← VeraX home
NDOVU ADVANCED SECURITY
CONTINUOUS COMPLIANCE · ATTESTATION · SPRS DEFENSIBILITY
REFERENCE   VRX-ARCH-DIB-v1.1
DATE   2026-09-19
CLASSIFICATION   Business Confidential — T3

VeraX — Operational Architecture

DIB Continuous Compliance & Attestation Orchestration — Seven-Layer Reference Topology with SP 800-171 R3 Control Overlay · SPRS Defensibility Edition
CUSTOMER CUI ENCLAVE · DFARS 252.204-7012 Raw CUI never leaves this boundary. Only signed evidence summaries cross. Microsoft 365 Entra ID · Graph API CrowdStrike Falcon Query API Azure GovCloud Resource Graph · Defender Okta / Duo Admin API Splunk REST Search API AWS GovCloud Security Hub · Config Defender XDR Endpoint · Identity Jira / SN Remediation loop L2 · MULTI-AGENT DISCOVERY Deployed inside the CUI enclave — read-only collectors, one per integrated tool Identity Reader 3.5.x · 3.1.x Endpoint Reader 3.14.x · 3.6.x Cloud Posture 3.13.x · 3.4.x Log/Audit Reader 3.3.x · 3.8.x EVIDENCE EGRESS Signed bundles only — NO raw CUI — VERAX CONTROL PLANE · AWS GOVCLOUD FedRAMP Moderate posture in progress. Customer-scoped signing keys in AWS CloudHSM. L1 · KNOWLEDGE GRAPH Apache AGE on PostgreSQL (per ADR-0006) — multi-tenant, per-customer namespace Assets · Controls · Findings · Evidence · Attestations · Relationships L3 · CONTINUOUS TESTING ENGINE Executes 800-171 R3 assessment objectives against the graph on a schedule Temporal workflows · deterministic replay · assessment-obj registry v0.5+ L4 · ATTESTATION ENGINE Renders evidence bundles · signs with CloudHSM · assembles SPRS Attestation Packages SSP · POA&M · DoD Assessment Methodology worksheet · signed_evidence.json · verifier · (C3PAO pkg latent) L5 · AGENTIC REMEDIATION (v1.0+ target) Proposes and (opt-in) executes deterministic fixes via connected IaC / config APIs L6 · AUDIT EVIDENCE VAULT Immutable, tamper-evident store keyed by tenant + control ID + date — point-in-time reconstruction S3 Object Lock (Compliance mode) · Postgres LISTEN/NOTIFY event log (per ADR-0010) L7 · SOC CONSOLE + API Next.js 15 operator UI · REST + GraphQL for MSP/MSSP channel integration Tenant dashboard · findings triage · SPRS attestation assembly · prime flow-down DIB ISSO operator Executive sponsor MSP/MSSP channel Prime / Counsel evidence consumer SP 800-171 R3 CONTROL FAMILY COVERAGE (VERAX v0.5) 14 families · Covered ≥80% controls · Partial 30-80% · Uncovered <30% 3.1 Access Control COVERED (21 / 22) Identity Reader · Cloud Posture 3.3 Audit & Accountability COVERED (9 / 9) Log/Audit Reader 3.4 Configuration Mgmt PARTIAL (6 / 9) Cloud Posture; needs IaC scan 3.5 Identification & Auth COVERED (11 / 11) Identity Reader (Okta / Entra) 3.6 Incident Response COVERED (3 / 3) Endpoint Reader · Log Reader 3.7 Maintenance PARTIAL (4 / 6) v0.7 target 3.8 Media Protection UNCOVERED (2 / 9) v1.0 target 3.13 Sys & Comms Prot COVERED (15 / 16) Cloud Posture · Identity Reader 3.14 Sys & Info Integrity COVERED (7 / 7) Endpoint Reader 3.11 Risk Assessment PARTIAL (2 / 3) Log Reader; needs threat feed 3.12 Sec Assessment PARTIAL (2 / 4) Continuous testing engine 3.2 / 3.9 / 3.10 (3 fams) UNCOVERED — v1.0 target Awareness · Personnel · Phys Prot v0.5 BASELINE 8 / 14 families continuous · Scored: 82 of 110 · Projected SPRS: 74 / 110 · Filed: 88 · Variance: −14

Legend

VeraX Layer (deployed platform component)
Customer CUI Enclave (DFARS 252.204-7012)
VeraX Control Plane (FedRAMP Moderate)
Control Family Covered (≥80%)
Control Family Partial (30–80%)
Control Family Uncovered (<30%)
Data / evidence flow
Trust boundary (CUI enclave edge)
Evidence Egress Gate (signed summaries only)