VectorCertain
36,181-TEST REGRESSION SUITE · ZERO FAILURES
230 CONTROL OBJECTIVES MAPPED
22-SPRINT ARC TO GA
Platform · General availability · 22-sprint engineering arc

SecureAgent ACA — Three-Tier Agentic AI Governance

From a free external assessment requiring nothing of you, to continuous event-driven governance of every agent in your tenant — one platform, three commitments levels.

LOAD-VERIFIED AT 50 CONCURRENT TENANTS
BYTE-IDENTICAL OUTPUT DETERMINISM · ZERO CARRY-FORWARD AT GA

SecureAgent ACA is the deployment platform for the VectorCertain governance stack: it takes the independence verification of HCF2-SG, the execution gating of MRM-CFS, and the certification and consortium layers, and ships them to enterprises as three graduated tiers. General availability closed a 22-sprint engineering arc with zero failing tests across a 36,181-test regression suite and zero carry-forward backlog [VC-C].

The tier structure is a commitment ladder, not a paywall ladder. Tier A asks nothing — no install, no credentials — and still delivers a real external assessment. Tier B asks for a 15-minute OAuth connection and returns a board-ready internal audit. Tier C stays resident and reacts to change. Each tier is fully useful on its own; each makes the next one's value obvious [VC-C].

Request the platform briefing

§ 1 · THE TIERSWhat Each Tier Delivers

Tier A — free, external, nothing to install

An external-perimeter assessment identifying non-human identities, MITRE technique coverage gaps [4][5], and vendor comparison — delivered as a self-contained interactive HTML report that opens on any laptop with no network access. See the Tier A Threat Report for the artifact itself [VC-C].

Tier B — 15-minute OAuth, board-ready output

An internal assessment via a four-agent consensus pipeline covering human identity, non-human identity deep scan, regulatory compliance mapping across 230 control objectives, and MITRE technique coverage — end to end in roughly five minutes, output as a board-ready document with a cryptographically signed manifest [VC-C].

Tier C — continuous, event-driven

Scheduled reassessment plus shadow observation that reacts to tenant change events — new identities, credential rotations, policy changes, deployments — in real time, with adversarial certification through MYTHOS and privacy-preserving consortium benchmarking through ZGTID [VC-C].

Three stacked tiers with increasing access and capability, feeding from the governance stack 500 TIER A · EXTERNAL ASSESSMENTno install · no credentials · self-contained HTML report510 TIER B · INTERNAL AUDIT15-min OAuth · 4-agent consensus · 230 objectives · signed manifest520 TIER C · CONTINUOUS GOVERNANCEevent-driven · MYTHOS certification · ZGTID benchmarking530
FIG. 1The three-tier ladder (500): Tier A external assessment (510) requires nothing; Tier B internal audit (520) requires OAuth; Tier C continuous governance (530) stays resident and consumes the full stack.
Table 1 · Tier capability matrix
CapabilityTier A (free)Tier B (OAuth)Tier C (continuous)
Access requiredNone15-minute OAuthResident connection
Non-human identity discoveryExternal perimeterDeep internal scanContinuous + event-driven
MITRE technique coverage [4][5]Gap overviewFull mappingContinuously refreshed
Compliance mapping230 control objectivesMonitored for drift
OutputInteractive HTML reportSigned board-ready documentLive posture + alerts
Adversarial certificationMYTHOS · 6 attack families
Peer benchmarkingVendor cohort comparisonZGTID consortium

§ 2 · THE DISCIPLINEThe Engineering Standard Behind GA

Every sprint in the 22-sprint arc closed through a five-gate audit — completeness, lock-chain integrity, evidence traceability, accuracy, and reproducibility — with three independent reviewer agents assessing security, performance, and test coverage against fresh context. A 57-file cryptographic baseline was verified byte-identical across all 22 sprints: zero drift [VC-C].

Release discipline carried to the end: the arc closed with zero carry-forward backlog — no deferred defects, no parked findings rolled into a post-GA queue. A platform that sells governed, evidence-gated operation has to be able to show the same property in its own change history, and the sealed sprint records exist so that a customer's diligence team can check the claim rather than take it [VC-C].

Load testing ran 50 concurrent tenants with no crash, no corruption, and no cross-tenant data leak, and output determinism was verified three-runs byte-identical on output hashes. The platform's assurance posture mirrors what it sells: measured, gated, and re-runnable — the same discipline the NIST AI RMF's MEASURE and MANAGE functions ask of governed AI systems [2][3].

§ 3 · QUESTIONSFrequently Asked Questions

What does each SecureAgent ACA tier require from my organization?

Tier A requires nothing — no installation, no credentials, no network access to view the resulting report; it assesses the external perimeter only. Tier B requires a 15-minute OAuth connection and returns a signed, board-ready internal assessment in roughly five minutes. Tier C requires a resident connection and delivers continuous, event-driven governance with adversarial certification and consortium benchmarking.

How is the platform output verified?

Tier B output ships with a cryptographically signed manifest, and platform-wide determinism is verified byte-identical across three runs on output hashes. The engineering baseline behind general availability: a 36,181-test regression suite at zero failures, a 57-file cryptographic baseline with zero drift across 22 sprints, and 50-tenant load testing with no crash, corruption, or cross-tenant leak.

Which frameworks does the compliance mapping cover?

Tier B maps findings across 230 regulatory control objectives and against MITRE technique coverage using both ATLAS and ATT&CK identifiers. Tier A includes a NIST CSF 2.0 coverage view in its report. The mappings are architectural alignments for comparability — the platform does not claim certification by any framework body.

CONTACTTalk to VectorCertain

Every figure on this page traces to sealed, hash-verified validation artifacts — including findings that contradicted our own published estimates, which we recorded rather than reconciled away. Technical briefings are available for enterprises, evaluators, and standards bodies.

Request the technical briefing

REFERENCES

  1. NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. nvlpubs.nist.gov
  2. NIST. AI Risk Management Framework (program page). nist.gov/itl/ai-risk-management-framework
  3. MITRE. ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems. atlas.mitre.org
  4. MITRE. ATT&CK. attack.mitre.org
First-party validation artifacts (VectorCertain, sealed and hash-verified):

[VC-C] Patent portfolio and platform engineering baseline — 77-claim hub filing, stack integration claims, 36,181-test regression suite; portfolio documentation, January 2026. Public URLs will replace artifact names when the corresponding research pages publish.

Join the waitlist

Our signup form is temporarily offline while we perform maintenance. Nothing is lost — reach us directly and we'll add you by hand.

PLACEHOLDER · Tally.so form returns here · engineering ticket open

Email us to join