One method. Two editions. What actually differs.
The editions differ by the standards they read against and the handling regime they run in. The engine, the record, the custody rules, and the gates are one. Choose by the regime your mission answers to, not by size.
| NatSec natsec.cloud-waypoint.com | PubSec pubsec.cloud-waypoint.com | |
|---|---|---|
| Reads against | DoD Cloud Computing Security Requirements Guide, IL5 and IL6, on NIST SP 800-53. | FedRAMP High and FISMA High on NIST SP 800-53. |
| Handling | Enclave and offline. Non-CUI by default; CUI on approved devices; never above. | Non-CUI by default. Lighter handling; the same custody rules. |
| Where the record lives | One self-contained file on the engagement's own machine. Nothing fetched, no telemetry, no account. | Local-first, the same single record, saved as a file the consultant exports. |
| At closeout | A client pack of documents only, beside the practice's full pack, and an erasure of the engagement from the machine with a printed receipt. | The same fifteen deliverables, the same handoff files, the same sealed record. |
| Studio | The CairnOps workbench: one file, every lens. | The Cloud Waypoint Studio. |
| Palette | Navy and gold | Pine and copper |
Each edition is a standards profile over the same engine. The visible difference is the word, the mark, and the palette; nothing in the method changes.
The rails are the same in both rooms.
The same calendar, the same record, the same handoff files.
Target posture, pace, funding, architecture, risk acceptance, and every authorization decision stay with the people who hold that authority.
Nothing is met vacuously. What the record does not hold is shown as not yet, never as zero.
Every inference waits in a queue with its reason and its source until a named person accepts it.
Exports and prints say what they lack. No figure is compiled into the build.
Sustainability is the acceptance test on every deliverable.