From 598046d22ca6525e564dcfc3963887f0de3d502b Mon Sep 17 00:00:00 2001 From: FosterStack Admin <317177128+fosterstack-admin@users.noreply.github.com> Date: Fri, 11 Sep 2026 15:12:01 -0400 Subject: [PATCH] Wedge page: for teams entering regulated markets MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Business-model work order §3, in the ordered shape: the situation (one customer, the pile), the mission sentence - the cost of compliance shouldn't determine who gets to compete - what our piece does and does not do (evidence and validated crypto FOR your program; never makes you compliant), the Compliance tier and its nouns, and verify-everything- free-first ending on the test we invite. No claims beyond what the cache does today; the evidence links point at RELEASING, SECURITY (including its not-yet-proven statements) and the requirements matrix. Linked from the Compliance column and the footer; added to the sitemap. --- index.html | 6 +- regulated/index.html | 145 +++++++++++++++++++++++++++++++++++++++++++ sitemap.xml | 4 ++ 3 files changed, 152 insertions(+), 3 deletions(-) create mode 100644 regulated/index.html diff --git a/index.html b/index.html index b85f00d..6f75def 100644 --- a/index.html +++ b/index.html @@ -164,7 +164,7 @@

What we do not collect

billing a customer requires an email address, and a privacy claim that is convenient but false is worse than none.

-

Pricing

+

Pricing

Per product. Free is the full product.

@@ -178,7 +178,7 @@

Pricing

+ LTS. Who this is for.
FreeTeamBusinessCompliance
$499/month, billed annually — everything in Business, plus the FIPS 140-3 applicability statement, signed per-release attestation letters addressed to you, security-questionnaire support up to 8 hours per year (async), and named-version - LTS.

No sales call. No per-seat tax. No enterprise pricing mystery.

@@ -219,7 +219,7 @@

Roadmap honesty

of the documented remote build cache HTTP protocol. Apache Maven is a trademark of the Apache Software Foundation; the Maven Build Cache Extension is Apache's project, not ours.

-

© 2026 FosterStack · github.com/fosterstack/cache · hello@fosterstack.com

+

© 2026 FosterStack · For regulated markets · github.com/fosterstack/cache · hello@fosterstack.com

diff --git a/regulated/index.html b/regulated/index.html new file mode 100644 index 0000000..a229035 --- /dev/null +++ b/regulated/index.html @@ -0,0 +1,145 @@ + + + + + +FosterStack for teams entering regulated markets + + + + + + + +
+ +
Infrastructure worth keeping.
+
+
+

For teams entering regulated markets

+ +

+ It usually starts with one customer. A contract lands on the table with + federal or compliance requirements attached — FIPS-validated cryptography, + SBOMs, provenance, a security questionnaire with two hundred rows — and + suddenly every tool in your build pipeline needs paperwork it has never + had. Big vendors sell their way through that pile with compliance teams + and six-figure contracts. Small teams mostly just lose the deal. +

+ +

The cost of compliance shouldn't determine who gets to + compete.

+ +

What our piece does — and does not do

+

+ FosterStack Cache is one component in your pipeline: a self-hosted remote + build cache. For that component, we do the evidence work a compliance + program needs: the -fips build links Go's FIPS 140-3 + validated cryptographic module (CMVP certificate #5247), and every + release ships with an SBOM, SLSA provenance, keyless signatures, and + published VEX statements. Our requirements and their evidence are public + in the repository, criterion by criterion. +

+

+ What it does not do: make you compliant. FedRAMP and CMMC attach to your + service and your organization, never to a component you deploy. What a + component can be is evidence and validated crypto for your + program — one row of that questionnaire where the answer is written, + signed, and checkable instead of a shrug. +

+ +

The Compliance tier

+

+ The evidence underneath is public and free — SBOMs, SLSA provenance, + signatures, VEX statements, the FIPS 140-3 validated module and its + certificate number — verifiable by anyone, no account, no purchase. What + the Compliance tier sells is the authored work on + top: a FIPS applicability statement mapping the validated module boundary + onto this product, per-release attestation letters addressed to you and + signed by FosterStack LLC, security-questionnaire support up to 8 hours + per year (async), and named-version LTS. +

+ +

Verify everything for free first

+

+ Before spending anything: pull the -fips image (public, no + login), run the signature and provenance verification commands in + RELEASING.md, + read the scan posture in + SECURITY.md + — including what it says is not yet proven — and check the + requirements + matrix that maps every product promise to its evidence. If the free + evidence doesn't hold up under your audit, the paid tier wouldn't either. + That's the test we invite. +

+
+ + + diff --git a/sitemap.xml b/sitemap.xml index 837c21a..8c1e470 100644 --- a/sitemap.xml +++ b/sitemap.xml @@ -6,6 +6,10 @@ file and keeps its noindex tag until then. --> + + https://fosterstack.com/regulated/ + 2026-09-11 + https://fosterstack.com/ 2026-08-18