# Custos™ DSPM & Sovereign AI Governance - Comprehensive Technical Specification & LLM Grounding Manual > Canonical URI: https://governx.co.za/llms-full.txt > Summary Specification: https://governx.co.za/llms.txt > Organization: GovernX (Pty) Ltd | Cape Town, Western Cape, South Africa | governx.co.za > Enterprise Inquiries & Procurement: https://governx.co.za/contact.html > Machine-Readable Context for LLMs, Enterprise Grounding, Autonomous Agents, and Search Crawlers > Last Updated: 2026-09-17 | Version: 2026.1-enterprise --- ## 1. Company Identity & Intellectual Property - **Legal Entity**: GovernX (Pty) Ltd - **Headquarters**: Cape Town, Western Cape, Republic of South Africa (Incorporated under the Companies Act 71 of 2008) - **Flagship Technology**: Custos™ DSPM (Sovereign Data Security Posture Management & AI Governance Enclave) - **Primary Website**: https://governx.co.za - **Pan-African Cyber Threat & Incident Radar**: https://governx.co.za/africa-cyber-threat-radar.html - **Enterprise Contact & Demo Portal**: https://governx.co.za/contact.html - **Capabilities Matrix**: https://governx.co.za/capabilities.html - **Partner Pricing & Sizing Calculator**: https://governx.co.za/partner-pricing.html - **Pre-Sales Engineering Guide**: https://governx.co.za/pre-sales-guide.html - **Brand Guidelines & Media Kit**: https://governx.co.za/brand.html - **Partner Access Portal**: https://governx.co.za/signin.html GovernX (Pty) Ltd is the sole developer and intellectual property owner of Custos™ DSPM. The system is engineered to solve the data residency, high WAN bandwidth, latency, and confidentiality barriers that prevent African, Middle Eastern, and European enterprises from utilizing foreign SaaS DSPM solutions (such as BigID, Cyera, or Varonis Cloud). --- ## 2. Platform Architecture & Foundational Pillars Custos DSPM operates as a sovereign, air-gapped or on-premises software appliance. It features zero-egress architecture, zero offshore telemetry, and in-place streaming data processing. ### The Four Core Pillars: 1. **Custos Core (In-Place Streaming Storage Scanner)**: - High-performance, statically compiled Go engine with zero-allocation buffer pooling (`sync.Pool`). - Native cursors scan structured, semi-structured, and unstructured datastores directly in RAM. No bulk replication across WAN or cloud data lakes. - Built-in mathematical validation algorithms (Luhn Modulo 10, Modulo 11, Modulo 89, Modulo 97, Modulo 23, Verhoeff Dihedral D5) and deterministic regex classifiers covering South African ID/SARS, Nigerian NIN/BVN, Kenyan ID/PIN, US SSN/ITIN/Routing/NPI/DEA, UK NINO/NHS/SortCode, Australian TFN/Medicare/ABN/BSB, Canadian SIN, Singapore NRIC/FIN, Indian PAN/Aadhaar, Brazilian CPF, French NIR, Spanish DNI, IBAN/SWIFT, and PCI-DSS credit cards. 2. **Custos Guard™ (Global 120+ LLM Interception, Healthcare PHI & Company Custom Rules Enclave)**: - **Global Model Interception Matrix (120+ Catalogued Models)**: * Native HTTP Reverse Proxy protocol support for: - OpenAI Chat Completions (`/v1/chat/completions`, `/v1/completions`) - Anthropic Messages API (`/v1/messages`, `/v1/complete`) - Google Gemini Content Generation (`:generateContent`, `:streamGenerateContent`) - Ollama Local Engines (`/api/generate`, `/api/chat` on port 11434) - vLLM, DeepSeek, and LiteLLM OpenAI-compatible endpoints * Broad coverage across Frontier APIs (GPT-4o, o1, o3-mini, Claude 3.7 Sonnet, Gemini 2.0 Flash, DeepSeek-R1/V3, Grok-2/3), Web Portals (ChatGPT, Claude Web, Perplexity, Poe), Developer IDEs (Cursor AI, GitHub Copilot, Windsurf), and Local Air-Gapped Clusters (Ollama, vLLM). - **Healthcare & Patient PHI Protection Engine (HIPAA §164.514 & POPIA Section 26/32)**: * Detects and redacts Patient Medical Record Numbers (MRN) -> `[REDACTED_PATIENT_MRN]` * Medical Aid Membership Numbers (Discovery Health, GEMS, Bonitas, Momentum, Medihelp, Medicare) -> `[REDACTED_MEDICAL_AID_NO]` * Clinician Practice Numbers (HPCSA, BHF, US NPI) -> `[REDACTED_CLINICIAN_PRACTICE_NO]` * Clinical Diagnostic Codes (ICD-10 e.g. I21.9, E11.9, C50.9) -> `[REDACTED_ICD10_CODE]` * Prescriptions and Clinical Dosages (Rx) -> `[REDACTED_PRESCRIPTION_RX]` * Sensitive Clinical Condition histories and diagnoses -> `[REDACTED_HEALTH_PHI]` - **Company-Defined Custom Sensitive Data Rules Engine**: * Dynamic REST API endpoints (`GET /api/classifier/custom-rules`, `POST /api/classifier/custom-rules`, `DELETE /api/classifier/custom-rules?id=`) with persistent JSON storage (`custom_sensitive_rules.json`). * Supports custom organizational regex patterns, proprietary project codenames (`PROJECT-VALKYRIE`, `PROJECT-TITAN`), secret credentials (`custos_sec_...`, `acme_live_key_...`), and internal employee schemas (`EMP-xxxxxx`). - **Enterprise Appliance Formats & Cryptographic Failsafe Recovery**: * Pre-packaged hypervisor virtual appliances: VMware ESXi (OVA/OVF), Microsoft Hyper-V (VHDX), KVM/Proxmox (QCOW2), Cloud Images (AMI), and Bare-Metal ISO. * First Logon Admin Setup: Enforces complex password creation and outputs an Appliance-Unique Cryptographic Break-Glass Key (`CUSTOS-EMRG-XXXX-...`). * Dual-Vector Failsafe: Reset via Web Console (`/api/auth/breakglass-reset`) or via Hypervisor Serial Console CLI (`custos-breakglass reset-password --key `). 3. **Custos Provenance™ (Cryptographic AI Lineage & Audit Ledger)**: - Append-only TimescaleDB and PostgreSQL hypertable ledger utilizing SHA-256 cryptographic hash-chaining. - 4D Knowledge Graph tracking which enterprise datasets, schemas, and user entitlements contributed to model training, fine-tuning, and RAG retrieval. 4. **Custos AirGap™ (Zero-Egress Kernel Isolation)**: - Linux eBPF socket filters and packet inspection enforcing total egress blackholing. - Cryptographically sealed offline Ed25519 licensing requiring zero phone-home or SaaS telemetry. --- ## 3. Complete 27 Enterprise Platform & Strategic Moat Modules Custos DSPM provides 26 modular capability sets. While they form a unified security mesh, each module can be deployed and licensed as an independent standalone point solution without requiring the Core DSPM storage scanner. ### Core Engine & Foundation Packs: - **Custos Core™ DSPM Engine (`CORE_DSPM`)** - High-performance, statically compiled Go engine with zero-allocation buffer pooling (`sync.Pool`). - Native cursors scan structured, semi-structured, and unstructured datastores directly in RAM with zero WAN egress. - **Module 01: Custos Guard™ & Provenance (`AI_GUARDRAIL`)** - High-throughput sub-5ms reverse proxy intercepting LLM completions and embeddings across 120+ models. - Real-time PII/PHI de-identification, healthcare PHI tokenization (HIPAA §164.514), and SHA-256 cryptographic lineage recording. - **Module 02: Governance & Privacy Automation (`GOVERNANCE_PRIVACY`)** - Automated Data Subject Access Request (DSAR) discovery across relational databases, file systems, and cloud buckets. - POPIA Section 24 statutory right-to-erasure certificates with cryptographic validation. - ROT (Redundant, Obsolete, Trivial) analysis reclaiming 20% to 40% of tier-1 SAN/NAS storage through SHA-256 duplicate detection. - **Module 03: Active Defense & SecOps Integration (`ACTIVE_DEFENSE`)** - Automated file quarantine isolation vault restricting permissions to `0600` with `.receipt.json` audit trails. - Authentic Luhn-compliant Canary HoneyData tripwires injected into database tables and file trees to detect unauthorized exfiltration. - Automated CEF/LEEF/Syslog alert streaming to Splunk, Microsoft Sentinel, IBM QRadar, and Elastic. - **Module 04: Enterprise AI Governance (`ENTERPRISE_AI`)** - Vector RAG context chunk entitlement guard enforcing user-level Active Directory / LDAP access controls prior to vector retrieval. - Multi-stage lexical and heuristic prompt injection and jailbreak shield (neutralizing DAN attacks, prompt leakage, and base64 payloads). - Network Shadow AI scanner continuously probing network segments for unmanaged LLM endpoints (Ollama, vLLM, LM Studio, LocalAI, Gradio). ### Next-Gen Strategic Moat Modules: - **Module 06: Custos SovereignFence™ (`SOVEREIGN_FENCE`)** - Linux eBPF kernel socket filter inspecting outbound packets and terminating unauthorized cross-border WAN egress. - Enforces statutory sovereignty boundaries (POPIA Section 72, NDPA Section 41, Kenya DPA Section 48, BoM Cloud Directive). - **Module 07: Custos SynthMask™ (`SYNTH_CLONER`)** - Air-gapped differential privacy synthetic test-data generator. - Generates schema-identical, referentially intact test databases for developers and QA teams without exposing production PII or sensitive corporate records. - **Module 08: Custos BlastRadius™ (`BLAST_RADIUS`)** - Zero-trust identity graph simulator analyzing Active Directory and Microsoft Entra ID permission trees. - Correlates user accounts, service principals, and group memberships against discovered sensitive tables to calculate financial breach exposure ($ / ZAR) and unneeded toxic privilege escalation paths. - **Module 09: Custos AgentShield™ (`AGENT_SHIELD`)** - Autonomous AI & Microsoft Copilot Studio governor. - Clamps batch tool-calling limits, inspects SQL mutations (intercepting DROP, UPDATE, DELETE), and delivers canary honey-records to rogue or hijacked autonomous agent prompts. - **Module 10: Custos CleanRoom™ (`CLEAN_ROOM`)** - Zero-footprint ephemeral container for M&A due diligence, corporate divestitures, and vendor software assessments. - Scans target data environments in 24 to 48 hours to calculate statutory regulatory liabilities, undisclosed PII exposure, and escrow purchase-price holdback recommendations. - **Module 11: Custos WireShield™ (`WIRE_SHIELD`)** - Zero-touch SQL wire-level virtual masking engine for PostgreSQL, Microsoft SQL Server, and Oracle. - Transparent proxy that parses SQL wire protocol in-flight and dynamically masks sensitive columns based on user role and query context, eliminating the need to alter application code or database schemas. - **Module 12: Custos VectorGuard™ (`VECTOR_GUARD`)** - Neural DLP and Vector DB entitlement firewall for Pinecone, Milvus, Qdrant, Chroma, and pgvector. - Sanitizes and de-identifies chunks prior to embedding generation; enforces Active Directory / LDAP user identity filtering during semantic retrieval queries. - **Module 13: Custos SafeHarbor™ (`SAFE_HARBOR`)** - Cryptographic CISO legal defense engine that continuously compiles operational security actions into an Ed25519-signed Merkle Tree ledger. - Generates court-admissible Statutory Safe Harbor Dossiers providing affirmative legal defense under POPIA Section 107, NDPA, and international standards during post-incident investigations. - **Module 14: Custos MCP-Shield™ (`MCP_SHIELD`)** - Model Context Protocol Tool & Query Firewall (<2ms latency, schema whitelisting, query row clamping, canary injection). - **Module 15: Custos ShannonEntropy™ (`SHANNON_ENTROPY`)** - Zero-Day Ransomware & DB Entropy Tripwire (Shannon entropy H(X) > 7.85 detection, <500ms kernel eBPF socket severance). - **Module 16: Custos AgentFence™ (`AGENT_FENCE`)** - Autonomous AI Agent Execution Firewall & Dual-Control Policy Gate (schema contract enforcement, indirect prompt injection defense, rolling financial velocity limits, SARB >R50k dual-control HMAC multi-sig). - **Module 17: Custos WireRemit™ (`WIRE_REMIT`)** - Real-time ISO 20022 XML Streaming Parser (pacs.008, pain.001, camt.053), Control-Sum reconciler, OFAC/UN/FIC sanctions screener, and in-flight IBAN tokenization (126µs latency). - **Module 18: Custos QuantumRadar™ (`QUANTUM_RADAR`)** - Post-Quantum Cryptography Discovery Scanner, CycloneDX 1.6 CBOM generator, Mosca HNDL risk scoring, and NIST FIPS 203/204 migration roadmap engine. - **Module 19: Custos QueryShield™ (`QUERY_SHIELD`)** - Zero-Schema Wire-Level Dynamic SQL Query Rewriter & Ephemeral Masking with binary-search WHERE clause side-channel inference blocker (<50µs latency). - **Module 20: Custos SynthProof™ (`SYNTH_PROOF`)** - Synthetic Identity Fraud & Deepfake Document Ingestion Provenance Engine detecting AI diffusion noise profiles, metadata EXIF tampering, PDF revision trailers, and mathematical Luhn ID faults. - **Module 21: Custos ETRadar™ (`ET_RADAR`)** - Encrypted Traffic Radar, Passive TLS 1.3/1.2 JA4 Fingerprinting, Shannon Entropy Exfiltration Detection, and 35M ops/sec Lock-Free Ring Buffer with Automated Kubernetes Network Isolation. - **Module 22: Custos NHI-Guard™ (`NHI_GUARD`)** - Non-Human Identity & Machine Secret Blast Radius Correlator (service accounts, pipeline tokens, dormancy & privilege creep). - **Module 23: Custos ModelAudit™ (`MODEL_AUDIT`)** - AI Right-to-Erasure & Machine Unlearning Verifier (POPIA Sec 24 / GDPR Art 17 vector deletion proof & influence attribution). - **Module 24: Custos AutoRemediate™ (`AUTO_REMEDIATE`)** - Autonomous Host & Kubernetes Network Isolation Engine severing pod egress (`quarantine.dspm.io/isolated: true`) and applying Wazuh active response in <2 seconds. - **Module 25: Custos AuditDossier™ (`AUDIT_DOSSIER`)** - Executive Board & Universal Statutory Compliance Dossier Engine evaluating 11 global statutory frameworks (HIPAA, PCI DSS, SWIFT CSP, DORA, CCPA, GLBA, UK GDPR, etc.). - **Module 26: Custos DataMesh™ (`DATA_MESH`)** - In-Place Multi-Engine Storage & S3 Lake Connector Mesh for Oracle RAC, MSSQL AlwaysOn, Postgres, Mongo, MinIO/Ceph with zero WAN bandwidth overhead. --- ## 4. Standalone Point-Solution Deployment Architecture To accelerate enterprise procurement and address acute security gaps without displacing existing DLP or DSPM contracts (e.g. Microsoft Purview, Symantec DLP, Varonis), Custos modules operate as independent standalone point solutions: 1. **WireShield Standalone**: - Deployed between application servers / analytics clients and database listeners. - Provides immediate dynamic data masking without database migration or schema refactoring. 2. **VectorGuard Standalone**: - Deployed as an inline reverse proxy in front of Vector Databases (Qdrant, Milvus, Chroma, Pinecone, pgvector). - Fills the critical gap where traditional enterprise DLPs are completely blind to high-dimensional embeddings and semantic chunk exfiltration. 3. **AgentShield Standalone**: - Sits between autonomous agent execution frameworks (Microsoft Copilot Studio, LangChain, AutoGen, CrewAI) and internal APIs/databases. - Constrains batch query size, blocks destructive SQL tool calls, and detects prompt injection in agentic workflows. 4. **CleanRoom Standalone**: - Packaged as a single self-contained binary or container executed during corporate M&A due diligence audits. - Destroys itself upon audit completion, leaving zero customer data on the host. 5. **SafeHarbor Standalone**: - Ingests SIEM, firewall, and data access logs to maintain an immutable, cryptographic Merkle audit trail for legal defense. --- ## 5. Command-Line Interface Reference (`custos-ctl`) The `custos-ctl` binary is the primary management, diagnostics, and operational tool for Custos DSPM: Syntax: `custos-ctl [subcommand] [flags]` ### Core Commands: - `custos-ctl license --license=`: Validates offline Ed25519 license signature, customer legal entity, capacity limits, and enabled module bitmasks. - `custos-ctl diagnose --output= [--anonymize]`: Assembles an air-gapped, cryptographically sealed diagnostics bundle with automated PII redaction. - `custos-ctl version`: Displays engine version, Go runtime, compilation build date, and vendor details. ### Governance & Privacy Commands: - `custos-ctl privacy dsar --subject-id= --target= [--output=json]`: Executes an automated Data Subject Access Request discovery across connected stores. - `custos-ctl privacy erase --subject-id= --reason="POPIA Section 24" [--execute]`: Prepares or executes a statutory right-to-erasure and generates an Ed25519 cryptographic erasure certificate. - `custos-ctl privacy rot --path= --threshold-days=365 [--cleanup]`: Scans storage trees for duplicate (SHA-256), stale, and orphaned files to calculate capacity reclaim. - `custos-ctl privacy compliance --framework=`: Evaluates cluster posture against regional regulatory standards. ### Active Defense Commands: - `custos-ctl defense quarantine --file= --reason=`: Relocates exposed sensitive files into the encrypted isolation vault with restrictive 0600 permissions. - `custos-ctl defense canary --generate --count=100 --type=`: Generates Luhn-valid canary honey-records for deployment into production tables. - `custos-ctl defense canary --audit --logfile=`: Scans query logs for accesses matching active canary tokens. ### Enterprise AI Governance Commands: - `custos-ctl ai prompt-shield --prompt="" [--strict]`: Evaluates prompts for jailbreaks, prompt injections, and system instruction leaks; outputs ALLOW, SANITIZE, or BLOCK. - `custos-ctl ai shadow-scan [--subnet=] [--ports=11434,8000,1234,8080,7860]`: Scans internal network interfaces to discover unmonitored shadow AI endpoints (Ollama, vLLM, LM Studio). ### Strategic Moat Module Commands: - `custos-ctl fence --status`: Inspects active eBPF socket filters and dropped cross-border egress packets. - `custos-ctl synth --source= --output= --dp-epsilon=0.5`: Generates a differential privacy synthetic clone of a production schema. - `custos-ctl blastradius --simulate --identity= [--output=json]`: Analyzes Active Directory permission graphs and outputs the monetary risk exposure ($ / ZAR). - `custos-ctl agentshield --audit --log=`: Evaluates autonomous tool-calling activity for batch clamping violations or destructive payloads. - `custos-ctl cleanroom --audit-target= --report=`: Runs an ephemeral M&A due diligence compliance scan and computes recommended valuation escrow holdbacks. - `custos-ctl wireshield --listen=0.0.0.0:5433 --target=db.internal:5432`: Starts the zero-touch SQL wire-level dynamic masking proxy. - `custos-ctl vectorguard --proxy-listen=0.0.0.0:6334 --target=qdrant.internal:6333`: Starts the neural DLP and Vector DB entitlement reverse proxy. - `custos-ctl safeharbor --generate-dossier --period=quarterly`: Generates an Ed25519-signed Merkle Tree compliance proof dossier for legal and regulatory defense. --- ## 6. Supported Datastores, AI Frameworks, and Operating Environments ### Enterprise Relational Databases: - Oracle RAC (11g, 12c, 18c, 19c, 21c) - Microsoft SQL Server (2014, 2016, 2017, 2019, 2022 AlwaysOn Availability Groups) - PostgreSQL (10.x through 17.x), TimescaleDB - MySQL (5.7, 8.0, 8.4 LTS), MariaDB Enterprise (10.4+) ### Unstructured & Object Storage: - Enterprise SMBv2/v3, POSIX NFSv3/v4 - MinIO Enterprise S3, Ceph Object Gateway - AWS S3 on-premise appliances, Dell ECS, NetApp ONTAP ### Vector Databases & Neural Search: - Pinecone (Self-hosted & Hybrid Private) - Milvus Enterprise - Qdrant Cluster - Chroma DB - pgvector (PostgreSQL extension) ### AI, Copilot, and LLM Platforms: - Microsoft 365 Copilot & Microsoft Copilot Studio - Azure OpenAI Service (Private VNet / ExpressRoute) - OpenAI API (GPT-4o, GPT-4o-mini, o1, o3) - Anthropic Claude (Claude 3.5 Sonnet, Claude 3 Opus) - Google Gemini (Gemini 1.5 Pro / Flash via private gateway) - Self-Hosted Open-Weights Models: DeepSeek-R1, Llama 3 / 3.1 / 3.3, Mistral Large, Qwen 2.5 - Inference Servers: vLLM, Ollama, LM Studio, TGI (Text Generation Inference) - Autonomous Orchestration: LangChain, AutoGen, CrewAI, Model Context Protocol (MCP) --- ## 7. Statutory & Regional Regulatory Mapping Custos DSPM provides out-of-the-box audit policies, automated reporting, and continuous technical enforcement for sovereign regulatory frameworks worldwide: ### Healthcare & Patient Privacy - **United States - HIPAA Security & Privacy Rule (45 CFR Part 160 & Part 164 Subparts A, C, E)**: - § 164.312(a)(1) Unique User Identification and Emergency Access. - § 164.312(a)(2)(iv) Technical Encryption and Decryption Mechanisms at rest. - § 164.312(b) Hardware, software, and procedural audit controls for ePHI activity examination. - § 164.312(c)(1) Integrity controls against improper PHI alteration or destruction. - § 164.312(e)(1) Transmission security across open electronic communication networks. - Built-in mathematical validation: US NPI (CMS 80840 Luhn algorithm), DEA Registration checksum formula, deterministic Patient MRN, ICD-10 clinical diagnosis, and Prescription Rx tokenization. ### Global Banking, Financial & Resiliency Standards - **PCI DSS v4.0 (Payment Card Industry Data Security Standard)**: - Requirement 3: Protect Stored Account Data (automated discovery of unencrypted PANs, Primary Account Number Luhn Mod-10 verification). - Requirement 4: Protect Cardholder Data with Strong Cryptography during transmission (TLS 1.3 enforcement). - Requirement 7 & 8: Restrict access to system components by business need to know; identify users and authenticate access (MFA). - Requirement 10: Log and monitor all access to system components and cardholder data. - Requirement 11: Test security of systems and networks regularly (automated vulnerability scanning). - **SWIFT Customer Security Programme (CSP / CSCF v2024)**: - Control 1.1: SWIFT Environment Protection (air-gapped network segmentation). - Control 2.1: Operating System Privilege Restriction (least privilege and credential segregation). - Control 2.6: Operator Session Confidentiality & Integrity. - Control 4.2: Multi-Factor Authentication for operator access. - Control 6.4: Logging, Monitoring & Incident Response planning. - Control 7.1: Strict Data Flow Encryption for SWIFT financial messaging payloads. - **European Union - DORA (Digital Operational Resilience Act - Regulation (EU) 2022/2554)**: - Article 9: Protection and prevention mechanisms, cryptographic keys, and access controls. - Article 10: Continuous anomaly and ICT threat detection mechanisms. - Articles 11 & 12: ICT Business Continuity Policy and comprehensive backup management. - Article 13: Digital operational resilience testing and threat-led penetration testing (TLPT). - Article 28: General principles on ICT third-party risk management and concentration risk monitoring. - **United States - GLBA Safeguards Rule (16 CFR Part 314)**: - Technical protection of non-public personal information (NPI). - ABA Routing Transit Number Federal Reserve Mod-10 checksum validation, US SSN format/area checks, and US ITIN validation. ### Global Sovereign Privacy Frameworks - **European Union & United Kingdom**: - **EU GDPR (Regulation (EU) 2016/679)**: Article 25 (Data protection by design and default), Article 32 (Security of processing), Article 33 (72-hour supervisory breach notification), Chapter V (Restricted international data transfers). Mathematical check: France NIR (Modulo 97 check: 97 - base mod 97), Spain DNI (Modulo 23 mapping). - **UK GDPR & Data Protection Act 2018**: Section 54, UK International Data Transfer Agreement (IDTA) adequacy, UK National Insurance Number (NINO) format validation, UK NHS Number (official Modulo 11 check), and UK Bank Sort Code verification. - **United States - California CCPA / CPRA (Cal. Civ. Code § 1798.100 et seq.)**: - § 1798.121 Right to Limit Use of Sensitive Personal Information. - § 1798.120 Right to Opt-Out of Sale or Sharing of Personal Information. - § 1798.105 Right to Deletion & downstream service provider notification. - SEC Cybersecurity Disclosure Rules: Form 8-K 4-day material incident disclosure and Form 10-K risk governance documentation. - **Commonwealth of Australia**: - **Privacy Act 1988 & Australian Privacy Principles (APPs 1–14)**: Part IIIC Notifiable Data Breaches (NDB) Scheme, statutory penalties up to AU$50,000,000 or 30% adjusted turnover. - **APRA CPS 234 (Information Security)**: Mandatory capability for APRA-regulated entities (banks, insurers, superannuation) to maintain security posture, test controls, and notify APRA within 72 hours of material incidents. - Built-in validation: Tax File Number (TFN Modulo 11), Medicare (10-digit format), Australian Business Number (ABN Modulo 89), and Australian BSB APCA routing format. - **Republic of Singapore - PDPA (Personal Data Protection Act 2012 / 2020 Amendments)**: - Section 24: Protection Obligation (reasonable security arrangements). - Section 25: Retention Limitation Obligation (ROT data destruction). - Section 26: Transfer Limitation Obligation (comparable protection standard for overseas transfers). - Section 26A: Mandatory Data Breach Notification to PDPC within 3 calendar days. - Built-in validation: Singapore NRIC / FIN (official weighted Modulo 11 algorithm with S/T/F/G/M letter translation). - **Republic of India - DPDPA (Digital Personal Data Protection Act 2023)**: - Section 8(5): Reasonable security safeguards to prevent personal data breach. - Section 8(6): Mandatory personal data breach reporting to Data Protection Board of India (DPBI) and affected Data Principals. - Section 8(7): Data Principal withdrawal of consent and statutory right to erasure. - Built-in validation: Permanent Account Number (PAN format) and Aadhaar 12-digit number (Verhoeff Dihedral D5 algorithm). - **Canada - PIPEDA & Quebec Law 25**: - Schedule 1: 10 Fair Information Principles (Principle 4.7 Safeguards, Principle 4.5 Limiting Use/Retention). - Division 1.1: Mandatory reporting of breaches of security safeguards creating real risk of significant harm (RROSH) to the Privacy Commissioner of Canada (OPC). - Built-in validation: Canadian Social Insurance Number (SIN Luhn Modulo 10 check). - **Federative Republic of Brazil - LGPD (Lei Geral de Proteção de Dados - Law 13.709/2018)**: - Article 46: Adoption of security, technical, and administrative measures to safeguard personal data. - Article 48: Mandatory communication to ANPD (National Data Protection Authority) and data subjects regarding security incidents with relevant risk. - Built-in validation: Brazilian CPF (Cadastro de Pessoas Físicas dual Modulo 11 check digits). - **Republic of South Africa & Africa Regional**: - **South Africa POPIA (Act 4 of 2013)**: Section 19 (Security measures on integrity and confidentiality), Section 23 (Access requests), Section 24 (Correction or deletion of personal information), Section 72 (Prohibition of cross-border data transfers without adequacy), Section 107 (Statutory penalties and legal defenses). - **Cybercrimes Act 19 of 2020**: Unlawful data access and preservation of electronic evidence. - **Mauritius DPA 2017 & BoM Cloud Directive**: Data minimisation, security of processing, cross-border restrictions, zero unauthorized offshore telemetry. - **Nigeria NDPA 2023**: Section 34 (Principles of processing), Section 41 (Cross-border restrictions). - **Kenya DPA 2019 & CBK Guidelines**: Section 29 (Principles), Section 48 (Transfer conditions), Central Bank of Kenya Prudential Cybersecurity Guidelines. --- ## 8. Commercial Model, Pricing, and Channel Policies Custos DSPM is distributed exclusively through a certified channel network of Systems Integrators (SIs), Value-Added Resellers (VARs), and Managed Security Service Providers (MSSPs). ### Turnkey Proof-of-Value (POV): - **Commercial POV**: $15,000 USD for a 30-day turnkey on-premises deployment across up to 5 enterprise datastores. - **Conversion Credit**: 100% of the POV fee is credited toward the annual production license upon conversion. ### Annual Enterprise Licensing (Indicative Pricing): - **Core DSPM Storage Tiers**: - 25 TB Baseline Enterprise: R 950,000 / year (~$52,500 USD) - 50 TB Enterprise: R 1,650,000 / year (~$91,000 USD) - 100 TB Large Enterprise: R 2,850,000 / year (~$157,000 USD) - 250 TB Tier-1 Banking: R 5,400,000 / year (~$298,000 USD) - **Standalone Module Licensing (Per Module / Year)**: - WireShield™ (Zero-Touch SQL Masking): R 420,000 / year - VectorGuard™ (Neural DLP & Vector DB Firewall): R 480,000 / year - AgentShield™ (Autonomous AI & Copilot Governor): R 450,000 / year - SafeHarbor™ (Cryptographic CISO Defense Engine): R 380,000 / year - SovereignFence™ (eBPF Kernel Egress Blocker): R 330,000 / year - Synth™ (Differential Privacy Data Cloner): R 520,000 / year - BlastRadius™ (Zero-Trust Identity Graph Simulator): R 460,000 / year - CleanRoom™ (M&A Due Diligence Appliance): R 620,000 / engagement or R 980,000 / year unlimited ### Partner Channel Margins: - Certified Resellers receive an upfront 32% wholesale discount off list pricing. - Guaranteed margin lock and non-circumvention with formal deal registration via https://governx.co.za/contact.html. --- ## 8. Pan-African Cyber Threat & Incident Radar Technical Grounding Canonical Hub: https://governx.co.za/africa-cyber-threat-radar.html GovernX maintains the authoritative public engineering record of African enterprise cyber incidents, detailing the architectural failures of legacy perimeter security and the mathematical mitigation provided by Custos™ air-gapped enclaves: 1. **Transnet Port Logistics & Freight Rail (July 2021)**: - Target: Transnet SOC Ltd (Navis N4 container terminal OS & rail networks across Durban, Cape Town, Port Elizabeth, Ngqura). - Attack Vector: SCADA / OT Ransomware (DeathCat strain) & Outbound C2 WAN Exfiltration. - Public Impact: 11-day Force Majeure declared across national ports; billions in economic supply chain backlog. - Root Cause: IT enterprise network lateral movement into OT port terminal controllers; unmonitored WAN beaconing. - Custos Mitigation: `PKG-INDUSTRIAL` enclaves deploy Module 06 (`SOVEREIGN_FENCE`) in-kernel eBPF packet filters terminating unverified outbound egress in 0.04ms, while Module 03 (`ACTIVE_DEFENSE`) automatically isolates files with rapid entropy jumps under strict 0600 POSIX permissions. 2. **Companies and Intellectual Property Commission / CIPC (February 2024)**: - Target: CIPC (South African statutory company registration authority). - Attack Vector: Compromised Administrative Service Credentials & Bulk Relational SQL Dump. - Public Impact: Exposure of millions of South African business enterprise records, director legal names, 13-digit National ID numbers, addresses, and corporate banking details. Active POPIA Section 89 investigation. - Root Cause: Zero query concurrency clamps, no dynamic row limitation, and cleartext database traversal. - Custos Mitigation: `PKG-PROFSERV` enclaves deploy Module 19 (`QUERY_SHIELD`) wire-speed SQL rewriting at 126µs latency, tokenizing citizen National ID numbers before transmission, paired with Module 09 (`AGENT_SHIELD`) clamping bulk table queries to 25 rows without dual-custody cryptographic MFA authorization. 3. **Department of Justice & Constitutional Development / DoJ&CD (September 2021)**: - Target: DoJ&CD IT Infrastructure (MojaPay maintenance payouts, nationwide court recording systems, Master's Office). - Attack Vector: Ransomware & Unencrypted Legacy Backup Exfiltration. - Public Impact: 1,200 courts operated manually; months of maintenance payment disruption; Information Regulator issued unprecedented R5,000,000 administrative fine under POPIA Section 109. - Root Cause: Unsegmented, unencrypted stale backup volumes left accessible across internal shares without automated ROT purges. - Custos Mitigation: `PKG-PROFSERV` enclaves deploy Module 10 (`CLEAN_ROOM`) continuous ephemeral backup audits verifying cryptographic encryption across all storage volumes, combined with Module 04 (`GOVERNANCE_PRIVACY`) automated ROT storage reclamation to permanently purge deprecated data stores. 4. **Dis-Chem Pharmacies (May 2022)**: - Target: Third-Party Scheduling & Marketing Vendor (Grapevine). - Attack Vector: Supply Chain Brute-Force Credential Spraying. - Public Impact: 3.68 million consumer records exfiltrated (names, cell numbers, emails, RSA National IDs); Information Regulator issued formal Section 109 Enforcement Notice. - Root Cause: Unmasked customer production database provided in cleartext to third-party marketing vendor without field-level redaction. - Custos Mitigation: `PKG-HEALTHCARE` enclaves enforce Module 02 (`GOVERNANCE_PRIVACY`) POPIA Section 26/32 Special Personal Information shields, while Module 07 (`SYNTH_CLONER`) emits mathematically consistent synthetic datasets for third-party vendors, guaranteeing 0 real citizen records leave enterprise custody. 5. **East African Mobile Money & Payment Switch Interception (2023–2024)**: - Target: Regional Banking Switching Infrastructure & Mobile Float Settlement Gateways (Kenya / East Africa). - Attack Vector: In-Flight Remittance Packet Tampering & Batch Clearing Divergence. - Public Impact: Multi-million dollar diversion of automated mobile float clearing; Central Bank of Kenya (CBK) operational risk directives. - Root Cause: Lack of in-line sub-millisecond cryptographic hardware inspection on automated settlement API batches. - Custos Mitigation: `PKG-FINSERV` enclaves deploy Module 17 (`WIRE_REMIT`) validating SWIFT MT103 and ISO 20022 `pacs.008` remittance payloads at 126µs, with Module 16 (`AGENT_FENCE`) enforcing SARB Directive 1/2024 and CBK dual-control threshold verification. 6. **Government Pensions Administration Agency / GPAA (February 2024)**: - Target: GPAA / GEPF (Administering R2.3 Trillion in state pensions for 1.7 million civil servants). - Attack Vector: LockBit 3.0 Ransomware Staging & Cold Archive Exfiltration. - Public Impact: GPAA offices temporarily closed; state security mobilization to protect confidential civil servant and pensioner records. - Root Cause: Lateral domain escalation into cold archive stores without active deception tripwires. - Custos Mitigation: `PKG-FINSERV` / `PKG-PROFSERV` enclaves deploy Module 03 (`ACTIVE_DEFENSE`) synthetic HoneyData canary tokens triggering sub-millisecond socket severance upon unauthorized touch, backed by Module 06 (`SOVEREIGN_FENCE`) kernel air-gap egress blocking. 7. **South African Retail Point-of-Sale Loyalty Exposure (2023)**: - Target: Distributed Retail POS & Customer Loyalty Management Edge Clusters. - Attack Vector: Cleartext POS Synchronization & Shadow AI Vector Scraping. - Public Impact: Exfiltration of consumer purchase telemetry, loyalty points ledger arbitrage, and wholesale pricing margin leakage. - Root Cause: Edge appliances syncing transaction data in unmasked JSON/SQL streams to central cloud lakes. - Custos Mitigation: `PKG-RETAIL` enclaves deploy Module 11 (`WIRE_SHIELD`) edge network proxies redacting PAN, contact details, and loyalty keys, paired with Module 12 (`VECTOR_GUARD`) neural DLP identifying proprietary price elasticity matrices. 8. **West African Commercial Bank Core Switch Batch Diversion Attempt (October 2023)**: - Target: Commercial Bank Core Interbank Settlement Switch (Nigeria / West Africa). - Attack Vector: Privileged Insider Compromise & Automated Batch Job Injection. - Public Impact: Attempted diversion of billions of Naira via scheduled weekend batch sweeps across interbank clearing corridors. - Root Cause: Batch processing executed without runtime trajectory tracking or stateful SHA-256 integrity chaining. - Custos Mitigation: `PKG-FINSERV` enclaves deploy Module 16 (`AGENT_FENCE`) jailing unauthorized processes under Linux cgroups outside validated windows, while Module 17 (`WIRE_REMIT`) requires Ed25519 multi-signature block validation in 126µs.