PromptFrame produces the governance evidence federal AI deployment requires — deterministic scoring against federal frameworks and the complete AI-governance evidence package for ATO preparation (the AI-system portion of the body of evidence), including machine-readable OSCAL that feeds your authorization platform. No LLM in the scoring path: same input, same result, every time. Self-hosted on your infrastructure. A complementary runtime enforcement layer is on the roadmap.
PromptFrame's design-time platform scores AI systems and generates the ATO evidence — deterministic, air-gapped, machine-readable. A complementary runtime enforcement layer is on the roadmap; the shipping product is design-time.
Deterministic 10-dimension scoring of AI system prompts. No LLM in the scoring path — same input always produces same output. The scoring method is defensible under C3PAO and 3PAO scrutiny. Auto-generates the complete AI-governance evidence package for ATO preparation (the AI-system portion of the body of evidence) per assessment.
A complementary runtime enforcement layer, designed to sit inline with LLM and agentic toolchains so every tool call executes within the approved policy boundary, each decision a cryptographically signed audit record. Architected and in development; not yet fielded. The shipping product today is Design-Time.
Standalone scanner for Windows, macOS, and Linux. Detects installed AI applications, browser extensions, IDE plugins, local model runners (Ollama, LM Studio), MCP server configs, and API credential files. Analyzes network logs in six formats: Apache/Nginx CLF, ArcSight CEF, CSV, DNS query logs, Cisco ASA/FTD syslog, and directory scan output.
A point-in-time audit cannot satisfy a continuously evolving AI deployment. The design-time platform delivers the design → approve → attest → decay → re-approve cycle today; the enforce step and its real-time feedback are part of the roadmap runtime layer. The full loop keeps your governance posture current as AI systems change.
This is not a design philosophy. It is a mathematical requirement derived from peer-reviewed research at NIST.
In a paper published in IEEE Security & Privacy, Apostol Vassilev of NIST applied Gödel's incompleteness theorems — mathematical results from 1931 proving the inherent limits of any formal rule system — to the domain of AI security.
The proof concerns adversarial robustness — whether a fixed rule set can withstand attack — and NIST draws an architectural conclusion from it: organizations must move from “one and done” security to continuous monitoring, with red-teaming, ongoing guardrail updates, and resilience planning for when exploits occur. The objective NIST states is making exploitation economically prohibitive, not achieving perfect impermeability. The implication for governance is that a point-in-time artifact cannot be the whole answer. PromptFrame delivers the design-time and re-attestation portions of that model today; the continuous-enforcement portion is the roadmap runtime layer.
This is why design-time governance is necessary but not sufficient on its own. A single compliance report, a point-in-time audit, or a static policy document answers what a system was designed to do — not how it behaves under adversarial pressure over time. Both layers are required.
"What this proof shows is that there is no finite set of guardrails that is universally robust against adversarial prompts."
* GSAR 552.239-7001 is a proposed rule pending GSA finalization. GSA published a Revised Clause on June 17, 2026; the public comment period closes August 3, 2026 (public listening session July 14, 2026). No enactment date has been announced. GotHawk submitted a formal public comment April 3, 2026, recommending GSA add a design-time documentation requirement — the governance gap PromptFrame was built to close.
Every DT assessment produces a complete, SHA-256 integrity-protected artifact package — deterministic, evidence-based, ready for a contracting officer, AO, or C3PAO assessor. Output includes machine-readable OSCAL (SSP + POA&M) so the evidence feeds an OSCAL-native authorization platform, not just a PDF.
Every AI system prompt is scored 0–10 across all 10 dimensions. Three dimensions are critical. A security dimension score below 3 triggers a GovCon-Not-Ready override regardless of overall score.
PromptFrame runs on your infrastructure as a Docker container stack. GotHawk delivers signed container images — no data is ever transmitted to GotHawk or any third party.
Your team runs the Docker stack on your own servers or cloud infrastructure. Compatible with air-gapped networks and CUI environments. FIPS 140-3 capable.
GotHawk never receives, processes, stores, or trains on client prompt data or assessment outputs. All data stays within your infrastructure boundary.
Any organization deploying AI systems that needs defensible governance documentation — from small contractors to defense primes.
Document AI system compliance for use-case inventories and procurement packages without a dedicated GRC team. Self-hosted deployment means no external data exposure.
Vet AI components across your delivery environment. Establish a documented compliance baseline for AI systems in contract performance. CMMC Level 2 and FedRAMP Moderate posture support.
Accelerate compliant agentic AI deployment by producing governance evidence up front. The roadmap runtime layer is designed to keep every deployed agent within its approved policy boundary, with a signed audit trail for oversight review.
Build AI use-case inventories and governance documentation for CMMC pre-assessments and ATO preparation. Deterministic scoring produces independently verifiable evidence.
PromptFrame maps to PA EO 2023-19. GotHawk is a PA-registered small business, BDISBO self-certified, active in the PA Suppliers Portal (Jaggaer). Engagements available through the portal or direct award.
Score system prompts before deployment to identify governance gaps early — before procurement reviews or buyer due diligence surfaces them in a contract.
Contact Williams Hawkins III to discuss your deployment. We'll walk through your AI systems, delivery environment, and compliance requirements — and get you set up with signed container images and deployment documentation.
Request Access717-489-9585 · williams@gothawksolutionsllc.com · We respond within one business day
State agencies and Pennsylvania-registered contractors deploying AI systems face the same governance gap as federal buyers. PromptFrame maps to PA EO 2023-19 and produces documented, reviewable evidence of AI system configuration for IT risk reviews, vendor due diligence, and internal AI governance policies.
GotHawk Solutions LLC is a Pennsylvania-based small business, BDISBO self-certified, and active in the PA Suppliers Portal. Engagements can be structured through the portal or via direct award under applicable thresholds.