Solutions Launchpad Launchpad DIB Raptor CyberTrust Networking Advisory Not sure which fits? Book a scoping call → PlatformIndustriesFAQsTalk to us
For the curious

Tech specs, the depth, for the technically curious

Most of marfi.io is deliberately jargon-free, because most people don't want to think about NIST control families or FIPS modules, they want to win the contract, pass the audit, and sleep at night. This page is the exception. It's for the people who do want the details: the CISO doing diligence, the security team reviewing a vendor, the defense contractor checking whether our enclave is real. Here's exactly what's under the hood, the frameworks we operate against, the architecture behind each product, and the proof points, stated plainly and without hand-waving. If you'd rather skip all this and just talk to a human, that's completely fine: book a call and we'll walk you through whatever matters to you.

How to read this page

A quick orientation before you dive in. We split our attestation language carefully, and we'd rather you hold us to the precise version than an inflated one. Three tiers of compliance language appear below, and they mean different things: - Attested / certified, independently examined and held today (e.g. SOC 2 Type II). - In progress, actively being pursued, not yet awarded (e.g. ISO 27001). - Aligned / operated against, we configure, enforce, document, and evidence the controls of a framework, and keep that evidence current, but the formal certificate is issued by a third party, not by us (e.g. CMMC, which only a C3PAO can certify). We will never blur those lines to sound more certified than we are. Where a number could read two ways, we keep it in its correct context.

  • Attested: SOC 2 Type II (Security, Availability, Confidentiality)
  • In progress: ISO 27001 certification
  • Aligned & evidenced: NIST 800-171 (all 110 controls), NIST 800-53, NIST CSF 2.0, CMMC L1/L2, HIPAA, PCI DSS, GDPR, FedRAMP-aligned
  • Hard line since founding (Aug 20, 2020): 100% US-based personnel, zero offshore

Managed IT, Launchpad, the foundation

Launchpad is our managed IT, security, and compliance platform, one US-based team running your entire environment, with AI-native monitoring 24/7 and all stack licensing included. It's AI-native: 80%+ of issues are resolved automatically before you ever notice them, and a US-based analyst owns whatever's left. It's SOC 2 and HIPAA aligned out of the box, because our delivery platform itself is SOC 2-certified, so onboarding clients inherit a baseline of controls and begin continuous evidence collection from day one rather than starting from zero. The whole point is replacing a stack of finger-pointing vendors with one accountable team, one bill, and a result somebody actually owns.

  • One US-based team; AI-native monitoring 24/7, human support during business hours; all stack licensing included
  • AI-native operations, 80%+ of issues auto-resolved before the client notices
  • SOC 2 + HIPAA aligned; clients inherit controls and begin continuous evidence from day one
  • Pricing stated publicly: $115-$250 per user / month, scales up or down
  • Scale today: 1,000+ endpoints protected; 99.9% uptime across the managed environment band
  • Onboarding measured in days, our first client went from exposed to secured in 7 days (2020)

Endpoint & identity

This is the layer most breaches actually start at, a stolen password, an unmanaged laptop, a user with more access than they need. We close those doors by default rather than as an upsell. Identity is built on phishing-resistant MFA (FIDO2 security keys, not just SMS codes that can be phished out of a user), single sign-on so there aren't dozens of passwords to leak, conditional access that only admits trusted devices and locations, and least privilege so a single compromised account can't reach everything. Endpoints run managed EDR, with data encrypted in transit and at rest and DLP guardrails so sensitive data doesn't walk out the door.

  • Phishing-resistant MFA (FIDO2), SSO, and conditional access enforced by default
  • Least privilege, access scoped to the job, so one compromised account can't reach everything
  • Managed EDR on every endpoint
  • Encryption in transit and at rest
  • DLP to keep sensitive data from leaving accidentally or deliberately
  • Maps directly to CMMC AC (Access Control) & IA (Identification & Authentication) families

Detection & response

Protection is layered on purpose, defense in depth, so that when any one control is bypassed, the next one still stops the threat. Our model runs five layers deep, monitored around the clock by AI, with US-based analysts on escalations during business hours. The last layer matters most when everything else fails: immutable backups that an attacker can't erase or tamper with, plus a tested disaster-recovery path. That's the line that turns a ransomware event from a catastrophe into an afternoon.

  • Layer 1, Perimeter & email: phishing and malicious mail stopped before delivery
  • Layer 2, Identity & access: phishing-resistant MFA + least privilege
  • Layer 3, Endpoint & network: managed EDR on every device; malicious traffic cut off
  • Layer 4, Monitoring & AI: 24/7 watch resolving 80%+ before you notice
  • Layer 5, Backup & recovery: immutable backups and tested disaster recovery as the last line
  • Built on best-in-class partners (e.g. CrowdStrike) so you get enterprise-grade tooling without managing it yourself

The secure enclave for defense work, Launchpad DIB

Launchpad DIB is Launchpad, rebuilt to the standard defense contractors are actually held to. If you handle CUI (Controlled Unclassified Information), usually because a prime flowed CMMC down to you, commercial Microsoft 365 isn't authorized for it. Launchpad DIB stands up a real, sovereign CUI enclave on GCC High and AWS GovCloud, so your controlled data never mingles with commercial cloud. ITAR/EAR-controlled data stays on US soil, in US hands. The architecture is four concentric layers wrapped around your CUI core, and we operate, monitor, and evidence all of it. Importantly: MARFI is not your assessor. Your formal certification is performed by an independent, government-authorized C3PAO. We get you ready and stand beside you through it, in partnership with Secureframe, a CMMC RPO (Registered Provider Organization). Note that here 'RPO' means Registered Provider Organization, the CMMC readiness role, not Recovery Point Objective.

  • Full CUI enclave on GCC High AND AWS GovCloud, sovereign perimeter, nothing in or out without permission
  • L1 CUI Boundary · L2 Identity & Access (FIDO2 MFA, conditional access, least privilege, CMMC AC & IA) · L3 Endpoint & Network (managed EDR, FIPS-validated encryption in transit and at rest, ITAR/EAR-aware) · L4 Monitoring & Evidence (24/7 AI watch, US-based analysts) · Core: your CUI isolated end to end
  • All 110 NIST 800-171 controls configured, enforced, documented, and continuously evidenced (110/110)
  • CMMC 2.0 Level 1 & Level 2; Level 2 maps to the 110 controls of NIST 800-171
  • Deliverables: a living SSP (System Security Plan), a tracked POA&M, and continuous control evidence
  • Path to certified: (1) Scope & SPRS, map CUI footprint, score current 800-171 posture vs Level 2; (2) Stand up the enclave (days); (3) Implement all 110 controls in a living SSP; (4) Stay assessment-ready year over year with continuous evidence and support through your C3PAO
  • MARFI is not the C3PAO, independent assessment is performed by an authorized C3PAO; readiness partnership with Secureframe (CMMC RPO)

Code & penetration testing, Raptor

Raptor is our AI-native penetration-testing platform: a 24-agent pipeline that moves the way a real adversary would, across five phases. The difference from a scanner is the whole point, a scanner flags possible issues and leaves your team triaging false positives for days. Raptor proves each finding by safely, non-destructively validating it into a confirmed, reproducible exploit, then chains individual bugs into real vertical-escalation breach paths (the kind that turn two 'low-severity' bugs into a full account takeover). Every finding ships with proof, an instant replay, CVE mapping, and automatic framework mapping. It runs strictly within the rules of engagement you authorize, only against assets you own, and it's AI-native but expert-reviewed, with a human in the loop before any report reaches you. Built by two Doctors of Engineering in Cybersecurity Analytics from George Washington University.

  • 24-agent pipeline, 5 phases: Recon → Discovery → Exploitation → Chaining → Reporting
  • Full pentest in minutes to under 4 hours (demo run: 3m 41s) vs weeks for traditional engagements
  • Validated, reproducible exploits only, no scanner noise, no false-positive triage
  • Chains bugs into real vertical-escalation breach paths a scanner never sees
  • Findings correlated to live CVE data to confirm actual exploitability, plus automatic framework mapping
  • Non-destructive, strictly scoped to authorized assets and rules of engagement; expert-reviewed before delivery
  • On-demand and re-testable, run it on every ship, with no per-test change order; hosted at raptor.marfi.app

Fractional leadership, Advisory

Sometimes what you need isn't another tool, it's a seasoned operator in the room when the stakes outgrow the org chart: a fundraise, an enterprise security review, entering a regulated market. Advisory gives you that leadership part-time, all senior people who've actually held the title, 100% US-based. Engagements run on a retainer, project, fractional, or outcome-driven basis, and pair naturally with Launchpad and Launchpad DIB. A typical engagement: discovery call, scope, a 90-day prioritized roadmap with owners and milestones, then execute and report to your board or customers.

  • vCISO, security strategy, risk, compliance, board-ready posture, audit readiness
  • vCTO, technology direction, architecture, scaling, build-vs-buy, hiring and roadmap
  • vCAIO, AI strategy, governance, policy, guardrails, and automation
  • Engagement models: retainer, project-based, fractional, outcome-driven
  • Senior operators only, 100% US-based; pairs with Launchpad and Launchpad DIB

Networking

Network-as-a-utility: your entire network designed, installed, and run by MARFI for one monthly fee, powered by Meter, managed by us. Flip the switch and it just works, like the lights. The hardware (enterprise access points, switches, firewalls/gateways) is specified per space and fully included, with zero capex, no big upfront equipment purchase, just a predictable monthly fee and one consolidated bill across every site. We handle the full lifecycle: site survey and design for coverage, capacity, and redundancy; procurement; cabling, mounting, and configuration; then 24/7 monitoring, patching, upgrades, and hardware replacement when anything fails.

  • Fully managed hardware: enterprise APs, switches (e.g. 48-port PoE+), and firewalls/gateways (firewall · SD-WAN), all gear included
  • Full lifecycle: site survey & design → procurement → cabling/mounting/configuration → 24/7 monitoring, patching, upgrades, replacement
  • Commercial model: one monthly fee per site, $0 capex, all network licensing included, one consolidated bill across sites
  • SLA: proactive monitoring targeting 99.99% uptime (this is the networking target, distinct from the 99.9%/99.93% managed-environment figures elsewhere)

Continuous compliance

Most companies experience compliance as an annual fire drill, scramble for evidence, scrape through the audit, exhale, repeat. We invert that. We engineered our control library around NIST 800-53, NIST 800-171, and SOC 2 back in 2022 and have collected control evidence continuously ever since, so compliance becomes something our clients simply have rather than something they chase. That means audit-ready, every day, an assessment becomes a quick confirmation instead of a months-long ordeal. The written practices an auditor looks for, data classification, a tested incident response plan, vendor risk assessments, change management, input validation, data subject access / consent / retention, are set up and kept current as part of the operating model, not bolted on at audit time. A note on SOC 2 for buyers doing diligence: SOC 2 is an AICPA framework built on five Trust Service Criteria (Security is always required; Availability, Processing Integrity, Confidentiality, and Privacy are chosen per customer requirement). Type I is a point-in-time snapshot; Type II observes controls operating over a 3-12 month period, which is what enterprises typically require. Realistic Type II readiness runs 3-6 months depending on your starting maturity. Our SOC 2 Type II covers Security, Availability, and Confidentiality; the report is available under NDA.

  • Control evidence collected continuously since 2022, audit-ready every day, not just at audit time
  • Frameworks operated against: SOC 2, ISO 27001 (in progress), NIST 800-171 (110/110), NIST 800-53, NIST CSF 2.0, CMMC L1/L2, HIPAA, PCI DSS, GDPR, FedRAMP-aligned
  • Auditor-facing practices maintained: data classification, incident response plan (documented & tested), vendor risk assessments, change management, input validation, data subject access / consent / retention
  • Deep Secureframe integration; vCISO available to own the program
  • SOC 2 Type II covers Security, Availability, and Confidentiality, report available under NDA (we state availability, not contents)

Operating model & proof

The differentiators that don't fit neatly in any one product, but underpin all of them. We're 100% US-based with zero offshore personnel, a line drawn on day one (Aug 20, 2020) and never moved. The people who touch your environment are on-shore, accountable, and reachable. For verification, our Trust Center is live and public.

  • 100% US-based, zero offshore; 24/7 AI-native monitoring with 80%+ of issues auto-resolved
  • 1,000+ endpoints protected; 99.93% uptime across managed environments
  • Certified personnel hold CISSP, CCSP, SSCP, Security+, CySA+, PenTest+, Network+, and A+
  • Technology partners: Microsoft (GCC High / Azure), AWS GovCloud, CrowdStrike, Secureframe, Meter
  • Live, public Trust Center with certifications, security practices, and real-time monitoring metrics: trust.marfi.io/monitoring
  • Free 60-second CyberTrust Score (no signup) checks email security, SSL/TLS, breach exposure, open ports, and DNS health, 7 modules mapped to NIST, SOC 2, and ISO 27001, at cybertrustscore.marfi.app
Frameworks we operate against

The full alphabet, covered.

SOC 2 Type II (Security, Availability, Confidentiality, Trust Service Criteria, AICPA)ISO 27001 (certification in progress)NIST SP 800-171, all 110 controlsNIST 800-53NIST CSF 2.0CMMC 2.0 Level 1 & Level 2HIPAAPCI DSSGDPRFedRAMP-aligned (defense/federal CUI practice)ITAR / EARSEC / FINRA evidence readiness

That’s the depth.
Now the easy part.

That's the depth. If you're the kind of person who wanted to see the control families, the enclave architecture, and which clouds the CUI actually lives on, now you have it, and we're happy to go deeper on any of it. And if you're everyone else, the part that matters is simpler: this is all handled, by one accountable US-based team, so you don't have to think about it. Either way, the next step is the same. Book a call and we'll scope it to your environment, no acronyms required.