Self-hosted CNAPP and AI control plane. Applies DISA STIG, CIS, and IEC 62443 baselines to containers, host OS, and OT firmware before they ship. Scans the running fleet on Apollo-style SLA clocks. Watches every autonomous agent in your stack. Emits compliance evidence live, on every request.
Move at mission speed · Operate with evidence · Run the agents
Bundled XCCDF library, per-rule pass / fail / N-A from the Spoke scanner, fix text verbatim from DISA, plus operator actions inline. CIS and IEC 62443 ride the same channel. OT and IoT firmware too.
Harden your own images. No distro lock-in.
// April 2026 STIG library, bundled
Containers, cloud config, Kubernetes posture, secrets, malware, SBOM, OT firmware. The attack-path graph surfaces toxic combinations in the hour. SLA clocks count down on every finding. Breached and approaching surface automatically.
// Verify capabilities
Inventory every model running in the fleet. Sign an MLBOM on every build. Screen every prompt and tool call for injection, jailbreak, and exfiltration. Govern every autonomous agent on top: identity, tools, data scope, memory, authority, handoffs.
Optimal already runs the model side. Agents adds the orchestration layer above it.
// AI security capabilities
Live HTML and JSON artifacts at compliance.gooptimal.io, re-emitted on every request from observed fleet state. Branded for the customer's audit. Auditor reads a live feed, not a quarterly screenshot binder.
Audit time stops being a fire drill.
// Frameworks covered
Optimal is built on best-in-class open-source security engines, with our opinionated hardening, remediation, evidence emission, and agent governance as the value-add layer. The whole platform runs inside your own Kubernetes cluster. One Helm chart, one command. Optimal never holds your credentials. Optimal never holds your data.
The Recall Agent (Claude Opus 4.7) proposes remediation plans on KEV-listed criticals and SLA breaches. Operator approves. The Orchestration Engine executes against the Hub, the Spokes, and the Edge Collectors.
// Hub orchestrates. Spokes scan. Edge reaches the firmware. Recall Agent proposes; operator approves; Orchestration Engine executes.
Move at mission speed. Operate with evidence. Run the agents.