PQC-Khepra MCP — CMMC Autopilot & AI Security Recorder
Official7 tools
by nouchix · TypeScript
Post-quantum CMMC compliance scanner & AI agent attestation. FIPS 140-3, ML-DSA-65, 36K+ mappings.
io.github.nouchix/pqc-khepra-mcp (MCP)
This MCP server provides a post-quantum CMMC compliance scanner and an AI agent attestation workflow. Its focus includes FIPS 140-3 and ML-DSA-65, along with “36K+ mappings,” indicating the volume of referenced compliance or technical mappings used by the scanner.
🛠️ Key Features
Post-quantum CMMC compliance scanning
AI agent attestation
FIPS 140-3 support
ML-DSA-65 support
36K+ mappings
🚀 Use Cases
Assessing CMMC-related compliance in post-quantum contexts
Verifying or documenting AI agent attestation requirements
⚡ Developer Benefits
Tooling aligned to stated post-quantum standards (FIPS 140-3, ML-DSA-65)
Large mapping set (“36K+”) to support compliance checks
⚠️ Limitations
Available documentation excerpt does not describe specific MCP tools, endpoints, inputs, or output formats beyond the stated capabilities.
Declared in the repository manifest (server.json). Not verified against a live endpoint.
ert_scan
Enterprise Risk & Threat (ERT) scan. Runs full STIG/CMMC/NIST 800-171 compliance scan and returns prioritized findings with dollar-denominated risk scores.
Parameters
No parameters.
stig_check
Validate a system path or configuration file against RHEL-09-STIG controls. Returns pass/fail per control with remediation steps.
Parameters
No parameters.
nist_map
Map CCI identifiers or STIG findings to NIST 800-53 Rev 5 controls. Uses 36,195 pre-computed cross-framework mappings (STIG → CCI → NIST → CMMC).
Parameters
No parameters.
cmmc_assess
Assess a system or artifact against CMMC Level 1, 2, or 3 practices. Returns a scored maturity report per practice domain.
Parameters
No parameters.
godfather_report
Generate a Godfather Report — an executive-facing, dollar-denominated cyber risk report from prior scan results. Suitable for C-suite and board briefings.
Parameters
No parameters.
attest_export
Export a PQC-signed (ML-DSA-65 / NIST FIPS 204) attestation package accepted by C3PAO intake, cyber insurance carriers, and RFP submissions.
Parameters
No parameters.
agent_record
Send AI agent tool calls and outputs to the SouHimBou AI Flight Recorder for tamper-evident capture with DAG-anchored PQC attestation.
Post-Quantum Cryptographic & Autonomous Flight Recording Kernel for AI Agents.
Air-gappable. Zero cloud telemetry. Zero token overhead.
Provides FIPS 203 (ML-KEM-768) and FIPS 204 (ML-DSA-65) post-quantum cryptographic signatures on every tool call, autonomous client-side NDJSON flight recording, and local host/asset discovery. Completely free and open-source under Apache 2.0.
Patent Reference: U.S. Prov. App. No. 63/942,886 (KHEPRA Protocol & Post-Quantum Evidence Weave) Corporate Identity: SecRed Knowledge Inc. (operating as NouchiX) — Delaware C-Corp (EIN 99-0529252), SDVOSB (Active Self-Certified / SBA VetCert in review), Active Secret Clearance. Live hosted endpoint:https://mcp.souhimbou.ai/sse — zero install, connect in 30 seconds. Self-host for sovereign/air-gap:Docker or binary.
Architecture: Free Community Kernel vs. KTOS Commercial Platform
To ensure clean commercial boundaries for partners, defense contractors, and developers, the KHEPRA ecosystem operates across two distinct layers:
Layer
Product
License
Scope & Capabilities
Layer 1
PQC-Khepra-MCP (This Repo)
Apache 2.0 (Open Source)
Free Community Kernel: ML-DSA-65 / ML-KEM-768 PQC cryptographic signing, client-side autonomous flight logging, agent registration, local host/asset enumeration, and threat lookup. Zero STIG or compliance databases.
Layer 2
KHEPRA Trust OS (KTOS)
Commercial ($499/mo to $250K/yr)
Sovereign Proof-and-Actuation OS: 36,195 cross-framework compliance mappings, live DISA STIGViewer API v2 batch crosswalks, CMMC Level 2/3 assessments, ERT multi-package engines, automated C3PAO evidence packages (OSCAL, DISA CKLB, signed POA&Ms), and bounded autonomous host remediation.
Tiers & Gating (The 4-Tier Commercial & Sovereign Model)
Health check: https://mcp.souhimbou.ai/mcp/v1/health
Data note: The hosted endpoint runs in edge mode — DAG is in-memory and ephemeral. For persistent, signed audit trails and air-gap deployment, use the self-hosted options below.
Self-Hosted Installation
For sovereign/air-gap deployment: Docker (recommended, no build required) or compiled binary (fastest startup, SCIF-ready). Both support the same environment variables and all MCP clients.
Requires Docker Desktop or Docker Engine. The image is pre-built and ships the full compliance database — no additional downloads in sovereign mode.
bash
# Pull once
docker pull ghcr.io/nouchix/pqc-khepra-mcp:latest
# Test it (should print the initialize response and exit)echo'{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":0}' \
| docker run --rm -i -e KHEPRA_MODE=sovereign ghcr.io/nouchix/pqc-khepra-mcp:latest
Option B: Compiled Binary
Requires Go 1.21+ for building, or download a pre-built release from GitHub Releases.
bash
git clone https://github.com/nouchix/PQC-Khepra-MCP.git
cd PQC-Khepra-MCP
# Build (cross-compile for your OS)
go build -o khepra-mcp ./cmd/khepra-mcp # Linux / macOS
go build -o khepra-mcp.exe ./cmd/khepra-mcp # Windows# Test the binaryecho'{"jsonrpc":"2.0","method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"test","version":"1.0"}},"id":0}' \
| KHEPRA_MODE=sovereign ./khepra-mcp
Windows — using the batch launcher
The repo ships a run-mcp.bat launcher for Windows. It uses the pre-built binary (fast path) and falls back to go run automatically:
bat
:: run-mcp.bat is already in the repo at the root of PQC-Khepra-MCP
:: Point your MCP client to: cmd /c C:\path\to\PQC-Khepra-MCP\run-mcp.bat
Example:"Run pqc_stig on my project and tell me if I'm CNSA 2.0 compliant"
nist_map
Map CCI identifiers or STIG findings to NIST 800-53 Rev 5 controls.
khepra_query_stig
Query the 36,195-row STIG/CCI/NIST/CMMC compliance database by control ID.
dark_crypto_contribute(opt-in)
Contribute anonymized cryptographic algorithm telemetry to the SouHimBou AI Dark Crypto Intelligence Network. No PII. Opt-in only — never fires without explicit invocation.
Pro / Enterprise / Sovereign Tier
ert_scan
Enterprise Risk & Threat scan across STIG, NIST 800-53, NIST 800-171, CMMC, and FedRAMP. Returns Godfather Report with dollar-denominated business impact.
Example:"Run ert_scan on /etc and generate a Godfather Report"
stig_check
Automated RHEL-09-STIG-V1R3 compliance scan against a live system or configuration path.
cmmc_assess
Full CMMC Level 1, 2, or 3 assessment with gap analysis and POA&M generation.
godfather_report
Generate an executive Godfather Report from prior scan results: top 10 findings ranked by dollar exposure, remediation ROI, and FAIR model business impact.
KHEPRA makes zero external network calls in sovereign and ironbank modes:
License validated offline via ML-DSA-65 signed license.adinkhepra file
Compliance databases (36,195 mappings) bundled in container — no external downloads
No telemetry, no heartbeat, no egress — verified at the transport layer
bash
# Transfer image to air-gapped network
docker save ghcr.io/nouchix/pqc-khepra-mcp:latest | gzip > khepra-mcp.tar.gz
# On air-gapped host:
docker load < khepra-mcp.tar.gz
Note on telemetry: The dark_crypto_contribute tool (Community tier) sends anonymized cryptographic algorithm telemetry to the SouHimBou AI intelligence network only when explicitly invoked by the user. It is never triggered automatically. In sovereign/ironbank mode, all network calls are blocked at the transport layer regardless.
Compliance Coverage
Framework
Version
Mappings
STIG (RHEL 9)
V1R3
Automated scanning
NIST 800-53
Rev 5
2,120 CCIs
NIST 800-171
Rev 2
320 controls
CMMC
Level 3
Full practice set
FedRAMP
High
Baseline scanning
PQC-01-STIG-V1R1
V1R1
17 PQC controls (CNSA 2.0)
Total
36,195+ mappings
Licensing
No per-token or per-query charges on any paid tier.
We accept encrypted reports via PGP (keys/security_contact.asc) and Post-Quantum channels (Dilithium / ML-DSA-65 keys in keys/). See SECURITY.md for the full disclosure policy and ASAF event taxonomy.
Security Posture
Deploying advanced post-quantum cryptography, air-gapped isolation, and comprehensive STIG mappings — built in direct alignment with NSA & ASD Model Context Protocol guidelines.
NSA & ASD MCP Security Alignment
The NSA and Australian Signals Directorate (ASD) have published specific threat vectors for AI systems interacting with local environments. KHEPRA MCP is explicitly designed to mitigate every identified vector:
NSA/ASD Requirement
KHEPRA Implementation
Cryptographic validation of tool responses
ML-DSA-65 (Dilithium) signatures on all JSON-RPC 2.0 payloads
Input validation & sanitization
Parameter injection resistance via strict JSON Schema validation
Principle of least privilege credentials
Short-lived ephemeral tokens tied to specific task execution windows
Comprehensive audit logging
Tamper-evident events compiled into an immutable DAG structure
Resource consumption limits
Rate limiting + backpressure for LLM request loops
Authorization gates for sensitive actions
Human-in-the-loop gate for destructive state changes
Environment isolation
Containerized execution with zero-egress sovereign mode
Software supply chain integrity
Manifest pinning for all loaded tools and dependencies
Network exposure reduction
Air-gappable — zero internet transit in sovereign/ironbank modes
Post-quantum resilience
PQC-signed DAG trail protecting against harvest-now-decrypt-later
Compliance Certifications
Framework
Status
Coverage
CMMC Level 2
✅
Automates evidence collection for AU, CM, SI, SC domains
NIST SP 800-171 Rev 2
✅
Logging, accountability, system integrity
NIST SP 800-53 Rev 5
✅
Continuous monitoring (AU-2, SI-4)
FIPS 203 (ML-KEM)
✅
Key encapsulation for secure transit
FIPS 204 (ML-DSA)
✅
Digital signatures for payload authentication
NSM-10 PQC Mandate
✅
National Security Memorandum 10 compliance
DFARS 252.204-7012
✅
Immutable forensic trails for cyber incident reporting
NSA MCP Security Guidelines
✅
Direct mapping to all published AI agent threat mitigations
Live Deployment — Physical Edge
Running continuously on constrained edge hardware since May 12, 2026 to prove efficiency in sovereign environments:
Hardware: Raspberry Pi 2 · 1 GB RAM · 900 MHz ARM · Live Spectrum Router
UAlbany AI Plus Symposium 2026 — "KHEPRA Protocol: Quantum-Resilient Agentic AI Security Using Cultural Cryptography"
March 7, 2026
NSA CAE-CDE Institution · 200+ audience
SUNY Albany Cybersecurity Showcase — First PQC key ceremony on STM32-class device (SCADA Pod)
May 12–13, 2026
Live demo · SCADA architecture poster
USPTO Provisional Patent Application No. 63/942,886 — pending.
🔒 Iron Bank containers in DISA vetting process.
Open-Core Architecture Notice
PQC-Khepra-MCP is an open-source Model Context Protocol server providing Post-Quantum Cryptographic primitives (ML-DSA-65, ML-KEM-768) and compliance tooling.
Proprietary runtime governance engines—including the KHEPRA Trust Operating System (KTOS), the ASAF Policy Declaration Language (APDL) Compiler, the Evolutionary Algorithm Lattice Auto-Tuning Kernel, the SEKHEM Polymorphic WAF Gateway, and the Full-Stealth Sovereign Mesh—are components of Khepra Enterprise and are licensed under commercial terms.
Find Us — MCP Registry Listings
PQC-Khepra-MCP is listed on every major MCP discovery platform:
Developed by SecRed Knowledge Inc. dba NouchiX, Albany, NY.
📋 TC-25 Operator Manual & Developer Runbook
PQC-Khepra-MCP is the open-core agent channel of the KHEPRA Trust OS (KTOS) architecture:
TC-25 Technical Operator & Maintenance Manual — Training Circular No. 25-KTOS-001 covering Four-Layer Sovereign Architecture, Tactical RF anti-jamming suite, Windows Event Viewer hierarchy (IDs 1001–1050), and Dual-Engine Adversarial Neutralization (58/58 Verified).
Developer Installation & Troubleshooting Runbook — Step-by-step runbook for Master Dev Machines, Antigravity IDE (mcp_config.json), Claude Code (.claude.json), and Sovereign Linux VPS deployment.