← Back to case studies

Garde1 by Complai Solutions: A CMMC Compliance Operating System Built From Scratch

Garde1 by Complai Solutions · Defense contractor compliance

The Challenge

CMMC compliance traditionally costs Defense Industrial Base contractors $50K to $200K in consultants and 6 to 12 months of manual work. Complai Solutions set out to turn that process into software.

The vision required measuring all 110 NIST SP 800-171 controls and 320 assessment objectives against contractors' live systems, continuously. No existing low-code or off-the-shelf tool could carry that load.

Key Challenges Faced

No Off-the-Shelf Fit
The problem was too complex and too regulated for configuration tools. It demanded a platform engineered from the ground up.
Regulatory Complexity at Scale
110 controls, 320 assessment objectives, 14 CMMC domains, and native SPRS scoring from -203 to +110, all modeled into a working evaluation engine.
Live Evidence, Not Screenshots
Compliance had to be proven from real system configuration, pulled automatically from 20+ security platforms and Windows endpoints, not from manually gathered PDFs.
Audit-Grade Integrity
Assessors, the C3PAOs who certify contractors, must trust the output. Every artifact needed versioning, content hashing, full traceability, and signed exports.

The Solution

TekConnected engineered a ground-up platform from scratch. Meeting all four constraints at once ruled out spreadsheets with automations bolted on and any rented workflow tool.

What We Engineered

Cloud-Native Web Application
Six integrated product modules in one system of record, hosted on AWS.
Connector Framework
20+ OAuth and API integrations across identity, cloud, endpoint, SIEM, and vulnerability tools.
Windows Endpoint Agent
A lightweight service collecting device-level evidence daily across the customer's fleet.
Multi-Workflow Evaluation Engine
Scores all 110 controls and 320 objectives against live evidence.
Tool-Grounded AI Assistant
The Garde1 Consultant answers cited to the organization's real controls and evidence, with no open-web lookups.
C3PAO Auditor Portal
Role-based, signed, tamper-evident audit exports.

Approach and Strategy

Domain-First Architecture
TekConnected modeled the full NIST SP 800-171 control set and its 320 objectives before building the interface, so the data model mirrored the regulation.
Evidence Pipeline Design
The connector and agent layer maps raw system data to specific controls automatically, eliminating manual screenshot collection.
Deterministic Evaluation Logic
Scoring reflects measured reality through native SPRS scoring, not policy text.
Audit-Grade Data Integrity
Version control, SHA-256 content hashing, and end-to-end traceability built into every document and evidence record.
Continuous Monitoring
Scheduled re-evaluation and drift detection so compliance holds after the assessment, not just before it.

The build case is that some problems outgrow no-code. When the logic runs this deep, across 320 objectives, deterministic scoring, and audit-grade integrity, configuration tools hit a ceiling. A purpose-built platform becomes the product itself: defensible IP rather than a rented workflow.

Technology Stack

Next.jsSupabaseAI/LLMVercel

Results & Outcomes

110 / 110 Controls Modeled
Full NIST SP 800-171 Rev. 2 coverage.
320 Assessment Objectives
Built into the evaluation engine.
14 CMMC Domains
Scored on a live compliance dashboard.
20+ Pre-Built Connectors
Plus a Windows agent for automated evidence collection.
6 Integrated Product Modules
In a single platform.
C3PAO Auditor Portal
Live and functional.

Strategic Impact

  • From paperwork to measurement: compliance proven from live systems, not static documents.
  • Out of MVP, in production: Garde1 is live and running real assessments at app.garde1.com.
  • Built to extend beyond CMMC, with architecture designed to layer additional frameworks (FedRAMP, ISO, SOC 2) over time.
  • Software economics: designed to replace $50K to $200K consultant engagements with a continuous SaaS workflow.
  • Assessor-trusted output: signed, versioned, fully traceable evidence packages.

Who This Applies To

This build pattern fits an organisation that:

  • Faces regulatory logic too deep for configuration tools to model
  • Must prove compliance from live system configuration rather than gathered screenshots
  • Needs an external auditor to trust versioned, hashed, fully traceable output
  • Wants a purpose-built platform as defensible IP instead of a rented workflow

Case Study Slides

Garde1 by Complai Solutions, slide 1Garde1 by Complai Solutions, slide 2Garde1 by Complai Solutions, slide 3Garde1 by Complai Solutions, slide 4Garde1 by Complai Solutions, slide 5Garde1 by Complai Solutions, slide 6Garde1 by Complai Solutions, slide 7

Ready to build your system?

Book a 30-minute strategy call. We'll map your workflow and tell you exactly what a build would look like.

Book a strategy call →