SecureAgent ACA is the deployment platform for the VectorCertain governance stack: it takes the independence verification of HCF2-SG, the execution gating of MRM-CFS, and the certification and consortium layers, and ships them to enterprises as three graduated tiers. General availability closed a 22-sprint engineering arc with zero failing tests across a 36,181-test regression suite and zero carry-forward backlog [VC-C].
The tier structure is a commitment ladder, not a paywall ladder. Tier A asks nothing — no install, no credentials — and still delivers a real external assessment. Tier B asks for a 15-minute OAuth connection and returns a board-ready internal audit. Tier C stays resident and reacts to change. Each tier is fully useful on its own; each makes the next one's value obvious [VC-C].
Request the platform briefing§ 1 · THE TIERSWhat Each Tier Delivers
Tier A — free, external, nothing to install
An external-perimeter assessment identifying non-human identities, MITRE technique coverage gaps [4][5], and vendor comparison — delivered as a self-contained interactive HTML report that opens on any laptop with no network access. See the Tier A Threat Report for the artifact itself [VC-C].
Tier B — 15-minute OAuth, board-ready output
An internal assessment via a four-agent consensus pipeline covering human identity, non-human identity deep scan, regulatory compliance mapping across 230 control objectives, and MITRE technique coverage — end to end in roughly five minutes, output as a board-ready document with a cryptographically signed manifest [VC-C].
Tier C — continuous, event-driven
Scheduled reassessment plus shadow observation that reacts to tenant change events — new identities, credential rotations, policy changes, deployments — in real time, with adversarial certification through MYTHOS and privacy-preserving consortium benchmarking through ZGTID [VC-C].
| Capability | Tier A (free) | Tier B (OAuth) | Tier C (continuous) |
|---|---|---|---|
| Access required | None | 15-minute OAuth | Resident connection |
| Non-human identity discovery | External perimeter | Deep internal scan | Continuous + event-driven |
| MITRE technique coverage [4][5] | Gap overview | Full mapping | Continuously refreshed |
| Compliance mapping | — | 230 control objectives | Monitored for drift |
| Output | Interactive HTML report | Signed board-ready document | Live posture + alerts |
| Adversarial certification | — | — | MYTHOS · 6 attack families |
| Peer benchmarking | Vendor cohort comparison | — | ZGTID consortium |
§ 2 · THE DISCIPLINEThe Engineering Standard Behind GA
Every sprint in the 22-sprint arc closed through a five-gate audit — completeness, lock-chain integrity, evidence traceability, accuracy, and reproducibility — with three independent reviewer agents assessing security, performance, and test coverage against fresh context. A 57-file cryptographic baseline was verified byte-identical across all 22 sprints: zero drift [VC-C].
Release discipline carried to the end: the arc closed with zero carry-forward backlog — no deferred defects, no parked findings rolled into a post-GA queue. A platform that sells governed, evidence-gated operation has to be able to show the same property in its own change history, and the sealed sprint records exist so that a customer's diligence team can check the claim rather than take it [VC-C].
Load testing ran 50 concurrent tenants with no crash, no corruption, and no cross-tenant data leak, and output determinism was verified three-runs byte-identical on output hashes. The platform's assurance posture mirrors what it sells: measured, gated, and re-runnable — the same discipline the NIST AI RMF's MEASURE and MANAGE functions ask of governed AI systems [2][3].
§ 3 · QUESTIONSFrequently Asked Questions
What does each SecureAgent ACA tier require from my organization?
Tier A requires nothing — no installation, no credentials, no network access to view the resulting report; it assesses the external perimeter only. Tier B requires a 15-minute OAuth connection and returns a signed, board-ready internal assessment in roughly five minutes. Tier C requires a resident connection and delivers continuous, event-driven governance with adversarial certification and consortium benchmarking.
How is the platform output verified?
Tier B output ships with a cryptographically signed manifest, and platform-wide determinism is verified byte-identical across three runs on output hashes. The engineering baseline behind general availability: a 36,181-test regression suite at zero failures, a 57-file cryptographic baseline with zero drift across 22 sprints, and 50-tenant load testing with no crash, corruption, or cross-tenant leak.
Which frameworks does the compliance mapping cover?
Tier B maps findings across 230 regulatory control objectives and against MITRE technique coverage using both ATLAS and ATT&CK identifiers. Tier A includes a NIST CSF 2.0 coverage view in its report. The mappings are architectural alignments for comparability — the platform does not claim certification by any framework body.
CONTACTTalk to VectorCertain
Every figure on this page traces to sealed, hash-verified validation artifacts — including findings that contradicted our own published estimates, which we recorded rather than reconciled away. Technical briefings are available for enterprises, evaluators, and standards bodies.
Request the technical briefingREFERENCES
- NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. nvlpubs.nist.gov
- NIST. AI Risk Management Framework (program page). nist.gov/itl/ai-risk-management-framework
- MITRE. ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems. atlas.mitre.org
- MITRE. ATT&CK. attack.mitre.org
[VC-C] Patent portfolio and platform engineering baseline — 77-claim hub filing, stack integration claims, 36,181-test regression suite; portfolio documentation, January 2026. Public URLs will replace artifact names when the corresponding research pages publish.