Framework · Security controls
800-53 evidence from where AI traffic crosses your boundary.
Meilynx sits between your applications and the models and tools they call. It applies access and information-flow policy inline, keeps a hash-chained record of every decision, and maps that evidence to NIST SP 800-53 Rev. 5 controls, one row per control.
Systems assessed against the federal control catalog.
Agencies, the contractors and service providers whose systems are assessed against 800-53, and organizations that build their own control sets on it. When AI enters the system, the assessor asks how those calls are controlled and recorded.
Where each family acts
Your applications and agents
Pointed at Meilynx with one endpoint change
Meilynx data plane
- IAAgent credentials verified
- ACModel, tool and agent access decided inline
- SCThe managed interface: only configured upstreams, TLS 1.2 or later
- SIDetectors, redaction and output filtering
Models and tool servers
Providers and agent tools you configure
- SRInventoried from traffic
- CMVersioned, digest-pinned policy baseline and change record
- AUHash-chained record of every decision, independently verifiable
Your applications and agents
Pointed at Meilynx with one endpoint change
Meilynx data plane
- IAAgent credentials verified
- ACModel, tool and agent access decided inline
- SCThe managed interface: only configured upstreams, TLS 1.2 or later
- SIDetectors, redaction and output filtering
Models and tool servers
Providers and agent tools you configure
- SRInventoried from traffic
- CMVersioned, digest-pinned policy baseline and change record
- AUHash-chained record of every decision, independently verifiable
Each control, to the evidence behind it.
Every row in the package carries one of four statuses, and the gaps stay on the list.
Status of the 39 controls in the package, by family
| Family | Enforced | Evidenced | Partial | Gap |
|---|---|---|---|---|
| AC Access Control | 2 | 1 | 2 | 0 |
| AU Audit and Accountability | 0 | 6 | 6 | 1 |
| CM Configuration Management | 1 | 3 | 2 | 0 |
| IA Identification and Authentication | 0 | 1 | 2 | 0 |
| SC System and Communications Protection | 1 | 0 | 4 | 1 |
| SI System and Information Integrity | 1 | 1 | 2 | 0 |
| SR Supply Chain Risk Management | 0 | 0 | 1 | 1 |
NIST SP 800-53 Rev. 5 → Meilynx controls
| Requirement | How Meilynx maps | Examination artifact |
|---|---|---|
Enforce approved authorizations for access 800-53 · AC-3 | Model allowlists, tool allowlists and a per-agent tool matrix are applied inline, before a request reaches a model or a tool. A refused call is recorded with the rule that refused it. | Access decisions and the refusals they produced |
Control the flow of information between systems 800-53 · AC-4 | Personal data, health data and credentials in prompts, responses and tool payloads can be blocked or redacted at the boundary, following the action your team sets for each detector. | Detection findings by category |
Log the events your audit function needs, with their content 800-53 · AU-2, AU-3 | Every model request, agent tool call, policy decision and administrative action produces a record: what happened, when, through which model, on whose behalf, and the outcome. | The audit record for the period |
Protect audit information from modification and deletion 800-53 · AU-9 | Records are hash-chained, so a change or a removal is detectable, and anyone holding the records can recompute the chain with an open verifier. In Fully Managed deployments the records sit in write-once storage under a locked retention period. | Integrity verification guide |
Keep a baseline and control changes to it 800-53 · CM-2, CM-3 | Policy is published as a versioned, digest-pinned bundle, each publication is recorded with the person who made it, and changes to system prompts and tool definitions are detected against an approved baseline. | Policy snapshot and change record |
Provide only the functions the mission needs 800-53 · CM-7 | Provider-run tools such as hosted search and code execution are refused unless allowed, and each agent tool server exposes only the tools assigned to it. | Allowed tools and the refusals outside them |
Monitor the system for attacks and unauthorized use 800-53 · SI-4 | Detectors watch prompts, responses and tool payloads for sensitive data, credentials and prompt-injection markers, and changed prompts, changed tools and unregistered agents raise findings. | Findings, with the rule and the action taken |
Filter information output 800-53 · SI-15 | Responses can be redacted or withheld before they reach the application, streamed responses included. | Redactions and withheld responses |
Enforce approved authorizations for access
800-53 · AC-3
Maps to · Model allowlists, tool allowlists and a per-agent tool matrix are applied inline, before a request reaches a model or a tool. A refused call is recorded with the rule that refused it.
Examination artifact · Access decisions and the refusals they produced
Control the flow of information between systems
800-53 · AC-4
Maps to · Personal data, health data and credentials in prompts, responses and tool payloads can be blocked or redacted at the boundary, following the action your team sets for each detector.
Examination artifact · Detection findings by category
Log the events your audit function needs, with their content
800-53 · AU-2, AU-3
Maps to · Every model request, agent tool call, policy decision and administrative action produces a record: what happened, when, through which model, on whose behalf, and the outcome.
Examination artifact · The audit record for the period
Protect audit information from modification and deletion
800-53 · AU-9
Maps to · Records are hash-chained, so a change or a removal is detectable, and anyone holding the records can recompute the chain with an open verifier. In Fully Managed deployments the records sit in write-once storage under a locked retention period.
Examination artifact · Integrity verification guide
Keep a baseline and control changes to it
800-53 · CM-2, CM-3
Maps to · Policy is published as a versioned, digest-pinned bundle, each publication is recorded with the person who made it, and changes to system prompts and tool definitions are detected against an approved baseline.
Examination artifact · Policy snapshot and change record
Provide only the functions the mission needs
800-53 · CM-7
Maps to · Provider-run tools such as hosted search and code execution are refused unless allowed, and each agent tool server exposes only the tools assigned to it.
Examination artifact · Allowed tools and the refusals outside them
Monitor the system for attacks and unauthorized use
800-53 · SI-4
Maps to · Detectors watch prompts, responses and tool payloads for sensitive data, credentials and prompt-injection markers, and changed prompts, changed tools and unregistered agents raise findings.
Examination artifact · Findings, with the rule and the action taken
Filter information output
800-53 · SI-15
Maps to · Responses can be redacted or withheld before they reach the application, streamed responses included.
Examination artifact · Redactions and withheld responses
Every gap is a listed row.
An assessor reads where the evidence ends on the page itself. Categorization, baseline selection and the authorization decision belong to your program.
Outside the package
- Other families and controls, including physical, personnel and contingency planning.
- Your identity provider, multifactor authentication and network boundary devices.
- FIPS 140 validated cryptography, listed as a gap under SC-13 unless scoped for your deployment.
- Categorization, baseline selection and authorization, which belong to your program.
What you hand an assessor.
A package in the order an assessor works: scope, control-by-control status, the evidence by family, and how to verify the record independently.
In the package
- Control-by-control status, with each control's baseline selection.
- Access, audit, configuration, boundary and integrity evidence for the period.
- Model, provider and tool inventory, drawn from traffic.
- A scope statement listing the families and controls outside the package.
- SHA-256 integrity hash over the audit chain, with verification steps.
800-53 and the AI in your system.
What is NIST SP 800-53?
NIST Special Publication 800-53 Revision 5 is the catalog of security and privacy controls used to assess US federal information systems, and the control set behind FedRAMP and agency authorizations. NIST SP 800-53B selects controls from it into Low, Moderate and High baselines. Many regulated organizations outside government use the same catalog for their own control sets.
Does Meilynx hold a FedRAMP authorization?
No. Meilynx holds no FedRAMP authorization, and the package asserts none. It provides evidence supporting the 800-53 controls in your own system's assessment, for the AI traffic that passes through Meilynx.
Which baseline does the package cover?
The package claims no baseline. Every row shows whether NIST SP 800-53B selects that control in the Low, Moderate or High baseline, so your team can place the evidence against the baseline your system is assessed at.
Which controls are in scope?
Selected controls from seven families: access control, audit and accountability, configuration management, identification and authentication, system and communications protection, system and information integrity, and supply chain risk management. Each is marked enforced, evidenced, partial or gap, and the gaps stay on the list.
Can Meilynx run inside a disconnected environment?
Yes, in Sovereign mode: the proxy, the control plane and the verifier run inside your boundary with no connection to Meilynx.
See exactly what an examiner receives
Request a sample examination package: model inventory, control coverage, a governance policy snapshot, and a SHA-256 integrity hash.