Executive Solution Brief Doc Ref: GX-DSPM-CAP-2026.1

Custos DSPM & AI Governance Platform

High-Level Capabilities Matrix & Architectural Specifications

Custos DSPM is the premier on-premises, air-gapped Data Security Posture Management and real-time AI Governance system engineered for sovereign global enterprises. Providing turnkey compliance across Global Privacy (POPIA, EU GDPR, UK DPA 2018, California CCPA/CPRA, Canada PIPEDA/Law 25, Brazil LGPD, Singapore PDPA, India DPDPA, Australia Privacy Act 1988), Global Banking & Financial Standards (PCI DSS v4.0, SWIFT CSP CSCF v2024, EU DORA, US GLBA, APRA CPS 234 & SOCI Act), and Healthcare & Clinical Privacy (HIPAA / HITECH 45 CFR § 164.312). Developed and owned by GovernX (Pty) Ltd, Custos discovers, classifies, and protects sensitive enterprise datastores and LLM pipelines in-place with zero WAN data movement.

Corporate Headquarters
GovernX (Pty) Ltd
Cape Town, Western Cape, South Africa
Official Desk: Enterprise Contact & Inquiries →
Web Presence: governx.co.za

Core Functional Capabilities Matrix

Pillar 01

Air-Gapped Sovereign Deployment

Operates in 100% disconnected data centers, sovereign private clouds, and SCIF environments with zero internet dependencies.

  • Zero WAN telemetry and zero cloud phone-home signals
  • Cryptographically sealed Ed25519 node-locked offline licenses
  • Kernel-level eBPF network boundaries block unauthorized egress
  • Offline container bundles, RPM/DEB packages, and Helm charts
Pillar 02

In-Place Discovery & Classification

Autonomous, high-throughput cursor-based scanning directly against live enterprise storage engines without copying data.

  • Natively connects to Oracle RAC 19c/21c, Microsoft SQL Server AlwaysOn
  • PostgreSQL, TimescaleDB, MongoDB, and MinIO/Ceph S3 object lakes
  • Unstructured scanning across enterprise SMB, NFS, and Hadoop HDFS
  • 80+ pre-trained African PII classifiers (ZA ID, SARS Tax, NIN, Huduma)
Pillar 03

Universal Multi-LLM AI Guardrails

In-line reverse proxy streaming guardrail that intercepts and inspects prompts and model completions with sub-5ms latency.

  • 120+ Global LLM Interception Matrix: Cloud APIs (OpenAI GPT-4o/o1, Claude 3.7, Gemini 2.0), Web Portals (ChatGPT, Claude Web), IDEs (Cursor AI, Copilot), and Local Engines (Ollama, vLLM)
  • Healthcare & Patient PHI Protection: HIPAA §164.514 & POPIA Sec 26/32 redaction for Patient MRN, Medical Aid (Discovery Health, GEMS, Bonitas), Clinician HPCSA, ICD-10, and Prescriptions
  • Company-Defined Custom Rules Engine: Dynamic CRUD regexes, project codenames (Project Valkyrie), and secret API token masking
  • Universal Streaming Guardrail: Real-time bidirectional token filtering with sub-2ms latency overhead
  • Semantic Entitlement Filter: Prevents M365 Copilot & Vector RAG oversharing beyond Active Directory permissions
  • Cryptographically Sealed Audit Trail: Append-only SHA-256 model lineage and Zero WAN telemetry
Pillar 04

Regulatory Sovereignty Engine

Automates compliance tracking and regulatory reporting specifically engineered for African data privacy legislation, Indian Ocean island directives, and global data protection standards.

  • POPIA Section 72 automated cross-border transfer risk assessment
  • Mauritius Data Protection Act 2017 (DPA 2017) compliance tracking
  • Bank of Mauritius (BoM) & FSC Cloud Computing and Data Residency directives
  • European Union General Data Protection Regulation (EU GDPR) Article 32 & Chapter V
  • Nigeria NDPA Section 41 and Kenya DPA Section 48 compliance posture
  • South African Reserve Bank (SARB) Cyber Resilience alignment
  • Central Bank of Kenya (CBK) Cybersecurity Guideline readiness
  • 1-Click Statutory Section 51 PAIA Manual audit exports
Pillar 05

Enterprise SIEM & SOAR Matrix

Multi-destination real-time event broadcasting to your existing Security Operations Center (SOC) infrastructure.

  • Microsoft Sentinel via Data Collection Endpoint (DCE/DCR API)
  • Splunk HTTP Event Collector (HEC) with index-level routing
  • IBM QRadar Log Event Extended Format (LEEF 1.0 & 2.0)
  • Micro Focus ArcSight Common Event Format (CEF v0)
  • Elastic Security (ECS) and Universal Syslog RFC 5424/3164 (TLS/TCP/UDP)
Pillar 06

Entitlement & Identity Governance (CIEM)

Continuous analysis of database privileges, role escalation risks, and dormant service account credentials.

  • Over-privileged DBA and application connection pool auditing
  • Detection of dormant database logins accessing sensitive PII tables
  • Schema-level credential leakage and hardcoded password alerts
  • Privilege drift tracking across test, staging, and production enclaves

Complete Enterprise Modules & Functional Directory (26 Modules & Core Appliance)

Every module is pre-compiled into the sovereign binary appliance and activated with offline Ed25519 node-locked keys with zero added infrastructure or downtime.

26 Modules Pre-Compiled
Custos Core™ DSPM Engine Emblem
CORE_DSPM
Core Engine

Custos Core™ DSPM Engine

In-Place Sovereign Discovery, Classification & Posture Management

High-throughput cursor scanner connecting natively to Oracle RAC, Microsoft SQL Server, PostgreSQL, MongoDB, MinIO S3 lakes, and enterprise NFS/SMB shares. Discovers and classifies sensitive data in-place with zero WAN egress.

Core Functional Capabilities:
  • ✓In-Place Zero-Copy Streaming: Scans live multi-terabyte datastores without moving or replicating data.
  • ✓80+ African & Global Classifiers: Pre-trained for ZA ID, SARS Tax, NIN, KRA PIN, Luhn cards, and passports.
  • ✓Shadow Datastore Discovery: Identifies unmanaged database instances, stale backups, and rogue exports.
  • ✓Sovereign Node Isolation: 100% air-gapped; operates in disconnected SCIFs with zero cloud telemetry.
$ custos-ctl diagnose -scrub-pii
• Status: 100% Disconnected Enclave | Scan Speed: 1.8 TB/hr
The Enterprise Moat & Value:

US SaaS competitors require streaming database copies or metadata to foreign clouds. Custos keeps 100% of data custody on-premise.

Governance & Privacy Pack Emblem
GOVERNANCE_PRIVACY
Add-On Module 01

Governance & Privacy Pack

Automated DSAR Discovery, POPIA Section 24 Erasure & ROT Storage Reclaim

Turnkey statutory compliance automation for Data Protection Officers, Chief Legal Counsel, and enterprise storage architects. Automates citizen Subject Access Requests across disconnected databases in seconds.

Core Functional Capabilities:
  • ✓Automated Cross-System DSAR Discovery: Instant multi-datastore query aggregating all personal data matching a citizen ID or passport.
  • ✓POPIA Section 24 In-Place Erasure: Zeroizes records with cryptographically signed ProofOfErasureCertificate records.
  • ✓ROT Storage Reclaim Engine: Rolling SHA-256 block hash engine detecting duplicate files, stale data (>1–3 years), and orphaned .bak dumps.
  • ✓Multi-Framework Readiness Audits: Automated gap scoring aligned with South Africa POPIA, Mauritius DPA 2017, and EU GDPR.
$ custos-ctl privacy dsar -citizen-id 8801015009087
• Verdict: 4 Datastores Queried | ProofOfErasure SHA-256 Sealed
The Enterprise Moat & Value:

Cuts legal and DBA investigation time by 90% and reclaims 20%–40% of expensive tier-1 SAN storage capacity.

Active Defense & SecOps Pack Emblem
ACTIVE_DEFENSE
Add-On Module 02

Active Defense & SecOps Pack

Zero-Trust Automated Quarantine, HoneyData Decoys & SIEM Integration

Autonomous containment that neutralizes exposed files in under 2 seconds and injects authentic Luhn-valid canary decoys into relational databases to trap malicious insiders.

Core Functional Capabilities:
  • ✓Automated Quarantine Vault: Severs open permissions and moves exposed files into an encrypted 0600 isolation vault.
  • ✓Canary HoneyData Decoys: Injects authentic South African citizen records passing valid Luhn check algorithms.
  • ✓Database Intrusion Tripwires: Intercepts unauthorized queries touching decoy records, tripping instant P1 alarms.
  • ✓Multi-SIEM/SOAR Dispatch: Real-time streaming into Microsoft Sentinel, Splunk HEC, IBM QRadar, and Elastic.
$ custos-ctl defense quarantine -path /shares/payroll
• Action: ISOLATED_ENCRYPTED_VAULT (Containment Latency: 1.2s)
The Enterprise Moat & Value:

Reduces Mean Time to Remediate from 14 days to under 2 seconds, neutralizing data spills before exfiltration occurs.

Enterprise AI Governance Pack Emblem
ENTERPRISE_AI
Add-On Module 03

Enterprise AI Governance Pack

Dynamic RAG ACL Filtering, Real-Time Prompt Injection Shield & Shadow AI Scanner

In-line reverse proxy streaming guardrail that inspects prompts and completions with sub-5ms latency, blocking prompt injections and enforcing Active Directory clearances on RAG context chunks.

Core Functional Capabilities:
  • ✓Dynamic RAG Context Entitlements: Intercepts vector retrievals and enforces AD/Entra ID group ACLs on chunks before prompt assembly.
  • ✓Prompt Injection & Jailbreak Shield: Blocks direct instruction overrides, DAN exploits, and Base64-smuggled payloads.
  • ✓Network Shadow AI Scanner: Continuously sweeps corporate subnets for unmonitored local LLM engines (Ollama, vLLM, LM Studio).
  • ✓Cryptographic Model Ledger: SHA-256 hash-chaining of all AI completions guaranteeing audit-proof model lineage.
$ custos-ctl ai shadow-scan -subnet 10.0.0.0/16
• Discovered: 2 Rogue Ollama Instances | 1 Unsanitized vLLM Socket
The Enterprise Moat & Value:

Guarantees employees cannot retrieve confidential HR or payroll data through Copilots beyond their security clearance.

Custos SovereignFence™ Emblem
SOVEREIGN_FENCE
Add-On Module 04

Custos SovereignFence™

Active Kernel eBPF WAN Cross-Border Blocker

Inspects egress network traffic at wire speed (<1 µs). If citizen PII is detected leaving approved national borders, it drops the TCP connection at the Linux kernel level, making foreign data transfer physically impossible.

Core Functional Capabilities:
  • ✓Kernel-Level eBPF Socket Filter: Operates inside the OS network stack without user-space context-switch overhead.
  • ✓Automated TCP Reset (RST): Instantly terminates unauthorized cross-border outbound sessions.
  • ✓Statutory Geofencing: Enforces South Africa POPIA Section 72 and Mauritius DPA 2017 Section 36 cross-border rules.
  • ✓Audit-Proof Kernel Proofs: Generates tamper-evident SHA-256 hash records for every blocked connection.
$ custos-ctl fence inspect -src 10.0.1.5 -dst 52.1.2.3
• Action: DROP_TCP_RST (POPIA Sec 72 / DPA Sec 36 Boundary Enforced)
The Enterprise Moat & Value:

Competitors merely log breaches after they occur. SovereignFence prevents exfiltration before packets leave the host.

Custos SynthMask™ Emblem
SYNTH_MASK
Add-On Module 05

Custos SynthMask™

Differential Privacy Synthetic Test-Data Engine & Schema Cloner

Clones Oracle, SQL Server, and Postgres databases into QA/Dev environments with mathematical ε-differential privacy. Preserves foreign key referential integrity while substituting all citizen identifiers with valid synthetic data.

Core Functional Capabilities:
  • ✓Mathematical Differential Privacy: Configurable ε privacy budget guarantees zero reconstruction risk.
  • ✓Full Relational Integrity: Preserves primary/foreign key relationships across complex relational schemas.
  • ✓Localized African Personas: Synthesizes authentic, checksum-valid South African IDs, Nigerian NINs, and Kenyan PINs.
  • ✓Zero Cloud Dependency: Generates synthetic test databases at up to 100,000 rows/second on local CPUs.
$ custos-ctl synth -table customers -count 10000
• Output: 10,000 Cloned Rows | Zero Real PII | FK Integrity Intact
The Enterprise Moat & Value:

Eliminates the #1 breach vector in banking: offshore QA contractors working on unmasked production database clones.

Custos BlastRadius™ Emblem
BLAST_RADIUS
Add-On Module 06

Custos BlastRadius™

Zero-Trust Identity Graph & Attack Path Simulator

Maps Entra ID, Active Directory, and SharePoint permissions directly to classified databases and document stores. Eliminates over-permissioned access before Microsoft 365 Copilot's semantic index exposes confidential files.

Core Functional Capabilities:
  • ✓Graph-Based Access Correlator: Visualizes transitive access paths from user groups to sensitive database tables.
  • ✓Financial Liability Simulator: Computes statutory breach exposure in ZAR and USD per overprivileged identity.
  • ✓Copilot Over-Sharing Prevention: Pinpoints SharePoint folders with excessive 'Everyone except external' sharing.
  • ✓Automated Clamping Guidance: Provides exact PowerShell and SQL remediation scripts to achieve least privilege.
$ custos-ctl blastradius -target "HR Confidential"
• Attack Paths: 14 Overprivileged AD Groups | Exposure: R 18.5M ZAR
The Enterprise Moat & Value:

Zero alert fatigue. Neutralizes M365 Copilot data harvesting and maps board-ready financial liabilities.

Custos AgentShield™ Emblem
AGENT_SHIELD
Add-On Module 07

Custos AgentShield™

Autonomous AI & Microsoft Copilot Studio Tool-Calling Governor

Secures autonomous multi-agent systems (Microsoft Copilot Studio, LangChain, AutoGen) invoking internal APIs, SharePoint, and SQL tools. Sanitizes query limits and blocks prompt-injected mutations (DROP/UPDATE).

Core Functional Capabilities:
  • ✓Tool-Call Authorization: Enforces strict role-based whitelists on agent function calling.
  • ✓Destructive Mutation Blocker: Intercepts and blocks SQL DROP/UPDATE/DELETE and OS shell commands.
  • ✓Query Bound Clamping: Prevents autonomous bots from dumping entire tables via unconstrained SELECTs.
  • ✓Honeypot Trap Injection: Serves synthetic honey-data when prompt anomalies or jailbreaks are detected.
$ custos-ctl agentshield -role MicrosoftCopilotStudioAgent -limit 50
• Decision: SANITIZE (Clamped to 5 Rows | Graph Context Shielded)
The Enterprise Moat & Value:

First-to-market autonomous AI & Copilot Studio governor. Protects core banking backends from agentic breakout.

Custos CleanRoom™ Emblem
Custos CleanRoom™
Add-On Module 08

Custos CleanRoom™

Zero-Footprint M&A & Vendor Data Liability Auditor

A single-binary ephemeral scanner deployed on target acquisition networks or vendor environments. Audits candidate datastores in 24 hours, computing statutory liabilities and recommended escrow purchase-price holdbacks.

Core Functional Capabilities:
  • ✓Zero-Footprint Ephemeral Audit: Runs without persistent agents, leaving zero forensic trace after completion.
  • ✓M&A Statutory Due Diligence: Quantifies POPIA and GDPR compliance gaps across candidate data estates.
  • ✓Escrow Holdback Calculator: Computes statistically sound purchase-price holdback figures in USD and ZAR.
  • ✓Cryptographic SHA-256 Deal Seal: Delivers court-admissible audit proof for acquisition legal counsel.
$ custos-ctl cleanroom -entity FinTechTargetLtd
• Recommended Escrow Holdback: $ 3.75M USD | SHA-256 Seal Valid
The Enterprise Moat & Value:

Allows private equity and banking acquirers to uncover hidden regulatory liabilities before closing commercial transactions.

Custos WireShield™ Emblem
WIRE_SHIELD
Add-On Module 09

Custos WireShield™

Zero-Touch SQL Wire-Level Virtual Masking Engine

Intercepts SQL query result streams at the network wire level (PostgreSQL, MSSQL TDS, Oracle TNS). Dynamically masks citizen PII for unprivileged users, BI dashboards, and AI bots without altering database schemas or breaking legacy systems.

Core Functional Capabilities:
  • ✓Wire-Level Protocol Inspection: Transparent proxy operating directly on TDS, TNS, and Postgres protocols.
  • ✓Zero Schema Migrations: No database views, triggers, or schema alterations required on production engines.
  • ✓Role-Aware Dynamic Masking: Full plaintext for authorized DBAs; dynamic asterisk masking for unprivileged analysts.
  • ✓Sub-Millisecond Wire Overhead: Zero-allocation stream buffers maintain wire-speed database performance.
$ custos-ctl wireshield -caller unprivileged
• Action: DYNAMIC_STREAM_MASKING (ZA ID & Salary Masked on Wire)
The Enterprise Moat & Value:

Solves the #1 flaw of DSPMs: active zero-disruption remediation without requiring dangerous database migrations.

Custos VectorGuard™ Emblem
VECTOR_GUARD
Add-On Module 10

Custos VectorGuard™

Neural DLP & Vector DB / RAG Entitlement Firewall

The world's first true Vector DB DSPM. Sanitizes chunks before embedding to prevent irreversible vector contamination, and filters RAG semantic retrieval chunks based on Active Directory clearance before LLM prompt assembly.

Core Functional Capabilities:
  • ✓Pre-Embedding Neural Sanitization: Intercepts document ingestion pipelines to prevent toxic PII contamination.
  • ✓Semantic RAG Entitlement Firewall: Filters vector similarity search results based on user identity clearance.
  • ✓Broad Vector DB Support: Native connectors for Pinecone, Milvus, Qdrant, Chroma, and pgvector.
  • ✓Embedding Inversion Defense: Prevents attackers from reconstructing original sensitive text from high-dimensional vectors.
$ custos-ctl vectorguard -mode rag -user [email protected]
• Filter: Dropped 2 Chunks (Clearance Denied on Restricted Context)
The Enterprise Moat & Value:

Protects modern high-dimensional vector databases where legacy regex DLP is 100% blind.

Custos SafeHarbor™ Emblem
SAFE_HARBOR
Add-On Module 11

Custos SafeHarbor™

Cryptographic CISO Legal Defense & Merkle Proof Ledger

Aggregates daily security safeguards into an immutable Ed25519-signed Merkle Tree. Generates court-admissible Statutory Safe Harbor Dossiers providing affirmative legal defense for CISOs under POPIA Section 107 and global regulations.

Core Functional Capabilities:
  • ✓Merkle Tree Audit Ledger: Cryptographically chains all scanning, masking, and quarantine events into daily roots.
  • ✓Ed25519 Hardware Signatures: Digital signatures verify continuous, uninterrupted security due diligence.
  • ✓Statutory Affirmative Defense: Generates court-admissible evidence proving due care under POPIA Section 107.
  • ✓Executive Liability Protection: Shields CISOs, CIOs, and directors from personal civil and criminal liability.
$ custos-ctl safeharbor -org "Standard Sovereign Bank"
• Signature Verified: true (Ed25519 Court-Admissible Proof Sealed)
The Enterprise Moat & Value:

Transforms technical safeguards into affirmative legal immunity for executive leadership against personal liability.

Custos MCP-Shield™ Emblem
MCP_SHIELD
Add-On Module 12

Custos MCP-Shield™

Model Context Protocol Tool & Query Firewall for LLMs

Zero-latency (<2ms) in-line proxy governing Anthropic Model Context Protocol (MCP) JSON-RPC tool-calling between local LLMs/Copilots and backend databases. Enforces schema whitelisting, query row-limit clamping, and canary trap injection.

Core Functional Capabilities:
  • ✓JSON-RPC Socket Inspection: Zero-latency (<2ms) in-line proxy inspecting stdio and SSE MCP traffic.
  • ✓Query Row-Limit Clamping: Automatically clamps query limits (e.g. from 50,000 to max 25 rows).
  • ✓Schema & Destructive Block: Prohibits SQL injection, DDL drops, and unauthorized tool calls.
  • ✓Canary Trap Echo Detection: Injects dummy canary records and severs sessions if agent echoes tokens.
$ custos-ctl mcpshield -server customer-db-mcp -limit 500
• Action: CLAMP_ROW_LIMIT (Clamped to 25 rows | Latency: 0.00ms)
The Enterprise Moat & Value:

Prevents prompt-injected LLMs from bulk dumping production SQL databases through open MCP server connections.

Custos ShannonEntropy™ Emblem
SHANNON_ENTROPY
Add-On Module 13

Custos ShannonEntropy™

Zero-Day Ransomware & DB Entropy Tripwire

Continuous kernel/storage monitoring calculating Shannon Entropy H(X) on database page blocks in real time. Detects silent cryptographic encryption (entropy spiking >7.85) and drops TCP connections via eBPF in <500ms before mass encryption completes.

Core Functional Capabilities:
  • ✓Shannon Entropy H(X) Engine: Mathematical calculation detecting sudden entropy spikes (>7.85 bits/byte).
  • ✓Sub-500ms Kernel Severing: Drops offending TCP connections via eBPF and locks down storage files.
  • ✓Automated WAL Isolation: Triggers instant WAL log checkpointing to preserve uncorrupted rollback states.
  • ✓Bypasses EDR Blindspots: Protects database storage directly, catching stealth ransomware that bypasses antivirus.
$ custos-ctl shannon -target oracle_payroll -simulate ransomware
• Action: SEVER_CONNECTION_AND_SEAL (Response Time: 0.53ms)
The Enterprise Moat & Value:

Traditional EDR misses in-memory database block encryption. ShannonEntropy catches zero-day database ransomware at the physical write layer.

Custos NHI-Guard™ Emblem
NHI_GUARD
Add-On Module 14

Custos NHI-Guard™

Non-Human Identity & Secret Blast Radius Correlator

Discovers unmanaged service principals, automated ETL batch tokens, K8s secrets, and connection strings. Correlates machine identities with sensitive PII tables to flag dormancy (>90 days inactive) and privilege creep, quantifying breach exposure in ZAR & USD.

Core Functional Capabilities:
  • ✓Machine Credential Discovery: Tracks connection strings, ETL tokens, and K8s service accounts.
  • ✓Dormancy & Privilege Creep: Flags accounts inactive >90 days holding admin rights to classified PII.
  • ✓Financial Blast Exposure: Calculates statutory breach exposure in ZAR & USD per unmanaged identity.
  • ✓Automated Token Deprovisioning: Emits revocation orders for stale credentials before compromise.
$ custos-ctl nhiguard -id svc-etl-nightly-billing
• Blast Exposure: R 6,750,000 ZAR ($ 369,863 USD) - DORMANT RISK
The Enterprise Moat & Value:

80% of enterprise breaches leverage compromised machine tokens. NHI-Guard shuts down over-privileged service accounts before attackers find them.

Custos ModelAudit™ Emblem
MODEL_AUDIT
Add-On Module 15

Custos ModelAudit™

AI Right-to-Erasure & Machine Unlearning Verifier

Automates POPIA Section 24 and GDPR Article 17 'Right to Erasure' across on-premises AI pipelines. Verifies vector chunk purging and runs differential influence-function attribution checks to issue court-admissible Proof of Machine Unlearning certificates.

Core Functional Capabilities:
  • ✓Vector Store Sanitizer: Automatically zeroes citizen embeddings across Pinecone, Milvus, and pgvector.
  • ✓Influence-Function Auditing: Mathematically proves citizen data no longer alters token distributions (influence score <= 0.0001).
  • ✓Unlearning Certificates: Generates court-admissible Ed25519-signed proof of algorithmic erasure.
  • ✓Protects Model Capital: Prevents costly regulatory forced destruction of proprietary enterprise AI models.
$ custos-ctl modelaudit -citizen ZA-9801125543088
• Influence Attribution: 0.000021 (POPIA Sec 24 VERIFIED)
The Enterprise Moat & Value:

Solves the nightmare of AI 'algorithmic disgorgement' by proving to regulators that citizen data no longer influences neural network outputs.

Custos AgentFence™ Emblem
AGENT_FENCE
Add-On Module 16

Custos AgentFence™

Autonomous AI Agent Runtime Execution Firewall & Dual-Control Gate

Enforces bank-grade 7-layer execution boundaries on autonomous agent tool calls (LangChain, AutoGen, Claude MCP, Copilot Studio). Detects indirect prompt injections, blocks unconstrained financial velocity, and triggers SARB dual-control HMAC multi-sig on high-value transfers.

Core Functional Capabilities:
  • ✓Strict Schema Contract Enforcement: Rejects undeclared parameters, prototype pollution, and out-of-bounds arguments.
  • ✓Indirect Prompt Injection Scanner: Detects system overrides, Base64 evasion, and invisible Unicode zero-width tags.
  • ✓Financial Velocity Limiter: Enforces rolling window transaction caps per agent session across ZAR, USD, GBP, and EUR.
  • ✓Dual-Control Escalation: Issues cryptographic HMAC-SHA256 tickets requiring human officer approval on amounts > R50k.
$ custos-ctl agentfence -role CorporateTreasuryAgent -amount 85000
• Gate: REQUIRE_APPROVAL (Challenge: CHG-17898... | SARB > R50k Dual-Control)
The Enterprise Moat & Value:

Eliminates the #1 existential threat to tier-1 banks adopting autonomous agents: accidental or poisoned financial execution.

Custos WireRemit™ Emblem
WIRE_REMIT
Add-On Module 17

Custos WireRemit™

ISO 20022 XML Streaming Parser, Control-Sum Reconciler & Sanctions Governor

Real-time zero-allocation streaming parser for ISO 20022 payment messages (pacs.008, pain.001, camt.053). Reconciles CtrlSum header values, performs in-flight PII/IBAN tokenization, and screens parties against OFAC SDN, UN, and SARB FIC watchlists with 126µs latency.

Core Functional Capabilities:
  • ✓Streaming XML Decoder: Parses multi-megabyte pacs.008 wire files with zero heap buffer exhaustion.
  • ✓Control Sum Integrity Reconciler: Catches corrupt or tampered files where transaction amounts deviate from CtrlSum.
  • ✓Watchlist & FATF Corridor Screening: In-memory Jaro-Winkler matching against OFAC, UN, and FIC sanctions lists.
  • ✓In-Flight IBAN/PII Tokenization: Replaces accounts with vault tokens while preserving UETR and BIC routing keys.
$ custos-ctl wireremit -tokenize
• Decision: TOKENIZED (4 PII Elements Masked | 126 µs Processing Latency)
The Enterprise Moat & Value:

Allows tier-1 banks to stream core SWIFT ISO 20022 wire feeds to cloud data lakes without violating cross-border PII laws or sanctions.

Custos QuantumRadar™ Emblem
QUANTUM_RADAR
Add-On Module 18

Custos QuantumRadar™

Post-Quantum Cryptography Discovery, CycloneDX CBOM & HNDL Migration Engine

Discovers all cryptographic algorithms (RSA, ECC, AES, 3DES) across banking TLS, database columns, and VPN pipes. Generates CycloneDX 1.6 Cryptographic Bill of Materials (CBOM), scores Harvest Now Decrypt Later (HNDL) risk, and builds migration roadmaps for NIST FIPS 203 (ML-KEM) & FIPS 204 (ML-DSA).

Core Functional Capabilities:
  • ✓In-Place Cryptographic Scanner: Classifies X.509 certs, TLS cipher suites, and database keys in-place.
  • ✓CycloneDX 1.6 CBOM Export: Standardized Cryptographic Bill of Materials for regulators (BIS, SARB, PRA).
  • ✓Mosca HNDL Risk Scoring: Evaluates data shelf-life against CRQC quantum arrival horizon (5µs latency).
  • ✓NIST PQC Migration Roadmap: Automated mapping to ML-KEM-768/1024 (FIPS 203) and ML-DSA-65 (FIPS 204).
$ custos-ctl quantumradar -roadmap
• Target: FIPS 203 ML-KEM-768 (X25519Kyber768 Hybrid) | Priority: IMMEDIATE
The Enterprise Moat & Value:

Regulatory mandate protection: equips bank CISOs with CBOM proofs ahead of impending mandatory 2026-2030 post-quantum migration deadlines.

Custos QueryShield™ Emblem
QUERY_SHIELD
Add-On Module 19

Custos QueryShield™

Zero-Schema Wire-Level Dynamic SQL Query Rewriting & Side-Channel Blocker

Intercepts incoming SQL queries on the wire (PostgreSQL, Oracle, MySQL, SQLServer) and rewrites column projections into native database masking expressions before execution. Blocks binary-search WHERE clause side-channel attacks with sub-1ms overhead and zero schema migrations.

Core Functional Capabilities:
  • ✓Zero Schema Alterations: No column encryption migrations; runs transparently at the database socket level.
  • ✓Dynamic Projection Rewriter: Automatically injects CONCAT/SUBSTRING PAN & ID masks and zeroes salaries.
  • ✓Side-Channel Inference Blocker: Blocks binary search attacks on sensitive WHERE clause predicates (e.g. card_pan LIKE).
  • ✓Differential Privacy Mode: Injects ROUND/noise for data scientists while preserving DBA superuser bypass.
$ custos-ctl queryshield -role CustomerSupportTier1
• Status: REWRITTEN & MASKED ON THE WIRE (50 µs Latency Overhead)
The Enterprise Moat & Value:

Solves the 20-year core banking dilemma: secures sensitive database columns without breaking legacy core banking applications.

Custos SynthProof™ Emblem
SYNTH_PROOF
Add-On Module 20

Custos SynthProof™

Synthetic Identity Fraud & Deepfake Document Ingestion Provenance Engine

Ingestion provenance gate protecting core banking KYC and onboarding systems. Detects AI diffusion generation signatures (Stable Diffusion, Midjourney), spectral entropy uniformity, layered PDF revision trailers, and mathematical Luhn ID faults before fraudulent accounts are created.

Core Functional Capabilities:
  • ✓Generative AI Footprint Scanner: Identifies Stable Diffusion, ComfyUI, DALL-E, and Canva signatures.
  • ✓Spectral Diffusion Noise Analysis: Distinguishes AI latent smoothness from real optical camera sensor shot noise.
  • ✓Statutory Identity Checksum Verifier: Mathematically validates Modulo 10 Luhn algorithms on extracted citizen IDs.
  • ✓Document Timeline Corroborator: Flags post-dated utility bills, stale documents, and fictitious municipal providers.
$ custos-ctl synthproof -ai-test
• Verdict: SYNTHETIC_FRAUD_DETECTED (Score: 100.0/100 | StableDiffusion Signature)
The Enterprise Moat & Value:

Shuts down Synthetic Identity Fraud (SIF) at the digital front door before AI-generated fake personas poison core AML/KYC databases.

Custos ETRadar™ Emblem
ET_RADAR
Add-On Module 21

Custos ETRadar™

Encrypted Traffic Radar, Passive JA4 Fingerprinting & Shannon Entropy Exfiltration Sensor

Passively dissects TLS 1.3 and TLS 1.2 handshakes at wire speed without SSL/TLS decryption. Generates JA4/JA4T fingerprints, evaluates real-time Shannon entropy across streaming flow buffers, detects periodic C2 beaconing jitter, and pumps flow telemetry through a 35M ops/sec lock-free ring buffer directly to SIEM and automated Kubernetes network quarantine.

Core Functional Capabilities:
  • ✓Passive TLS 1.3 Dissector (467ns): Extracts SNI, ALPN, Cipher Suites, and calculates JA4 hashes without MitM key escrow.
  • ✓Shannon Entropy Exfiltration Radar: Continuous 8.0-bit entropy scoring catches high-volume covert encrypted data dumps.
  • ✓C2 Beaconing Timing Jitter Analyzer: Evaluates packet inter-arrival times (IAT) to detect automated malware callbacks (CobaltStrike, AsyncRAT).
  • ✓35M Ops/Sec Lock-Free SPSC Ring: Zero-allocation atomic ring buffer with 27.85ns latency protects payment switches from packet drops.
  • ✓Automated Infrastructure Quarantine: Dispatches CEF/JSON SIEM alerts and triggers Kubernetes pod isolation in real time.
$ custos-ctl etradar -monitor -interface eth0
• JA4: t13d0204h2_62ed6f6ca7ad_f4a44468fbae | Threat: ANOMALOUS_EXFILTRATION | Pod: QUARANTINED
The Enterprise Moat & Value:

Enables Tier-1 banks and defense enclaves to detect covert encrypted data exfiltration and rogue C2 channels without violating banking secrecy or breaking end-to-end TLS session encryption.

Custos Guard™ Emblem
CUSTOS_GUARD
Add-On Module 22

Custos Guard™

In-Line Sub-5ms AI Reverse Proxy & Healthcare PHI Interception Enclave

High-throughput reverse proxy intercepting 120+ frontier cloud and local LLMs (GPT-4o, Claude 3.7, Gemini 2.0, Ollama, DeepSeek-R1). Performs real-time bidirectional PII/PHI de-identification and cryptographic SHA-256 lineage tracking.

Core Functional Capabilities:
  • ✓120+ LLM Interception Matrix: Native HTTP reverse proxy for OpenAI, Anthropic, Gemini, Ollama, and vLLM.
  • ✓Healthcare PHI Protection: Enforces HIPAA §164.514 and POPIA Sec 26/32 redacting MRN, Medical Aid, NPI, and ICD-10.
  • ✓Bidirectional Tokenization: Retains semantic reasoning tokens while blocking customer identifiers.
  • ✓Cryptographic Lineage Ledger: TimescaleDB SHA-256 hash-chaining proving exact training data exposure.
$ custos-ctl proxy -listen 0.0.0.0:8443 -mode inline-intercept
• LLM Gate Active: 120+ Models | Latency: 1.84ms | Zero Cloud Egress
The Enterprise Moat & Value:

Allows hospitals and banks to adopt frontier LLMs and developer AI IDEs with mathematical zero-leakage guarantees.

Custos AutoRemediate™ Emblem
AUTO_REMEDIATE
Add-On Module 23

Custos AutoRemediate™

Autonomous Host & Kubernetes Network Isolation Engine

Zero-delay automated infrastructure remediation engine. Upon threat or exfiltration detection, instantly applies Kubernetes NetworkPolicy route severing, host-level firewall quarantine, and SIEM active response in <2 seconds.

Core Functional Capabilities:
  • ✓Automated K8s Network Severing: Applies strategic merge patch quarantine.dspm.io/isolated: true to halt pod egress.
  • ✓eBPF & Host Firewall Quarantine: Restricts compromised host permissions to 0600 and drops socket routes instantly.
  • ✓Wazuh & SIEM Active Response: Dispatches authenticated JSON commands to host-level security agents for process termination.
  • ✓Tamper-Evident Receipts: Generates cryptographically signed .receipt.json audit trails for every automated isolation event.
$ custos-ctl isolate -pod payment-gateway-7df8 -mode strict-egress
• Remediation Applied in 1.64ms | Wazuh Active Response Confirmed
The Enterprise Moat & Value:

Eliminates the human-in-the-loop delay during ransomware encryption or data exfiltration by severing routes at kernel speed.

Custos AuditDossier™ Emblem
AUDIT_DOSSIER
Add-On Module 24

Custos AuditDossier™

Executive Board & Universal Statutory Compliance Dossier Engine

Automated PDF and HTML regulatory audit reporting engine. Compiles continuous telemetry into verified Board Risk summaries, POPIA Sec 19/24, HIPAA 45 CFR § 164.312, PCI DSS v4.0, EU DORA, and APRA CPS 234 compliance dossiers.

Core Functional Capabilities:
  • ✓11 Statutory Engines: Natively evaluates HIPAA, PCI DSS v4.0, SWIFT CSP, DORA, CCPA, GLBA, UK GDPR, PDPA, DPDPA, PIPEDA, LGPD.
  • ✓Board-Ready Risk Scoring: Translates technical scan results into monetary liability estimates, ROT savings, and posture scores.
  • ✓Ed25519 Cryptographic Attestation: Embeds digital signatures and SHA-256 Merkle roots into every generated dossier.
  • ✓Air-Gapped Offline Generation: Operates entirely within offline enclaves without external SaaS PDF conversion APIs.
$ custos-ctl report generate -standard HIPAA,PCI-DSS,DORA -out /audit/
• Dossier Compiled: Custos_Statutory_Audit_2026.pdf (SHA-256: 8f41...)
The Enterprise Moat & Value:

Provides CISOs, CROs, and external statutory auditors with instant, verifiable legal proof of technical data governance.

Custos DataMesh™ Emblem
DATA_MESH
Add-On Module 25

Custos DataMesh™

In-Place Multi-Engine Storage & S3 Lake Connector Mesh

Ultra-high-throughput native cursor connection mesh for heterogeneous banking and enterprise datastores. Directly queries Oracle RAC, Microsoft SQL Server AlwaysOn, PostgreSQL, MongoDB, MinIO/Ceph S3, and NFS/SMB with zero data replication.

Core Functional Capabilities:
  • ✓Multi-Database In-Memory Cursors: Zero-allocation connection pooling for Oracle RAC (11g–21c), MSSQL, PostgreSQL, MySQL.
  • ✓S3 & Object Lake Streaming: Direct multipart streaming inspection for AWS S3 appliances, MinIO, Ceph, and Dell ECS.
  • ✓Enterprise SMB & POSIX NFS: High-speed recursive directory traversal with metadata caching and permission inspection.
  • ✓Zero WAN Bandwidth Overhead: Computes PII classifications locally in RAM, transmitting zero raw customer data across the network.
$ custos-ctl connectors discover -sweep 10.0.4.0/24 -ports 1521,1433,5432
• 18 Enterprise Datastores Onboarded | In-Place Memory Streaming Active
The Enterprise Moat & Value:

Eliminates costly WAN data transfer bills and complex ETL pipelines by scanning enterprise storage exactly where it resides.

Technical & Architectural Specifications

Domain Specification / Standard Enterprise Sovereign Detail
Supported Operating Systems RHEL 8/9, Rocky Linux 9, Ubuntu 22.04/24.04 LTS, Windows Server 2022 Bare-metal and virtualized installations; kernel 5.4+ with eBPF support enabled.
Container Platforms Red Hat OpenShift 4.12+, Kubernetes 1.28+, SUSE Rancher, Docker EE Certified offline Helm charts; runs in rootless, unprivileged container namespaces.
Scanning Throughput Up to 1.8 TB / hour per scanner worker node Zero-copy cursor streaming; multi-threaded regex and compiled NLP inference.
In-Memory Guardrail Latency < 5.0 milliseconds per stream token chunk Compiled Go core with zero-allocation buffers; supports 5,000+ concurrent LLM sessions.
Target Datastores Oracle RAC (11g/12c/19c/21c), Microsoft SQL Server (2014-2022), PostgreSQL / TimescaleDB, MySQL & MariaDB (5.7/8.0+), MongoDB, Redis, MinIO/Ceph S3, SMB/NFS Agentless read-only connections with configurable rate-limiting and query windowing.
Cryptographic Protocols TLS 1.3, AES-256-GCM, Ed25519 Signatures, SHA-256 Ledgers All internal cluster communications encrypted; air-gapped cryptographic licensing.
Telemetry & Phone-Home Absolute Zero (0 bytes) No external internet connectivity required at installation, runtime, or license renewal.

Comparative Analysis: Custos DSPM vs. Cloud-Only US DSPM Vendors

Capability Dimension Custos DSPM (GovernX) US Cloud DSPM Vendors (SaaS)
Deployment Model 100% Air-Gapped / On-Premises Multi-tenant US/EU Cloud SaaS only
Cross-Border WAN Egress Zero (0 Bytes leave data center) Transfers metadata, schemas & data samples overseas
Sovereign, Financial & Healthcare Compliance Native HIPAA (45 CFR § 164.312), PCI DSS v4.0, SWIFT CSP, DORA, CCPA, PIPEDA, LGPD, PDPA, DPDPA, APRA CPS 234, Privacy Act 1988 (AU), POPIA, NDPA Generic GDPR/CCPA mapping; no local mathematical check digits or interbank eBPF zoning
Multi-LLM Streaming Guardrails Included (Gemini, Claude, GPT-4o, Local R1) Static post-hoc data scanning only; no active LLM proxy
SIEM & SOC Forwarding Native Sentinel, Splunk, LEEF, CEF, Syslog Requires webhook to public internet endpoints
License Activation Offline Hardware-Locked Token (Ed25519) Requires persistent outbound phone-home connection
Database Remediation WireShield™: Zero-Touch SQL Virtual Masking Read-only reports; forces risky schema migrations
Vector DB & RAG Protection VectorGuard™: Neural DLP & Context Firewall 100% blind to high-dimensional vector embeddings
CISO Legal Immunity SafeHarbor™: Ed25519-Signed Merkle Tree Dossier Mutable text syslog files; zero statutory legal safe harbor

Enterprise Evaluation & Partner Accreditation

GovernX works exclusively through accredited systems integrators, value-added resellers, and dedicated sovereign security teams across Africa. Request a 30-day on-premises Proof of Value (POV) or apply for reseller accreditation.

All inquiries submitted through GovernX portals trigger automated verification and dispatch via Azure Communication Services directly to GovernX executive leadership and the applicant.