EXPLAINABLE AI FOR SOFTWARE AUTHORIZATION DOD BUILT · COMMERCIAL READY

Automated container security review.
Attested, authorized,
on record.

Every release automatically scanned. Every finding ranked with the fix that closes it. Serious failures go back to engineering automatically and never reach approval.

What remains is justified from the evidence, each sentence cited. Then one qualified person makes the call, in minutes, and signs it by name.

Built on the pipeline Ulap runs for the U.S. Department of Defense. The proof it produces is the proof your auditor, your regulator, and your biggest customer are already asking you for.

FOR TEAMS SHIPPING CONTAINERS THROUGH A CI/CD PIPELINE.
WE READ EVERY REQUEST AND REPLY PERSONALLY.

130+Containers in production
12Scanners every push
1Signature that counts
CDSO · AUTHORIZATION RUNRUNNING

      

Every verdict cites policy version, rule, and evidence hash

apex_api 1.1.2◆sbom PASS◆secrets PASS◆malware PASS◆misconfig PASS◆cve 3 ACCEPTED, JUSTIFIED◆11/12 GATES◆SIGNED @mikeperez◆sha 4f9c2ae◆

Scan. Remediate. Authorize.
Every step explained.

CYBO Attest scans every push with twelve tools, drives the fixes, and then does the part nothing else does: it closes the loop. A named person accepts or refuses what remains, on a stated basis, in a record that outlives the release. Finding a risk is not disposing of it, and the disposition is what an auditor, a regulator, or a customer's security team is actually asking you to produce.

CYBO ATTEST

The approval, with proof

Permission: approved to ship, with proof

ALL IN ONE APPSEC

A list, in one place

Detection: findings ranked, and left with you

HARDENED IMAGES

Cleaner ingredients

Prevention: for the parts you buy from them

DEVOPS PLATFORMS

The toolbox

Platform: the substrate we build on

Already running some of these? Keep them. Fewer findings arrive, your platform stores the artifacts, and CYBO Attest performs the approval nobody else does.

Seven steps.
One auditable record.

Every step leaves evidence, and every explanation cites it.

01

Scan

Twelve tools on every push. Evidence lands in immutable, hash verified directories in your own security repo.

02

Explain

Every verdict expands to policy, rule, threshold, and evidence hash, plus what would make a failure pass.

03

Justify

What cannot be fixed yet is assessed for reachability, upgrade path, and compensating controls. Drafted from evidence, every sentence cited. Engineers own the words.

04

Submit

A complete package opens the review and joins the queue. Nothing incomplete reaches a reviewer.

05

Review

One decision at a time, in reviewer language, with claims that split the queue across a team.

AUTOMATION ENDS HERE
06

Authorize

Approve under your own verified identity, enforced by the platform. Never a bot, never on someone's behalf.

07

On record

Attributed, timestamped, anchored to an evidence hash, and exportable the day an auditor, a regulator, or a customer asks.

Three seats.
One shared record.

One trace engine, three questions. Nobody reads a summary of somebody else's work.

The developer

Every failed check explains itself the moment you push: what rule, what evidence, and exactly what change makes it pass.

Security stops being the team you wait on.

The reviewer

Everything arrives ready to judge. A drafted basis is waiting, but the judgment and the signature are always yours.

Minutes per decision instead of days per package.

The risk owner

Who decided what, on which evidence, and why, across every release your organization ships. Exports for an auditor, a regulator, or a customer under contract.

Speed and accountability stop being a trade off.

Early access pricing · first 150 teams

Explainable AI accelerating your pipeline,
hardening what you build and deploy.

Early access pricing is for teams that want Explainable AI working alongside them now: scanning what they build, explaining every verdict in plain language, and driving the fixes before anything ships. Findings arrive ranked with the fix that closes them, serious failures return to engineering automatically and never reach approval, and distroless bases are standard. One price for the whole environment, with reviewers and developers unlimited. The first 150 teams keep their rate for as long as they stay with us.

Connected

Your pipeline, your software, your reviewers

$199per environment, per month Early access rate, first 150 teams

  • Explainable AI on every gate, every finding, every justification
  • Unlimited reviewers and developers, at no extra cost, ever
  • One environment carries a full container fleet
  • Runs against your existing CI/CD pipeline, self managed or hosted
  • Evidence stays in your own security repo, with the full rule trace

Most teams start here

Managed review

Your pipeline, our reviewers

Talk to usScoped to your queue

  • Everything in Connected
  • Ulap reviewers work your queue under agreed policy
  • Time to authorize reported against a target
  • Your people can take any decision back at any time

Program

Regulated, air gapped, or at scale

Talk to usAnnual agreement

  • Dedicated tenancy in your cloud, including IL5+ environments
  • Policy authored to your control set
  • Named support and onboarding
  • SBIR Phase III sole source eligible

Early access rates hold when the product opens up.

Questions people
actually ask.

Do containers come out with zero CVEs?

No, and neither does anything else. There is no such thing as a zero CVE container, only a container that was clean at the moment somebody measured it. Not every CVE applies to how you actually deploy either: a vulnerability in a code path you never call is not the same risk as one on your front door.

So the pipeline does three things instead of promising a number. Every finding arrives ranked with the fix that closes it. Serious failures return to engineering automatically and never reach approval. What remains is assessed for reachability, upgrade path, and compensating controls, and whatever is accepted is accepted knowingly, in writing, by a person whose name is on it.

Does the AI approve anything?

No, and it never will. Steps 01 through 05 run without you. Step 06 is a person: a named reviewer approves under their own verified identity, enforced by the platform's own permissions. Never a bot, never on someone's behalf. Explainable AI drafts the justification from the evidence with every sentence cited; the words and the signature stay yours.

What do we have to change to use it?

Connect your pipeline. Evidence publishes to your own private security repo in immutable, hash verified directories, and the review opens in the project your team already works in. Self managed or hosted, in your cloud or ours.

Where does our code and evidence live?

With you. Scan output lands in your security repo. We do not take custody of your source or your artifacts, and every record we produce points back to a hash you can verify yourself.

What scanners does it run?

Twelve open source tools on every push, covering SBOM, vulnerabilities, exposed secrets, misconfiguration, and malware. The pipeline is not hardcoded. As tools change, the gates and the record change with them.

We already pay for an AppSec platform. Why add this?

Because none of them end in a decision. Detection tools hand your team a list, hardened images cover the parts you buy, your platform stores the artifacts, and every one of those leaves a person staring at unresolved risk with no way to dispose of it on the record. CYBO Attest scans on every push and then produces the signed authorization, which is the only thing an auditor, a regulator, or a customer accepts as proof.

What happens when a container has not changed?

It is recognized as unchanged and the re-review cites the delta rather than starting over. Minutes, not days, and the record says exactly why it was quick.

What can we hand an auditor?

An attributed, timestamped decision tied to an evidence hash: what was found, what was fixed, what was accepted, on what basis, and who decided. It exports for a SOC 2 auditor, an ISO 27001 review, a regulator, or a customer's security questionnaire.

Who is behind it?

Ulap Inc., a minority owned small business, profitable since 2019 and fully self funded, with multiple Army and Air Force SBIR Phase I and II awards and significant investment from U.S. Cyber Command and AFWERX.

Read it before
you talk to us.

The same material we would walk you through on a call. Ask for either and we send it.

A person answers every request the same day.

Built to the hardest standard
in software. Ready for yours.

Ulap partnered with Army Cyber and U.S. Cyber Command to build and operate cDSO, the framework that automates security scanning, testing, and approval of containerized software for IL5+ environments in days, not weeks or months. As an original contributor to the platform built with ARCYBER at Unified Platform, Ulap manages 130+ containers through it today.

CYBO Attest is built on that core engine, and extends it. The platform Army Cyber built and operates does the scanning and the automation, and what it produces arrives as raw pipeline output, log files, and markdown. Ulap adds the layer nobody had built: Explainable AI that puts every verdict in plain language, and a console that walks developers, architects, reviewers, and product owners through submission, remediation, review, and approval. Nobody reads a log file to find out where they stand.

Nothing about that is defense specific. A signed decision tied to evidence is what a SOC 2 auditor wants, what an ISO 27001 surveillance review wants, what the EU Cyber Resilience Act pushes onto every software vendor selling into Europe, and what shows up in the security questionnaire from your largest customer. We built it where the bar is highest. It runs against your existing CI/CD pipeline, in your cloud or ours.

Profitable since 2019, fully self funded, with significant investment from U.S. Cyber Command and AFWERX.

130+Containers in production
IL5+Environments, and any commercial cloud
cATOThe review and approval behind it

Deployed today.
Not open to everyone yet.

CYBO Attest is performing verified authorizations in production right now. We onboard a small number of teams at a time so that every one of them gets our engineers on the call. Commercial and government teams both welcome.

EARLY ACCESS PRICING FOR THE FIRST 150 TEAMS. YOUR RATE HOLDS FOR AS LONG AS YOU STAY.

01

HANDS ON ONBOARDING

Your first authorization happens with our engineers on the call.

02

A SAY IN WHAT COMES NEXT

Early teams shape what we build next, and we tell you where you landed.

03

EARLY ACCESS PRICING

First 150 teams keep their rate for as long as they stay with us.

YOU ARE A FIT IF
  • You build and ship containers through a CI/CD pipeline.
  • Somebody is accountable for approving a release, whatever their title says.
  • An auditor, a regulator, or a customer wants more than a scan report.
REQUEST EARLY ACCESS◆PRICING◆FAQ◆RESOURCES◆CONTACT@ULAP.CO◆ULAP INC.◆