Powered by Understand Tech Developer API

    From product documentation to a certification-ready Security Target - in hours, not months.

    Upload your product docs, Protection Profiles, and reference STs. CC ST Builder generates a CC:2022-compliant Security Target in DITA XML, DOCX, or PDF — with full traceability from every SFR back to source page, and an evaluator-ready validation report.

    Writing a Security Target takes weeks. It shouldn't.

    A Security Target is the single most important document in a Common Criteria evaluation — and the most painful to write. Mapping product architecture into CC vocabulary. Translating threats into SFRs. Keeping traceability between objectives and Part 2 identifiers. Re-reading Annex D for the seventh time to check section depth. Then re-doing it all when the Protection Profile gets revised.

    Most teams spend 4 to 12 weeks on a single ST. We make it hours — not by removing the engineer, but by removing the bookkeeping.

    Six steps. One Security Target.

    Linear flow, backward navigation always allowed, resumable jobs.

    01Setup
    02Ingest
    03Extract
    04Build
    05Validate
    06Export
    Step 01

    Setup

    Name the project. Pick product type (25+ categories from HSM to firewall to IoT device). Set target EAL. Pick a Reference ST and optional Protection Profile.

    Step 02

    Ingest

    Upload product docs (PDF, TXT, MD, XML, DITA). Multimodal vision pass extracts text and diagrams. Live progress with page and chunk counts.

    Step 03

    Extract

    AI builds a structured security model: TOE, Assets, Threats, Assumptions, OSPs, Security Functions, Crypto Mechanisms. Every item is inline-editable.

    Step 04

    Build

    Generate the full CC ST in three sequential batches with frozen-state injection: Chapters 1-2, then 3-5, then 6-7. SFRs validated against Part 2 identifiers.

    Step 05

    Validate

    AI Review Agent runs SFR→Threat coverage, orphan detection, missing rationales, PP conformance gaps. Outputs a deterministic Certification Readiness Score.

    Step 06

    Export

    DITA XML, DOCX, or PDF, with branding customisation and multi-language support.

    Built for evaluator-grade output

    AI & intelligence

    Three model tiers with automatic fallback — Understand AI (private), GPT-4.1 (default), Mistral Medium (fast). Strict JSON schema enforcement with retry-on-malformed-JSON. Frozen-state injection keeps the seven chapters internally consistent.

    Standards & compliance

    CC:2022 Rev 1 / ISO/IEC 15408 Part 1 Annex D structure. Protection Profile auto-detection with lock badges for PP-mandated items. Cryptographic mechanisms aligned to FCS_COP.1. Built-in CC Part 2 SFR catalogue and Part 3 SAR catalogue.

    Reliability & scale

    Handles 1,000+ page documents without data loss. Async job orchestration with claim, 300-second lease, 20-second heartbeat state machine. Concurrency-controlled to protect inference backends.

    Productivity

    6-step guided wizard with resumable state. Inline editing on every extracted item. Floating CC Assistant widget for ad-hoc questions during any step. Real-time animated feedback during AI processing gaps.

    Export & branding

    DITA XML (preferred), DOCX with dynamic headers and page numbering, and PDF. Custom logos, footers, and multi-language export (EN default).

    Security & privacy

    Per-user Master Key API provisioning with manual rotation. Optional client-side encryption for Understand AI traffic. No email persistence — identity is derived from Firebase JWT only. Enterprise subscription gate.

    What makes it different from a generic LLM tool

    Domain-tuned, not a chatbot

    Knows CC vocabulary. Annex D layout in muscle memory. SFR identifiers validated against the actual CC Part 2 catalogue, not pattern-matched from training data.

    Vision-aware ingestion

    Architecture diagrams, dataflow drawings, and component layouts are read, not skipped. Pages with diagrams go through a multimodal vision pass at 1.5x rendering scale.

    Traceability-first

    Every Asset, Threat, Assumption, OSP, Objective, SFR, and SAR is linked back to source document, page range, and chunk index. An evaluator can audit any claim in two clicks.

    Deterministic readiness scoring

    The Certification Readiness Score is a formula, not an LLM opinion. SFR coverage, orphan detection, rationale completeness, PP conformance — all measurable and reproducible.

    Built for the people who actually do the work

    Certification consultants

    Stops re-typing the same ST sections for every client. Reuses Reference STs as style templates without copy-paste drift.

    Product security engineers

    Translates internal architecture docs into CC language without learning the full standard. The AI knows the vocabulary; you stay in your domain.

    Evaluators (ITSEF)

    Receives a clean, pre-validated, traceable ST that drastically shortens the EOR cycle — no more chasing missing rationales or orphan SFRs.

    Standards we speak natively

    CC:2022ISO/IEC 15408Protection ProfileEAL1–EAL7DITA XMLDOCXPDFFCS_COP.1CC Part 2CC Part 3CEM

    Built against the actual standard, not a paraphrase. SFR identifiers validated by regex against the CC Part 2 catalogue on every ST generation.

    Powered by Understand Tech Developer API

    The same multimodal AI infrastructure that runs across the Understand Tech platform — tuned for technical security documentation.

    Private AI option

    Use Understand AI for fully private inference — product documentation never leaves your perimeter. Critical for customers under NDA or export-controlled.

    Multimodal vision

    developer.understand.tech endpoints handle the diagram-reading pass that no general-purpose chatbot does reliably. Architecture drawings become structured security context.

    Three model tiers

    Understand AI, GPT-4.1, and Mistral Medium. Automatic fallback if a tier is unavailable. Choose by privacy, speed, or cost.

    FAQ

    Cut weeks of ST drafting to an afternoon.

    CC ST Builder is in Enterprise availability for certification consultancies and vendor security teams.

    Chat with AI Assistant