[{"data":1,"prerenderedAt":185},["ShallowReactive",2],{"navigation":3,"legal":48,"software-assurance":88},[4,23],{"title":5,"path":6,"stem":7,"children":8,"icon":22},"Getting Started","\u002Fdocs\u002Fgetting-started","1.docs\u002F1.getting-started\u002F1.index",[9,12,17],{"title":10,"path":6,"stem":7,"icon":11},"Introduction","i-lucide-house",{"title":13,"path":14,"stem":15,"icon":16},"Installation","\u002Fdocs\u002Fgetting-started\u002Finstallation","1.docs\u002F1.getting-started\u002F2.installation","i-lucide-download",{"title":18,"path":19,"stem":20,"icon":21},"Usage","\u002Fdocs\u002Fgetting-started\u002Fusage","1.docs\u002F1.getting-started\u002F3.usage","i-lucide-sliders",false,{"title":24,"path":25,"stem":26,"children":27,"page":22},"Essentials","\u002Fdocs\u002Fessentials","1.docs\u002F2.essentials",[28,33,38,43],{"title":29,"path":30,"stem":31,"icon":32},"Markdown Syntax","\u002Fdocs\u002Fessentials\u002Fmarkdown-syntax","1.docs\u002F2.essentials\u002F1.markdown-syntax","i-lucide-heading-1",{"title":34,"path":35,"stem":36,"icon":37},"Code Blocks","\u002Fdocs\u002Fessentials\u002Fcode-blocks","1.docs\u002F2.essentials\u002F2.code-blocks","i-lucide-code-xml",{"title":39,"path":40,"stem":41,"icon":42},"Prose Components","\u002Fdocs\u002Fessentials\u002Fprose-components","1.docs\u002F2.essentials\u002F3.prose-components","i-lucide-component",{"title":44,"path":45,"stem":46,"icon":47},"Images and Embeds","\u002Fdocs\u002Fessentials\u002Fimages-embeds","1.docs\u002F2.essentials\u002F4.images-embeds","i-lucide-image",{"id":49,"extension":50,"meta":51,"stem":52,"trademarkNotice":53,"trademarksPage":54,"__hash__":87},"legal\u002Flegal.yml","yml",{},"legal","Aesir Systems, the Aesir logo, and all related product names are trademarks of Aesir Systems, Inc. All other trademarks are the property of their respective owners.",{"title":55,"description":56,"intro":57,"marks":58,"otherMarks":86},"Trademarks","The trademarks and service marks of Aesir Systems, Inc.","The following are trademarks of Aesir Systems, Inc. in the United States. Use of these marks requires the prior written permission of Aesir Systems, Inc. This list is not exhaustive, and the absence of a mark from this list does not waive any intellectual property rights that Aesir Systems, Inc. has established in its marks.",[59,62,65,68,71,74,77,80,83],{"name":60,"generic":61},"Aesir Systems™","company name and house mark",{"name":63,"generic":64},"Aesir Systems Automation Platform™","security compliance automation platform",{"name":66,"generic":67},"Aesir Systems Automation Content™","security hardening and validation content library",{"name":69,"generic":70},"Aesir Systems Bifrost™","compliance knowledge engine and API",{"name":72,"generic":73},"Aesir Systems Vara™","compliance assessment and visualization platform",{"name":75,"generic":76},"Aesir Systems Sindre™","security guidance authoring platform",{"name":78,"generic":79},"Aesir Systems Mimir™","security-compliance AI engine",{"name":81,"generic":82},"Aesir Systems Wellspring™","compliance AI appliance",{"name":84,"generic":85},"Order over Chaos™","company tagline","All other trademarks, service marks, and trade names referenced on this site — including those of standards bodies, open-source projects, and technology partners — are the property of their respective owners, and their use does not imply any affiliation with or endorsement by their owners.","lliLUNkR0xLHBx8UX3rJ21bLUiKhu7cGgvGhxUoBGS0",{"id":89,"title":90,"body":91,"cta":92,"definition":106,"description":91,"extension":50,"harness":91,"hero":114,"matrix":117,"meta":151,"navigation":152,"path":153,"practice":154,"pyramid":91,"seo":160,"stem":163,"themes":164,"__hash__":184},"assurance\u002Fsoftware-assurance.yml","Software Assurance",null,{"title":93,"description":94,"links":95},"Where Is Your Program's Assurance Bottleneck?","See the platform that runs this lifecycle end to end — or start with the open standard underneath it.",[96,100],{"label":97,"to":98,"icon":99},"Explore the Platform","\u002Fplatform","i-lucide-layout-dashboard",{"label":101,"to":102,"color":103,"variant":104,"trailingIcon":105},"Standards & Open Source","\u002Fstandards","neutral","subtle","i-lucide-arrow-right",{"title":107,"intro":108,"items":109,"outro":113},"What Is AI-Driven Software Assurance?","AI-driven software assurance is the practice of constantly proving your software is safe and compliant, including all its applications, its pipelines, and its AI components, by using:",[110,111,112],"Machine-readable standards for evidence","Automated verification against authoritative requirements","AI that answers from cited sources rather than generated guesses","It replaces point-in-time, document-driven assessment with assurance that operates at the speed of AI.",{"headline":115,"description":116},"AI-Driven Software Assurance","With the advent of AI, software engineering now moves at machine speeds. Trust, however, still moves at human speed.",{"title":118,"description":119,"phases":120,"targets":126},"Three Key Targets to Achieve Software Assurance","Assurance must span across the software lifecycle and be applied to three targets. Read across the columns and the pattern compounds below. Supply-chain assurance is application assurance shifted into the pipeline. AI assurance is supply-chain assurance applied to models.",[121,122,123,124,125],"Specify","Verify","Evidence","Argue","Watch",[127,135,143],{"name":128,"cells":129},"Applications",[130,131,132,133,134],"Baselines and tailored guidance","Hardening and validation content","Scan results, normalized","ATO posture and readiness","Continuous compliance",{"name":136,"cells":137},"Pipelines & supply chain",[138,139,140,141,142],"Pipeline gates as requirements","CI\u002FCD-embedded checks and SBOM scans","SBOMs and attestations on the same evidence spine","Continuous authorization","Every commit re-verified",{"name":144,"cells":145},"AI models & agents",[146,147,148,149,150],"Model behavior policies","Accuracy measured against deterministic ground truth","Training provenance and cited retrievals","AI subsystem accreditation","Drift detection and controlled updates",{},true,"\u002Fsoftware-assurance",{"title":155,"paragraphs":156},"Building at the Frontier of Secure AI",[157,158,159],"At Aesir Systems, we push agentic AI to its limits but with a steady hand. It is the only way to truly know what these systems are capable of, where the risks live, what securing them actually means, and what is still missing. We conduct research programming by driving the tool to its limits, instrumenting everything, and letting the practice teach us.","Every AI-assisted change at Aesir Systems is planned against written acceptance criteria, bound by rules the assistant operates under and cannot override, and independently verified before it is accepted. Trust-but-verify is engineered into the development loop.","We built our careers defining secure software standards at the frontier, and we are doing it again for the AI era.",{"title":161,"description":162},"AI-Driven Software Assurance — Aesir Systems","Software now moves at machine speed. Trust has to keep up. AI-driven software assurance covers applications, pipelines, and AI itself with machine-readable evidence, automated verification, and AI that cites its sources.","software-assurance",{"title":165,"description":166,"items":167},"Practices for AI-Driven Software Assurance","Focus areas for assurance across the software development lifecycle.",[168,172,176,180],{"title":169,"description":170,"icon":171},"Software Supply Chain","SBOMs, AIBOMs, attestations, waivers, risk adjustments -- all are necessary components of the evidence package. They are normalized into the same standard format, connected to the requirements they satisfy, and re-verified as components change.","i-lucide-boxes",{"title":173,"description":174,"icon":175},"Pipeline & Application Assurance","Assurance shifts into the pipeline. Gates become requirements. Checks run on every commit. The evidence for your authorization assembles itself as you build.","i-lucide-git-branch",{"title":177,"description":178,"icon":179},"Continuous Compliance","Frameworks change, systems change, and threats change. But posture is recomputed as evidence arrives, not reconstructed annually, so the assurance case is always current.","i-lucide-refresh-cw",{"title":181,"description":182,"icon":183},"AI-Aware SDLC & Agentic Workflows","AI agents in the development lifecycle are part of the security boundary. Their access is governed, their outputs are verifiable, and the systems they touch stay continuously assured.","i-lucide-bot","DK-PeM4QRjhnJE0REq8rzLZsHU96G0zAa0q8tnL0Krc",1788836106141]