Air-gapped • NISPOM-compliant • AI-powered

POAMForge AI

Automate STIG compliance and POAM generation in minutes instead of weeks. Built for defense contractors and government agencies operating on classified and controlled networks where cloud tools are prohibited.

Collapses hours of manual POAM authoring into minutes — generate a full remediation package for a large finding set in a single pass.

Capabilities

End-to-end STIG compliance automation from scan import to eMASS-ready export.

STIG import & parsing

Parse DISA STIG Viewer CKL files automatically. Extract severity, status, fix text, and check content with full severity breakdown dashboards.

AI-powered POAM generation

Generate 8-step remediation plans with 5 calendar-dated milestones, automatic NIST 800-53 control mapping, and domain-aware classification across 10 security domains.

AI recommendations engine

4-tier prioritization strategy with pattern detection, quick-win grouping, executive risk summary, and professional multi-page PDF output.

Compliance-ready exports

  • eMASS-compatible Excel — 16 required columns, ready for direct upload
  • Color-coded Excel reports — CAT I (red), CAT II (orange), CAT III (blue)
  • Professional PDF reports — individual and batch with pagination
  • CSV export — DoD 8140 compliant with all POAM fields

Severity-scaled timelines

  • CAT I (Critical) — 30-day remediation deadline with immediate actions
  • CAT II (Moderate) — 90-day phased remediation with verification
  • CAT III (Low) — 180-day timeline with scheduled maintenance windows
  • Automatic NIST 800-53 Rev 5 mapping — 79 controls across 20 families

Security & architecture

Built from the ground up for classified and controlled environments.

Security posture

  • Desktop application with no network dependency — zero internet, zero cloud APIs, zero telemetry
  • Argon2id password hashing with per-user salt
  • ML-DSA-65 post-quantum digital signatures (FIPS 204) for license integrity
  • NISPOM-aligned, SHA-256 tamper-evident audit chain
  • Data at rest protected by host full-disk encryption (BitLocker/FDE) — STIG-standard on DoD/CUI systems

Enterprise features

  • Multi-user RBAC — Admin, User, and Auditor roles
  • Account lockout after 5 failed attempts (15-minute cooldown)
  • Session management with 15-minute timeout + activity extension
  • Version-tracked POAM edits for full change history
  • Tamper-proof audit chain with integrity verification

Technology stack

  • Rust backend via Tauri 2 — memory-safe, high performance
  • 3 isolated SQLite databases (auth, data, audit)
  • 47 IPC commands for complete backend/frontend communication
  • Optional Ollama integration for local AI-enhanced generation

Dual-mode AI engine

  • Rule-based engine — deterministic, domain-aware, always available
  • AI mode (Ollama) — enhanced natural language remediation plans
  • Compliance chatbot for STIG, NIST, RMF, and NISPOM questions
  • Dashboard indicator shows AI connection status in real time
All data stored locally in %LOCALAPPDATA%\POAMForgeAI\ — nothing leaves the machine.

Use cases

Where automated POAM generation creates immediate operational value.

Defense contractors

Automate POAM generation from quarterly STIG scans across multiple systems. Reduce IA team workload from weeks to minutes while maintaining audit-ready documentation.

Government agencies

Maintain continuous ATO compliance with standardized remediation plans. Export directly to eMASS with all 16 required fields populated and validated.

Classified environments

Operate on air-gapped networks with zero internet dependency. NISPOM-compliant audit trail ensures every action is logged, hashed, and verifiable.

Compliance & framework alignment

POAMForge AI is designed to support programs operating under these frameworks:

DoD & federal compliance

  • NIST SP 800-53 Rev 5 — automatic control mapping (79 controls, 20 families)
  • NIST Risk Management Framework (RMF) — full lifecycle support
  • DISA STIGs — native CKL import and severity classification
  • eMASS — direct export with validated field mapping

Security standards

  • NISPOM — tamper-proof audit trail with hash chain verification
  • DFARS 252.204-7012 — safeguarding covered defense information
  • DoD CMMC — aligned to assessment requirements
  • NIST SP 800-171 — protecting CUI in non-federal systems
POAMForge AI supports compliance workflows — actual compliance depends on your environment, policies, and configuration.

Pricing & licensing

Perpetual licenses with no recurring subscription fees — pricing scales with deployment size. Here's what's included.

What you get

  • Perpetual license — own it outright, no annual renewal
  • Unlimited POAM generation — no per-finding or per-system metering
  • Every export format — eMASS Excel, color-coded reports, batch PDF, DoD 8140 CSV
  • Dual-mode AI + rule-based engine — runs fully offline
  • AI recommendations engine and compliance chatbot included

Licensing & support

  • Scales from single-seat to enterprise and defense-contractor deployments
  • Multi-user RBAC — Admin, User, and Auditor roles
  • Priority and dedicated support tiers available
  • Custom AI model tuning for larger programs
  • 14-day evaluation available before purchase
Ready to deploy POAMForge AI?

14-day free trial available. Email animusai.devops@gmail.com to request pricing, a trial key, or a deployment package.

Contact