ForteFide

Scanner, remediation engine, and signed evidence producer for CMMC Level 2 — bound cryptographically to your license. Your key is your proof.

Download ForteFide v26.07.10.0709 — Free scanner. 110 NIST 800-171 controls evaluated: 79 assessed automatically, 31 organizational. Auto-remediation with rollback.

7-Step Guided Workflow

From network discovery through signed evidence collection in 7 structured steps. Zero guesswork — the dashboard guides you through discovery, preparation, scanning, review, remediation, and teardown.

Zero-Credential Scanning

Deploy SSH keys or certificates during endpoint preparation. Admin credentials are entered once — all subsequent scanning and remediation uses deployed keys automatically. No passwords on the wire.

Bulletproof Remediation

Smart ordering, lockout detection, auto-rollback, and safety timeouts. CM.3.067 always runs last. DANGER MODE for high-risk controls with confirmation overlay and rollback capability.

Signed Evidence Package

23-document evidence package with SHA-256 hashes and Ed25519 digital signatures. Baseline auto-collected after scan, final package after remediation. Both ZIPs submitted to your C3PAO.

Produce Secure Verifiable Evidence with ForteFide

Aligned cybersecurity scanning that produces evidence which holds up under any assessor's scrutiny — without forcing your operations to revolve around the audit.

Written for C3PAO Assessors

ForteFide ships its own C3PAO Assessor Guide — a document built for the auditor, not the buyer. The signed evidence package contains everything an assessor needs to verify your CMMC posture offline, with no callback to DenseDefense in the trust path.

Wide OS Coverage Out of the Box

11 Linux distributions and 7 Windows distributions tested and supported. No agent install — scanning works against your existing systems as they are.

Right-Sized for Your Environment

Target counts adapt to server size, hardware constraints, and regional spread. Scan a single server or a multi-region fleet without re-architecting the tool around the assessment.

100% Tier 1 Cert Auth — Even Server 2012 R2

Every supported Windows version — including the long-standing Server 2012 R2 holdout — and every Linux family runs scan and remediation under Tier 1 SSH certificate authentication. 30-day per-target certs derived from your license. No persistent admin credential. No long-lived static key.

100% Airgap Operation

The scanner NEVER reaches densedefense.com. Not for packages, not for licenses, not for evidence verification. Sneakernet the .deb in, sneakernet the signed ZIP out. Your CUI never leaves your boundary.

Optional Air-Gap Tooling

Air-gap-constrained environments get the additional tooling they need bundled and ready. Connected environments use the same installer with the air-gap pieces inactive.

Signed Evidence + Standalone Offline Verifier

Every signed evidence ZIP carries an Ed25519 signature, SHA-256 per-artifact hashes, and a standalone Python verifier script. Your assessor verifies the package offline, on their own machine, with no DenseDefense callback in the trust path.

Leave-No-Trace — You Can't Be Left Worse Off

Every change captures a rollback bundle before it lands. An on-target emergency-revert.sh restores pre-engagement state with no ForteFide, no network, and no hypervisor required. After Teardown, ForteFide leaves no service account, no key, no cert, no scalpel.

License = Key = Proof

Your license.key file IS the cryptographic trust anchor for every signed package ForteFide produces. The same license that proves you're licensed proves the evidence is yours. Lose the license, lose the chain of custody. Keep the key, keep the proof — forever.

Optional Cloud Evidence Vault

For connected environments. Your license key never leaves your machine — the vault stores signed packages, never signing material.

For You

Push completed evidence packages from ForteFide to a per-user vault scoped by license. You retain the license key. The vault holds the artifact, not the proof.

For Your C3PAO

Grant your assessor an engagement-scoped, expiring read link. They download the package, verify locally with your license key, and validate against the same cryptographic chain ForteFide produces in the field.

For Airgapped Environments

If your scanner has no internet, the vault is optional. ForteFide produces the same signed package locally for sneakernet handoff to the assessor — chain-of-custody preserved either way.

If You Lose The Key

If you uninstall ForteFide or lose your license file, the vault marks your packages as revoked-proof. The artifacts remain — but DenseDefense no longer warrants their cryptographic verifiability. Customer custody of the key IS the trust anchor.

Scanner Free — scan all 110 controls
Pro Module Licensed — automated remediation
Air-Gap Ready No internet required at any stage

Protection Layers

1
Paisley String Encryption

8,800+ strings encrypted with SHA-256 stream cipher + HMAC integrity. Plaintext exists only in RAM during execution.

2
AES-256-GCM Command Encryption

Every remediation command encrypted at rest with authenticated encryption.

3
Ed25519 License Verification

Offline cryptographic license validation with tamper-proof signatures.

4
SHA-256 Integrity Checks

Runtime self-verification of critical files and module structure at startup.