Core Functional Capabilities Matrix
Air-Gapped Sovereign Deployment
Operates in 100% disconnected data centers, sovereign private clouds, and SCIF environments with zero internet dependencies.
- Zero WAN telemetry and zero cloud phone-home signals
- Cryptographically sealed Ed25519 node-locked offline licenses
- Kernel-level eBPF network boundaries block unauthorized egress
- Offline container bundles, RPM/DEB packages, and Helm charts
In-Place Discovery & Classification
Autonomous, high-throughput cursor-based scanning directly against live enterprise storage engines without copying data.
- Natively connects to Oracle RAC 19c/21c, Microsoft SQL Server AlwaysOn
- PostgreSQL, TimescaleDB, MongoDB, and MinIO/Ceph S3 object lakes
- Unstructured scanning across enterprise SMB, NFS, and Hadoop HDFS
- 80+ pre-trained African PII classifiers (ZA ID, SARS Tax, NIN, Huduma)
Universal Multi-LLM AI Guardrails
In-line reverse proxy streaming guardrail that intercepts and inspects prompts and model completions with sub-5ms latency.
- 120+ Global LLM Interception Matrix: Cloud APIs (OpenAI GPT-4o/o1, Claude 3.7, Gemini 2.0), Web Portals (ChatGPT, Claude Web), IDEs (Cursor AI, Copilot), and Local Engines (Ollama, vLLM)
- Healthcare & Patient PHI Protection: HIPAA §164.514 & POPIA Sec 26/32 redaction for Patient MRN, Medical Aid (Discovery Health, GEMS, Bonitas), Clinician HPCSA, ICD-10, and Prescriptions
- Company-Defined Custom Rules Engine: Dynamic CRUD regexes, project codenames (Project Valkyrie), and secret API token masking
- Universal Streaming Guardrail: Real-time bidirectional token filtering with sub-2ms latency overhead
- Semantic Entitlement Filter: Prevents M365 Copilot & Vector RAG oversharing beyond Active Directory permissions
- Cryptographically Sealed Audit Trail: Append-only SHA-256 model lineage and Zero WAN telemetry
Regulatory Sovereignty Engine
Automates compliance tracking and regulatory reporting specifically engineered for African data privacy legislation, Indian Ocean island directives, and global data protection standards.
- POPIA Section 72 automated cross-border transfer risk assessment
- Mauritius Data Protection Act 2017 (DPA 2017) compliance tracking
- Bank of Mauritius (BoM) & FSC Cloud Computing and Data Residency directives
- European Union General Data Protection Regulation (EU GDPR) Article 32 & Chapter V
- Nigeria NDPA Section 41 and Kenya DPA Section 48 compliance posture
- South African Reserve Bank (SARB) Cyber Resilience alignment
- Central Bank of Kenya (CBK) Cybersecurity Guideline readiness
- 1-Click Statutory Section 51 PAIA Manual audit exports
Enterprise SIEM & SOAR Matrix
Multi-destination real-time event broadcasting to your existing Security Operations Center (SOC) infrastructure.
- Microsoft Sentinel via Data Collection Endpoint (DCE/DCR API)
- Splunk HTTP Event Collector (HEC) with index-level routing
- IBM QRadar Log Event Extended Format (LEEF 1.0 & 2.0)
- Micro Focus ArcSight Common Event Format (CEF v0)
- Elastic Security (ECS) and Universal Syslog RFC 5424/3164 (TLS/TCP/UDP)
Entitlement & Identity Governance (CIEM)
Continuous analysis of database privileges, role escalation risks, and dormant service account credentials.
- Over-privileged DBA and application connection pool auditing
- Detection of dormant database logins accessing sensitive PII tables
- Schema-level credential leakage and hardcoded password alerts
- Privilege drift tracking across test, staging, and production enclaves
Complete Enterprise Modules & Functional Directory (26 Modules & Core Appliance)
Every module is pre-compiled into the sovereign binary appliance and activated with offline Ed25519 node-locked keys with zero added infrastructure or downtime.
Custos Core™ DSPM Engine
In-Place Sovereign Discovery, Classification & Posture Management
High-throughput cursor scanner connecting natively to Oracle RAC, Microsoft SQL Server, PostgreSQL, MongoDB, MinIO S3 lakes, and enterprise NFS/SMB shares. Discovers and classifies sensitive data in-place with zero WAN egress.
- ✓In-Place Zero-Copy Streaming: Scans live multi-terabyte datastores without moving or replicating data.
- ✓80+ African & Global Classifiers: Pre-trained for ZA ID, SARS Tax, NIN, KRA PIN, Luhn cards, and passports.
- ✓Shadow Datastore Discovery: Identifies unmanaged database instances, stale backups, and rogue exports.
- ✓Sovereign Node Isolation: 100% air-gapped; operates in disconnected SCIFs with zero cloud telemetry.
• Status: 100% Disconnected Enclave | Scan Speed: 1.8 TB/hr
US SaaS competitors require streaming database copies or metadata to foreign clouds. Custos keeps 100% of data custody on-premise.
Governance & Privacy Pack
Automated DSAR Discovery, POPIA Section 24 Erasure & ROT Storage Reclaim
Turnkey statutory compliance automation for Data Protection Officers, Chief Legal Counsel, and enterprise storage architects. Automates citizen Subject Access Requests across disconnected databases in seconds.
- ✓Automated Cross-System DSAR Discovery: Instant multi-datastore query aggregating all personal data matching a citizen ID or passport.
- ✓POPIA Section 24 In-Place Erasure: Zeroizes records with cryptographically signed
ProofOfErasureCertificaterecords. - ✓ROT Storage Reclaim Engine: Rolling SHA-256 block hash engine detecting duplicate files, stale data (>1–3 years), and orphaned .bak dumps.
- ✓Multi-Framework Readiness Audits: Automated gap scoring aligned with South Africa POPIA, Mauritius DPA 2017, and EU GDPR.
• Verdict: 4 Datastores Queried | ProofOfErasure SHA-256 Sealed
Cuts legal and DBA investigation time by 90% and reclaims 20%–40% of expensive tier-1 SAN storage capacity.
Active Defense & SecOps Pack
Zero-Trust Automated Quarantine, HoneyData Decoys & SIEM Integration
Autonomous containment that neutralizes exposed files in under 2 seconds and injects authentic Luhn-valid canary decoys into relational databases to trap malicious insiders.
- ✓Automated Quarantine Vault: Severs open permissions and moves exposed files into an encrypted
0600isolation vault. - ✓Canary HoneyData Decoys: Injects authentic South African citizen records passing valid Luhn check algorithms.
- ✓Database Intrusion Tripwires: Intercepts unauthorized queries touching decoy records, tripping instant P1 alarms.
- ✓Multi-SIEM/SOAR Dispatch: Real-time streaming into Microsoft Sentinel, Splunk HEC, IBM QRadar, and Elastic.
• Action: ISOLATED_ENCRYPTED_VAULT (Containment Latency: 1.2s)
Reduces Mean Time to Remediate from 14 days to under 2 seconds, neutralizing data spills before exfiltration occurs.
Enterprise AI Governance Pack
Dynamic RAG ACL Filtering, Real-Time Prompt Injection Shield & Shadow AI Scanner
In-line reverse proxy streaming guardrail that inspects prompts and completions with sub-5ms latency, blocking prompt injections and enforcing Active Directory clearances on RAG context chunks.
- ✓Dynamic RAG Context Entitlements: Intercepts vector retrievals and enforces AD/Entra ID group ACLs on chunks before prompt assembly.
- ✓Prompt Injection & Jailbreak Shield: Blocks direct instruction overrides, DAN exploits, and Base64-smuggled payloads.
- ✓Network Shadow AI Scanner: Continuously sweeps corporate subnets for unmonitored local LLM engines (Ollama, vLLM, LM Studio).
- ✓Cryptographic Model Ledger: SHA-256 hash-chaining of all AI completions guaranteeing audit-proof model lineage.
• Discovered: 2 Rogue Ollama Instances | 1 Unsanitized vLLM Socket
Guarantees employees cannot retrieve confidential HR or payroll data through Copilots beyond their security clearance.
Custos SovereignFence™
Active Kernel eBPF WAN Cross-Border Blocker
Inspects egress network traffic at wire speed (<1 µs). If citizen PII is detected leaving approved national borders, it drops the TCP connection at the Linux kernel level, making foreign data transfer physically impossible.
- ✓Kernel-Level eBPF Socket Filter: Operates inside the OS network stack without user-space context-switch overhead.
- ✓Automated TCP Reset (RST): Instantly terminates unauthorized cross-border outbound sessions.
- ✓Statutory Geofencing: Enforces South Africa POPIA Section 72 and Mauritius DPA 2017 Section 36 cross-border rules.
- ✓Audit-Proof Kernel Proofs: Generates tamper-evident SHA-256 hash records for every blocked connection.
• Action: DROP_TCP_RST (POPIA Sec 72 / DPA Sec 36 Boundary Enforced)
Competitors merely log breaches after they occur. SovereignFence prevents exfiltration before packets leave the host.
Custos SynthMask™
Differential Privacy Synthetic Test-Data Engine & Schema Cloner
Clones Oracle, SQL Server, and Postgres databases into QA/Dev environments with mathematical ε-differential privacy. Preserves foreign key referential integrity while substituting all citizen identifiers with valid synthetic data.
- ✓Mathematical Differential Privacy: Configurable ε privacy budget guarantees zero reconstruction risk.
- ✓Full Relational Integrity: Preserves primary/foreign key relationships across complex relational schemas.
- ✓Localized African Personas: Synthesizes authentic, checksum-valid South African IDs, Nigerian NINs, and Kenyan PINs.
- ✓Zero Cloud Dependency: Generates synthetic test databases at up to 100,000 rows/second on local CPUs.
• Output: 10,000 Cloned Rows | Zero Real PII | FK Integrity Intact
Eliminates the #1 breach vector in banking: offshore QA contractors working on unmasked production database clones.
Custos BlastRadius™
Zero-Trust Identity Graph & Attack Path Simulator
Maps Entra ID, Active Directory, and SharePoint permissions directly to classified databases and document stores. Eliminates over-permissioned access before Microsoft 365 Copilot's semantic index exposes confidential files.
- ✓Graph-Based Access Correlator: Visualizes transitive access paths from user groups to sensitive database tables.
- ✓Financial Liability Simulator: Computes statutory breach exposure in ZAR and USD per overprivileged identity.
- ✓Copilot Over-Sharing Prevention: Pinpoints SharePoint folders with excessive 'Everyone except external' sharing.
- ✓Automated Clamping Guidance: Provides exact PowerShell and SQL remediation scripts to achieve least privilege.
• Attack Paths: 14 Overprivileged AD Groups | Exposure: R 18.5M ZAR
Zero alert fatigue. Neutralizes M365 Copilot data harvesting and maps board-ready financial liabilities.
Custos AgentShield™
Autonomous AI & Microsoft Copilot Studio Tool-Calling Governor
Secures autonomous multi-agent systems (Microsoft Copilot Studio, LangChain, AutoGen) invoking internal APIs, SharePoint, and SQL tools. Sanitizes query limits and blocks prompt-injected mutations (DROP/UPDATE).
- ✓Tool-Call Authorization: Enforces strict role-based whitelists on agent function calling.
- ✓Destructive Mutation Blocker: Intercepts and blocks SQL DROP/UPDATE/DELETE and OS shell commands.
- ✓Query Bound Clamping: Prevents autonomous bots from dumping entire tables via unconstrained SELECTs.
- ✓Honeypot Trap Injection: Serves synthetic honey-data when prompt anomalies or jailbreaks are detected.
• Decision: SANITIZE (Clamped to 5 Rows | Graph Context Shielded)
First-to-market autonomous AI & Copilot Studio governor. Protects core banking backends from agentic breakout.
Custos CleanRoom™
Zero-Footprint M&A & Vendor Data Liability Auditor
A single-binary ephemeral scanner deployed on target acquisition networks or vendor environments. Audits candidate datastores in 24 hours, computing statutory liabilities and recommended escrow purchase-price holdbacks.
- ✓Zero-Footprint Ephemeral Audit: Runs without persistent agents, leaving zero forensic trace after completion.
- ✓M&A Statutory Due Diligence: Quantifies POPIA and GDPR compliance gaps across candidate data estates.
- ✓Escrow Holdback Calculator: Computes statistically sound purchase-price holdback figures in USD and ZAR.
- ✓Cryptographic SHA-256 Deal Seal: Delivers court-admissible audit proof for acquisition legal counsel.
• Recommended Escrow Holdback: $ 3.75M USD | SHA-256 Seal Valid
Allows private equity and banking acquirers to uncover hidden regulatory liabilities before closing commercial transactions.
Custos WireShield™
Zero-Touch SQL Wire-Level Virtual Masking Engine
Intercepts SQL query result streams at the network wire level (PostgreSQL, MSSQL TDS, Oracle TNS). Dynamically masks citizen PII for unprivileged users, BI dashboards, and AI bots without altering database schemas or breaking legacy systems.
- ✓Wire-Level Protocol Inspection: Transparent proxy operating directly on TDS, TNS, and Postgres protocols.
- ✓Zero Schema Migrations: No database views, triggers, or schema alterations required on production engines.
- ✓Role-Aware Dynamic Masking: Full plaintext for authorized DBAs; dynamic asterisk masking for unprivileged analysts.
- ✓Sub-Millisecond Wire Overhead: Zero-allocation stream buffers maintain wire-speed database performance.
• Action: DYNAMIC_STREAM_MASKING (ZA ID & Salary Masked on Wire)
Solves the #1 flaw of DSPMs: active zero-disruption remediation without requiring dangerous database migrations.
Custos VectorGuard™
Neural DLP & Vector DB / RAG Entitlement Firewall
The world's first true Vector DB DSPM. Sanitizes chunks before embedding to prevent irreversible vector contamination, and filters RAG semantic retrieval chunks based on Active Directory clearance before LLM prompt assembly.
- ✓Pre-Embedding Neural Sanitization: Intercepts document ingestion pipelines to prevent toxic PII contamination.
- ✓Semantic RAG Entitlement Firewall: Filters vector similarity search results based on user identity clearance.
- ✓Broad Vector DB Support: Native connectors for Pinecone, Milvus, Qdrant, Chroma, and pgvector.
- ✓Embedding Inversion Defense: Prevents attackers from reconstructing original sensitive text from high-dimensional vectors.
• Filter: Dropped 2 Chunks (Clearance Denied on Restricted Context)
Protects modern high-dimensional vector databases where legacy regex DLP is 100% blind.
Custos SafeHarbor™
Cryptographic CISO Legal Defense & Merkle Proof Ledger
Aggregates daily security safeguards into an immutable Ed25519-signed Merkle Tree. Generates court-admissible Statutory Safe Harbor Dossiers providing affirmative legal defense for CISOs under POPIA Section 107 and global regulations.
- ✓Merkle Tree Audit Ledger: Cryptographically chains all scanning, masking, and quarantine events into daily roots.
- ✓Ed25519 Hardware Signatures: Digital signatures verify continuous, uninterrupted security due diligence.
- ✓Statutory Affirmative Defense: Generates court-admissible evidence proving due care under POPIA Section 107.
- ✓Executive Liability Protection: Shields CISOs, CIOs, and directors from personal civil and criminal liability.
• Signature Verified: true (Ed25519 Court-Admissible Proof Sealed)
Transforms technical safeguards into affirmative legal immunity for executive leadership against personal liability.
Custos MCP-Shield™
Model Context Protocol Tool & Query Firewall for LLMs
Zero-latency (<2ms) in-line proxy governing Anthropic Model Context Protocol (MCP) JSON-RPC tool-calling between local LLMs/Copilots and backend databases. Enforces schema whitelisting, query row-limit clamping, and canary trap injection.
- ✓JSON-RPC Socket Inspection: Zero-latency (<2ms) in-line proxy inspecting stdio and SSE MCP traffic.
- ✓Query Row-Limit Clamping: Automatically clamps query limits (e.g. from 50,000 to max 25 rows).
- ✓Schema & Destructive Block: Prohibits SQL injection, DDL drops, and unauthorized tool calls.
- ✓Canary Trap Echo Detection: Injects dummy canary records and severs sessions if agent echoes tokens.
• Action: CLAMP_ROW_LIMIT (Clamped to 25 rows | Latency: 0.00ms)
Prevents prompt-injected LLMs from bulk dumping production SQL databases through open MCP server connections.
Custos ShannonEntropy™
Zero-Day Ransomware & DB Entropy Tripwire
Continuous kernel/storage monitoring calculating Shannon Entropy H(X) on database page blocks in real time. Detects silent cryptographic encryption (entropy spiking >7.85) and drops TCP connections via eBPF in <500ms before mass encryption completes.
- ✓Shannon Entropy H(X) Engine: Mathematical calculation detecting sudden entropy spikes (>7.85 bits/byte).
- ✓Sub-500ms Kernel Severing: Drops offending TCP connections via eBPF and locks down storage files.
- ✓Automated WAL Isolation: Triggers instant WAL log checkpointing to preserve uncorrupted rollback states.
- ✓Bypasses EDR Blindspots: Protects database storage directly, catching stealth ransomware that bypasses antivirus.
• Action: SEVER_CONNECTION_AND_SEAL (Response Time: 0.53ms)
Traditional EDR misses in-memory database block encryption. ShannonEntropy catches zero-day database ransomware at the physical write layer.
Custos NHI-Guard™
Non-Human Identity & Secret Blast Radius Correlator
Discovers unmanaged service principals, automated ETL batch tokens, K8s secrets, and connection strings. Correlates machine identities with sensitive PII tables to flag dormancy (>90 days inactive) and privilege creep, quantifying breach exposure in ZAR & USD.
- ✓Machine Credential Discovery: Tracks connection strings, ETL tokens, and K8s service accounts.
- ✓Dormancy & Privilege Creep: Flags accounts inactive >90 days holding admin rights to classified PII.
- ✓Financial Blast Exposure: Calculates statutory breach exposure in ZAR & USD per unmanaged identity.
- ✓Automated Token Deprovisioning: Emits revocation orders for stale credentials before compromise.
• Blast Exposure: R 6,750,000 ZAR ($ 369,863 USD) - DORMANT RISK
80% of enterprise breaches leverage compromised machine tokens. NHI-Guard shuts down over-privileged service accounts before attackers find them.
Custos ModelAudit™
AI Right-to-Erasure & Machine Unlearning Verifier
Automates POPIA Section 24 and GDPR Article 17 'Right to Erasure' across on-premises AI pipelines. Verifies vector chunk purging and runs differential influence-function attribution checks to issue court-admissible Proof of Machine Unlearning certificates.
- ✓Vector Store Sanitizer: Automatically zeroes citizen embeddings across Pinecone, Milvus, and pgvector.
- ✓Influence-Function Auditing: Mathematically proves citizen data no longer alters token distributions (influence score <= 0.0001).
- ✓Unlearning Certificates: Generates court-admissible Ed25519-signed proof of algorithmic erasure.
- ✓Protects Model Capital: Prevents costly regulatory forced destruction of proprietary enterprise AI models.
• Influence Attribution: 0.000021 (POPIA Sec 24 VERIFIED)
Solves the nightmare of AI 'algorithmic disgorgement' by proving to regulators that citizen data no longer influences neural network outputs.
Custos AgentFence™
Autonomous AI Agent Runtime Execution Firewall & Dual-Control Gate
Enforces bank-grade 7-layer execution boundaries on autonomous agent tool calls (LangChain, AutoGen, Claude MCP, Copilot Studio). Detects indirect prompt injections, blocks unconstrained financial velocity, and triggers SARB dual-control HMAC multi-sig on high-value transfers.
- ✓Strict Schema Contract Enforcement: Rejects undeclared parameters, prototype pollution, and out-of-bounds arguments.
- ✓Indirect Prompt Injection Scanner: Detects system overrides, Base64 evasion, and invisible Unicode zero-width tags.
- ✓Financial Velocity Limiter: Enforces rolling window transaction caps per agent session across ZAR, USD, GBP, and EUR.
- ✓Dual-Control Escalation: Issues cryptographic HMAC-SHA256 tickets requiring human officer approval on amounts > R50k.
• Gate: REQUIRE_APPROVAL (Challenge: CHG-17898... | SARB > R50k Dual-Control)
Eliminates the #1 existential threat to tier-1 banks adopting autonomous agents: accidental or poisoned financial execution.
Custos WireRemit™
ISO 20022 XML Streaming Parser, Control-Sum Reconciler & Sanctions Governor
Real-time zero-allocation streaming parser for ISO 20022 payment messages (pacs.008, pain.001, camt.053). Reconciles CtrlSum header values, performs in-flight PII/IBAN tokenization, and screens parties against OFAC SDN, UN, and SARB FIC watchlists with 126µs latency.
- ✓Streaming XML Decoder: Parses multi-megabyte pacs.008 wire files with zero heap buffer exhaustion.
- ✓Control Sum Integrity Reconciler: Catches corrupt or tampered files where transaction amounts deviate from CtrlSum.
- ✓Watchlist & FATF Corridor Screening: In-memory Jaro-Winkler matching against OFAC, UN, and FIC sanctions lists.
- ✓In-Flight IBAN/PII Tokenization: Replaces accounts with vault tokens while preserving UETR and BIC routing keys.
• Decision: TOKENIZED (4 PII Elements Masked | 126 µs Processing Latency)
Allows tier-1 banks to stream core SWIFT ISO 20022 wire feeds to cloud data lakes without violating cross-border PII laws or sanctions.
Custos QuantumRadar™
Post-Quantum Cryptography Discovery, CycloneDX CBOM & HNDL Migration Engine
Discovers all cryptographic algorithms (RSA, ECC, AES, 3DES) across banking TLS, database columns, and VPN pipes. Generates CycloneDX 1.6 Cryptographic Bill of Materials (CBOM), scores Harvest Now Decrypt Later (HNDL) risk, and builds migration roadmaps for NIST FIPS 203 (ML-KEM) & FIPS 204 (ML-DSA).
- ✓In-Place Cryptographic Scanner: Classifies X.509 certs, TLS cipher suites, and database keys in-place.
- ✓CycloneDX 1.6 CBOM Export: Standardized Cryptographic Bill of Materials for regulators (BIS, SARB, PRA).
- ✓Mosca HNDL Risk Scoring: Evaluates data shelf-life against CRQC quantum arrival horizon (5µs latency).
- ✓NIST PQC Migration Roadmap: Automated mapping to ML-KEM-768/1024 (FIPS 203) and ML-DSA-65 (FIPS 204).
• Target: FIPS 203 ML-KEM-768 (X25519Kyber768 Hybrid) | Priority: IMMEDIATE
Regulatory mandate protection: equips bank CISOs with CBOM proofs ahead of impending mandatory 2026-2030 post-quantum migration deadlines.
Custos QueryShield™
Zero-Schema Wire-Level Dynamic SQL Query Rewriting & Side-Channel Blocker
Intercepts incoming SQL queries on the wire (PostgreSQL, Oracle, MySQL, SQLServer) and rewrites column projections into native database masking expressions before execution. Blocks binary-search WHERE clause side-channel attacks with sub-1ms overhead and zero schema migrations.
- ✓Zero Schema Alterations: No column encryption migrations; runs transparently at the database socket level.
- ✓Dynamic Projection Rewriter: Automatically injects CONCAT/SUBSTRING PAN & ID masks and zeroes salaries.
- ✓Side-Channel Inference Blocker: Blocks binary search attacks on sensitive WHERE clause predicates (e.g. card_pan LIKE).
- ✓Differential Privacy Mode: Injects ROUND/noise for data scientists while preserving DBA superuser bypass.
• Status: REWRITTEN & MASKED ON THE WIRE (50 µs Latency Overhead)
Solves the 20-year core banking dilemma: secures sensitive database columns without breaking legacy core banking applications.
Custos SynthProof™
Synthetic Identity Fraud & Deepfake Document Ingestion Provenance Engine
Ingestion provenance gate protecting core banking KYC and onboarding systems. Detects AI diffusion generation signatures (Stable Diffusion, Midjourney), spectral entropy uniformity, layered PDF revision trailers, and mathematical Luhn ID faults before fraudulent accounts are created.
- ✓Generative AI Footprint Scanner: Identifies Stable Diffusion, ComfyUI, DALL-E, and Canva signatures.
- ✓Spectral Diffusion Noise Analysis: Distinguishes AI latent smoothness from real optical camera sensor shot noise.
- ✓Statutory Identity Checksum Verifier: Mathematically validates Modulo 10 Luhn algorithms on extracted citizen IDs.
- ✓Document Timeline Corroborator: Flags post-dated utility bills, stale documents, and fictitious municipal providers.
• Verdict: SYNTHETIC_FRAUD_DETECTED (Score: 100.0/100 | StableDiffusion Signature)
Shuts down Synthetic Identity Fraud (SIF) at the digital front door before AI-generated fake personas poison core AML/KYC databases.
Custos ETRadar™
Encrypted Traffic Radar, Passive JA4 Fingerprinting & Shannon Entropy Exfiltration Sensor
Passively dissects TLS 1.3 and TLS 1.2 handshakes at wire speed without SSL/TLS decryption. Generates JA4/JA4T fingerprints, evaluates real-time Shannon entropy across streaming flow buffers, detects periodic C2 beaconing jitter, and pumps flow telemetry through a 35M ops/sec lock-free ring buffer directly to SIEM and automated Kubernetes network quarantine.
- ✓Passive TLS 1.3 Dissector (467ns): Extracts SNI, ALPN, Cipher Suites, and calculates JA4 hashes without MitM key escrow.
- ✓Shannon Entropy Exfiltration Radar: Continuous 8.0-bit entropy scoring catches high-volume covert encrypted data dumps.
- ✓C2 Beaconing Timing Jitter Analyzer: Evaluates packet inter-arrival times (IAT) to detect automated malware callbacks (CobaltStrike, AsyncRAT).
- ✓35M Ops/Sec Lock-Free SPSC Ring: Zero-allocation atomic ring buffer with 27.85ns latency protects payment switches from packet drops.
- ✓Automated Infrastructure Quarantine: Dispatches CEF/JSON SIEM alerts and triggers Kubernetes pod isolation in real time.
• JA4: t13d0204h2_62ed6f6ca7ad_f4a44468fbae | Threat: ANOMALOUS_EXFILTRATION | Pod: QUARANTINED
Enables Tier-1 banks and defense enclaves to detect covert encrypted data exfiltration and rogue C2 channels without violating banking secrecy or breaking end-to-end TLS session encryption.
Custos Guard™
In-Line Sub-5ms AI Reverse Proxy & Healthcare PHI Interception Enclave
High-throughput reverse proxy intercepting 120+ frontier cloud and local LLMs (GPT-4o, Claude 3.7, Gemini 2.0, Ollama, DeepSeek-R1). Performs real-time bidirectional PII/PHI de-identification and cryptographic SHA-256 lineage tracking.
- ✓120+ LLM Interception Matrix: Native HTTP reverse proxy for OpenAI, Anthropic, Gemini, Ollama, and vLLM.
- ✓Healthcare PHI Protection: Enforces HIPAA §164.514 and POPIA Sec 26/32 redacting MRN, Medical Aid, NPI, and ICD-10.
- ✓Bidirectional Tokenization: Retains semantic reasoning tokens while blocking customer identifiers.
- ✓Cryptographic Lineage Ledger: TimescaleDB SHA-256 hash-chaining proving exact training data exposure.
• LLM Gate Active: 120+ Models | Latency: 1.84ms | Zero Cloud Egress
Allows hospitals and banks to adopt frontier LLMs and developer AI IDEs with mathematical zero-leakage guarantees.
Custos AutoRemediate™
Autonomous Host & Kubernetes Network Isolation Engine
Zero-delay automated infrastructure remediation engine. Upon threat or exfiltration detection, instantly applies Kubernetes NetworkPolicy route severing, host-level firewall quarantine, and SIEM active response in <2 seconds.
- ✓Automated K8s Network Severing: Applies strategic merge patch
quarantine.dspm.io/isolated: trueto halt pod egress. - ✓eBPF & Host Firewall Quarantine: Restricts compromised host permissions to
0600and drops socket routes instantly. - ✓Wazuh & SIEM Active Response: Dispatches authenticated JSON commands to host-level security agents for process termination.
- ✓Tamper-Evident Receipts: Generates cryptographically signed
.receipt.jsonaudit trails for every automated isolation event.
• Remediation Applied in 1.64ms | Wazuh Active Response Confirmed
Eliminates the human-in-the-loop delay during ransomware encryption or data exfiltration by severing routes at kernel speed.
Custos AuditDossier™
Executive Board & Universal Statutory Compliance Dossier Engine
Automated PDF and HTML regulatory audit reporting engine. Compiles continuous telemetry into verified Board Risk summaries, POPIA Sec 19/24, HIPAA 45 CFR § 164.312, PCI DSS v4.0, EU DORA, and APRA CPS 234 compliance dossiers.
- ✓11 Statutory Engines: Natively evaluates HIPAA, PCI DSS v4.0, SWIFT CSP, DORA, CCPA, GLBA, UK GDPR, PDPA, DPDPA, PIPEDA, LGPD.
- ✓Board-Ready Risk Scoring: Translates technical scan results into monetary liability estimates, ROT savings, and posture scores.
- ✓Ed25519 Cryptographic Attestation: Embeds digital signatures and SHA-256 Merkle roots into every generated dossier.
- ✓Air-Gapped Offline Generation: Operates entirely within offline enclaves without external SaaS PDF conversion APIs.
• Dossier Compiled: Custos_Statutory_Audit_2026.pdf (SHA-256: 8f41...)
Provides CISOs, CROs, and external statutory auditors with instant, verifiable legal proof of technical data governance.
Custos DataMesh™
In-Place Multi-Engine Storage & S3 Lake Connector Mesh
Ultra-high-throughput native cursor connection mesh for heterogeneous banking and enterprise datastores. Directly queries Oracle RAC, Microsoft SQL Server AlwaysOn, PostgreSQL, MongoDB, MinIO/Ceph S3, and NFS/SMB with zero data replication.
- ✓Multi-Database In-Memory Cursors: Zero-allocation connection pooling for Oracle RAC (11g–21c), MSSQL, PostgreSQL, MySQL.
- ✓S3 & Object Lake Streaming: Direct multipart streaming inspection for AWS S3 appliances, MinIO, Ceph, and Dell ECS.
- ✓Enterprise SMB & POSIX NFS: High-speed recursive directory traversal with metadata caching and permission inspection.
- ✓Zero WAN Bandwidth Overhead: Computes PII classifications locally in RAM, transmitting zero raw customer data across the network.
• 18 Enterprise Datastores Onboarded | In-Place Memory Streaming Active
Eliminates costly WAN data transfer bills and complex ETL pipelines by scanning enterprise storage exactly where it resides.
Technical & Architectural Specifications
| Domain | Specification / Standard | Enterprise Sovereign Detail |
|---|---|---|
| Supported Operating Systems | RHEL 8/9, Rocky Linux 9, Ubuntu 22.04/24.04 LTS, Windows Server 2022 | Bare-metal and virtualized installations; kernel 5.4+ with eBPF support enabled. |
| Container Platforms | Red Hat OpenShift 4.12+, Kubernetes 1.28+, SUSE Rancher, Docker EE | Certified offline Helm charts; runs in rootless, unprivileged container namespaces. |
| Scanning Throughput | Up to 1.8 TB / hour per scanner worker node | Zero-copy cursor streaming; multi-threaded regex and compiled NLP inference. |
| In-Memory Guardrail Latency | < 5.0 milliseconds per stream token chunk | Compiled Go core with zero-allocation buffers; supports 5,000+ concurrent LLM sessions. |
| Target Datastores | Oracle RAC (11g/12c/19c/21c), Microsoft SQL Server (2014-2022), PostgreSQL / TimescaleDB, MySQL & MariaDB (5.7/8.0+), MongoDB, Redis, MinIO/Ceph S3, SMB/NFS | Agentless read-only connections with configurable rate-limiting and query windowing. |
| Cryptographic Protocols | TLS 1.3, AES-256-GCM, Ed25519 Signatures, SHA-256 Ledgers | All internal cluster communications encrypted; air-gapped cryptographic licensing. |
| Telemetry & Phone-Home | Absolute Zero (0 bytes) | No external internet connectivity required at installation, runtime, or license renewal. |
Comparative Analysis: Custos DSPM vs. Cloud-Only US DSPM Vendors
| Capability Dimension | Custos DSPM (GovernX) | US Cloud DSPM Vendors (SaaS) |
|---|---|---|
| Deployment Model | 100% Air-Gapped / On-Premises | Multi-tenant US/EU Cloud SaaS only |
| Cross-Border WAN Egress | Zero (0 Bytes leave data center) | Transfers metadata, schemas & data samples overseas |
| Sovereign, Financial & Healthcare Compliance | Native HIPAA (45 CFR § 164.312), PCI DSS v4.0, SWIFT CSP, DORA, CCPA, PIPEDA, LGPD, PDPA, DPDPA, APRA CPS 234, Privacy Act 1988 (AU), POPIA, NDPA | Generic GDPR/CCPA mapping; no local mathematical check digits or interbank eBPF zoning |
| Multi-LLM Streaming Guardrails | Included (Gemini, Claude, GPT-4o, Local R1) | Static post-hoc data scanning only; no active LLM proxy |
| SIEM & SOC Forwarding | Native Sentinel, Splunk, LEEF, CEF, Syslog | Requires webhook to public internet endpoints |
| License Activation | Offline Hardware-Locked Token (Ed25519) | Requires persistent outbound phone-home connection |
| Database Remediation | WireShield™: Zero-Touch SQL Virtual Masking | Read-only reports; forces risky schema migrations |
| Vector DB & RAG Protection | VectorGuard™: Neural DLP & Context Firewall | 100% blind to high-dimensional vector embeddings |
| CISO Legal Immunity | SafeHarbor™: Ed25519-Signed Merkle Tree Dossier | Mutable text syslog files; zero statutory legal safe harbor |
Enterprise Evaluation & Partner Accreditation
GovernX works exclusively through accredited systems integrators, value-added resellers, and dedicated sovereign security teams across Africa. Request a 30-day on-premises Proof of Value (POV) or apply for reseller accreditation.