OpenRMF® Professional combined
with Elastic AI

Use the power of Elastic AI with
OpenRMF® Professional data and automation

Automate your cyber compliance across your team with OpenRMF® Professional.

Use the Elastic AI Service Provider Interface (SPI) to sync your frameworks and compliance data with Elastic 9.x or higher.

Use AI to analyze and search your generated compliance, STIG checklists, patch data, hardware, software, ports/protocols/services, and more.

Search your documents and evidence through conversational queries and other agents to gain insight, match compliance needs.

Use Elastic AI Search Agents to analyze cyber hygiene data, and find gaps in your current compliance programs.

Combine with Elastic SIEM, Workflows, Cases and more for a true end-to-end compliance solution.

Elastic AI is model agnostic. You can use the model best suited for your needs.

Combine with Elastic SIEM, Workflows, Cases and more for a true end-to-end compliance solution.

This combined solution works whether in the cloud, on-premise, or an air-gapped network.

Use this as a foundation for automated Risk Profiling, Pre-Assessment and more.

Elastic AI Portfolio Manager Agent

Search across your entire portfolio of accreditation data, including documents, with OpenRMF Professional Elastic AI Service Provider Interface connected to your cluster.


Whether you are searching at the macro level across everything, all data types, just within a system package itself, or even combined with other data in Elastic like CVE or KEV listings. The Portfolio Manager Agent allows all of that and more.

Elastic AI for CVE and KEV Search and Report

Using the new Elastic AI Service Provider Interface (SPI) being developed by Soteria Software, see how you can load OpenRMF Professional data for all your accreditations, add in CVE and KEV data, and start to ask questions around vulnerabilities, scores, and due dates in a quick conversational query.


Match your patch vulnerabilities or container image scan vulnerabilities quickly and easily.

Elastic AI to Research Elastic Compliance

Using the Elastic AI Service Provider Interface (SPI) with OpenRMF Professional, you can use the AI Agent to ask questions of your frameworks with direct relation to how Elastic itself is setup with all its components.


And then see how to track RMF, FedRAMP, CMMC, and other compliance controls and their status based on how you configure your Elastic cluster itself. Find configuration settings, policies, queries, and directions on showing control compliance from within Elastic itself.

Elastic AI Authorizing Official Interview - Part 1

Use Elastic AI and our OpenRMF Professional Elastic AI Service Provider Interface (SPI) to interview your compliance data from the viewpoint of an assessor or authorizing official (AO).


See how you can ask questions of your data in a conversational way, interview your accreditation package, and see where you stand from a high level perspective of an assessor. This lets you see where you stand, where you have gaps, where you may have some "gotchas" and lets you and your team concentrate on closing the compliance gap. Then get on to cyber hygiene and cyber security in the best way possible.

OpenRMF Professional combined with
our Elastic AI SPI -- An Example

OpenRMF® Professional data in Elastic AI for CCI Research

How to use the power of Elastic AI with the OpenRMF Professional service provider interface for that, to load and search across all your framework specific information in a conversational way.


Use industry standard or even your own custom Frameworks, framework levels, controls, control families, linked CCIs, even assessment procedures that you already have loaded in your OpenRMF Professional installation.

Elastic AI for Conversational Search across all data - Part 1

See how to combine OpenRMF Professional for automated cyber compliance and Elastic AI through our SPI to have conversations and interviews with all your compliance data.


We automatically link up and push compliance data into the correct AI Tools and Agents. You ask questions regardless of AI model you use. And get details at the macro and micro level from all your data, scans, and documentation.

Elastic AI for Conversational Search across all data - Part 2

See how to combine OpenRMF Professional for automated cyber compliance and Elastic AI through our SPI to have conversations and interviews with all your compliance data.


We automatically link up and push compliance data into the correct AI Tools and Agents. You ask questions regardless of AI model you use. And get details at the macro and micro level from all your data, scans, and documentation.

Elastic AI for Conversational Search across all data - Part 3

Search across all your data, including scans and documentation, regardless of your cyber framework knowledge and expertise. See how to combine OpenRMF Professional for automated cyber compliance and Elastic AI through our SPI to have conversations and interviews with all your compliance data.


We automatically link up and push compliance data into the correct AI Tools and Agents. You ask questions regardless of AI model you use. And get details at the macro and micro level from all your data, scans, and documentation.

Asking about Revision 4 controls to Revision 5 and DRP

Use the results of our OpenRMF Professional Elastic AI Service Provider Interface (SPI) to see how an older Revision 4 control was migrated to Revisoin 5 for NIST 800-53 controls. We also investigate Disaster Recovery Plan information, where that resides in different controls, where that is covered, and what it should entail. Again by conversations with our framework data.

Combine OpenRMF® Professional, RapidFort, Elastic AI and Elastic SIEM

Combine the reduced footprint and hardened images from RapidFort, with automated cyber compliance in OpenRMF Professional, and Elastic SIEM for security monitoring allows a true continuous ATO (cATO). Add in Elastic AI for agentic searching and tools, and you have a living breathing cATO that tracks data live. That you can have a conversation with interactively. And that aids in not cyber compliance, cyber hygiene, and cyber security from day 1.