Foxx Cyber vCISO
A personal virtual CISO you talk to in plain English. It keeps your risk register, policies and decisions in order, and changes nothing without your say-so.
Pricing on request
Foxx Cyber builds security software for businesses too small to hire a security team: a personal virtual CISO that talks to you, Bedrock CMMC for defense contractors who need Level 2, and Flowdown for the primes who manage them. Create one account and pick what you need.
The full story of each product lives on its own site. This page is the short version, and the door.
A personal virtual CISO you talk to in plain English. It keeps your risk register, policies and decisions in order, and changes nothing without your say-so.
Pricing on request
Build and mature your CMMC Level 2 package, then hand it to your assessor without rebuilding it. One chain of custody from control narrative to SPRS affirmation.
From $149/month
A live roster of your subcontractors' CMMC and DFARS status, evaluated against the level each contract flows down. Subs update through a private link.
Pricing on request
One account, one bill, one place to manage your team and reach support.
1
An email and a password, verified. It is the account you use for every product, so you only ever do this once.
2
Monthly or annual, paid by card through Stripe. Change or cancel from your account page, not by emailing anyone.
3
We provision the product, send you the activation link, and you sign in there. Billing, your team and support stay here.
Foxx Cyber is a practitioner shop, not a marketing one. The proof we offer is the kind you can verify.
Founded by an active CMMC-domain practitioner with DoD and Air National Guard background.
Foxx Cyber pursues its own Level 2 on Bedrock CMMC, and publishes the security posture behind every product.
Skein, Loom, Bedrock RMF and more are public at gitlab.com/foxxcyber-oss. Read the code before you trust it.
Free, unofficial, no sign-up
We read the same regulations you do, so we published a plain-language reading aid: every one of the 110 requirements with the original text beside it, a worksheet for the CUI question, and a straight answer on Rev. 2 versus Rev. 3.
The plain version, the verbatim wording, the assessment objectives, and the SPRS weight. One page each.
Three questions, at mostEnds in a determination or the exact email to send your contracting officer. Over-protecting is recoverable.
Status firstWhat your contract requires today, what NIST has published, and why those are different things.
Practitioner guides
Creating an account costs nothing and commits you to nothing. Plans, billing, your team and support all live behind it.