← VeraX home
NDOVU ADVANCED SECURITY
CONTINUOUS COMPLIANCE · ATTESTATION · SPRS DEFENSIBILITY
REFERENCE   VRX-DEMO-DIB-v1.1
DATE   2026-09-19
CLASSIFICATION   Business Confidential — T3

VeraX — End-to-End Demo Flow

DIB Customer Journey — Eight-panel storyboard, first sales conversation through signed SPRS attestation
1DAY 0 · DISCOVERY CALL
First Sales Conversation
Ndovu meets a 340-employee DIB prime that filed a SPRS score of 88 last November and has no evidence trail behind it.
DIANE PARK · CIO, KESTREL DEFENSE
CMMC Phase II just got suspended, so honestly our board thinks we're off the hook. But our SPRS score is from last November and nobody could tell you what evidence backed it. And I keep reading about DOJ False Claims Act settlements. What can VeraX do that our existing stack can't?
RICKY · NDOVU
Your board is half right — the third-party assessment is paused. But your SPRS score is still a certification to the government, and DOJ is collecting on the ones that don't hold up. VeraX sits on top of what you already own and turns it into a signed weekly evidence bundle keyed to every 800-171 R3 control. When someone asks what was true on the date you filed, you hand them a signed package — not a reconstruction.
DIANE PARK
What's the on-ramp look like? We can't take a hit on operations right now.
RICKY · NDOVU
90-day pilot. Day 14 we're connected to your M365, CrowdStrike, and AWS. Day 30 you know whether your 88 is real. Day 45 you have a signed weekly bundle running. Day 75 you have an attestation package a prime or outside counsel will sign off on. Day 90 you re-affirm in SPRS with evidence behind it.
Ndovu leads with the attestation-liability framing: the suspension paused the assessor, not the obligation. VeraX is the orchestration layer over what the customer already owns. The 90-day pilot removes purchase risk — the customer sees signed weekly bundles before subscription conversion.
VALUE SIGNAL — "IS OUR SPRS SCORE TRUE?" BECOMES ANSWERABLE
2DAY 1 · TENANT PROVISION
Onboarding Wizard
The ISSO completes tenant provisioning. Customer-scoped HSM signing key is generated in AWS CloudHSM.
https://verax.ndovu.io/onboarding/step-2
NDOVU · VERAX
Onboarding · Kestrel Defense
TENANT
HSM KEY
INTEGRATIONS
SSP UPLOAD
FIRST SWEEP
Step 2 of 5 — Generate Customer-Scoped Signing Key
VeraX will generate a customer-scoped RSA-4096 key pair in AWS CloudHSM (FIPS 140-3 Level 3). The private key never leaves the HSM. Every evidence bundle signed for your tenant will be signed with this key. Any prime, auditor, counsel, or assessor can validate signatures using your public key alone — no VeraX involvement required.
HSM DETAILS
Cluster: us-gov-east-1 · cluster-kestrel-01
Algorithm: RSA-PSS with SHA-384 · 4096-bit
Key Alias: kestrel-defense-signing-2026
Attestation: FIPS 140-3 Level 3 module cert #4823
GENERATE KEY →
Customer holds the keys — literally. This design decision is deliberate: the customer's public key is what a prime, auditor, counsel, or assessor uses to validate signatures, and the private key sits in a hardware module the customer controls. Ndovu cannot forge evidence even if we wanted to.
TRUST SIGNAL — FIPS 140-3 LEVEL 3 · CUSTOMER-CONTROLLED SIGNING
3DAYS 3–7 · INTEGRATIONS
Connecting the Customer's Existing Tools
Read-only OAuth to what Kestrel already owns. No agents, no duplicate telemetry.
https://verax.ndovu.io/onboarding/integrations
NDOVU · VERAX
Integrations
Connect Your Existing Security Stack
Microsoft 365 · Entra ID
Graph API — Security & Compliance reads
✓ CONNECTED · 2 min ago
CrowdStrike Falcon
Query API — OAuth · 3 scopes
✓ CONNECTED · 4 min ago
AWS GovCloud
Security Hub · Config · IAM AA
✓ CONNECTED · 6 min ago
Okta
Admin API — read-only token
✓ CONNECTED · 9 min ago
Splunk Cloud
REST search · TI enrichment
CONNECT →
Jira Cloud
Remediation loopback
CONNECT →
All permissions read-only unless explicitly opted into Agentic Remediation. Zero customer data leaves the enclave — only signed evidence summaries.
Four integrations connected in the first hour. Read-only by default. The most common objection ("this is going to require another agent") is defused by design: VeraX is API-level orchestration, not endpoint sprawl.
FRICTION KILLER — ZERO ADDITIONAL AGENTS · READ-ONLY DEFAULT
4DAY 10 · FIRST SWEEP
Full Discovery Run in Progress
Baseline discovery across all connected surfaces. First evidence sweep produces the initial knowledge graph.
https://verax.ndovu.io/tenant/kestrel/sweeps/current
NDOVU · VERAX
Sweep · Baseline · Started 47 min ago
Baseline Sweep — Kestrel Defense
Est. 3–6 hours end-to-end · Progress 47%
●
Identity Reader (Entra + Okta)
✓ 1,247 users · 82 groups · 34 apps
●
Endpoint Reader (CrowdStrike)
✓ 412 hosts · 8,400 detections analyzed
●
Cloud Posture (AWS GovCloud)
✓ 27 accounts · 1,890 resources
◐
Cloud Posture (Azure GovCloud)
◐ 62% · 8 subs of 13
◐
Log/Audit Reader (Splunk)
◐ Running · 30-day window
○
Software BoM Scanner
Queued
○
Continuous Testing Engine
Awaits discovery complete
Knowledge graph state: 2,562 assets · 18,940 relationships · signed as of 14:22 UTC
Discovery is a read operation, not an install. No agents deployed, no changes to production systems. The ISSO watches the graph fill in real time. First real value signal for the customer: they see the actual scope of their footprint, often for the first time.
CUSTOMER INSIGHT — "WE DIDN'T KNOW WE HAD THAT MANY ASSETS"
5DAY 24 · GAP ANALYSIS
Baseline Findings Delivered to Leadership
Every SP 800-171 R3 control marked. Executive-defensible SPRS projection. First remediation queue built.
https://verax.ndovu.io/tenant/kestrel/findings
NDOVU · VERAX
Findings · 24 open · Baseline
Baseline Gap Analysis
Projected SPRS: 62 / 110 · Filed on record: 88 · Variance: −26
DOWNLOAD GAP MEMO ↓
CRIT
M365 CUI mailbox litigation hold missing 3.8.9
18 mailboxes flagged CUI · media protection failure
-5 SPRS
CRIT
S3 CUI bucket allows cross-account read 3.13.11
s3://kestrel-cui-eng · confidentiality boundary
-5 SPRS
HIGH
7 endpoints below CIS L1 hardening baseline 3.4.6
Config Mgmt · 3 assets serve CUI users
-3 SPRS
HIGH
3 SPN missing conditional access policy 3.5.10
Entra ID · privileged service principals
-3 SPRS
MED
Package inventory incomplete 3.4.2
Chocolatey/winget · 22 hosts
-1 SPRS
+ 19 more · every finding maps to an 800-171 R3 assessment objective
This is the pilot's hardest and most valuable moment. The customer learns their filed score is 26 points higher than what the evidence supports. VeraX turns an undiscovered liability into a dated record plus a remediation roadmap — which is exactly what good-faith looks like to a prime, an auditor, or DOJ.
LEADERSHIP MOMENT — UNDISCOVERED LIABILITY BECOMES DOCUMENTED REMEDIATION
6DAYS 30-45 · REMEDIATION
Finding → Jira Ticket → Fix → Re-Attest
Automated ticket creation into the customer's ticketing system. Agentic Remediation proposes deterministic fixes.
VERAX-892
3.13.11 · S3 CUI bucket policy allows cross-account read
Auto-created from VeraX Finding F-2026-0088 · 2026-08-29 · Priority: Critical
Asset: s3://kestrel-cui-eng
Owner: M. Ochoa
SPRS Δ: -5
Age: 2d
The S3 bucket kestrel-cui-eng — tagged CUI in the asset inventory — has a bucket policy that allows read from AWS account 551422881107 outside the Kestrel Defense organization. SP 800-171 R3 §3.13.11 requires cryptographic protection of CUI in transit and at rest, and by extension boundary confidentiality.
◈ AGENTIC REMEDIATION PROPOSAL
Remove the offending statement from the bucket policy. Preview available. Requires ISSO approval before execution.
REVIEW & APPROVE → DEFER TO MANUAL
EVIDENCE TRAIL: aws-config-rule-2026-08-29T14:12Z · s3-bucket-policy-scan-892 · verax-signature-a8f2:6b1c
Findings become tickets in whatever the customer already uses. The Agentic Remediation proposal is opt-in per control family — VeraX writes the fix, the ISSO approves it. On the next sweep, the finding closes automatically, the evidence bundle updates, and the SPRS score climbs 5 points.
LOOP CLOSED — DETECT · PROPOSE · APPROVE · EXECUTE · RE-ATTEST
7DAY 45 · WEEKLY BUNDLE
Signed Evidence Bundle — Continuous Rhythm
Sunday 02:00 UTC. Automated sweep completes; evidence bundle is signed with the customer HSM key.
WEEKLY EVIDENCE BUNDLE
#14 · 2026-09-14
SHA256:8f2a5b1c9e70…6b1cab48d321
✓ SIGNED · CUSTOMERHSM/KESTREL-01
Bundle Contents
Asset Inventory JSON ✓ 2,617 assets
Control Family Evidence · 8 families ✓ 82 controls scored
Findings Snapshot · 7 open ✓ 3 closed since last
SPRS Scoring Worksheet ✓ 74 / 110 projection
Cryptographic Signature ✓ RSA-PSS-4096 SHA-384
Signer Attestation ✓ FIPS 140-3 L3
✓ ARCHIVED TO AUDIT VAULT
S3 Object Lock (Compliance mode) · Immutable · Retrievable via C3PAO handoff
Every Sunday at 02:00 UTC. Without operator intervention. Evidence provenance is cryptographically enforced — any prime, auditor, or counsel can validate the bundle's signature against the customer's public key with no involvement from Ndovu. Twelve weeks of these is a point-in-time record of what was true, when.
RHYTHM ESTABLISHED — CONTINUOUS · TAMPER-EVIDENT · INQUIRY-PROOF
8DAY 90 · SPRS ATTESTATION
Signed SPRS Attestation Package — Affirmed on Record
One click. Signed archive assembled, externally validated, filed alongside the SPRS affirmation. Defensible on the date it was certified.
✓

SPRS ATTESTATION PACKAGE — AFFIRMED

kestrel-sprs-attestation-2026-11-15.zip · 31.2 MB · Signed & sealed · Archived with filing

88
Affirmed SPRS
14/14
Control Families
12wk
Evidence History
Package Contents — Archived With SPRS Filing
System Security Plan (SSP v3.2) ✓
POA&M · 7 open items with remediation dates ✓
Evidence Bundle · 12 weeks · 168 artifacts · point-in-time indexed ✓
DoD Assessment Methodology Worksheet · Signed & timestamped ✓
Verifier Binary · Windows · Linux · macOS ✓
Customer Public Key · signature validation ✓
EXTERNAL VALIDATION: Prime supply-chain security — accepted · Outside counsel — inquiry-sufficient · C3PAO (latent) — format ready
Ninety days end-to-end. The customer re-affirms a SPRS score of 88 — this time with twelve weeks of signed evidence behind it and a prime and outside counsel who have reviewed the package. When Phase II returns, the C3PAO feature switches on against a year of history. Kestrel Defense becomes the first named VeraX reference customer.
OUTCOME — DEFENSIBLE ATTESTATION · REFERENCE CUSTOMER · PHASE II READY