Solutions

Solutions

Two engines.
One doctrine.

ScanSet builds the reference implementations. Each one applies the same primitives, signed events, deterministic decisions, verifiable logs, to a specific surface where proof matters more than narrative.

// ProofLayer

Cyber and cloud assurance

Prove your security posture, continuously.

ProofLayer runs as a single VM inside your authorization boundary. It evaluates controls against your live system using credentialed access you already manage, signs the evidence at the moment of evaluation, and records every result in a tamper-evident log a third party can verify without trusting you.

  • Single VM, in-boundary deployment. No multi-tenant cloud.
  • Signed at the moment of evaluation, not assembled after the fact.
  • Self-maintaining state-of-system record. The artifact stays current as the system does.
  • Append-only transparency log with inclusion proofs (RFC 6962 pattern).
  • Same primitives generalize across NIST 800-53, 800-171 / CMMC L2, FedRAMP, NSA ZIG, SOC 2, ISO 27001, NIST CSF.

Tenets satisfied · 01 · 02 · 04 · 05 · 06

// StAG · In development

Structural assurance for AI agents

Your agent can act. Can it prove it should have?

A deterministic broker designed to sit at your agent’s tool boundary. Every proposed action becomes an allow, deny, or escalate from a rule, not a guess. Every decision leaves a signed record an assessor will accept. Bring your own agent, in any framework. You do not rewrite it.

  • Reproducible authorization. The model proposes. A deterministic policy decides. The rule that fires will fire the same way every time.
  • Provenance that drives the decision. Origin-bound taint. Untrusted-origin data cannot reach a field that authorizes an action.
  • Deterministic downstream of the planner. Detection tools sit upstream and guess. StAG sits downstream and bounds. The model is never in the decision path.
  • Model-agnostic by construction. The assurance is in the structure around the model, not in the model. The next model does not change the gate.
  • Single Go binary. Runs in your environment. No source or agent state leaves your boundary.
  • Signed record per decision. Verifiable against your policy and the signature, without trusting the producer.

Design intent · 04 · 05 · 07

Which surface matters to you first?

A thirty-minute discovery call. We will scope your highest-leverage surface and propose the smallest engagement that closes it.

Book a Discovery Call

Scroll to Top