No slideware. Each of the three engines is built and proven on its own. What isn't built is the product that joins them — and that join is exactly what the six-week validation is.
Read left to right per layer. Nothing in the first column is a promise — it's verified, read-only, on the live demo.
"lift" means the algorithms live in three separate repos that have never run in one process — that cross-repo integration is the work. De-risked, not free.
The validation and the build are the same scope, two views. It costs IP Fabric nothing, builds nothing on their side, and either party can walk away at any point.
Freeze the data contracts; the kill-risk spike — prove 1 of 4 hero devices reaches a crown jewel and 3 don't; build the whole pipeline on fixtures; start the longest-pole port. Narrative is a captured fixture.
Rules-of-engagement bound to the exact instance + snapshot; the single guarded client; live inventory + path + config reads. The hero CVE grounds to a real ACL/zone path; decoys drop; the audit log shows only reads; write + actuator attempts fail closed.
Promote the narrative from fixture to a live model on a dedicated instance advertising only emit — actuators structurally absent. Vendor the full safety backstops and prove write + actuator attempts fail closed end-to-end. Evidence output + review dry-run.
Stand up an ephemeral copy of the 4–8 device slice on vExpertAI metal only, test that a candidate ACL breaks the reachability, tear it down. Never on IP Fabric's kit; no IP Fabric credentials involved.
Week 6 — the review gate: judged against four criteria agreed up front. Failing them is an acceptable outcome. Better to know in six weeks than in six months.
Six weeks and a review gate. We keep building on the demo instance, read-only, exactly as today. You give one technical contact ~2 hours a week to tell us when we're wrong. At week six, we judge it against criteria agreed up front. It costs you nothing, you build nothing, your IP stays yours, and either side can walk away at any point.