Every product in one place -- what it does, whether it ships today, what it costs, and how a customer gets it. One evidence chain, from assess to attest.
.exe and Linux .deb installers -- free to scan.DenseDefense is a compliance-readiness suite for DoD contractors that handle CUI. It carries a job through one evidence chain: assess a CMMC Level 2 / NIST 800-171 posture, prove it with signed, tamper-evident evidence a C3PAO accepts, contain the exposure a passing scan does not catch, and attest that the evidence is unaltered.
ForteFide is the flagship and the only product shipping today -- free to scan, with a per-target license that unlocks remediation and signed evidence. The rest of the suite is in active development (Early Adopter) or on the waitlist; each is described below by purpose, and this reference marks which capabilities are shipped versus intended.
Status mirrors the site: GA ships now; Early Adopter is in active development / early access; Waitlist has not started; ForteBase is the bundle.
| Product | What it does | Status | Offer & pricing | Delivery |
|---|---|---|---|---|
| ForteFide | Evaluates all 110 CMMC L2 / NIST 800-171 controls (78 auto-checked, 32 by attestation), auto-remediates the technical gaps it can safely reverse, and produces signed C3PAO evidence. | GA | Free scanner; per-target license unlocks remediation + signed evidence. <=5 $89, 6-25 $65, 26-100 $46, 101-200 $34 per target/mo. Annual = 10x monthly. 200+ custom. | Local Windows .exe + Linux .deb; local license-gated REST API in-product. |
| ForteStrike | Runs the attack path against your own hosts and reports which controls actually survived contact -- assessor-grade evidence. | Early Adopter | Contact for early access. Standalone or part of the ForteBase family. | Contact / early-access list. |
| ForteLock | Continuous active-protect: adopts your approved exposure as a baseline, then reversibly contains any new unauthorized port -- containment only, no exploitation. | Early Adopter | Contact for early access. The defensive sibling to ForteStrike. | Contact / early-access list. |
| DenseSense | Finds where regulated / CUI data actually sits -- by disk, marking, form and pattern -- so scope is drawn against the truth, not a guess. | Early Adopter | Standalone-purchasable (or a ForteFide add-on); commercial terms at general availability. | Early access; reads only -- changes nothing. |
| DenseAIArmour | Inventories your AI attack surface -- local model endpoints, agent configs, credentials at rest -- and marks anything unreachable "not assessed," not passed. | Early Adopter | Contact for early access. Standalone or part of the ForteBase family. | Contact / early-access list; read-only. |
| DDVault + DDWitness | DDWitness attests a package is unaltered without ever holding the evidence itself; DDVault is the optional vault that stores it. | Early Adopter | DDWitness is free for the life of your license -- included with any licensed edition, 30-day post-cancellation retention. DDVault is the optional SaaS vault. | DDWitness travels with the license; DDVault is a SaaS vault (airgapped sites hand off by sneakernet). |
| ForteFed | The ForteFide model brought to NIST 800-53 / FedRAMP -- scan every control, secure what it can, seal signed evidence -- for the federal cloud authorization above CMMC. | Waitlist | Join the waitlist. Planned as a free scanner, mirroring ForteFide. | Waitlist; installer-based scanner planned. |
| ForteBase | The suite bundle / console and the licensing backbone -- one place to run assess (ForteFide), prove (ForteStrike), contain (ForteLock), discover (DenseSense) and inventory AI (DenseAIArmour). | Early Adopter | Take the family bundled or standalone. Contact for early access. | Suite console + entitlement backbone; one evidence chain. |
Scanner, remediation engine, and signed-evidence producer for CMMC Level 2. It evaluates all 110 controls; 78 are auto-checked on both Windows and Linux and 32 are organizational / attestation controls judged by interview and documentation. Auto-remediation is offered on the technical gaps it can safely reverse (with a stored rollback), and it flags the rest -- it never applies a change that would break its own re-scan.
Free to scan, unlimited endpoints. A per-target license unlocks auto-remediation, batch remediation, rollback, certificate / zero-trust auth, signed C3PAO evidence, and key inventory + LDAP/AD. Buy per target (<=5 $89, 6-25 $65, 26-100 $46, 101-200 $34 per target/mo), rate locked for the life of the license; annual is 10x monthly; self-serve checkout up to 200 targets, 200+ is a custom quote.
Local Windows .exe and Linux .deb installers (Nuitka-compiled, self-contained, air-gap ready). Free account to download. A local, license-gated REST API runs in-product on the customer's own host.
ForteStrike (Early Adopter) is the offensive sibling: it independently runs the attack path against your own authorized hosts and re-tests after a fix, so a control only counts as closed if ForteStrike can no longer get through -- a retest diff that becomes assessor-grade evidence. It documents the intended API surface of a preview product; it is not yet generally available.
ForteLock (Early Adopter) is the defensive sibling: a continuous guard that adopts your approved exposure as a baseline and reversibly contains any new, unauthorized port the moment it appears -- containment only, never exploitation, always undoable. ForteStrike finds the lock; ForteLock throws it.
DenseSense (Early Adopter) answers a question a compliance scan cannot: where does your regulated / CUI data actually sit? It reads the disk by marking, form and pattern and reports the locations, so scope is drawn against the truth instead of a guess. Available standalone or as a ForteFide add-on.
DenseAIArmour (Early Adopter) inventories the AI attack surface -- local model endpoints, agent configs, credentials at rest, the AI vendor org itself -- and marks anything it cannot reach "not assessed," never "passed." Read-only by design: it changes nothing on your systems.
The custody layer beneath the suite's signed evidence, and the clearest place the two names get confused, so state it plainly:
ForteFed (Waitlist) is the ForteFide model brought to NIST 800-53 Rev 5 / FedRAMP: scan every control, secure what it can, seal signed evidence -- for the federal cloud authorization that sits above CMMC. Planned as a free scanner mirroring ForteFide (no license required to scan). Join the waitlist to help shape it.
ForteBase (Early Adopter) is the suite bundle / console and the licensing backbone: one place to run the products that answer what a compliance scan cannot -- whether controls hold (ForteStrike / ForteLock), where regulated data sits (DenseSense), and what AI tooling exposes (DenseAIArmour). Take the family bundled or standalone, or plug it into ForteFide and run everything from one place. One platform, one evidence chain.
The whole path, in order -- each step carries into the next:
.exe or Linux .deb; all 110 controls, unlimited endpoints.Licenses are machine-bound: the signing key material is derived per-license and the customer's machine fingerprint is required, so a license and the evidence it signs cannot silently move to another machine. Evidence is signed per license with Ed25519, and the verifying public key travels inside the signed manifest -- so a C3PAO assessor verifies a package fully offline, with no key to distribute and no callback.
Documentation (this page and the product guides / API references) sits behind the same free registration. DDWitness attestation is free for the life of the license, with 30-day post-cancellation retention so evidence outlives a lapse.
The suite ships one product at a time, in the order of the evidence chain, each with its own announcement:
ForteFide (GA, today) -> ForteStrike (prove) -> ForteLock (contain) -> DDVault / DDWitness (attest) -> DenseSense, DenseAIArmour and ForteFed as they mature. The suite vision is fixed; the members arrive as proof.