DESIGN PARTNER PROGRAM — SCOPED · PAID · SLOTS LIMITED

A small number of partners. A scoped pilot. Direct say in the roadmap.

We are onboarding a limited cohort of NatSec, defense, and critical-infrastructure design partners. The pilot is paid, bounded, and deployed with our engineers — and every dollar is credited toward a year-one Enterprise contract.

FIG. 1 — COMMERCIAL TERMS, STATED UP FRONT
FEE Scoped per engagement and set with you at the briefing — credited in full toward a year-one Enterprise contract
DURATION Scoped to your mission and objectives — focused and time-boxed, with success criteria agreed up front (no open-ended drift)
SCOPE One real boundary you govern — a workforce surface, an agent fleet, or a disconnected/DDIL edge node — sized by enforcement point and mission, not seats. Deployed alongside our engineers
ROADMAP Direct input — design partners set priorities for the surfaces they govern
EXIT Convert to Enterprise with the fee credited — or walk away and keep the evidence pack and policy bundle
FIG. 2 — WHO THE COHORT IS FOR
A FIT IF —
✓ You operate in NatSec, defense, critical infrastructure, or a regulated enterprise
✓ You have one real boundary to govern now — employee AI use, an agent fleet, or an edge/OT crossing
✓ A named security lead can join weekly working sessions
✓ You can bring real policies — export-control, CUI, acceptable-use — not hypotheticals
NOT A FIT IF —
✕ You need a certified, ATO'd product this quarter — our certification roadmap is underway, and we won't pretend otherwise
✕ You want a proof-of-concept without a path to production
✕ No one on your side can own the pilot — deployed-with-you only works if "you" shows up
One control plane, three moments of risk. The same deterministic discipline governs three boundaries: the human prompt (AI Chat Firewall, between an employee and the AI provider), the agent action (Agent Governance, between an agent and a tool or system), and the mission boundary (Mission Authorization Gateway, between an AI system and an edge, domain, or OT environment). All three run intercept, canonicalize, evaluate, enforce, audit.
FIG. A — ONE ENFORCEMENT LAYER, THREE MOMENTS OF RISKCONTAINMENT.AI
FIG. 3 — THE ENGAGEMENT, PHASE BY PHASE
PHASE 01 · SCOPE
Scope & policy
Boundary selected, success criteria fixed, your policies translated into versioned, testable enforcement rules.
PHASE 02 · DEPLOY
Deploy & enforce
Rollout across the governed boundary — workforce AI use, an agent fleet, or an edge/DDIL crossing — our engineers in the loop for tuning and escalations.
PHASE 03 · TUNE
Tune & measure
Policy iteration against live traffic; weekly working sessions; your shadow-AI picture takes shape in the receipts.
PHASE 04 · DECISION
Evidence & decision
Evidence pack delivered — enforcement receipts, baseline report, policy bundle — and the Enterprise decision, made on data.
THE PROGRESSION — SHADOW FIRST, THEN ENFORCE
Every pilot deploys in shadow mode first: every decision is ruled and receipted, nothing is blocked. Enforce mode is then flipped per action class — after you have seen the rulings against your live traffic and signed off. The flip is an explicit, recorded decision, not a default.
EXAMPLE SUCCESS CRITERIA, BY BOUNDARY — FIXED WITH YOU IN PHASE 01
EMPLOYEE AI USE Paste attempts that match configured export-control or CUI policy blocked at the point of use in enforce mode; a measured shadow-AI baseline your CISO signs; the policy bundle versioned for review
AGENT ACTIONS Consequential agent actions ruled on before execution; a receipt for every decision; enforce mode live on your highest-risk action class by pilot end
MISSION BOUNDARY Fail-closed behavior demonstrated under disconnect; zero unauthorized crossings while in enforce mode; the decision log exportable as accreditation evidence
FIG. 4 — WHAT YOU GET · WHAT WE ASK
YOU LEAVE WITH —
— A reviewable decision-record package from your own traffic, including rulings, policy versions, and the applicable signing / verification method
— A measured shadow-AI baseline your CISO can put in front of leadership
— A versioned policy bundle you keep, whatever you decide
— A production-shaped deployment — not a sandbox demo
WE ASK FOR —
— A named security lead and a weekly working session
— A real boundary to govern — a workforce surface, an agent fleet, or an edge node — and real policies
— Honest feedback — it sets the roadmap for the surfaces you govern
FIG. 5 — THE QUESTIONS PROCUREMENT WILL ASK
How do we contract this?
Direct commercial agreement, with the fee and scope set with you at the briefing and a time-boxed term. The fee is credited in full against a year-one Enterprise contract if you convert.
Where does our data live?
Decision receipts and policy bundles are yours. Data-handling specifics are scoped at briefing and stated in the pilot agreement — the canonical posture is on the Trust page.
Can the pilot run disconnected or air-gapped?
Connected-tier managed pilots of the AI Chat Firewall are available now. DDIL, OT, and air-gap-capable environments start with a Gateway briefing.
What happens when the pilot ends?
Two clean outcomes: convert to Enterprise with the fee credited, or stop — and keep the evidence pack, the baseline report, and the policy bundle either way.
APPLY — DESIGN-PARTNER FIT REVIEW
30 minutes against the boundary you pick. Enforcement, live — not slides.
Bring your security lead and your contracting officer's hardest question.
01We reply within one business day — a human reads everything.
0230-minute briefing against your boundary, not a slide deck.
03If it's a fit: scope document and pilot agreement within a week.
Do not submit classified information, CUI, export-controlled technical data, credentials, or other sensitive content. We will establish an approved exchange if the engagement proceeds.
NO NURTURE SEQUENCE. NO SPAM. ONE THREAD, ONE HUMAN.