Design-Time + Runtime · Self-Hosted · Air-Gap Native · FIPS 140-3

Unified AI Governance for Federal Contractors.

PromptFrame governs AI systems at both design time and runtime — scoring prompts against federal frameworks, auto-generating ATO artifact packages, and enforcing tool boundaries inline with cryptographically signed gate decisions. One product. One price. Your infrastructure.

Request Access See the Platform
Frameworks: NIST AI RMF EO 14179 OMB M-25-21/22/26-04 GSAR 552.239-7001 (proposed) CMMC Level 2 NIST SP 800-53 PA EO 2023-19

The Platform

Design-Time + Runtime. One Product.

Two components that work together across the AI governance lifecycle. DT and RT are not sold separately.

Design-Time (DT)
Governance Scoring & ATO Artifact Generation

Deterministic 10-dimension scoring of AI system prompts. No LLM in the scoring path — same input always produces same output. C3PAO and 3PAO defensible. Auto-generates a complete ATO artifact package per assessment.

  • SSP narratives (per dimension)
  • NIST SP 800-53 Rev 5 control family crosswalk
  • POA&M in FedRAMP format
  • GSAR 552.239-7001 (proposed) compliance checklist (14 paragraphs)
  • SPRS export
  • Per-dimension remediation report
  • Executive engagement summary
  • All artifacts SHA-256 integrity-protected · HMAC-signed audit chain
Runtime (RT)
Inline Enforcement Gate

Sits inline with LLM and agentic toolchains. Evaluates tool calls against policy before execution — unauthorized calls are blocked, not logged after the fact. Every gate decision is a cryptographically signed audit record.

  • Tool authorization enforcement
  • Scope boundary enforcement
  • Data exfiltration attempt blocking
  • Privilege escalation blocking
  • Anomalies promoted to DT in real time
  • All gate decisions independently verifiable
  • Not black-box AI outputs — deterministic policy enforcement
10
DT Governance Dimensions
4
RT Enforcement Categories
14
GSAR Paragraphs Mapped
FIPS 140-3
AES-256-GCM
HMAC-SHA256
Zero External API Calls

* GSAR 552.239-7001 is a proposed rule pending GSA finalization. GotHawk submitted a formal public comment April 3, 2026.

Assessment Output

What DT Produces

Every DT assessment produces a complete, SHA-256 integrity-protected artifact package — deterministic, evidence-based, ready for a contracting officer, AO, or C3PAO assessor.

32
Overall Governance Score (0–100)
Non-Compliant
Example: Ollama local model · 10 gaps · 6 critical
SHA-256 verified · HMAC-signed audit chain
Compliance Tier Non-Compliant (<70)
GovCon Ready No — critical gaps
Dimensions Scored 10 of 10
ATO Artifacts Generated 7 — all SHA-256 signed
NIST 800-53 Crosswalk Included
POA&M (FedRAMP format) Included
GSAR Checklist (proposed rule) Included

Scoring Framework

10 Design-Time Governance Dimensions

Every AI system prompt is scored 0–10 across all 10 dimensions. Three dimensions are critical — a score below 7 on any critical dimension triggers a GovCon-Not-Ready flag regardless of overall score.

Dimension 01
Identity Clarity
NIST AI RMF GOVERN 1.1 · EO 14179 §4(a) · OMB M-25-21 §5
Critical
Dimension 02
Scope Boundaries
NIST AI RMF MAP 1.1 · OMB M-25-21 §3 · GSAR 552.239-7001 (proposed)
Dimension 03
Data Handling Disclosure
NIST AI RMF GOVERN 6.1 · OMB M-25-22 §4 · PA EO 2023-19
Dimension 04
Bias & Fairness Controls
NIST AI RMF MEASURE 2.5 · OMB M-25-21 §5(b) · OMB M-26-04
Dimension 05
Human Oversight Mechanism
NIST AI RMF MANAGE 1.3 · EO 14179 §4(b) · OMB M-25-22 §5
Critical
Dimension 06
Refusal & Constraint Enforcement
NIST AI RMF MANAGE 2.2 · GSAR 552.239-7001 (proposed) · OMB M-25-21 §4
Critical
Dimension 07
Transparency & Explainability
NIST AI RMF GOVERN 1.7 · OMB M-25-22 §3 · PA EO 2023-19
Dimension 08
Tool Coverage & Capability Declaration
NIST AI RMF MAP 5.1 · OMB M-25-21 §3(a) · GSAR 552.239-7001 (proposed)
Dimension 09
Agent Loop Controls
NIST AI RMF MANAGE 1.3 · EO 14179 §4 · OMB M-26-04 §3
Dimension 10
Incident & Escalation Pathway
NIST AI RMF MANAGE 3.1 · OMB M-25-22 §6 · PA EO 2023-19

Deployment

Self-Hosted. Your Infrastructure. Your Data.

PromptFrame runs on your infrastructure as a Docker container stack. GotHawk delivers signed container images — no data is ever transmitted to GotHawk or any third party.

Self-Hosted Container
Available Now

Your team runs the Docker stack on your own servers or cloud infrastructure. Compatible with air-gapped networks and CUI environments. FIPS 140-3 capable (Red Hat UBI 9).

✓  Signed Docker container images
✓  Deployment documentation
✓  CUI / air-gapped environment configuration
✓  SHA-256 pinned framework file
✓  Ongoing image updates and security patches
Data Handling Guarantee

GotHawk never receives, processes, stores, or trains on client prompt data or assessment outputs. All data stays within your infrastructure boundary.

Security Specs
FIPS 140-3 capable · Red Hat UBI 9
AES-256-GCM encryption
RS256 JWT · Argon2id key derivation
HMAC-SHA256 audit chain
Zero external API calls

Intended Users

Built For

Any organization deploying AI systems that needs defensible governance documentation — from small contractors to defense primes.

🏢
Small Federal Contractors

Document AI system compliance for use-case inventories and procurement packages without a dedicated GRC team. Self-hosted deployment means no external data exposure.

🏛️
Defense Primes & Mid-Tier Contractors

Vet AI components across your delivery environment. Establish a documented compliance baseline for AI systems in contract performance. CMMC Level 2 and FedRAMP Moderate posture support.

🛡️
DoD Program Offices

Require agentic AI systems to produce governance evidence before deployment. RT enforcement gates provide real-time tool boundary enforcement with a signed audit trail.

⚖️
Compliance & Risk Teams

Build AI use-case inventories and governance documentation for CMMC pre-assessments and ATO preparation. Deterministic scoring produces independently verifiable evidence.

🌿
PA State Agencies & Vendors

PromptFrame maps to PA EO 2023-19. GotHawk is a PA-registered small business, BDISBO self-certified, active in the PA Suppliers Portal (Jaggaer). Engagements available through the portal or direct award.

🧠
AI Product Teams

Score system prompts before deployment to identify governance gaps early — before procurement reviews or buyer due diligence surfaces them in a contract.


Deploy PromptFrame

Contact Williams Hawkins III to discuss your deployment. We'll walk through your AI systems, delivery environment, and compliance requirements — and get you set up with signed container images and deployment documentation.

Request Access

717-489-9585  ·  williams@gothawksolutionsllc.com  ·  We respond within one business day


Pennsylvania State Procurement

Available to PA State Agencies & Contractors

State agencies and Pennsylvania-registered contractors deploying AI systems face the same governance gap as federal buyers. PromptFrame maps to PA EO 2023-19 and produces documented, reviewable evidence of AI system configuration for IT risk reviews, vendor due diligence, and internal AI governance policies.

GotHawk Solutions LLC is a Pennsylvania-based small business, BDISBO self-certified, and active in the PA Suppliers Portal. Engagements can be structured through the portal or via direct award under applicable thresholds.

BDISBO Small Business Self-Certified BDISBO Micro Business Self-Certified PA Suppliers Portal Active (Jaggaer) Vendor No. 0000569874 Commodity 43230000 Commodity 80100000 Commodity 81111800 Commodity 84110000
Contact Us for a PA State Engagement PA Vendor Credentials → Capability Statement →