Platform

Two engines. One question asked in two directions.

What must we protect, and where does it live? And: what are the organizations we depend on obligated to protect? Both reduce to reading obligations and tracing them to something real. The difference is whose environment is in view and what evidence is available.

The two engines

Inward — your environment

Data-Protection Scoping

Turns the obligations in your contracts into a defensible boundary, from your own documents and your own systems.

Input
Contracts, task orders, flow-downs, DD 254s, and your declared data estate
Method
NIST SP 800-60 categorization, the CUI Registry, and NIST SP 800-171
Obligation status
Reaches confirmed — the clause is quoted from your document, with the line cited
  • Traceable decision model, clause to safeguard
  • Boundary with a recorded basis for every inclusion and exclusion
  • Decision records with owner, authority, and review cadence
  • Prioritized protection roadmap

Outward — your supply chain

Contractor Risk Intelligence

Assesses a federal contractor from public sources when you have no access to their documents or systems.

Input
Public award, subaward, registration, exclusion, and screening data
Method
Three risk domains, nineteen weighted factors, and classification gates
Obligation status
Stops at strongly indicated — public data cannot confirm a clause
  • Composite classification with an explicit confidence figure
  • Organizational, data, and supply-chain domain scores
  • Inferred obligations with the basis for each
  • The sources that were not available, stated plainly

Risk intelligence, not a compliance determination. It renders no CMMC, FOCI, or export-control determination, and is not for consumer-credit, employment, or insurance-eligibility use.

What they share

The same discipline about what counts as evidence.

  1. 01

    Absence is never scored as safety.

    A source that could not be reached is recorded as missing. In the risk engine it lowers confidence and widens the reported range; in the scoping engine it leaves an asset undetermined rather than quietly outside the boundary. Neither engine improves a result because it failed to look.

  2. 02

    The model is a file, not a black box.

    Clause patterns, information types, impact levels, factor weights, and gates all live in versioned configuration that ships with a fingerprint. Every output names the exact version that produced it, so a result can be reproduced or disputed years later.

  3. 03

    Deterministic, with no generative step.

    Identical inputs against an identical model version produce an identical result, byte for byte. There is no language model anywhere in either decision path — nothing to re-roll, and nothing that answers differently on a second reading.

  4. 04

    Inference is labeled as inference.

    Every finding carries the strength of the evidence behind it. Confirmed requires the clause text. The engines are built so that the difference between reading a contract and inferring from metadata is visible in the output rather than blurred by it.

Used together

Your boundary does not stop at your own perimeter.

DFARS 252.204-7012 flows down. So does the export-control obligation. The scoping engine identifies which subcontractors sit inside your boundary and whether the flow-down was executed; the risk engine tells you what public evidence says about those same organizations. One names the dependency, the other characterizes it.

01Scope your boundary

The scoping engine finds the flow-down obligations and the suppliers your covered information actually reaches.

02Assess the dependencies

The risk engine profiles those suppliers from public award, exclusion, and screening data.

03Act on both

Missing flow-downs and unobservable supplier programs surface as roadmap actions with the clause that requires them.

Where the suite is today

What is built, and what is not.

CapabilityScopingRisk intelligence
Deterministic engine with test suiteAvailableAvailable
Multi-organization API with approvalsAvailableSingle-tenant API
Document ingestionExtracted textNot applicable
Contractor-provided evidence (Level 2)PlannedPlanned
Model calibrationReference data versionedHarness built; findings open

Stated plainly because the alternative is discovering it during an evaluation. Model version 0.1.0, reference data v0.1.0 (b3f405ecd9472474).

Start with the boundary you have to defend.