Company Overview
GotHawk Solutions LLC is a Pennsylvania-based small business delivering AI governance technology to federal contractors of all sizes — small businesses, mid-tier firms, and defense primes — as well as DoD program offices and state agencies. We built PromptFrame — a deterministic, air-gapped AI governance platform. Design-Time (DT), the shipping product, scores AI system prompts deterministically across 10 governance dimensions and auto-generates the complete AI-governance evidence package for ATO preparation — the AI-system portion of the body of evidence, including machine-readable OSCAL (SSP + POA&M) that feeds an OSCAL-native authorization platform. A complementary Runtime (RT) enforcement layer — designed to gate agentic tool calls inline against approved policy — is architected and in development, not yet fielded.
PromptFrame is fully air-gapped: zero external API calls, FIPS 140-3 capable (Red Hat UBI 9), AES-256-GCM encryption, HMAC-SHA256 audit chain. No LLM in the DT scoring path — same input always produces same output. Deployed as a self-hosted container stack on client infrastructure — GotHawk provides signed container images only. No client data is ever transmitted to GotHawk or any third party.
Core Capabilities
Design-Time (DT) — Governance Scoring & ATO Artifact Generation
Deterministic 10-dimension scoring of AI system prompts — no LLM in the path, C3PAO and 3PAO defensible. Auto-generates per engagement: SSP narratives, NIST SP 800-53 Rev 5 crosswalk, POA&M (FedRAMP format), GSAR 552.239-7001 (proposed) compliance checklist, SPRS export, per-dimension remediation report, and executive summary. All artifacts SHA-256 integrity-protected with HMAC-signed audit chain. Verbatim regulatory citations from primary sources throughout.
Runtime (RT) — Inline Enforcement Gate · Roadmap
A complementary runtime enforcement layer — architected and in development, not yet fielded. It is designed to sit inline with LLM and agentic toolchains and gate tool calls against approved policy before execution, logging each decision as a cryptographically signed audit record across four categories: tool authorization, scope boundary, data exfiltration attempt, and privilege escalation. The shipping product today is Design-Time.
Shadow AI & Foreign AI Detection
Retrospective workspace scanner identifies installed AI tools, browser extensions, AI-related environment variables, and network log contacts with AI endpoints. Foreign-origin contacts (DeepSeek/China, Mistral/France, etc.) flagged per GSAR 552.239-7001 §(e)(2) American AI Systems requirement (proposed rule). Supports Cisco ASA syslog, CLF, CEF, CSV, and DNS query log formats. HMAC-signed scan report produced as a standalone artifact.
AI Governance Advisory & Teaming
Fixed-scope engagements sized for small contractors through primes: OMB M-25-21 AI use-case inventory alignment, CMMC Level 2 AI governance posture review, FedRAMP Moderate AI governance gap assessment. Small contractors can engage directly — no large program required. Available as AI governance subcontractor under prime AI modernization and DoD agentic AI programs. Fixed-price SOWs available. Engagement floor: $12,500.
Regulatory Coverage
NIST AI RMF (NIST AI 100-1) — All four functions
EO 14179 — Federal AI governance & removing barriers to American AI leadership
OMB M-25-21 / M-25-22 / M-26-04 — Federal AI policy
GSAR 552.239-7001* — 14 paragraphs mapped at clause resolution
NIST SP 800-53 Rev 5 — 10 control families (AU/AC/IA/SI/CM/CP/PL/SA/SC/MP)
CMMC Level 2 / NIST SP 800-171 Rev 2 — 110 practices
PA EO 2023-19 — Pennsylvania responsible AI
*Proposed — pending GSA finalization
Differentiators
- Produces the design-time governance evidence federal AI deployment requires — DT scoring + ATO artifact generation + machine-readable OSCAL; a roadmap RT layer would extend coverage to the runtime portion of the lifecycle
- Maps GSAR 552.239-7001 at paragraph resolution (14 paragraphs); GotHawk submitted a formal public comment on the proposed rule (April 3, 2026) recommending GSA add a design-time documentation requirement — the governance gap PromptFrame was built to close
- Deterministic scoring — no LLM in the DT path; same input always produces same output; independently verifiable and C3PAO defensible
- Air-gap native — FIPS 140-3 capable, AES-256-GCM, HMAC-SHA256 audit chain; zero external API calls; CUI-environment ready
- The roadmap RT gate is designed so every decision is cryptographically signed and independently verifiable — not inferred risk scores from an AI model