Upload your product docs, Protection Profiles, and reference STs. CC ST Builder generates a CC:2022-compliant Security Target in DITA XML, DOCX, or PDF — with full traceability from every SFR back to source page, and an evaluator-ready validation report.
A Security Target is the single most important document in a Common Criteria evaluation — and the most painful to write. Mapping product architecture into CC vocabulary. Translating threats into SFRs. Keeping traceability between objectives and Part 2 identifiers. Re-reading Annex D for the seventh time to check section depth. Then re-doing it all when the Protection Profile gets revised.
Most teams spend 4 to 12 weeks on a single ST. We make it hours — not by removing the engineer, but by removing the bookkeeping.
Linear flow, backward navigation always allowed, resumable jobs.
Name the project. Pick product type (25+ categories from HSM to firewall to IoT device). Set target EAL. Pick a Reference ST and optional Protection Profile.
Upload product docs (PDF, TXT, MD, XML, DITA). Multimodal vision pass extracts text and diagrams. Live progress with page and chunk counts.
AI builds a structured security model: TOE, Assets, Threats, Assumptions, OSPs, Security Functions, Crypto Mechanisms. Every item is inline-editable.
Generate the full CC ST in three sequential batches with frozen-state injection: Chapters 1-2, then 3-5, then 6-7. SFRs validated against Part 2 identifiers.
AI Review Agent runs SFR→Threat coverage, orphan detection, missing rationales, PP conformance gaps. Outputs a deterministic Certification Readiness Score.
DITA XML, DOCX, or PDF, with branding customisation and multi-language support.
Three model tiers with automatic fallback — Understand AI (private), GPT-4.1 (default), Mistral Medium (fast). Strict JSON schema enforcement with retry-on-malformed-JSON. Frozen-state injection keeps the seven chapters internally consistent.
CC:2022 Rev 1 / ISO/IEC 15408 Part 1 Annex D structure. Protection Profile auto-detection with lock badges for PP-mandated items. Cryptographic mechanisms aligned to FCS_COP.1. Built-in CC Part 2 SFR catalogue and Part 3 SAR catalogue.
Handles 1,000+ page documents without data loss. Async job orchestration with claim, 300-second lease, 20-second heartbeat state machine. Concurrency-controlled to protect inference backends.
6-step guided wizard with resumable state. Inline editing on every extracted item. Floating CC Assistant widget for ad-hoc questions during any step. Real-time animated feedback during AI processing gaps.
DITA XML (preferred), DOCX with dynamic headers and page numbering, and PDF. Custom logos, footers, and multi-language export (EN default).
Per-user Master Key API provisioning with manual rotation. Optional client-side encryption for Understand AI traffic. No email persistence — identity is derived from Firebase JWT only. Enterprise subscription gate.
Knows CC vocabulary. Annex D layout in muscle memory. SFR identifiers validated against the actual CC Part 2 catalogue, not pattern-matched from training data.
Architecture diagrams, dataflow drawings, and component layouts are read, not skipped. Pages with diagrams go through a multimodal vision pass at 1.5x rendering scale.
Every Asset, Threat, Assumption, OSP, Objective, SFR, and SAR is linked back to source document, page range, and chunk index. An evaluator can audit any claim in two clicks.
The Certification Readiness Score is a formula, not an LLM opinion. SFR coverage, orphan detection, rationale completeness, PP conformance — all measurable and reproducible.
Stops re-typing the same ST sections for every client. Reuses Reference STs as style templates without copy-paste drift.
Translates internal architecture docs into CC language without learning the full standard. The AI knows the vocabulary; you stay in your domain.
Receives a clean, pre-validated, traceable ST that drastically shortens the EOR cycle — no more chasing missing rationales or orphan SFRs.
Built against the actual standard, not a paraphrase. SFR identifiers validated by regex against the CC Part 2 catalogue on every ST generation.
The same multimodal AI infrastructure that runs across the Understand Tech platform — tuned for technical security documentation.
Use Understand AI for fully private inference — product documentation never leaves your perimeter. Critical for customers under NDA or export-controlled.
developer.understand.tech endpoints handle the diagram-reading pass that no general-purpose chatbot does reliably. Architecture drawings become structured security context.
Understand AI, GPT-4.1, and Mistral Medium. Automatic fallback if a tier is unavailable. Choose by privacy, speed, or cost.
