01 · PRODUCT MODEL
One product focus. A repeatable maintained-image operating model.
Citadel replaces a hand-built operating-system starting point with a repeatable, PCI-focused cloud image that is refreshed monthly. Select the operating system and architecture that fit your application, then validate the exact release against your workload.
New image releases are patched, tested, and published through an automated pipeline.
Architecture availability is identified on each cloud Marketplace listing.
Subscribe and launch through the cloud account and purchasing path your team already uses.
Product questions reach a US-only team based in the United States.
02 · PCI-READY IMAGES
Start the PCI review path with the OS layer already addressed.
Citadel is built for fintech, payments, SaaS, and other teams that need a hardened cloud baseline organized around PCI DSS requirements. It shortens the operating-system portion of the readiness program without pretending that one image makes the broader workload compliant.
Best fit
- A PCI deadline is driving the infrastructure decision.
- The team needs a reviewable OS baseline without building it from scratch.
- Engineering wants self-service procurement rather than a consulting engagement.
- The evaluator expects PCI-focused documentation and evidence status.
Product standard
- PCI-focused operating-system configuration baseline.
- Per-image evidence pack as published for the specific product.
- Monthly refreshed images plus an expedited critical-update path.
- x86 and ARM options where listed, with US-based product support.
03 · WHAT TO VERIFY
Choose by workload fit, then verify the exact product record.
| Decision area | What to confirm |
|---|---|
| Operating system | The OS family and version match application and support requirements |
| Architecture | x86_64 or ARM64 / Graviton matches the planned AWS instance family |
| PCI focus | The product is built to help meet relevant PCI DSS operating-system requirements |
| Evidence | The specific release identifies which evidence artifacts are currently published |
| Maintenance | Monthly image releases and the critical-update path fit the rollout process |
| Procurement | Current price, regions, terms, and subscription path are confirmed on Marketplace |
| Support | The applicable product terms and US-based support scope match team expectations |
04 · RESPONSIBILITY BOUNDARY
Citadel owns the maintained image. Your team owns the workload.
Citadel supplies and maintains the image-level baseline described by the selected product. Your team remains responsible for application security, cloud architecture, identity, networking, logging, deployment, operations, evidence retention, and any assessor or compliance decision.