Control Evidence Agent · CMMC L2 / NIST 800-171 · runs offline at $0

The whole loop in four beats

A grounded compliance agent that drafts cited 800-171 findings — and knows where not to trust itself. Watch the floor it has to beat, the assessor-ready deliverable it produces, the confident lie it refuses, and the map of where a model can be trusted. Every line is real output, and every runnable beat ran on a laptop with the network off.

01
FLOORGrounding eval · make rag-evalpending
02
DELIVERABLEPOA&M + adversarial panelpending
03
REFUSALGrounding gatepending
04
TRUST-MAPThe whole standardpending
demo-walkthrough.cast REC 00:00
The whole loopOffline · $0 · nothing left the machine

Grounding floor → a cited, assessor-ready POA&M → the tool auditing its own calls → the refusal of a confident false pass → the map of where to trust the model. That map is the deliverable — a single averaged accuracy number ranks the models backwards. And the whole thing runs inside your environment: it never sees your CUI.

Provenance. Beats 1–2 run live from the repo (make rag-eval, make reconcile/poam); Beat 2 replays a recorded Amazon Bedrock run (Opus 4.5 / Haiku 4.5, 2026-07-26) so it is instant and free — real model output, reproduced on local hardware. Beat 3 is an excerpt of the full four-gate recording (four-gate-catch.html). Beat 4 is the whole-standard result from the case study (qwen2.5:14b vs. stub, 14 families). Synthetic app + evidence only — no client data.