Skip to main content

Security & Compliance

Built for the airgap

Loadout is a lab training aid designed to run disconnected, on government-controlled training assets. Its security posture follows from that: a small, offline attack surface, openly-synthetic data, and supply-chain assurance a deploying program can verify and inherit.

Architecture and data

A small, offline surface

  • Airgap-friendly.Designed for standalone, disconnected lab operation. No external internet dependency, no external APIs, and no inbound network services. Device communication is local.
  • Openly-synthetic data.Every artifact is openly-synthetic scenario data. No real PII and no credentials are handled. A documented ground-truth manifest records exactly what was placed, where, and when.
  • Training devices only.Loadout targets lab-owned, instructor-controlled training devices. It is not for evidentiary, personal, or third-party devices.
  • Transparent by design.Injected data is openly synthetic and documented in a ground-truth manifest, so it is never presented as authentic. Removal is verified by read-back between exercises.

Supply-chain assurance

Verified on every build

The build pipeline treats dependencies and secrets as first-class gates, not afterthoughts.

  • Locked dependencies

    Every component pins its dependency graph with a committed lockfile, so what ships is reproducible and fully visible to scanners.

  • Blocking CVE gate

    A blocking dependency and vulnerability scan runs on every change and on a weekly schedule. A fixable medium-or-higher CVE in a shipped dependency fails the build.

  • Secret scanning

    Secret scanning over the full git history is a blocking gate. Static analysis (SAST) runs alongside it on each build.

  • Signed SBOM

    A CycloneDX software bill of materials is produced per component at release and cryptographically signed with a public transparency record.

Authorization readiness

Designed to inherit your accreditation

An Authority to Operate (ATO) is granted by an Authorizing Official to a system within an accreditation boundary. Loadout is a component that runs inside, and inherits from, the lab or range enclave a deploying program already controls. It does not carry, and does not claim, its own ATO.

The airgapped, no-external-interface design makes Loadout a strong fit for a lightweight determination rather than a standalone authorization: inheriting the enclave ATO, an Assess-Only determination, or interim test authorization, as the deploying program's ISSM and Authorizing Official decide. To support that decision, an inheritance support pack is available, including a NIST SP 800-53 control-responsibility matrix (what Loadout provides versus what it inherits) and the hardening posture.

Container and AWS GovCloud delivery target those environments; availability of a deployment package does not imply an existing ATO or Iron Bank registry acceptance, which are established per deploying program.

Accessibility

Section 508 and WCAG 2.1 AA

The site and the operator tooling are engineered to Section 508 and WCAG 2.1 AA. Conformance is self-assessed and a VPAT is available on request. Full detail is on the accessibility statement.

Evidence on request

Documentation for evaluators

Under an Accelera Solutions engagement we can provide the artifacts a security reviewer expects: the signed SBOM, the authorization inheritance support pack and 800-53 control-responsibility matrix, the static-analysis baseline, and a VPAT. These are shared on request rather than published, so they stay current and scoped to your environment.

dayel.ostraco@accelerasolutions.com

Last reviewed: