Pennsylvania · Small Business · SAM.gov Active · CAGE 1M4D4

AI Governance & Runtime Enforcement for Federal Contractors.

PromptFrame by GotHawk Solutions LLC — a unified AI governance platform for federal contractors of all sizes, DoD program offices, and state agencies. Design-Time scoring and ATO artifact generation. Runtime inline enforcement with cryptographically signed gate decisions. One product, one price, air-gap native.

View Capability Statement PromptFrame →
🏛️
SAM.gov Active · CAGE 1M4D4
🔢
Primary NAICS 541512 — IT Consulting
🏢
Entity Type LLC · Small Business
📍
Location Dillsburg, Pennsylvania

10
Design-Time Governance Dimensions · NIST AI RMF
4
Runtime Gate Categories · Inline Enforcement
14
GSAR Paragraphs Mapped (Proposed Rule)
Air-Gap Native
Zero External API Calls · CUI Ready
FIPS 140-3 · AES-256-GCM · HMAC-SHA256
Core Capabilities

One Platform. Design-Time + Runtime.

PromptFrame is a unified AI governance platform for federal contractors and DoD program offices. Design-Time and Runtime components are not sold separately.

🔍
Design-Time (DT) — Governance Scoring & ATO Artifacts PromptFrame

10-dimension deterministic scoring of AI system prompts — no LLM in the assessment path, same input always produces same output, independently verifiable and C3PAO defensible. Aligned to NIST AI RMF, EO 14179, OMB M-25-21/22, OMB M-26-04, GSAR 552.239-7001 (proposed, 14 paragraphs), CMMC Level 2, and PA EO 2023-19. Auto-generates complete ATO artifact packages: SSP narratives, POA&M, NIST 800-53 crosswalk, GSAR checklist, SPRS export, executive summary — all SHA-256 integrity-protected.

Deterministic · Air-gap native · HMAC-signed audit chain
🛡️
Runtime (RT) — Inline Enforcement Gate

Sits alongside LLM and agentic toolchains. Blocks unauthorized tool calls before execution. Logs every gate decision as a cryptographically signed audit record. Promotes anomalies to Design-Time in real time. Four enforcement categories: tool authorization, scope boundary, data exfiltration attempt, privilege escalation. All gate decisions are independently verifiable — not black-box AI outputs.

Inline · Cryptographically signed · Real-time DT promotion
🕵️
Shadow AI & Foreign AI Detection

Workspace scanner detects installed AI applications, browser extensions, AI-related environment variables, and network log contacts with AI endpoints. Foreign-origin contacts (DeepSeek/China, Mistral/France, etc.) flagged per EO 14179 §2. Supports Cisco ASA syslog, CLF, CEF, CSV, and DNS log formats. HMAC-signed scan report.

🔒
FIPS 140-3 & CUI-Ready Architecture

Built on Red Hat UBI 9 (FIPS 140-3 capable). AES-256-GCM encryption, RS256 JWT, Argon2id key derivation, HMAC-SHA256 audit chain. Zero external API calls — fully self-contained, works in CUI environments and air-gapped networks.

📋
AI Governance Advisory & Teaming

Fixed-scope engagements: governance gap assessments, OMB M-25-21 AI use-case inventory alignment, CMMC Level 2 AI governance posture review. Available as AI governance subcontractor under prime contractor AI modernization efforts. Fixed-price SOWs available.


Delivery Model

Self-Hosted. Your Infrastructure. Your Data.

PromptFrame is deployed as a self-hosted container stack on client infrastructure. GotHawk provides signed container images — no data is ever transmitted to GotHawk or any third party. Full data residency control from day one.

Self-Hosted Container
Available Now

Client runs the Docker stack on their own infrastructure. GotHawk delivers signed container images only. No data leaves the client environment — ever. Compatible with air-gapped networks and CUI environments. FIPS 140-3 capable (Red Hat UBI 9).

What GotHawk Provides
✓  Signed Docker container images
✓  Deployment documentation
✓  Configuration for CUI / air-gapped environments
✓  Framework file (SHA-256 pinned)
✓  Ongoing image updates and security patches
GotHawk never receives, processes, or stores client prompt data or assessment outputs.

Registration & Codes

NAICS Codes

Applicable NAICS codes for federal procurement purposes. SAM.gov active — CAGE 1M4D4.

NAICS Code Description SBA Size Standard Status
541512 Computer Systems Design Services Primary $34M annual revenue Applicable
541511 Custom Computer Programming Services $34M annual revenue Applicable
541519 Other Computer Related Services $34M annual revenue Applicable
Registrations & Certifications
SAM.gov — Active
CAGE Code — 1M4D4
Pennsylvania LLC — Active
SBA Small Business — Qualifies
Partnerships

Teaming & Subcontracting

GotHawk is positioned for subcontract teaming under prime contractor AI modernization and DoD AI governance efforts. Open to teaming conversations with large and mid-tier primes.

AI Governance Subcontractor — Design-Time + Runtime

GotHawk Solutions LLC brings specialized AI governance capabilities to prime contractors pursuing federal AI modernization, CMMC compliance, and DoD agentic AI programs. PromptFrame's unified DT + RT architecture covers the full governance lifecycle — from design-time ATO artifact generation to inline runtime enforcement with cryptographically signed gate decisions.

Engagement floor: $12,500 per assessment. Fixed-price SOWs available. SAM.gov active · CAGE 1M4D4.

NIST AI RMF EO 14179 OMB M-25-21 / M-25-22 / M-26-04 GSAR 552.239-7001 (proposed) — 14 Paragraphs CMMC Level 2 NIST SP 800-53 / 800-171 Small Business Set-Aside Fixed-Price SOW / T&M

Teaming Contact

👤
Point of Contact Williams Hawkins III
📞
Phone 717-489-9585
📍
Location Dillsburg, Pennsylvania