🇿🇦 CUSTOMER-HOSTED PRIVATE PERIMETER • AZURE SA NORTH / AWS CAPE TOWN / PRIVATE ON-PREMISES
WORLD FIRST: SOVEREIGN HYBRID CYBER DEFENSE & ACTIVE EXECUTION MESH

The Sovereign Hybrid / Cloud Cyber Defense Enclave &
Active Execution Mesh for South Africa

Engineered exclusively for South African enterprise retailers, commercial banks, healthcare networks, and critical datacenters. Seamlessly federates customer-hosted private cloud enclaves (Azure South Africa North, AWS Africa Cape Town) with on-premises VMware ESXi, SAP S/4HANA, Oracle RAC, and physical bare-metal systems — with 100% module parity and strict cryptographic guarantees of zero cross-border telemetry egress under POPIA § 72 and SARB Directive 2/2023. Deployed directly within your perimeter as a capitalizable software asset under IAS 38 & SARS Section 11(e), eliminating the perpetual EBITDA penalty of multi-tenant vendor SaaS.

Mesh Latency
0.42 ms
Gauteng In-Region Wire
Autonomous Severance
126 µs
Kernel Socket Cut (LotL)
Vendor Data Ingestion
0.00 KB/s
100% In-Perimeter Hosted
Accounting & Tax
100% CAPEX
IAS 38 & SARS § 11(e) 3-Yr
Architecture Parity
100% Parity
All 20 Modules On-Prem & Cloud

How the Sovereign Hybrid System Works

Unlike foreign multi-tenant SaaS vendors that force raw data ingestion into third-party vendor clouds, Custos is deployed entirely inside your own enterprise perimeter (customer-owned Azure SA North / AWS Cape Town subscriptions and on-premises VMware/bare-metal). In-place compiled Go daemons execute continuous zero-copy inspection, communicating across your dedicated private mesh over an encrypted, sub-millisecond WireGuard/mTLS wire protocol with 100% module parity.

01

In-Place On-Premises Interception & Discovery

A single compiled Go daemon (custos-agent) hooks into local datastores including SAP S/4HANA, Oracle RAC, Microsoft SQL Server AlwaysOn, PostgreSQL, VMware ESXi, and Windows Server Active Directory. It performs in-memory streaming pattern discovery using deterministic Luhn, Verhoeff, and Modulo algorithms without copying or moving raw datasets across the network.

Key Mechanism: Zero-copy cursor streaming
Memory Footprint: <14MB RAM (No JVM / No Python)
Zero WAN Impact: No database replication overhead
02

Sub-Millisecond Wire Protocol & eBPF Egress Fence

Telemetry is condensed into cryptographic metadata envelopes signed via Ed25519 and tunneled over mTLS 1.3 / WireGuard to Azure South Africa North. In-kernel eBPF WAN filters inspect packet routing headers in real time, automatically dropping any TCP/UDP transmission attempting to route through foreign trans-Atlantic submarine cables.

Wire Latency: 0.42ms average round-trip
Data Residency: Locked strictly to RSA borders
Egress Assurance: 100% POPIA § 72 compliant
03

Autonomous LotL Ransomware Severance

The agent monitors Volume Shadow Copies (VSS), Kerberos ticket anomalies, and Living-off-the-Land (LotL / MITRE ATT&CK T1490) recovery inhibitors. If an attacker or compromised service account triggers encryption primitives or attempts to delete immutable backup snapshots, the agent severs network sockets in 126 microseconds.

Severance Speed: 126 microseconds line-rate
MITRE Coverage: T1490, T1078, T1059, T1558
Containment Vector: Kernel socket teardown
04

SARB Directive 2/2023 Dual-Control HITL

To prevent rogue administrator actions or algorithmic false positives from disrupting banking operations, high-impact quarantine actions or data changes exceeding R50,000 require Dual-Key Human-In-The-Loop (HITL) authorization. Two distinct cryptographic keys from certified security officers must be presented to validate the challenge token.

Mandate Alignment: SARB Directive 2/2023 § 4.3
Challenge Scheme: Shamir Secret / Dual-Key Token
Timeout Window: 15-minute challenge invalidation
05

SafeHarbor™ Cryptographic Defense Dossier

Every discovery, policy enforcement, quarantine, and AI prompt inspection is permanently inscribed to an append-only SHA-256 Merkle chain ledger. In the event of a regulatory inquiry by the Information Regulator of South Africa or SARB Prudential Authority, CISOs can instantly export an unalterable forensic defense dossier.

Audit Integrity: Cryptographic SHA-256 hash chaining
Regulatory Readiness: 1-click legal evidence export
Immutability: Read-only WORM ledger storage
06

Customer-Hosted Private Cloud Enclave

The cloud management control plane runs physically inside the customer's own cloud subscription (Microsoft Azure South Africa North or AWS Africa Cape Town) with customer-managed keys and zero vendor data access. GovernX never ingests, stores, or processes raw customer records or telemetry in a vendor cloud. Security operations teams gain centralized visibility across multi-branch retail distribution centers, banking networks, and healthcare nodes with 100% module parity and complete data sovereignty.

Deployment Perimeter: Customer's Azure/AWS Subscription
Vendor Access: Zero Data Ingestion / Signed Binaries Only
Module Parity: 100% Identical Feature Set On-Prem & Cloud

The Complete Cyber Defense Feature Suite

Everything required to safeguard mission-critical data, contain autonomous AI agents, comply with South African banking directives, and withstand zero-day ransomware attacks.

🗄️

Sovereign DSPM & In-Place Data Discovery

Continuous in-memory scanning across legacy relational databases, object storage, and unmapped network shares without WAN data copying.

  • ✓ Universal Connector Matrix: Oracle RAC 11g-21c, Microsoft SQL AlwaysOn, PostgreSQL, MongoDB, and MinIO/S3.
  • ✓ Mathematical Classifiers: Luhn Mod-10, Modulo 11/89/97/23, and Verhoeff D5 algorithm checks.
  • ✓ South African PII Patterns: SA ID, SARS Tax Numbers, NHI health codes, bank account schemas, and POPIA special personal data.
  • ✓ Non-Human Identity (NHI) Graph: Entra ID/Active Directory blast radius simulation identifying stale service account attack paths.
🛡️

Custos AgentShield™ AI Execution Firewall

Sub-millisecond Layer-7 security fencing and socket severance for autonomous AI agents, LLM tool execution, and MCP endpoints.

  • ✓ 126µs Socket Severance: Stops agent privilege escalation and data exfiltration before packet transit.
  • ✓ 120+ LLM Inspection Matrix: Full proxy inspection across OpenAI, Anthropic, Gemini, DeepSeek, and local Ollama/vLLM engines.
  • ✓ Prompt Injection & Jailbreak Shield: Neutralizes direct & indirect prompt injections and multi-turn extraction attacks.
  • ✓ Vector RAG Entitlements: Prevents AI models from retrieving unauthorized document chunks during semantic search.
🏛️

Tier-1 Banking & Financial Clearing Rails

Engineered specifically for South African commercial banks and clearing institutions under SARB Prudential Authority governance.

  • ✓ SARB Directive 2/2023 Enforcement: Dual-control cryptographic authorization on transfers and system actions >R50,000.
  • ✓ WireRemit™ ISO 20022 Governor: 126µs inspection of SWIFT pain.001/pacs.008 messages for sanction bypass attempts.
  • ✓ SynthProof™ Deepfake KYC Gate: Real-time neural artifact detection preventing synthetic identity fraud in digital onboarding.
  • ✓ QueryShield™ SQL Rewriter: Zero-schema dynamic SQL transformation preventing side-channel data inference.
⚛️

Post-Quantum Cryptography & Micro-Patching

Future-proof resilience against "Harvest Now, Decrypt Later" adversaries and zero-day memory corruption vulnerabilities.

  • ✓ QuantumRadar™ Discovery: Automated post-quantum cryptographic inventory generating CycloneDX 1.6 CBOMs.
  • ✓ Zero-Trust Micro-Patching: Injects dynamic memory shields to neutralize zero-day exploits without server reboots.
  • ✓ Firmware Baseline Verifier: Verifies motherboard UEFI and server firmware integrity against supply-chain tampering.
  • ✓ Deterministic Rollback: Instant rollback payloads if hot-patches cause performance regressions.
🔒

AirGap™ & Differential Privacy SCIF Engine

Full functionality in completely disconnected environments or national grid outages, with mathematical data anonymization.

  • ✓ 100% Offline SCIF Engine: Operates during undersea cable severances or localized communication blackouts.
  • ✓ SynthCloner™ Differential Privacy: Clones production banking databases into mathematically safe synthetic test datasets.
  • ✓ CleanRoom™ M&A Enclave: Self-destructing ephemeral audit environments for investment banking due diligence.
  • ✓ WireShield™ Dynamic Masking: Dynamic SQL wire-masking preventing database administrators from seeing raw PII.
🔐

Enterprise Security, 2FA & SOC Alerting

High-assurance authentication and multi-tenant administrative controls built directly into every sovereign workspace.

  • ✓ Hardware & App 2FA: TOTP QR-code enrollment for Google/Microsoft Authenticator with offline emergency backup codes.
  • ✓ Enforced Password Policy: 12+ character complexity, entropy verification, and dictionary rejection.
  • ✓ Per-Tenant Email Alerting: Custom SMTP configuration (Office 365, Exchange, SendGrid) with SOC severity routing.
  • ✓ Role-Based Access Control (RBAC): Granular separation of duties between Owner, Admin, Security Analyst, and Auditor.

Why South African CISOs Choose GovernX

Comparing GovernX Sovereign Hybrid Mesh against US-headquartered cloud DSPM vendors and traditional legacy endpoint tools.

Capability / Requirement 🛡️ GovernX Sovereign Hybrid Mesh Foreign Cloud DSPMs (BigID, Cyera, Varonis) Legacy SIEM / EDR (CrowdStrike, Splunk)
Data Telemetry Residency 100% In-Country: Azure South Africa North (JHB) & local datacenter only. Zero cross-border packets. Foreign Hosted: Streams database schemas and telemetry to US East or Frankfurt servers. Multitenant Cloud: Aggregates system telemetry in overseas clouds, subject to US CLOUD Act.
POPIA § 72 & SARB 2/2023 Built-in Native Compliance: Zero legal exposure; satisfies SARB dual-control mandate natively. Non-Compliant: Requires transborder data transfer legal waivers and CISO liability sign-offs. Partial: Logs host metrics but lacks data residency guarantees or banking dual-control.
Autonomous Threat Severance 126 Microseconds: In-kernel eBPF socket cut stops ransomware encryption (T1490) in real time. Passive Alerting: Generates alerts 15–60 minutes after data exfiltration has occurred. Host Isolation: High false-positive rate; severs entire machine disrupting core banking operations.
AI Agent & LLM Guardrail Layer-7 AgentShield™: 120+ LLMs inspected; blocks prompt injections and agent privilege abuse. None: No real-time proxy interception or autonomous agent socket bounding. Limited: Endpoint process monitoring only; cannot parse prompt vectors or RAG chunk entitlements.
WAN Bandwidth Cost Zero WAN Tax: In-place streaming cursor scanner; only lightweight cryptographic hashes traverse mesh. High WAN Egress: Replicates heavy sample datasets and schemas across international pipes. High Ingestion Tax: Charges customers per-gigabyte of logs transmitted across network.
Offline / Disaster Resilience 100% AirGap™ Engine: Retains full protection during undersea cable severances or power blackouts. Fails Closed/Open: Becomes blind if internet connectivity to foreign cloud is severed. Limited Offline: Loses cloud-assisted neural behavioral correlation models when offline.
Financial & Tax Accounting (CAPEX vs OPEX) Genuine CAPEX Asset (IAS 38 & SARS § 11(e)): Customer retains machine-code binary possession inside own perimeter. Capitalized on balance sheet; 3-year straight-line tax write-off (33.3% p.a.). Zero EBITDA penalty. 100% OPEX SaaS Drag: Bound by IFRIC 2021 SaaS agenda decision. Recurring subscription costs hit operating expenses directly, reducing enterprise EBITDA. Volatile OPEX + Ingestion Runaway: Unpredictable monthly consumption billing directly hitting operating expenditures.
Deployment Perimeter & Module Parity Customer Perimeter + 100% Parity: Hosted entirely in customer's Azure/AWS tenant & on-premises datacenters. All 20 modules run identically with zero vendor data ingestion. Vendor Cloud Locked: Requires copying customer schemas and sensitive telemetry into vendor's multi-tenant cloud infrastructure. Fragmented Hybrid: Distinct agents, fractured rule engines, and separate licensing tiers for on-premises vs cloud.
Commercial Pricing Currency Predictable ZAR Contracts: Fixed Rand pricing protected from ZAR/USD currency devaluations. Volatile USD: Budget unpredictability due to foreign exchange fluctuations and egress spikes. Volatile USD / Usage: Pay-per-ingestion billing spikes during major cybersecurity incidents.

Universal Global Privacy Laws & Statutory Enclaves Embedded

Custos is engineered with pre-compiled, kernel-enforced classifier rulesets and mathematical cryptographic guarantees for all major continental African and international privacy jurisdictions. Because the platform runs directly inside the client's datacenter and private cloud enclave, compliance is active and automated with zero WAN data transfer.

🇿🇦 South Africa: POPIA & SARB Directive 2/2023 🇦🇺 Australia: Privacy Act 1988 & APPs 1–13 🇳🇿 New Zealand: Privacy Act 2020 & IPPs 1–13 🇬🇧 United Kingdom: UK GDPR & Data Protection Act 2018 🇩🇪 Germany: BDSG (Bundesdatenschutzgesetz) & EU GDPR 🌍 Pan-Africa: Mauritius DPA 2017 • Kenya DPA 2019 • Nigeria NDPA 2023 🇺🇸 Global: US HIPAA (ePHI) • PCI DSS v4.0 • EU DORA
🇿🇦
DOMESTIC SOVEREIGN

South Africa: POPIA & SARB Directive 2/2023

POPIA Section 72: Explicitly restricts transferring personal information cross-border. Custos locks all database telemetry strictly to domestic perimeters (Azure JHB / on-premises).

SARB Directive 2/2023 & Cybercrimes Act: Built-in dual-control cryptographic Human-in-the-Loop (HITL) sign-off for critical commands (>R50,000) and Ed25519 Merkle-audit trails under Cybercrimes Act 19 of 2020.

🇦🇺
APPs 1–13 EMBEDDED

Australia: Privacy Act 1988 & APPs

Australian Privacy Principles (APPs): Full in-memory classification for Medicare Numbers, Tax File Numbers (TFN), Australian Business Numbers (ABN), and Patient Health Records under the My Health Records Act.

APP 8 Cross-Border Disclosure & NDB Scheme: Guarantees zero offshore data disclosure to foreign cloud providers, actively mitigating Notifiable Data Breaches (NDB) scheme exposure.

🇳🇿
IPPs 1–13 EMBEDDED

New Zealand: Privacy Act 2020

Information Privacy Principles (IPPs): Built-in detection for Inland Revenue Department (IRD) numbers, National Health Index (NHI) identifiers, and driver licenses.

IPP 12 Offshore Disclosure Control: Enforces mandatory cross-border disclosure safeguards, ensuring sensitive Kiwi citizen and Maori genealogical data remains securely contained.

🇬🇧
ICO / UK DPA 2018

United Kingdom: UK GDPR & DPA 2018

Information Commissioner's Office (ICO) Compliance: Automated right-to-erasure certificates, Subject Access Request (DSAR) tokenization, and strict NHS Number classification.

Chapter V International Transfers: Eliminates International Data Transfer Agreement (IDTA) legal friction by keeping all data parsing and AI model guardrails on-premises.

🇩🇪
BDSG & EU GDPR

Germany: BDSG & EU GDPR (DSGVO)

Bundesdatenschutzgesetz (BDSG): Strict employee privacy protections (Sec 26 BDSG), works council audit trails, German Steuer-ID, and statutory health insurance (Krankenversichertennummer).

EU DORA & Schrems II Immunity: Direct on-premises execution renders cloud provider CLOUD Act extraterritorial subpoena risks mathematically impossible.

🌍
PAN-AFRICAN CORRIDORS

Pan-Africa: Mauritius, Kenya, Nigeria & SADC

Mauritius DPA 2017 & Bank of Mauritius (BoM): Offshore financial banking secrecy and FSC regulatory compliance without cross-border telemetry.

Kenya DPA 2019 & Nigeria NDPA 2023: Full native classification for Kenyan Huduma Namba, Nigerian Bank Verification Numbers (BVN), and National Identity Numbers (NIN).

Why Custos is Genuine CAPEX: Accounting & Tax Justification

How South African retail conglomerates, commercial banks, and listed enterprises eliminate the SaaS OPEX EBITDA penalty, retain operational software sovereignty, and claim statutory 3-year tax depreciation under IAS 38 and SARS Section 11(e).

📋 IAS 38 CRITERIA MET

1. Software Control & Possession (IAS 38)

Under International Accounting Standard 38 (IAS 38) and the landmark 2021 IFRIC Agenda Decision on Cloud Computing Arrangements (SaaS), customers cannot capitalize vendor-hosted subscriptions because they lack legal and operational control over the software code and hosting servers.

The Custos Distinction: Enterprises receive compiled machine-code binaries executed exclusively inside their private perimeter (customer-owned Azure/AWS tenant and on-premises VMware/bare-metal). The enterprise exercises complete runtime sovereignty, operational control, and data ownership, qualifying the license as an identifiable capital intangible asset.

Accounting Standard: IAS 38 § 13–17 (Control & Identifiability)
IFRIC 2021 Impact: Exempt from SaaS OPEX classification
🇿🇦 SARS 3-YEAR WRITE-OFF

2. SARS Section 11(e) Tax Depreciation

Under Section 11(e) of the South African Income Tax Act (and Section 11(gC) for software intellectual property and capital acquisitions), corporate taxpayers are entitled to write off capital assets used in the production of income.

SARS Interpretation Note 47 (Issue 5): Prescribes an approved write-off period of 3 years (33.3% per annum, straight-line) for customized enterprise application software. This delivers a substantial annual tax shield deduction against corporate taxable income, directly enhancing net after-tax cash flows.

Statutory Basis: SARS Section 11(e) / IN 47 (Issue 5)
Write-off Schedule: 33.3% p.a. straight-line deduction
📈 EBITDA PROTECTION

3. EBITDA & Operating Margin Protection

For JSE-listed retail enterprises (such as Shoprite, Woolworths, Pick n Pay, Takealot) and major financial institutions, multimillion-rand cybersecurity licenses booked as cloud SaaS OPEX directly reduce Earnings Before Interest, Taxes, Depreciation, and Amortization (EBITDA).

Balance Sheet Value: Custos enables corporate treasuries to treat the platform as a balance sheet capital software asset. Amortization occurs below the EBITDA line, preserving operating profit margins and strengthening institutional valuation multiples.

Corporate Metric: Operating EBITDA preservation
Balance Sheet Impact: Identifiable intangible asset creation
⚙️ 100% MODULE PARITY

4. Zero Cloud Lock-In & 100% Parity

Unlike foreign vendors whose on-premises agents are hollow forwarders that require external cloud APIs to function, every single one of Custos's 20 modules executes locally within compiled machine code.

Identical Capabilities Across All Formats: Whether deployed on-premises on VMware/bare-metal, in a customer-hosted Azure/AWS enclave, or in a full hybrid mesh, your teams retain 100% module parity — from in-place DSPM and AI AgentShield to SafeHarbor™ Merkle ledgers and AirGap™ engines.

Code Delivery: Signed standalone Go binaries
Cloud Independence: Zero feature degradation offline
EXECUTIVE SUMMARY FOR CFOS & AUDIT COMMITTEES

Why SaaS Contracts are an OPEX Trap vs. Custos Sovereign Capitalization

Request CFO Tax Briefing Pack →
❌ Multi-Tenant Vendor SaaS (OPEX Penalty)
  • • Hits operating expenditure directly, immediately reducing reported EBITDA.
  • • Disqualified from capitalization under the 2021 IFRIC SaaS Agenda Decision.
  • • Zero balance sheet asset value upon contract termination.
  • • Volatile USD pricing and unbudgeted cloud data egress surcharges.
✅ Custos Sovereign Capital License (CAPEX Advantage)
  • • Capitalized on balance sheet as an identifiable intangible software asset under IAS 38.
  • • Protects EBITDA margins; amortized below the operating profit line.
  • • 3-Year 33.3% p.a. straight-line tax write-off under SARS Section 11(e) / IN 47.
  • • Fixed ZAR pricing with zero vendor telemetry ingestion or egress fees.

Institutional Capital Licenses & Turnkey POV Schedule

Structured for rapid proof of value, predictable ZAR procurement, and strict domestic governance. All enterprise capital licenses qualify under IAS 38 and SARS Section 11(e) for 3-year tax depreciation.

TURNKEY EVALUATION GUARANTEE 🇿🇦 100% CAPITAL FEE CREDIT

30-Day Turnkey Production Proof of Value (POV)

Deploy into your enterprise staging or production perimeter within 5 business days. Includes complete DSPM forensic scanning, AgentShield™ AI firewall configuration, and unalterable SafeHarbor™ executive dossiers. 100% of your turnkey POV fee is credited directly toward your annual production capital license upon conversion. Scoping and quotation schedules are provided via our contact page.

Schedule Turnkey POV →
CLOUD SOVEREIGN ENCLAVE CAPEX QUALIFIED
Sovereign Cloud Enclave
Custom Enterprise Capital License • IAS 38 & SARS § 11(e)

Provisioned directly inside your dedicated Microsoft Azure South Africa North (JHB) or AWS Africa Cape Town subscription with customer-managed keys and zero vendor data access.

  • ✓ Multi-Cloud DSPM (Azure + AWS + S3 + RDS)
  • ✓ Shannon Entropy Ransomware Tripwire
  • ✓ AgentShield™ Real-Time AI Prompt Firewall
  • ✓ Unlocked Forensic Dossiers & Schema Exports
  • ✓ Ed25519 Cryptographic Cloud Enclave License
  • ✓ 0.00 KB/s Vendor Telemetry Ingestion Guarantee
Procurement Schedule: Official corporate quotes and licensing schedules are issued directly upon request. Contact our team via the Contact Page.
Request Cloud Enclave Schedule →
PREFERRED ENTERPRISE FLAGSHIP
FULL HYBRID MESH 100% MODULE PARITY
Full Hybrid Sovereign Mesh
Dual-Estate Federation • 100% POV Fee Credit

Seamlessly federates your customer-hosted cloud enclave with on-premises VMware ESXi, SAP S/4HANA, Oracle RAC, and Active Directory clusters under strict POPIA Section 72 and SARB Directive 2/2023 mandates.

  • ✓ Dual-Estate Federation (Cloud + On-Premises VMware/Bare-Metal)
  • ✓ Calico eBPF + ChaCha20 WireGuard mTLS Sub-ms Mesh
  • ✓ 0.00 KB/s International WAN Egress Pinned
  • ✓ 126µs Autonomous LotL Ransomware Severance
  • ✓ SARB Directive 2/2023 Dual-Control HITL Sign-Off
  • ✓ All 20 Capability Modules with 100% Architecture Parity
  • ✓ 3-Year 33.3% p.a. Tax Write-Off (SARS Section 11(e))
POV Conversion Benefit: 100% of your Turnkey POV fee is credited toward this license upon annual conversion. Request your schedule on our Contact Page.
Request Hybrid Mesh Schedule →
FULL ON-PREMISES ZERO-WAN SCIF
Full On-Premises Air-Gapped Mesh
Zero-WAN SCIF • IAS 38 & SARS § 11(e)

Isolated bare-metal Go binaries engineered for interbank payment switches, national clearing infrastructure, and sovereign defense installations with zero public Internet egress.

  • ✓ Standalone Zero-WAN Mesh with Local Offline DB
  • ✓ Ed25519-Signed Plan B Golden Firmware Rollback
  • ✓ Dual-Key Cryptographic Sign-Off (SARB HITL)
  • ✓ Court-Admissible SafeHarbor™ Merkle Logs
  • ✓ Turnkey Air-Gapped SCIF Architecture
  • ✓ 100% Functionality with Zero Cloud Dependencies
Procurement Schedule: Official quotes and SCIF implementation schedules are provided via our Contact Page.
Request On-Premises Schedule →

Frequently Asked Questions

Common questions from Chief Information Security Officers, Chief Financial Officers, and Enterprise Architects.

What is a Sovereign Hybrid Cyber Defense Enclave?

A Sovereign Hybrid Cyber Defense Enclave is a dual-plane security architecture designed specifically for regulated environments. It pairs an ultra-lightweight on-premises Go daemon inside your physical datacenters with an isolated cloud enclave running physically inside Microsoft Azure's South Africa North datacenter in Johannesburg or AWS Africa Cape Town. Telemetry is encrypted over mTLS 1.3 with strict in-kernel eBPF inspection guaranteeing that zero packets cross international borders.

Why is GovernX Custos classified as genuine CAPEX under IAS 38 and SARS Section 11(e)?

Under the 2021 IFRIC Agenda Decision on Cloud Computing Arrangements (SaaS), typical multi-tenant cloud software cannot be capitalized as an intangible asset because the enterprise does not control the software code or the server infrastructure. With Custos, the customer takes physical possession of standalone compiled Go machine-code binaries deployed inside their own cloud tenant or on-premises servers. Because the enterprise exercises full operational control and runtime sovereignty, it meets all IAS 38 capitalization criteria. Furthermore, under Section 11(e) of the South African Income Tax Act and SARS Interpretation Note 47 (Issue 5), customized enterprise software qualifies for a 3-year straight-line (33.3% per annum) tax wear-and-tear allowance, protecting operating EBITDA margins and lowering corporate tax liabilities.

Does GovernX or Microsoft ever have access to our raw retail or financial data?

No. In enterprise deployments, the enclave is provisioned entirely inside the customer's own cloud subscription (Azure South Africa North or AWS Cape Town) or within on-premises virtualization clusters. GovernX never ingests, stores, or processes raw customer records, transactions, or schemas. GovernX only issues the signed Ed25519 cryptographic license key. Zero customer data leaves your perimeter (0.00 KB/s vendor egress).

Do all 20 modules run identically on-premises and in our private cloud enclave?

Yes. Custos provides 100% module and architectural parity. Every module—including in-place streaming DSPM, Custos AgentShield™ AI Execution Firewall, WireRemit™ ISO 20022 governor, Shannon Entropy Ransomware tripwires, SafeHarbor™ Merkle audit ledgers, and the AirGap™ SCIF engine—executes natively in compiled machine code across bare-metal, VMware ESXi, Windows Server, and cloud VMs with zero cloud dependency or feature degradation.

How does the Turnkey Proof of Value (POV) model and 100% conversion credit work?

The 30-Day Turnkey Proof of Value (POV) is designed for rapid enterprise validation without production friction. GovernX engineers deploy the sovereign enclave into your staging or production estate within 5 business days, delivering full DSPM discovery, AI firewall rules, and executive risk dossiers. When your enterprise converts to an annual production capital license within 60 days, 100% of your turnkey POV investment is credited directly against the production software license fee, making the POV effectively zero net cost. Full scoping, evaluation timelines, and commercial schedules are provided via our Contact Page.

Why can't South African banks and retailers use US-hosted DSPMs like BigID, Cyera, or Varonis?

US-headquartered DSPMs host their central analytics and machine learning engines in US East (N. Virginia) or EU (Frankfurt) clouds. When they scan your datastores, sensitive schemas, file hashes, and telemetry traverse transoceanic fiber cables. This directly exposes institutions to POPIA Section 72 cross-border non-compliance penalties, US CLOUD Act extraterritorial subpoenas, high WAN data egress fees, and perpetual SaaS OPEX EBITDA drag.

How does Custos AgentShield™ prevent autonomous AI agents from leaking bank or retail data?

Custos AgentShield™ acts as an inline Layer-7 execution firewall. It proxies agent LLM queries, Model Context Protocol (MCP) tool bindings, and vector database embeddings. If an agent hallucinates, suffers a prompt injection attack, or attempts to retrieve data outside its authorized scope, AgentShield severs the socket connection in 126 microseconds, preventing the data transmission before it reaches the model.

Does deploying the hybrid agent require system reboots or downtime?

No. The agent is packaged as a single standalone executable consuming less than 14MB of RAM with zero JVM or Python dependencies. It attaches to database cursors and filesystem APIs in non-blocking read-only streaming mode, requiring zero maintenance windows, zero schema modifications, and zero server reboots.

How does GovernX satisfy SARB Directive 2/2023 for destructive commands?

GovernX enforces a built-in Dual-Control Human-In-The-Loop (HITL) challenge protocol. Whenever an administrator or automated rule attempts a destructive remediation, datastore quarantine, or action involving financial assets exceeding R50,000, two certified officers must provide their cryptographic signatures within a 15-minute challenge window before the command executes.

Deploy the Hybrid Agent in Under 2 Minutes

Connect on-premises Linux, Windows Server, or VMware nodes to your dedicated Johannesburg enclave.

// 1. Download and verify the signed South African Sovereign Node binary
curl -sSL https://custos-ai.governx.co.za/downloads/custos-agent-linux-amd64 -o /usr/local/bin/custos-agent
chmod +x /usr/local/bin/custos-agent
// 2. Register node with your sovereign Johannesburg enclave token
custos-agent register --enclave="https://custos-ai.governx.co.za" --region="southafricanorth" --popia-pinning=true
// 3. Enable and start autonomous protection daemon
systemctl enable --now custos-agent
// 4. Verify sub-millisecond mTLS 1.3 mesh connection to Johannesburg
custos-agent status --verify-mesh
Request Enterprise POV Briefing