Built from 10 years
in the field.

Solo-founder product from 10 years of federal RMF/ATO work. No investors, no sales team.

Cameron Stihel

Cameron Stihel

Founder & Developer

Certifications

CISSPCASP+

Verifiable on LinkedIn

Why this exists

I spent 10+ years in federal cybersecurity and DevSecOps — guiding systems through RMF/ATO lifecycles, leading cyber teams, managing security controls in eMASS, and building automation to cut down manual compliance work.

The same problem kept showing up: security teams spending more time writing documentation than doing security work. Drawing network diagrams in Visio, tracking controls in spreadsheets, copy-pasting boilerplate into Word templates, and assembling authorization packages by hand.

I built CompliNIST to solve the specific problem I kept running into. It's not a generic GRC platform that tries to cover 30 frameworks. It's a focused tool for teams that need to produce NIST 800-53 ATO packages — built by someone who's actually had to produce them.

Background

  • Guided federal systems through full RMF authorization lifecycles
  • Led cybersecurity teams and managed security controls in eMASS
  • Built DevSecOps pipelines and compliance automation tooling
  • Written hundreds of NIST 800-53 control narratives across LOW, MODERATE, and HIGH baselines

How the product is built

100% local processing

Your network diagrams, SSPs, and control narratives stay in a Docker volume on your machine. No telemetry, no analytics, no cloud sync.

Works offline

After pulling the Docker image, the app runs fully offline. Build topologies, write narratives, and generate SSPs without an internet connection. Suitable for air-gapped networks and environments with strict data-handling requirements.

No cloud dependency

The CompliNIST Docker app does not sync compliance data to the cloud. Website accounts (Clerk) and optional subscriptions (Stripe) are separate from running the app — no account required to use the full toolkit.

Responsible disclosure

Security issues can be reported to cam@complinist.com with a 24-hour response commitment. Full policy on the vulnerability disclosure page.

Company

CompliForged LLC

Parent company

United States

Based & operated

cam@complinist.com

Direct line to the founder

Built for teams who hate manual SSP assembly