PYRNOVATrust
Trust

The basis of a conclusion is inspectable, including our own claims.

What the system does, what has been tested, and what has not been verified in production. Stated plainly.

Capability review: 2026-09-21

Fact and assessment

Separated by construction
Observed fact
Attribution
Retained source record
Identity
Source id and provenance
Content
Point-in-time hash
Pyrnova assessment
Attribution
Derived from evidence
Type
Calculated or inferred
Model role
Explanation, attributed

Provenance and evidence

Statements cite retained evidence by identifier. A single authoritative source is treated as not corroborated.

Evidencenotice:SAM 3 refscorroboration: single sourceprogram crosswalk

Uncertainty and falsification

Unresolved
Would weaken or falsify
  • A separate direct-award path is retained for the requirement.
  • The engineering scope leaves the consolidated vehicle.

Absence of evidence is not treated as a win, a loss or a completed outcome. A conclusion can be strengthened, weakened, contradicted or falsified without erasing the earlier call.

Point-in-time integrity

AS OF and replay
t0AS OF cutoffnow AS OF eligible excluded from earlier view

Current posture

Implemented and tested, and what is not
Implemented / tested

Product behaviour with repository evidence

Credential-based authentication. Fail-closed application-layer tenant isolation covered by offline tests; customer identity bound to the credential and cross-customer requests rejected. This is application-layer isolation, not database row-level security.

Evidence provenance, source attribution, the observed-versus-assessed distinction, materiality and confidence, AS OF views and historical replay, source-rights controls, bounded retries, durable checkpoints, restart and recovery, duplicate suppression, fail-closed customer export authorization and provider-neutral STANDARD regulated-information containment are implemented and covered by repository acceptance evidence.

Not yet verified

Production deployment and control posture

Offline application tests are not a production security assessment. We do not claim verified production backups, disaster recovery, encryption at rest, production TLS architecture or 24/7 monitoring.

We do not claim database row-level security, production MFA or SSO, penetration testing, SOC 2, ISO 27001, FedRAMP or CMMC certification. No authority to process FCI, CUI or classified information is represented.

STANDARD information boundary

STANDARD is unclassified and non-CUI. It is intended for authorized public and external intelligence, ordinary commercial information and ordinary customer-confidential business information within the implemented boundary. Do not provide CUI, classified information, credentials or private keys, highly sensitive internal security or network telemetry, or FCI unless Pyrnova has separately authorized the applicable profile and contractual basis. Export-controlled information requiring controls outside the authorized environment is also prohibited.

An evaluation tests Pyrnova against a real external change affecting your organization.

See the company-specific consequence, the evidence behind it, the uncertainty it keeps visible and the point in time it was knowable.

See how evaluation works