Secure manufacturing for defense suppliers
Designs, build files and machines, under control you can evidence.
Nexus governs who may touch a file, what may run on a machine, and what happened afterwards, so that a requirement written in a contract can be shown to have been met.
For a separate view of distributed work patterns, Monitask can provide time and activity context; it is not a certification or assessment service.
For an independent reference point, see PMI project-management resources.
The problem
The gap is between the requirement and the shop floor
A contract names a standard and a level. The standard assumes an information system with identities, logging and access control. A machine tool on the floor has a controller from an earlier decade, a shared login and a USB port.
Most of the distance between the two is not a technology problem. It is that nobody can currently say which files went where, and a requirement you cannot evidence is a requirement you have not met.
The Cybersecurity Maturity Model Certification programme and the NIST publication it draws its controls from, both published in full by the issuing bodies.
The requirement to protect controlled unclassified information and to evidence that protection is set out there rather than by this company.
The platform
Three parts, one governed environment
Alchemi Compliance Enclave (ACE)
A governed environment for controlled unclassified information, built on infrastructure that inherits a documented set of controls rather than reimplementing them.
Alchemi Execution Environment (AXE)
Control over what runs, where, and against which files, applied at the machine on the shop floor rather than at the network edge.
ShieldCRS
Detection of insider activity: who touched which file, when, and whether that pattern is consistent with the work they do.
Sectors
Where this applies
Manufacturing
Designs, build files, machine programs and process data, most of it on equipment that predates every security requirement now applied to it.
Defense
Controlled unclassified information under a contract that names a standard, a level and a date, with eligibility for future work attached to it.
Certification
What we will and will not say about timelines
Certification depends on the scope of your boundary, the state of your documentation, the availability of an assessor and the findings that come back. Any vendor quoting a fixed duration before seeing your environment is quoting a marketing figure.
The site describes requirements and operating patterns without asserting a specific authorisation or guaranteed certification timeline.
Who this is for
Suppliers with a clause and a date
A manufacturer whose contract names a standard and a level, whose covered information lives partly on equipment nobody would call an information system, and who has been told that self-attestation is no longer enough.
Typically between twenty and five hundred people, with one person carrying compliance alongside another job, and with a shop floor whose oldest machine is older than the person operating it. That combination is the ordinary case rather than the difficult one.
If your covered information never leaves a small set of managed laptops, your problem is smaller than this platform and you should be told so in the first conversation rather than the third.
What it takes
The work is producing evidence
Most suppliers already do a good deal of what the standard asks. What they cannot do is show it: no record of who authorised a transfer, no log from the machine, no document stating where the boundary runs and why.
An assessment tests what you can demonstrate rather than what you do. That distinction is the whole project, it is longer than the technical work, and it is the reason a tool that governs and records is worth more here than a tool that only prevents.
Evidence
Why this site marks its own claims
Every page here distinguishes two kinds of statement. A requirement, which comes from a published standard and carries a note naming it. And a claim about this company, which carries a note saying whether it has been confirmed.
Several claims on the previous version of this site were about certification timelines, infrastructure authorisations, patents and awards. Some of them are likely to be accurate. None of them is republished on the strength of an archived page, and where one appears here it appears marked as outstanding.
For a company selling governance of information, showing which of your own statements are evidenced is not a flourish. It is the product demonstrated on the website.
What we do not sell
Two things, stated plainly
Covert monitoring. Watching staff without telling them is unlawful in many jurisdictions, it destroys the trust an organisation runs on when it is discovered, and it is discovered. We do not supply it and we will not advise on it.
Judgement about intent. A system can establish that a file was copied at an unusual hour by an account that does not usually copy files. It cannot establish why. Anything sold as identifying malicious insiders is overstating what detection can do, and the overstatement is what produces the alert volume nobody reads.
What detection produces is a signal for a person to look at. The value is in how few of those there are and how good each one is.
Resources
Written for the people doing the work
Twenty-four entries on the requirement, the shop floor, insider risk and the assessment itself. Where the honest answer is that a control does not apply to you, or that a product does not solve the problem, the entry says so.
Honest limits
What a platform cannot do
It cannot write your system security plan, decide where your boundary runs, or make a judgement an assessor will accept. Those are decisions about your business and somebody in it has to own them.
It cannot certify you. No product can. A vendor offering certification is offering to help you prepare for an assessment conducted by somebody else.
And it cannot fix a machine whose controller cannot be changed. It can put something between that machine and everything else, which is a different and more honest claim.
The order
What to do before buying anything
Read the clause. Your contract names what applies. Suppliers routinely plan against a level their contracts do not require, in both directions, and the correction is free.
Walk the floor with a notebook. Which machines handle covered information, how a file reaches each one, and who can touch it. Almost nobody has this list and every assessment requires it.
Establish what is logged today. Not what could be: what is. The gap between those two is the size of the project.
Those three cost a week of somebody's attention and no money. A vendor who wants a purchase order before you have done them is selling to your anxiety about the date.
Start here
The first task is a scoping decision
Establish what is in the boundary, which clause applies, and what can currently be evidenced. That decision determines the systems, people, suppliers and records the programme must cover.
Independent guides
Detailed tool comparisons
Three research-based shortlists explain where compliance automation, AI governance and enterprise security platforms differ—and what to validate before buying.