StillTrue

Continuous verification for FedRAMP 20x.

FedRAMP 20x swaps the yearly paper audit for ~45 Key Security Indicators, checked continuously and filed machine-readable, with an Ongoing Certification Report due every three months. New Rev5 certifications stop on June 11, 2027.

Right now KSI evidence gets produced the way it always has: someone runs the collection scripts, the JSON gets uploaded, the report goes out. Between those runs, nothing is watching. So when an assessor asks whether a control actually held last Tuesday at 3am, the honest answer is a snapshot from whenever the scripts last ran.

What it does

StillTrue is software you deploy inside your own boundary. It checks the controls continuously against your live system and hands you the evidence. We never access your environment and never hold your credentials: you run it, it reports to you, and nothing external reaches in. The evidence says a control held when it was tested, not that some other tool reported it did.

Your quarterly report ends up assembled from proof that already exists rather than scraped together the week it is due. And every check writes a signed, tamper-evident transcript your assessor can re-run and reproduce, so nobody is taking your word or ours for it.


Where this stands

There is no shipped product yet, and we are not pretending otherwise. We are taking on two or three design partners, CSPs on the 20x path plus an assessor or two, to shape the first version around one KSI family end to end. Partners get real say in what gets built and pricing locked for three years. You owe nothing unless the pilot delivers.

If your 20x evidence should be more than a snapshot:

founder@stilltrue.io. Thirty minutes, and we will show the difference between formatting evidence and proving it.