Controls mapped to CMMC, NIST and the EU AI Act
An audit trail, rollback and exportable evidence.
Controls that map to framework requirements, with a change log, publish history and per-decision events you can hand to an assessor.
| Timestamp | Action | Site | Query Name | Source IP | Reason |
|---|---|---|---|---|---|
| 2026-09-15 10:04:11 | accept | j.rivera | policy: corp-office | greylist.mode | disabled to enabled |
| 2026-09-15 10:04:11 | accept | j.rivera | publish #4412 | auto | succeeded, 2 keys |
| 2026-09-15 09:51:40 | block | api: splunk-soar | list: blocked-iocs | push | +3 entries, SOAR-4412 |
| 2026-09-15 09:12:02 | accept | m.chen | list: approved-ai | entry | +app.summarizeit-pro.io |
Assessors ask for the record, not the tool
A control narrative needs three things: the configuration in force, who changed it and when, and evidence that it operated. Most DNS products give you the first. Securd records all three by default.
Boundary control
Which named services each network segment and agent may reach, stated in a policy and enforced at the resolver.
Change management
Every policy, list and feed change with user, timestamp and content. Every publish with a rollback point.
Audit records
Every resolution decision as an event, retained and forwarded to the SIEM of record.
Three artifacts, kept automatically
Configuration
Policies, lists and categories per site and per agent role. Exportable through the API at any time.
Change log and publishes
Who changed what, when, and the publish that carried it to the resolvers. Roll back to any prior publish.
Decision events
Accept, block, threat and greywall with the reason. Syslog, CEF, JSON, API and webhooks.
Compliance controls
Change log
User, timestamp, object and content for every change. Filter by object, user or date; export.
Publish history and rollback
Every publish is a snapshot. Restore a known-good configuration in one action, recorded like any other change.
Decision events
Every lookup logged with action and reason. Retention per plan; forward for longer.
Roles and scoped keys
Console roles for people. Thirteen scopes for automation. Keys expire and rotate without downtime.
Default deny
A policy with Default Action Deny is a written, enforced allow list for a boundary.
US operations
US-based company and support. Data handling terms published on this site.
Where each artifact applies
A starting point for the control narrative. Your assessor decides sufficiency; Securd supplies the evidence.
NIST SP 800-171 / CMMC
3.13.1 Monitor, control and protect communications at boundaries .... policy per site, Default Action Deny, Traffic Logs
3.14.6 Monitor to detect attacks and indicators ..................... threat events, feeds, security categories
3.3.1 Create and retain audit records ............................. events forwarded to the SIEM, change log
NIST AI RMF
Map / Manage ....................................................... AI service inventory, per-team policies, approvals
EU AI Act
Art. 12 record-keeping ............................................. Traffic Logs, change log, publish history
Art. 14 human oversight ............................................ Greywall hold and approval entriesQuestions teams ask
Is Securd certified for CMMC?
Securd is a control you deploy inside your boundary, not a certified enclave. The mapping shows where its artifacts support your assessment.
Is the audit trail immutable?
The change log and events are tamper-evident and forwardable. Retain them in your SIEM of record for the immutability your framework requires.
Can we export everything?
Yes. Traffic Logs as CSV, JSON or CEF; the change log and configuration through the API.
Walk your assessor through the record
Configuration, change log and events, exported from one console.