About
We built ScanSet because describing your systems stopped being enough.
We build the engines that make modern systems prove what they are actually doing, continuously and cryptographically, without anyone having to take a vendor’s word for it.
Why we exist.
The buyer’s question has not changed in fifty years. How do you know?
What has changed is what sits on the other side of the question. Once it was a configuration. Then it was a cloud. Now it is an agentic system that authorizes its own actions and produces text confident enough to fool any reader. The question got harder. Most of the answers got weaker.
The discipline of answering “how do you know?” with proof has been practiced inside the highest-stakes federal environments for years. It has not, until now, been brought as engineering to anyone else. The market built a category around the paperwork. We built the category around the proof.
ScanSet is that discipline, named, codified, and shipped. We did not invent the primitives. They are mature, well-cited, and already live in production systems all over the world. We assembled them under the right operational discipline and built reference implementations that show what assurance actually looks like when it is engineered in instead of asserted.
Who is behind it.
Curtis Slone
// Founder
Ten years building and securing systems inside Special Operations and Intelligence Community programs, where the answer to how do you know? had to be proof. US Army Special Operations Command veteran. Two master’s degrees, the second in software engineering.
Founded ScanSet to take that discipline out of the SCIF and into everything else modern infrastructure runs.
What we believe.
Five operating principles. They are how we decide what to build, what to leave to others, and what every implementation has to satisfy before it ships.
-
Security is the product. Evidence is the exhaust.
Assurance is engineered into the system. It is not assembled at audit time. -
The verifier should not have to trust the producer.
Integrity is a property of the artifact, not the reputation of the vendor. -
A system that cannot be reproduced cannot be defended.
Determinism is the line between proof and opinion. Non-determinism in the trust path is a defect. -
Open source the engine. The implementation is the moat.
Anyone should be able to read what the system does. Nobody should be able to fake the proof it produces. -
Build the engineering. The story takes care of itself.
Federal buyers read specs. Enterprise buyers run scanners. The page is only worth the proof underneath it.
Talk to us.
We want to hear about the systems you have to prove things about, and where the answer to how do you know? gets the most uncomfortable. Bring that conversation.

