Executive & Technical Inquiries
Frequently Asked Questions
Common questions from Chief Information Security Officers, Chief Financial Officers, and Enterprise Architects.
What is a Sovereign Hybrid Cyber Defense Enclave?
A Sovereign Hybrid Cyber Defense Enclave is a dual-plane security architecture designed specifically for regulated environments. It pairs an ultra-lightweight on-premises Go daemon inside your physical datacenters with an isolated cloud enclave running physically inside Microsoft Azure's South Africa North datacenter in Johannesburg or AWS Africa Cape Town. Telemetry is encrypted over mTLS 1.3 with strict in-kernel eBPF inspection guaranteeing that zero packets cross international borders.
Why is GovernX Custos classified as genuine CAPEX under IAS 38 and SARS Section 11(e)?
Under the 2021 IFRIC Agenda Decision on Cloud Computing Arrangements (SaaS), typical multi-tenant cloud software cannot be capitalized as an intangible asset because the enterprise does not control the software code or the server infrastructure. With Custos, the customer takes physical possession of standalone compiled Go machine-code binaries deployed inside their own cloud tenant or on-premises servers. Because the enterprise exercises full operational control and runtime sovereignty, it meets all IAS 38 capitalization criteria. Furthermore, under Section 11(e) of the South African Income Tax Act and SARS Interpretation Note 47 (Issue 5), customized enterprise software qualifies for a 3-year straight-line (33.3% per annum) tax wear-and-tear allowance, protecting operating EBITDA margins and lowering corporate tax liabilities.
Does GovernX or Microsoft ever have access to our raw retail or financial data?
No. In enterprise deployments, the enclave is provisioned entirely inside the customer's own cloud subscription (Azure South Africa North or AWS Cape Town) or within on-premises virtualization clusters. GovernX never ingests, stores, or processes raw customer records, transactions, or schemas. GovernX only issues the signed Ed25519 cryptographic license key. Zero customer data leaves your perimeter (0.00 KB/s vendor egress).
Do all 20 modules run identically on-premises and in our private cloud enclave?
Yes. Custos provides 100% module and architectural parity. Every module—including in-place streaming DSPM, Custos AgentShield™ AI Execution Firewall, WireRemit™ ISO 20022 governor, Shannon Entropy Ransomware tripwires, SafeHarbor™ Merkle audit ledgers, and the AirGap™ SCIF engine—executes natively in compiled machine code across bare-metal, VMware ESXi, Windows Server, and cloud VMs with zero cloud dependency or feature degradation.
How does the Turnkey Proof of Value (POV) model and 100% conversion credit work?
The 30-Day Turnkey Proof of Value (POV) is designed for rapid enterprise validation without production friction. GovernX engineers deploy the sovereign enclave into your staging or production estate within 5 business days, delivering full DSPM discovery, AI firewall rules, and executive risk dossiers. When your enterprise converts to an annual production capital license within 60 days, 100% of your turnkey POV investment is credited directly against the production software license fee, making the POV effectively zero net cost. Full scoping, evaluation timelines, and commercial schedules are provided via our Contact Page.
Why can't South African banks and retailers use US-hosted DSPMs like BigID, Cyera, or Varonis?
US-headquartered DSPMs host their central analytics and machine learning engines in US East (N. Virginia) or EU (Frankfurt) clouds. When they scan your datastores, sensitive schemas, file hashes, and telemetry traverse transoceanic fiber cables. This directly exposes institutions to POPIA Section 72 cross-border non-compliance penalties, US CLOUD Act extraterritorial subpoenas, high WAN data egress fees, and perpetual SaaS OPEX EBITDA drag.
How does Custos AgentShield™ prevent autonomous AI agents from leaking bank or retail data?
Custos AgentShield™ acts as an inline Layer-7 execution firewall. It proxies agent LLM queries, Model Context Protocol (MCP) tool bindings, and vector database embeddings. If an agent hallucinates, suffers a prompt injection attack, or attempts to retrieve data outside its authorized scope, AgentShield severs the socket connection in 126 microseconds, preventing the data transmission before it reaches the model.
Does deploying the hybrid agent require system reboots or downtime?
No. The agent is packaged as a single standalone executable consuming less than 14MB of RAM with zero JVM or Python dependencies. It attaches to database cursors and filesystem APIs in non-blocking read-only streaming mode, requiring zero maintenance windows, zero schema modifications, and zero server reboots.
How does GovernX satisfy SARB Directive 2/2023 for destructive commands?
GovernX enforces a built-in Dual-Control Human-In-The-Loop (HITL) challenge protocol. Whenever an administrator or automated rule attempts a destructive remediation, datastore quarantine, or action involving financial assets exceeding R50,000, two certified officers must provide their cryptographic signatures within a 15-minute challenge window before the command executes.