The Tier A report is a single self-contained HTML artifact delivering an organization's external AI governance exposure through interactive visualization: an attack-path graph, non-human identity lineage tracing, NIST CSF 2.0 coverage radar, an animated threat globe, and a narrative walkthrough of what was found and why it matters. No server, no dependencies, no install — the design constraint that shaped everything was that a CISO forwards it to a board member who opens it on a personal laptop with no network access, and it works [VC-C].
It is the free entry tier of SecureAgent ACA, delivered uninvited and requiring nothing of the recipient. The report is the argument.
Request a sample report§ 1 · THE FRAMINGOutside-In: What an Observer Already Knows
Most security reporting shows an organization its own perimeter. The Tier A report inverts the camera: it shows what an outside observer can already determine about your AI governance exposure — external non-human identities, coverage gaps against MITRE technique families [4][5], and comparison against a vendor cohort — without any access being granted. That framing is the substantive decision underneath the visual work: the gap between what you disclose and what is observable is, itself, the finding [VC-C].
| Visualization | Question it answers |
|---|---|
| Attack-path graph | How could an outsider chain exposed AI surfaces into an intrusion? |
| Non-human identity lineage | Which agents, keys, and service identities are externally visible, and what spawned them? |
| MITRE technique coverage map [4][5] | Which technique families have no visible mitigation? |
| NIST CSF 2.0 radar | How does observable posture distribute across framework functions? |
| Vendor cohort comparison | Where does exposure sit against comparable organizations? |
| Narrative walkthrough | What was found, why it matters, what to do first |
§ 2 · THE STANDARDPresentation-Layer Work, Backend Rigor
Engineering rigor was applied at the same standard as the governance backend rather than treated as presentation-layer work: 114 test assertions across five suites, five validation gates plus a determinism gate, and behavioral testing that verifies render assertions per visualization — not just that the page loads. A DOM-injection security finding surfaced during the build was carried forward and closed rather than deferred, and the delivered artifact runs at roughly 14% of its size ceiling with every visualization embedded [VC-C]. The report's assurance mirrors the platform's: gated, deterministic, re-runnable — the evidence posture the NIST AI RMF's MEASURE function describes [2][3].
§ 3 · THE ON-RAMPFrom One File to Continuous Governance
Tier A is deliberately complete on its own — a real assessment, not a teaser — and deliberately the first rung: the identities it finds externally are the ones Tier B scans internally across 230 control objectives, and the coverage gaps it maps are the ones Tier C monitors continuously with MYTHOS certification. An organization can stop at the free file and still be better informed than it was; the ladder is there when the file makes the case [VC-C].
Requesting one requires exactly what viewing one does: nothing. A sample report against a reference organization is available through the briefing link below, and a report against your own external perimeter needs only a domain name [VC-C].
§ 4 · QUESTIONSFrequently Asked Questions
What does the Tier A report cost, and what access does it need?
Nothing, and none. Tier A is the free entry tier of SecureAgent ACA: it assesses the external perimeter only, requires no installation and no credentials, and ships as one self-contained HTML file the recipient can open on any laptop — including one with no network access.
Is a free external scan actually useful?
It is a complete assessment of what an outside observer can already determine: externally visible non-human identities, MITRE technique coverage gaps, a NIST CSF 2.0 posture view, and comparison against a vendor cohort. That outside-in view is precisely the exposure most internal reporting never shows — the gap between what you disclose and what is observable is the finding.
How is a report artifact tested to a platform standard?
With 114 test assertions across five suites, five validation gates plus a determinism gate, and behavioral render assertions verified per visualization. A DOM-injection finding surfaced during the build was closed rather than deferred. The report earns the same evidence posture as the governance backend it introduces.
CONTACTTalk to VectorCertain
Every figure on this page traces to sealed, hash-verified validation artifacts — including findings that contradicted our own published estimates, which we recorded rather than reconciled away. Technical briefings are available for enterprises, evaluators, and standards bodies.
Request the technical briefingREFERENCES
- NIST. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1. nvlpubs.nist.gov
- NIST. AI Risk Management Framework (program page). nist.gov/itl/ai-risk-management-framework
- MITRE. ATLAS — Adversarial Threat Landscape for Artificial-Intelligence Systems. atlas.mitre.org
- MITRE. ATT&CK. attack.mitre.org
[VC-C] Patent portfolio and platform engineering baseline — 77-claim hub filing, stack integration claims, 36,181-test regression suite; portfolio documentation, January 2026. Public URLs will replace artifact names when the corresponding research pages publish.