The basis of a conclusion is inspectable, including our own claims.
What the system does, what has been tested, and what has not been verified in production. Stated plainly.
Capability review: 2026-09-21
Fact and assessment
- Attribution
- Retained source record
- Identity
- Source id and provenance
- Content
- Point-in-time hash
- Attribution
- Derived from evidence
- Type
- Calculated or inferred
- Model role
- Explanation, attributed
Provenance and evidence
Statements cite retained evidence by identifier. A single authoritative source is treated as not corroborated.
Uncertainty and falsification
- A separate direct-award path is retained for the requirement.
- The engineering scope leaves the consolidated vehicle.
Absence of evidence is not treated as a win, a loss or a completed outcome. A conclusion can be strengthened, weakened, contradicted or falsified without erasing the earlier call.
Point-in-time integrity
Current posture
Product behaviour with repository evidence
Credential-based authentication. Fail-closed application-layer tenant isolation covered by offline tests; customer identity bound to the credential and cross-customer requests rejected. This is application-layer isolation, not database row-level security.
Evidence provenance, source attribution, the observed-versus-assessed distinction, materiality and confidence, AS OF views and historical replay, source-rights controls, bounded retries, durable checkpoints, restart and recovery, duplicate suppression, fail-closed customer export authorization and provider-neutral STANDARD regulated-information containment are implemented and covered by repository acceptance evidence.
Production deployment and control posture
Offline application tests are not a production security assessment. We do not claim verified production backups, disaster recovery, encryption at rest, production TLS architecture or 24/7 monitoring.
We do not claim database row-level security, production MFA or SSO, penetration testing, SOC 2, ISO 27001, FedRAMP or CMMC certification. No authority to process FCI, CUI or classified information is represented.
STANDARD is unclassified and non-CUI. It is intended for authorized public and external intelligence, ordinary commercial information and ordinary customer-confidential business information within the implemented boundary. Do not provide CUI, classified information, credentials or private keys, highly sensitive internal security or network telemetry, or FCI unless Pyrnova has separately authorized the applicable profile and contractual basis. Export-controlled information requiring controls outside the authorized environment is also prohibited.
An evaluation tests Pyrnova against a real external change affecting your organization.
See the company-specific consequence, the evidence behind it, the uncertainty it keeps visible and the point in time it was knowable.