FREESanctions, PEP & AML/CFT screening database. Search any name.
Subject
National capability inventory, the authorization model, and sovereignty obligations
Audience
Ministers, procurement authorities, oversight bodies, national CERT directors
Issued
September 2026  ·  Autogon Inc.
Status
Open publication. Part 4 of 5.

Capability is only capability if it is lawful and it is yours.

Eighteen platforms covering every layer an adversary can touch, an authorization model that holds offensive capability accountable by construction, and six commitments a government should demand of anyone selling it national defense.

Bottom line up front
  1. The integration is the sovereign capability. The individual products exist on the open market. What is not sold to a government is one grid where an endpoint detection, a firmware measurement, a directory attack path and a red team result are the same kind of object.
  2. Offensive capability is made procurable by accountability, not by restraint. Authorization, scope limits, serialization and audit are enforced in the tooling, which is what lets an oversight body approve holding it at all.
  3. A vendor that declines the six commitments in section 4 is selling a dependency. That includes us, and the commitments are written so they can be tested rather than trusted.
1
OwnershipEvery platform is accountable to a named role in Part 3. A platform without an owner is an expense, not a capability.

The grid a nation operates

Grouped by what they do rather than by product line. Deployment is on national infrastructure, queried together, and acted on through a single authorization workflow.

Table 7  ·  Sensing and enforcement
PlatformDomainFunctionOwner
Nemesis BlueEndpointKernel grade detection and response across Windows, Linux and macOS, enforcing locally when the console is unreachableOS-06
Nemesis RelayIndustrialPassive protocol aware sensing and controller firmware attestation for equipment that will never accept an agentHW-01
Nemesis EdgePerimeterTraffic level shielding and per host posture, moving from learning through observation to enforcementNET-03
Nemesis GridSubstrateLine rate network sensing, agentless cloud posture, and the resilient core every other platform reports intoCMD-24
Nemesis ShieldApps and AILearns the legitimate behavior of services, APIs and AI agents, then refuses everything off that baselineAPP-11
Nemesis KeystoneIdentityContinuous attack path computation across the directory estate, cutting the highest value privilege edges automaticallyCLD-10
Nemesis ProvenanceSupply chainAttestation from source commit to running binary, with behavioral diffing of dependencies between releasesAPP-13
Table 8  ·  Response and investigation
PlatformDomainFunctionOwner
Nemesis SentinelAutonomous responseTriage, enrichment and containment at machine speed, with irreversible actions held behind human approvalAI-16
Nemesis ScalpelMalwareCaptured samples torn down automatically and converted into detections that reach the fleet the same dayMAL-17
Nemesis InquestForensicsAI assisted forensic investigation: fleet wide evidence acquisition, automatic timeline reconstruction, and an intrusion narrative with chain of custody intact for court and for allied disclosureINT-22
Nemesis IntelligenceThreat intelligenceFeeds and internal findings scored and pushed to sensors without a ticket in betweenINT-20
Nemesis CommandMission operationsNational watchfloor, detection foundry and incident casework, with an auditable authorization workflowCMD-23
Nemesis ForwardDeployableA self contained kit that stands up sensing on an unfamiliar network in hours, runs offline, and leaves nothing behindINT-21
Table 9  ·  Offensive, under authorization
PlatformDomainFunctionOwner
Nemesis RedAssessmentDemonstrates exploitation rather than listing possibilities, inside a cryptographically scoped engagementAPP-12
Nemesis ForgeDiscoveryAutonomous discovery of previously unreported defects in the software a nation cannot stop usingOS-08
Nemesis RemedyRepairCarries a finding to a candidate patch with evidence that the defect is closed and behavior is unchangedOS-08
Nemesis OrdnanceCapabilityAn armory rather than a toolkit: every capability serialized, scoped by signed authorization, logged in use and retired on commandMAL-19
Nemesis AssayAssuranceFires real techniques against the live estate on a schedule and reports which defenses actually triggeredAI-15
2
Design claimPolicy fails during a crisis. Controls compiled into the tooling do not.

How offensive capability is held lawfully

A national force needs offensive capability: authorized assessment of its own systems, adversary emulation against real tradecraft, vulnerability research, and operations conducted under the nation's own legal authority. What turns that from a liability into an asset is that the authorization is machine enforced rather than written in a policy nobody reads at three in the morning.

Table 10  ·  Controls enforced in the product
ControlWhat it does
Signed scope tokensEach engagement carries a cryptographically signed target scope with an expiry. Out of scope targets are refused by the tooling, not by operator discipline
Dual controlDestructive or irreversible actions require two named authorizers. One person cannot take a national system down alone, including deliberately
Immutable auditWho authorized what, against which target, at what time, with what result. Append only, and exportable for oversight that does not trust the vendor
Deconfliction registryActive authorized operations are registered so defenders are not chasing their own red team during a genuine intrusion
Kill switchOne command halts every running operation across the force, exercised on a schedule so it is known to work before it is needed
Separated staffingOffensive and defensive missions are not drawn from the same pool. Where they share people, the offensive mission quietly consumes the defensive one
3

Where the hardest buyers say the gaps are

These six capabilities are not chosen because they are convenient to build. Each answers a gap that the most demanding defense and civilian cyber organizations have stated publicly and funded, and that no vendor currently ships as a finished product.

Table 11  ·  Stated capability gaps
GapWhy it persistsAnswered by
Discovery with verified repairFinding defects at machine speed is demonstrated. Producing a patch that provably closes the defect without changing behavior is not, and nobody will apply an unattended patch to national infrastructure on faithForge, Remedy
Sensing without an agentIndustrial controllers, medical devices and building systems refuse endpoint agents, so the most consequential estate a nation owns is the least instrumented part of itRelay, Anvil
Deployable huntHunting on a partner network means arriving with a self contained kit, operating offline on undocumented infrastructure, and leaving nothing behind. Cloud dependent platforms are structurally excludedForward
Malware at sample scaleSample volume exceeds trained analyst capacity by orders of magnitude, and the path from captured sample to deployed detection is still largely manualScalpel
Forensics that survives challengeAttribution used publicly, shared with allies or taken to court has to withstand adversarial scrutiny, and timeline reconstruction is still assembled by hand under time pressureInquest
Accountable offenseThe binding constraint on offensive operations in a democracy is provable accountability rather than technical capability, and no product enforces rules of engagement cryptographicallyOrdnance, Red

Table 11. Endpoint detection, vulnerability scanning and log aggregation are deliberately absent. They are solved markets with entrenched incumbents, and a small force can only enter where the mandate is clear and the product is not.

4
Ask this of everyoneIncluding of us. Each commitment is written to be tested rather than trusted.

What a nation is entitled to verify

Sovereignty in this domain is not a slogan. It is six specific obligations, and a vendor that declines any of them is selling a dependency regardless of what the contract says.

Table 12  ·  Sovereignty commitments
CommitmentWhat it means in practice
No phone homeEvery platform runs fully offline. Telemetry leaves the jurisdiction only if the nation configures it to, and the default is that it never does
National signing keysThe nation holds its own keys for agents, rules and model bundles, so a vendor compromise cannot push code into a sovereign fleet
Offline updatesSigned bundles cross an air gap and verify on arrival, so classified environments stay current without connectivity
Source escrowSource deposited with an agreed third party, with reproducible builds so the binary can be confirmed against the source that was reviewed
Exportable auditEvery consequential action produces an immutable record the nation exports and holds independently of the platform that generated it
Right to forkDefined conditions under which the nation maintains its own build without us. This is what makes a dependency acceptable for national defense
5
RuleEvery engagement ends in a capability the nation keeps, not a document it files.

What we do for a government

Seven engagements, each scoped to produce something operational. They can be taken in sequence or on their own, though an assessment almost always comes first, because no program should be designed against an assumed threat picture.

Table 13  ·  Engagements
EngagementOutputDuration
Posture assessmentWhat an adversary can reach today, established by authorized assessment against the real estate rather than by questionnaire, with the paths that need closing ranked by evidence6 to 10 weeks
Treasury integrityGhost workers on the payroll, subsidy and benefit fraud, procurement fraud and revenue leakage, found and stopped before payout. Between three and eight percent of a national budget drains away this way each year, which is usually what makes the wider program self funding30 day pilot, then continuous
Sovereign capability buildThe grid standing on national infrastructure, the force recruited and trained, and the legal authority placed around it, sequenced so each phase delivers defense rather than preparation12 to 36 months
National exerciseAdversary emulation against ministries, operators and the defending force, using the tradecraft of actors that target the country. Every finding leaves a detection behindPer exercise
Response and surgeRetained capacity agreed and priced in peacetime, with forensic acquisition, containment sequencing and decision support at ministerial levelRetainer
Discovery programContinuous autonomous discovery against the software estate the nation depends on, including foreign vendor products, with coordinated disclosure handled on its behalfContinuous
Workforce academyThe operations tier trained on the country's own telemetry and its own incidents, because a nucleus can be recruited but a workforce has to be grownOngoing

Table 13. Treasury integrity is listed second deliberately. For most governments it is the engagement that returns more than it costs, and the one that makes the rest of the program affordable without a new budget line.

6

We are structured to leave

A foreign partner permanently embedded in a nation's cyber defense is a dependency, not a capability. The phases below are ordered so our involvement decreases as the national force takes the mission.

Phase 1

Assess

Establish real exposure and real visibility, so the program is designed against evidence rather than assumption.

Phase 2

Build

Deploy on national infrastructure, recruit and train the force, place the legal authority around it.

Phase 3

Operate

Run the mission jointly while the national force takes progressively more of it, proven by exercise rather than by report.

Phase 4

Transfer

Hand over command, keys, source and build capability. Success is the nation rebuilding the grid without us.

  • No one can guarantee a nation will not be breached. Agencies with thousands of staff are breached. Anyone promising otherwise is selling.
  • Technology does not substitute for legal authority. Without mandate, telemetry access and reporting obligations, the best platform available underdelivers.
  • Capability cannot be bought without building a workforce. Tools procured without people become an expensive audit finding.
  • We do not operate against networks a client has no authority over. Offensive capability is supplied for use under a government's own legal authority, with authorization enforced in the product itself.

Procurement should begin with evidence, not with a catalogue.

The first engagement establishes what an adversary can reach today, proven rather than assumed. Everything in this part follows that evidence, in the order the evidence dictates.

Autogon Inc.. Platforms are at differing stages of maturity and current status is disclosed in writing before any commitment. Offensive capability is supplied for use under a government's own legal authority and subject to applicable export control law.