Trust & Architecture

Security & Privacy

Banks and healthcare organizations ask specific questions before they'll hand over infrastructure configuration. Here are direct answers — how data is handled, how findings are generated, how AI is used, and how evidence is stored.

01 — Data Handling

What do you actually receive from us, and what do you send us?

We analyze declared infrastructure configuration — a Terraform, CloudFormation, ARM/Bicep, or GCP Deployment Manager file, or a landing-zone posture document you provide. We do not connect to your live environment, request cloud credentials, or run anything against production systems.

This is static analysis: we read what your configuration says should exist, not what's actually running. That boundary is stated in every report we deliver, not just here.

Why this matters: static analysis eliminates credential exposure, runtime risk, and production impact — the concerns that lead most institutions to prohibit automated scanning tools from external vendors in the first place.
We never process customer information, ePHI, or transaction data — only infrastructure configuration. Nothing about your customers or patients passes through this assessment at any point.

Configuration files are transferred using your preferred secure method — encrypted email, secure file transfer, or your own portal. We don't require a specific channel; we work within your existing data-handling policy, not around it.

Access Method
Client-provided config file, not live credentials
Runtime Access
None — no probing, no penetration testing
Assessment Type
Point-in-time, static configuration analysis
Supported Formats
Terraform, CloudFormation, ARM/Bicep, GCP Deployment Manager
02 — Finding Generation

How is a finding actually produced — is it AI-generated?

No. Every finding is produced by deterministic rule evaluation against your declared configuration — a fixed set of checks looking for specific conditions (MFA not enforced, encryption not configured, logging disabled, and similar), each one mapped to a specific regulatory citation before any report is written.

Nothing about whether a finding exists, what severity it carries, or what citation it maps to is decided by a language model. Two runs against the identical configuration will always produce the identical findings.

Finding Source
Rule-based evaluation, not AI inference
Citation Mapping
Fixed lookup tables — 16 CFR 314, 45 CFR 164.312, AICPA TSC
Reproducibility
Identical input always produces identical findings
Maturity Scoring
Calculated from finding severity and density — a fixed formula
03 — Where AI Is Actually Used

You mention AI-augmented reporting. Where does it actually touch the process?

In exactly one place: drafting the plain-language Executive Briefing and Board Reporting Narrative sections that summarize findings which were already fixed by the deterministic engine before the model ever runs. The model writes prose around numbers it cannot change.

It runs on a local model, on-premises — never a cloud API. Your configuration data and findings never leave the assessment environment for this step. If the narrative generation fails, times out, or the local model isn't available, the report is delivered without it — the deterministic findings, evidence, and corrective action plan are never affected.

Output is also automatically screened: if narrative text ever contained defense-sector-specific terminology inappropriate to a commercial engagement, it's discarded and the deterministic sections are used alone.

04 — Evidence Storage

Where does our data and our report history live?

Locally, within the assessment environment. Each engagement's findings, reports, and re-assessment history are stored as files on the system running the assessment — not uploaded to a shared cloud service or a multi-tenant database.

Re-assessments are compared against your organization's own prior runs to build an evidence-trend record over time — new findings, resolved findings, and how long open items have remained outstanding against their target remediation window.

Retention: assessment history is retained by default because it's what makes evidence-trend reporting possible — without it, every re-assessment would be a disconnected snapshot with no way to show what's actually improved. You control it: request deletion of your engagement history at any time, including immediately after final delivery if you'd rather not retain it.
Storage Location
Local to the assessment environment
Multi-Tenant Exposure
None — no shared database across clients
Retention
Client-controlled; re-assessment history persists until removed
05 — Scope & Limitations

What does this assessment not cover?

We say this plainly in every report, not just here. Technical-safeguard assessment does not cover organizational and administrative safeguards — a written risk assessment narrative, workforce training records, sanction policy documentation, service-provider oversight contracts, incident response plan testing, or a Qualified Individual's sign-off. Those require evidence beyond infrastructure configuration, and remain your organization's responsibility, supported by your counsel or compliance officer.

Questions before you send us anything?

Ask before you engage — we'd rather answer now than after.