Platform Proof

Proof, with names on it.

A real engagement with a defense contractor. A platform we run our own company on, live, today. Real product screenshots. No invented quotes, no invented metrics — if we can't show it or stand behind it, it isn't on this page.

Lighthouse Engagement

Our first defense-contractor implementation

The facts of the engagement — nothing dressed up.

  • A defense contractor engaged Cabrillo Club for an implementation running January through December 2026.
  • Scope: ProposalOS and our AI products, implemented under CMMC 2.0 / NIST 800-171 controls.
  • Delivered on infrastructure their data never leaves.

We're not naming the customer or publishing outcome metrics for this engagement until we have their permission to do so. When we do, it'll show up here as a named quote, backed by structured data — see the testimonials section below.

Running Live

We run our own company on this platform.

Cabrillo Club uses Signals to find opportunities, ProposalOS to capture and write them, and Temporal-orchestrated workflows with CMMC-aligned compliance tracking to deliver the work. It isn't a demo environment — it's the same production stack we implement for customers. The current, real numbers (never invented — refreshed periodically against our own systems) are on the homepage and the platform page, not duplicated here.

Certifications & Compliance Roadmap

The same standard we hold customers to: say where you actually are, including the unfinished parts. Nothing below is a certification we hold.

FedRAMP High infrastructure

FedRAMP

Cabrillo software: not authorized

We deploy inside your boundary on AWS GovCloud (US), which is FedRAMP High authorized — deployments inherit its controls, which is not the same as authorizing our software. We hold no FedRAMP authorization of our own; for an in-boundary deployment your CUI does not rest on one.

In preparation

SOC 2 Type 1

Not yet certified

Internal readiness assessment across all five trust service criteria completed May 2026; we are working the gaps it identified. Not SOC 2 certified, and we will say so until a report exists.

Running our own 800-171 program

CMMC Level 2

Not CMMC-certified

The same program we build for clients: documented SSP, all 110 NIST SP 800-171 Rev 2 controls enumerated with the 87 applicable to our enclave tracked continuously, POA&Ms where remediation is outstanding, self-assessment in progress. Not CMMC-certified — and not a C3PAO, deliberately, so we can prepare a contractor without ever competing for their assessment.

Built for organizations that can't afford to get security wrong

FedRAMP-aligned architecture
NIST 800-171 aligned
Air-gap capable deployment
Complete audit logging
No third-party data dependencies
CMMC-aligned platform

Architecture aligned with compliance frameworks. Certification status varies by deployment.

Compliance Framework Alignment

Platform architecture designed to address the frameworks that matter most to defense contractors.

NIST SP 800-171 Rev 2
CMMC 2.0 Level 2
FedRAMP Moderate
NIST 800-207 Zero Trust
DFARS 252.204-7012

Architecture aligned with listed frameworks. See compliance roadmap for certification status.

Ready to see for yourself?

25-minute assessment. You leave with a custom implementation plan.

Or schedule an assessment

Built for defense contractors. Cleared workforce. Your CUI never leaves your environment. CMMC 2.0 ready.