Products

What your investment leaves behind.

Six customer-controlled decision assets turn one assurance engagement into priorities leadership can fund, execution teams can own, and evidence stakeholders can reuse.

One executive decision view. Six linked records.

These are not software modules, licenses, or another dashboard. They are durable records delivered through Sprint, Continuous, or Portfolio that show what the system depends on, what can change the outcome, and what leadership should do next.

The scope changes by engagement. Provenance, evidence state, decision logic, accountable ownership, and customer control remain consistent.

The business question each record answers, what evidence it contains, which decision it supports, how it is delivered, and what it does not prove.

01

Foldspan System Map

Expert-operated and delivered inside a scoped engagement.

Question answered

What does the investment actually depend on?

An inspectable whole-system view of the architecture, ownership, and dependencies capable of changing the business outcome.

What it contains

  • People, identities, agents, models, tools, data, applications, APIs, cloud services, network paths, endpoints, vendors, controls, and critical dependencies.
  • Flows, permissions, calls, trust relationships, administration paths, update paths, boundaries, scope, owners, and source evidence.

Decision supported

Decide whether the system boundary is understood well enough to proceed, which hidden dependencies need investment, and where deeper proof is warranted.

Delivery form

Customer-controlled diagrams and structured relationship data with scope and source evidence retained alongside the map.

What it does not prove

The map reflects the agreed evidence window and must not be treated as complete after unreviewed material change.

02

Foldspan Assurance Baseline

Expert-operated and delivered inside a scoped engagement.

Question answered

Where is confidence unsupported, and where should investment go?

An eight-domain assurance view that separates control capability from evidence confidence so leadership can direct time and capital by materiality.

What it contains

  • Architecture, identity, data, application, cloud and infrastructure, network and edge, AI and autonomy, and governance and operations domains.
  • Cited evidence, confidence state, freshness, coverage, risk weighting, recorded exceptions, and reviewer context.

Decision supported

Prioritize security and engineering investment, expose unsupported confidence, and determine where stronger evidence or specialist proof can change the decision.

Delivery form

A scored assessment record with cited evidence and separate capability and evidence-confidence views.

What it does not prove

It is not an externally calibrated industry benchmark, certification, regulatory approval, or substitute for the underlying evidence.

03

Foldspan Threat Ledger

Expert-operated and delivered inside a scoped engagement.

Question answered

Which scenarios can change the business outcome?

A living, prioritized record of the abuse, failure, and adversary paths that can alter launch, resilience, customer trust, or the investment case.

What it contains

  • Material scenarios, affected architecture, assumptions, evidence, controls, tests, decisions, exceptions, owners, and residual risk.
  • Threat reasoning informed by relevant abuse cases, failure modes, adversary behaviors, AI and agent patterns, and domain-specific concerns.

Decision supported

Fund mitigation, buy targeted proof, redesign, defer, or accept material risk without burying the decision in low-value findings.

Delivery form

A prioritized register connected directly to architecture elements, evidence, requirements, decisions, and outcomes.

What it does not prove

The ledger reflects the agreed system and threat window. It is not a claim that every possible scenario has been enumerated.

04

Foldspan Decision Record

Expert-operated and delivered inside a scoped engagement.

Question answered

How does the decision become funded, owned, and closed?

One accountable record from material finding through funded requirement, action, proof, approval, exception, and residual risk.

What it contains

  • Named owners, due dates, requirements, acceptance criteria, compensating controls, implementation evidence, retest results, exceptions, approvals, and residual risk.
  • Traceability back to the affected system element, threat, control, evidence, and stakeholder decision.

Decision supported

Turn priorities into sequenced execution and preserve the documented basis for closure, exception, or authorized risk acceptance.

Delivery form

A portable record in an agreed customer-controlled format with traceability from finding to outcome.

What it does not prove

Foldspan records and supports decisions. The authorized customer decision maker retains approval and risk-acceptance authority.

05

Foldspan Evidence Pack

Expert-operated and delivered inside a scoped engagement.

Question answered

What evidence can leadership and stakeholders rely on?

One cited source record rendered for leadership, engineering, customers, auditors, insurers, and other authorized decision makers without creating competing accounts.

What it contains

  • Audience-specific summaries, evidence indexes, source citations, confidence and freshness states, decisions, ownership, limitations, and exportable views.
  • A consistent underlying record even when the level of technical detail changes by audience.

Decision supported

Support launch, customer, board, audit, insurer, risk, and engineering decisions from one traceable assurance basis.

Delivery form

Customer-controlled, audience-specific views and portable evidence indexes with minimal unnecessary retention of raw sensitive data.

What it does not prove

An Evidence Pack does not create certification, regulatory approval, or independent truth beyond the evidence and validation states it cites.

06

Foldspan Cryptography Baseline

Expert-operated and delivered inside a scoped engagement.

Question answered

Which cryptographic dependencies can block launch, resilience, or future change?

An architecture-level view of the cryptographic trust, lifecycle controls, evidence, exceptions, and release gates the business outcome depends on.

What it contains

  • Protocols, certificates, keys, signing, hashing, KMS and HSM use, rotation, recovery, revocation, artifact integrity, secure updates, and time-bound exceptions.
  • Design requirements, runtime or implementation evidence, validation needs, migration dependencies, and release conditions.

Decision supported

Fund and sequence design, migration, exception, validation, and release requirements for the cryptographic trust the system depends on.

Delivery form

Architecture inventory, control review, design requirements, and validation gates connected to the broader assurance record.

What it does not prove

It is not cryptographic certification, formal protocol proof, or a claim that implementation security has been independently validated unless that testing is explicitly included.

One basis for funding, risk, and accountability.

The six records keep architecture, material exposure, funding priorities, accountable execution, and stakeholder evidence connected. Human judgment stays visible anywhere assurance, approval, exception, or risk acceptance matters.

  1. 01System

    Scope, architecture, flows, identities, dependencies, and owners.

  2. 02Evidence

    Source, provenance, confidence, freshness, coverage, and limitations.

  3. 03Threat

    Material abuse, failure, and adversary paths connected to the architecture.

  4. 04Decision

    Requirement, owner, acceptance criteria, proof, exception, and residual risk.

Evidence and provenance

Give every material conclusion a source, owner, confidence state, freshness window, and authorization context that leadership can inspect.

Architecture and dependencies

Show what the investment depends on by connecting people, identities, agents, models, data, applications, infrastructure, vendors, and controls through their real relationships.

Threats, controls, and decisions

Connect material threats to funded requirements, tests, owners, exceptions, remediation, acceptance criteria, and residual risk.

Human attestation and export

Keep human judgment visible by separating what is asserted, documented, observed, independently validated, and approved, then leave portable records with the customer.

The decision becomes a maintained capability.

The same connected records support a one-time decision, preserve its basis as conditions change, and create a comparable view across authorized systems or companies.

Sprint

Establish the decision basis

Align the system, material exposure, investment priorities, owners, acceptance criteria, and decision evidence for one consequential commitment.

Continuous

Protect the original investment

Reassess material change against the approved basis, then redirect funding, evidence, or risk authority only where the outcome may have changed.

Portfolio

Direct attention across assets

Compare exposure, dependencies, evidence confidence, integration requirements, and ownership without flattening the context of each company or system.

The records and the decision remain yours.

Collection is customer-controlled, least-privilege, and read-only by default. Conclusions retain citations, provenance, freshness, confidence, reviewer, and approval state. Human approval remains required for attestation, risk acceptance, and any action that changes a customer system.

Founder-built and third-party capabilities enter an offer only after ownership, permission, deployment boundaries, data handling, validation evidence, limitations, support, incident ownership, and commercial relationships are documented and disclosed. Assurance judgment remains independent of tool choice.

Leave with a basis you can use.

Start with the decision leadership must make. Foldspan will identify which records, evidence, and specialist proof are worth the investment before technical discovery begins.

Discuss a Solution

Please do not send sensitive system details. A protected channel will be established before technical discovery.