Sign inSign up

scanset/prooflayer-alpha-v0_1

By scanset

•Updated 4 months ago

Agentless continuous-compliance: turns every scan into a signed, replayable, control-mapped proof.

Image
Security
Integration & delivery
0

390

scanset/prooflayer-alpha-v0_1 repository overview

⁠Prooflayer — Alpha (Evaluation Build)

Agentless continuous-compliance that turns every scan into a signed, replayable, control-mapped proof.

Prooflayer reaches your assets over pluggable channels (local / SSH / AWS SSM / Azure Bastion / WinRM), runs declarative policies through a built-in engine, and emits proofs, not just findings — every result is a signed, replay-hashable, transparency-logged evidence envelope mapped to compliance controls (FedRAMP 20x KSI, NIST 800-53, NIST 800-171). Nothing is installed on the scanned endpoint.

This image is an all-in-one evaluation build: server, operator UI, datastore, and scanner in one container that provisions itself on first launch.


⁠Quick start

docker pull scanset/prooflayer-alpha-v0_1:0.1-alpha

docker run -d --name prooflayer \
  -p 8080:80 \
  -p 9090:8081 \
  -v prooflayer-data:/var/lib/prooflayer \
  scanset/prooflayer-alpha-v0_1:0.1-alpha

Then open http://localhost:8080⁠, accept the EULA, and log in:

  • Username: super-admin
  • Password: prooflayer

The read-only CMR oversight API (for an AO, a SIEM/SOAR, or an AI assistant given a key) is on http://localhost:9090⁠ under /cmr-api/*.

First launch generates its own PKI and secrets, seeds the datastore and control catalog, and starts the server automatically — give it a few seconds, then go.


⁠The loop

add credential → discover assets → auto-link policies → assign channel + credential → scan → read & verify the proof

  • -p 8080:80 — operator console (system-ui) + API
  • -p 9090:8081 — read-only oversight API only

⁠📖 Documentation & Claude companion

Full guided quick-start, concept reference, API docs, and a built-in AI assistant: Prooflayer Claude Companion⁠ — point Claude Code at it to ask how to use Prooflayer, run the evaluation loop, and understand the proof chain.

Open source ESP engine: Endpoint-State-Policy⁠ · scanner/agent SDK: Agent-SDK⁠


⁠Alpha scope — read before you judge it

Evaluation build only — not for production or live/regulated data:

  • Plain HTTP in the eval image (no browser TLS); the self-signed PKI signs scan evidence + the transparency log, not the connection.
  • Fixed default login (super-admin / prooflayer), single super-admin model — no user creation.
  • Non-FIPS dev build (production links FIPS 140-3 validated OpenSSL).
  • Single container, single datastore, no HA.

scanset.io⁠ Email: [email protected]⁠

Tag summary

Content type

Image

Digest

sha256:a5bed9228…

Size

413.8 MB

Last updated

4 months ago

docker pull scanset/prooflayer-alpha-v0_1:0.1-alpha