Scanner, remediation engine, and signed evidence producer for CMMC Level 2 — bound cryptographically to your license. Your key is your proof.
From network discovery through signed evidence collection in 7 structured steps. Zero guesswork — the dashboard guides you through discovery, preparation, scanning, review, remediation, and teardown.
Deploy SSH keys or certificates during endpoint preparation. Admin credentials are entered once — all subsequent scanning and remediation uses deployed keys automatically. No passwords on the wire.
Smart ordering, lockout detection, auto-rollback, and safety timeouts. CM.3.067 always runs last. DANGER MODE for high-risk controls with confirmation overlay and rollback capability.
23-document evidence package with SHA-256 hashes and Ed25519 digital signatures. Baseline auto-collected after scan, final package after remediation. Both ZIPs submitted to your C3PAO.
Aligned cybersecurity scanning that produces evidence which holds up under any assessor's scrutiny — without forcing your operations to revolve around the audit.
ForteFide ships its own C3PAO Assessor Guide — a document built for the auditor, not the buyer. The signed evidence package contains everything an assessor needs to verify your CMMC posture offline, with no callback to DenseDefense in the trust path.
11 Linux distributions and 7 Windows distributions tested and supported. No agent install — scanning works against your existing systems as they are.
Target counts adapt to server size, hardware constraints, and regional spread. Scan a single server or a multi-region fleet without re-architecting the tool around the assessment.
Every supported Windows version — including the long-standing Server 2012 R2 holdout — and every Linux family runs scan and remediation under Tier 1 SSH certificate authentication. 30-day per-target certs derived from your license. No persistent admin credential. No long-lived static key.
The scanner NEVER reaches densedefense.com. Not for packages, not for licenses, not for evidence verification. Sneakernet the .deb in, sneakernet the signed ZIP out. Your CUI never leaves your boundary.
Air-gap-constrained environments get the additional tooling they need bundled and ready. Connected environments use the same installer with the air-gap pieces inactive.
Every signed evidence ZIP carries an Ed25519 signature, SHA-256 per-artifact hashes, and a standalone Python verifier script. Your assessor verifies the package offline, on their own machine, with no DenseDefense callback in the trust path.
Every change captures a rollback bundle before it lands. An on-target emergency-revert.sh restores pre-engagement state with no ForteFide, no network, and no hypervisor required. After Teardown, ForteFide leaves no service account, no key, no cert, no scalpel.
Your license.key file IS the cryptographic trust anchor for every signed package ForteFide produces. The same license that proves you're licensed proves the evidence is yours. Lose the license, lose the chain of custody. Keep the key, keep the proof — forever.
For connected environments. Your license key never leaves your machine — the vault stores signed packages, never signing material.
Push completed evidence packages from ForteFide to a per-user vault scoped by license. You retain the license key. The vault holds the artifact, not the proof.
Grant your assessor an engagement-scoped, expiring read link. They download the package, verify locally with your license key, and validate against the same cryptographic chain ForteFide produces in the field.
If your scanner has no internet, the vault is optional. ForteFide produces the same signed package locally for sneakernet handoff to the assessor — chain-of-custody preserved either way.
If you uninstall ForteFide or lose your license file, the vault marks your packages as revoked-proof. The artifacts remain — but DenseDefense no longer warrants their cryptographic verifiability. Customer custody of the key IS the trust anchor.
8,800+ strings encrypted with SHA-256 stream cipher + HMAC integrity. Plaintext exists only in RAM during execution.
Every remediation command encrypted at rest with authenticated encryption.
Offline cryptographic license validation with tamper-proof signatures.
Runtime self-verification of critical files and module structure at startup.