Sits above Records Vault. It ingests the evidence your products already export — it
adds no new system of record. Self-hosted on your infrastructure; air-gap capable.
Proven, not asserted
| GRC SaaS (Vanta / Drata / OneTrust) | Compliance Command Center | |
|---|---|---|
| Evidence | Attestation + dashboards, vendor-trust | Every figure backed by a signed chain |
| Verification | Trust the vendor | Offline, public key only — re-verify it yourself |
| Deployment | SaaS | Self-hosted, air-gap capable, sovereign |
| Cryptography | Classical | Post-quantum (Falcon-1024) |
What it does
- Aggregates your posture. Records preserved, read-access events, active legal holds, consents, key rotations — each tile shows its value and its verification status.
- Re-verifies, continuously. Every signed chain across the ingested evidence is recomputed offline; a failure surfaces immediately.
- Exports an auditor pack. One click bundles the evidence plus a verification summary into an archive your auditor, regulator, or counterparty verifies independently.
Enterprise from day one
- Role-based access. Administrator, compliance officer, auditor, and read-only viewer roles govern who can see which evidence, run which reports, and export packs.
- Single sign-on. Authenticate against your directory — LDAP / Active Directory — with directory groups mapped to roles. Local accounts for fully disconnected operation.
- Bring-your-own-key custody. The console’s own signing key can live in your AWS KMS, HashiCorp Vault, or PKCS#11 HSM — unwrapped only at the moment of signing, never at rest.
- A signed console audit log. Every console action — who signed in, who viewed what, who exported — is appended to a Falcon-signed, hash-linked chain. The console holds itself to the same standard: who did what in the console is itself offline-verifiable evidence.
How it fits
| Below | Records Vault and the rest of your estate — preserve records as signed evidence |
| This | the management layer — aggregate, re-verify, report, and export across the estate |
| Custody | composes with Bring Your Own Keys |
Availability
A self-hosted Enterprise product, available from the suite store (AV-CCC). Installs token-gated from the AlgoVoi
private index — including fully air-gapped, with no PyPI. Runtime-licensed, fail-closed.
See also
- Records Vault — the evidence this manages
- Bring Your Own Keys — key custody across the estate
- .epi Evidence Export — hand portable evidence to a third party