
What makes it different

Where it leaves the alternatives behind.

1

Upstream compliance

Policy-as-code tools scan after the code is written. CirraCore mutates the configuration to satisfy 916 rules before HCL emission — and then re-scans to prove it.

2

Signed deployment bundle

One signed artifact carries the inputs, the Terraform, the plan, the scan output, a frozen rule snapshot, and full provenance — air-gappable and re-evaluatable on the classified side.

3

Two modes on one core

An unclassified studio with a conversational agent (14 typed tools, SSE streaming) for design. A classified deploy mode with zero LLM, zero internet, and baked rules. The same bundle format across both.

How it works

From prompt to signed bundle.

No commercial equivalent.

01

Compliance pre-pass

916 rules across NIST 800-53, the DISA Cloud SRG, FedRAMP, and FIPS 140-2 mutate the configuration to satisfy every rule before HCL is emitted.

02

IL5 generator

39 IL5-hardened AWS services emitted as compliant Terraform — VPC, S3, RDS, EKS, KMS, IAM, GuardDuty, WAF, and more.

03

Plan-based scanner

Validates the actual Terraform plan JSON, catching semantic AWS-API errors that static HCL parsers sign off on.

04

Signed deployment bundle

Inputs, Terraform, plan, scan output, a frozen rule snapshot, and full provenance in one signed artifact — air-gappable and re-evaluatable on the classified side.

Standards & posture

Aligned to the frameworks you're accredited against.

  • NIST 800-53
  • DISA Cloud SRG (IL5)
  • FedRAMP
  • FIPS 140-2

Available now to government customers

ZTI CirraCore has been assessed awardable through the CDAO Tradewinds Solutions Marketplace as an awardable solution. Government users with a Tradewinds account can view the solution pitch and initiate a procurement conversation directly.

Search “CirraCore 2.0” in the Tradewinds Solutions Marketplace
Resources

Go deeper on CirraCore 2.0.

More detail is on the way. Reach out for a briefing, or check back as we publish documentation for ZTI CirraCore.

Datasheet
Coming soon

One-page capability and specification overview.

Deployment guide
Coming soon

Reference architecture and install notes for networked and air-gapped modes.

Live demo
By request

Walk through CirraCore 2.0 with the team that built it.

Talk to the team that built CirraCore 2.0.

Jared Johnson leads product and business development for ZTI Solutions.