VectorCertain
1 FILE · ZERO DEPENDENCIES · NO NETWORK NEEDED
114 TEST ASSERTIONS · 5 SUITES
FREE · NOTHING REQUIRED OF RECIPIENT
Platform · Free tier · One self-contained file

Tier A Threat Report — Interactive AI Exposure

Security findings die in PDFs. This is an assessment report an executive will actually finish — one HTML file, no server, no dependencies, opens anywhere.

RUNS AT ~14% OF SIZE CEILING, ALL VISUALIZATIONS EMBEDDED
FIVE VALIDATION GATES + DETERMINISM GATE

The Tier A report is a single self-contained HTML artifact delivering an organization's external AI governance exposure through interactive visualization: an attack-path graph, non-human identity lineage tracing, NIST CSF 2.0 coverage radar, an animated threat globe, and a narrative walkthrough of what was found and why it matters. No server, no dependencies, no install — the design constraint that shaped everything was that a CISO forwards it to a board member who opens it on a personal laptop with no network access, and it works [VC-C].

It is the free entry tier of SecureAgent ACA, delivered uninvited and requiring nothing of the recipient. The report is the argument.

Request a sample report

§ 1 · THE FRAMINGOutside-In: What an Observer Already Knows

Most security reporting shows an organization its own perimeter. The Tier A report inverts the camera: it shows what an outside observer can already determine about your AI governance exposure — external non-human identities, coverage gaps against MITRE technique families [4][5], and comparison against a vendor cohort — without any access being granted. That framing is the substantive decision underneath the visual work: the gap between what you disclose and what is observable is, itself, the finding [VC-C].

Single HTML file containing embedded visualizations, opening directly on a laptop with no external connections ONE .HTML FILE1010 ATTACK-PATH GRAPH IDENTITY LINEAGE NIST CSF RADAR THREAT GLOBE + NARRATIVE ~14% of size ceiling · 114 assertions · determinism-gated forward ANY LAPTOPno network · no server · no installopens. works.1020 1000
FIG. 1Anatomy of the single-file artifact (1000): all visualizations, data, and interactivity embedded in one HTML file (1010) that opens with no network, no server, and no install (1020).
Table 1 · What the report contains, and the question each view answers
VisualizationQuestion it answers
Attack-path graphHow could an outsider chain exposed AI surfaces into an intrusion?
Non-human identity lineageWhich agents, keys, and service identities are externally visible, and what spawned them?
MITRE technique coverage map [4][5]Which technique families have no visible mitigation?
NIST CSF 2.0 radarHow does observable posture distribute across framework functions?
Vendor cohort comparisonWhere does exposure sit against comparable organizations?
Narrative walkthroughWhat was found, why it matters, what to do first

§ 2 · THE STANDARDPresentation-Layer Work, Backend Rigor

Engineering rigor was applied at the same standard as the governance backend rather than treated as presentation-layer work: 114 test assertions across five suites, five validation gates plus a determinism gate, and behavioral testing that verifies render assertions per visualization — not just that the page loads. A DOM-injection security finding surfaced during the build was carried forward and closed rather than deferred, and the delivered artifact runs at roughly 14% of its size ceiling with every visualization embedded [VC-C]. The report's assurance mirrors the platform's: gated, deterministic, re-runnable — the evidence posture the NIST AI RMF's MEASURE function describes [2][3].

§ 3 · THE ON-RAMPFrom One File to Continuous Governance

Tier A is deliberately complete on its own — a real assessment, not a teaser — and deliberately the first rung: the identities it finds externally are the ones Tier B scans internally across 230 control objectives, and the coverage gaps it maps are the ones Tier C monitors continuously with MYTHOS certification. An organization can stop at the free file and still be better informed than it was; the ladder is there when the file makes the case [VC-C].

Requesting one requires exactly what viewing one does: nothing. A sample report against a reference organization is available through the briefing link below, and a report against your own external perimeter needs only a domain name [VC-C].

§ 4 · QUESTIONSFrequently Asked Questions

What does the Tier A report cost, and what access does it need?

Nothing, and none. Tier A is the free entry tier of SecureAgent ACA: it assesses the external perimeter only, requires no installation and no credentials, and ships as one self-contained HTML file the recipient can open on any laptop — including one with no network access.

Is a free external scan actually useful?

It is a complete assessment of what an outside observer can already determine: externally visible non-human identities, MITRE technique coverage gaps, a NIST CSF 2.0 posture view, and comparison against a vendor cohort. That outside-in view is precisely the exposure most internal reporting never shows — the gap between what you disclose and what is observable is the finding.

How is a report artifact tested to a platform standard?

With 114 test assertions across five suites, five validation gates plus a determinism gate, and behavioral render assertions verified per visualization. A DOM-injection finding surfaced during the build was closed rather than deferred. The report earns the same evidence posture as the governance backend it introduces.

CONTACTTalk to VectorCertain

Every figure on this page traces to sealed, hash-verified validation artifacts — including findings that contradicted our own published estimates, which we recorded rather than reconciled away. Technical briefings are available for enterprises, evaluators, and standards bodies.

Request the technical briefing

REFERENCES

  1. NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. nvlpubs.nist.gov
  2. NIST. AI Risk Management Framework (program page). nist.gov/itl/ai-risk-management-framework
  3. MITRE. ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems. atlas.mitre.org
  4. MITRE. ATT&CK. attack.mitre.org
First-party validation artifacts (VectorCertain, sealed and hash-verified):

[VC-C] Patent portfolio and platform engineering baseline — 77-claim hub filing, stack integration claims, 36,181-test regression suite; portfolio documentation, January 2026. Public URLs will replace artifact names when the corresponding research pages publish.

Join the waitlist

Our signup form is temporarily offline while we perform maintenance. Nothing is lost — reach us directly and we'll add you by hand.

PLACEHOLDER · Tally.so form returns here · engineering ticket open

Email us to join