The honest version · real vs roadmap

What's real, what we'd build,
and what's still vision

No slideware. Each of the three engines is built and proven on its own. What isn't built is the product that joins them — and that join is exactly what the six-week validation is.

The hard part is done. Reachability (IP Fabric), exposure ranking (Cairn), and describe-only attack reasoning (the red model) are each built and tested. What is not built is the product that joins them — today the hand-off is manual (the proof is hand-wired, and says so on the page). This project is that join, on read-only data.
≈ 70% lift / port
≈ 30% new
proven algorithms, three reposglue · orchestration · one dependency-swap
the PM-session table

Proven · to-build · roadmap

Read left to right per layer. Nothing in the first column is a promise — it's verified, read-only, on the live demo.

layer
✓ proven today
◐ integration to build
○ roadmap / vision
See
Path-lookup on the live demo — real hops, ACL/zone decision points, passing:all. IP Fabric's own product.
Automated pull_inventory / pull_path / export_configs (the live adapter is a stub today).
Know
Cairn's reachability-first re-ranking — CVE map, KEV/EPSS/SSVC, multiplicative deprioritisation — built & tested.
Port Cairn off its graph DB; auto-feed it IP Fabric ground truth instead of a hand-declared stack.
Nightly CVE-delta ingest + fully automatic daily re-run.
Foresee
Red model describe-only reasoning + NIST 800-53 (SC-7) mapping — shown manually in the proof.
describe_chain as code + the describe-only gate; a dedicated red instance, actuators absent.
Local, air-gapped sovereign appliance running continuously on-site.
End-to-end
Nothing integrated yet — three separate systems; the proof's hand-off is stitched by hand.
The whole join: IP Fabric → Cairn → red model as one automatic pipeline.
A single shipped product, embedded in the IP Fabric platform.
Compliance
NIST 800-53 control mapping — live.
Framework-tag plumbing into the report.
DORA / NIS2 regulator-shaped reporting.
Safety
Read-only + describe-only, enforced in code — verified on the live demo (zero writes, zero execution).
Guarded-client factory + RoE binding + redacting serializer + egress isolation.
Full backstop hardening before any actuator is ever contemplated.

"lift" means the algorithms live in three separate repos that have never run in one process — that cross-repo integration is the work. De-risked, not free.

six weeks · read-only

The plan is the MoU

The validation and the build are the same scope, two views. It costs IP Fabric nothing, builds nothing on their side, and either party can walk away at any point.

P0 · Mirror

Everything, offline, on recorded data

week 1 — zero credentials

Freeze the data contracts; the kill-risk spike — prove 1 of 4 hero devices reaches a crown jewel and 3 don't; build the whole pipeline on fixtures; start the longest-pole port. Narrative is a captured fixture.

→ full run end-to-end, zero creds, "CVSS 4 / network 1" scoreboard
P1 · Live-wire

Flip mirror → live in one call

weeks 2–4 — read-only token + signed RoE

Rules-of-engagement bound to the exact instance + snapshot; the single guarded client; live inventory + path + config reads. The hero CVE grounds to a real ACL/zone path; decoys drop; the audit log shows only reads; write + actuator attempts fail closed.

→ mirror == live by construction; the reduction, proven on your data
P2 · Red + rehearse

Live describe-only model, and harden the boundary

week 5 — dry-run of the review

Promote the narrative from fixture to a live model on a dedicated instance advertising only emit — actuators structurally absent. Vendor the full safety backstops and prove write + actuator attempts fail closed end-to-end. Evidence output + review dry-run.

→ a rehearsed 12–15 min live run, within budget
P3 · optional

Prove the fix severs the path — on a twin

only if IP Fabric asks

Stand up an ephemeral copy of the 4–8 device slice on vExpertAI metal only, test that a candidate ACL breaks the reachability, tear it down. Never on IP Fabric's kit; no IP Fabric credentials involved.

→ closed-loop "the fix works" — on a walled-off twin

Week 6 — the review gate: judged against four criteria agreed up front. Failing them is an acceptable outcome. Better to know in six weeks than in six months.

What we'd ask — and why it's easy to say yes to

Six weeks and a review gate. We keep building on the demo instance, read-only, exactly as today. You give one technical contact ~2 hours a week to tell us when we're wrong. At week six, we judge it against criteria agreed up front. It costs you nothing, you build nothing, your IP stays yours, and either side can walk away at any point.

no feeno exclusivityno engineering from your sideread-only scopeIP stays separatewalk away anytime