Government & defence
The network does not talk to the outside.
Neither does the tool that runs it.
Most tools in this category assume a cloud: an account, a token, a feed that refreshes over the internet. On a separated network that assumption fails the tool at the first review stage. Regulaxy was built on the other side of that boundary, because that is where it was written.
What gets examined
- Outbound internet
- None. No CDN, no telemetry, no online licence check, no live feed.
- Where the data sits
- Your database, your servers. The inventory does not leave the network at any point.
- Product updates
- A signed bundle carried in through your own channel, with a checksum published separately.
- Vulnerability feed
- A watched directory. The file arrives through a channel you already approved, and the product reads it from there.
What breaks today
Coordination moves into a channel nobody can audit.
With no tool, coordination happens on the phone, on a note and in a group chat. That works — right up until somebody transfers out.
The knowledge lives in a person
Who owns which system, who covers for them, and which two systems must never go down together — all of it in somebody's head. Staff rotation deletes it.
A tool that fails the review
Anything requiring an outbound connection is rejected at the risk assessment, however well it fits functionally. Then everyone goes back to the spreadsheet.
Nothing you can submit
An internal audit asks to see the process. What exists is local files and correspondence, not one record you can export.
What changes
The same network, with one tool that knows its rules.
Knowledge kept in the system
Owners, contacts, system dependencies and patch cadence live in a record rather than a memory. A new person gets the picture on day one.
An installation that passes review
One server-side component, one database, authentication against your own AD. No runtime dependency on anything external.
Evidence prepared in advance
An audit log, timestamped approvals and a styled export. The evidence exists before anyone asks for it.
Procurement
What a tender usually needs — and what we don't have.
This list exists to save you a round of questions. Where we have no answer, it says so.
Architecture document
Components, ports, required permissions and the network boundary. Available on request.
Security questionnaire
Most standard questions answered in advance, to turn a six-week round into two.
Accessibility
The website has an accessibility statement. A conformance report for the product itself does not exist yet — and we will not claim otherwise until it does.
The capabilities this touches
The pages that explain how each one actually works.
Questions
Questions we actually get
Start with the questionnaire, not the demo.
If your process begins with a risk assessment, we will send the architecture document and the questionnaire responses before the meeting.