posted an update

We have architected a Full-Stack Security suite designed to provide absolute data integrity in complex environments. To ensure long-term sustainability and enterprise adoption, we are employing an Open Core business model.

  1. The Open Core Architecture (OSS vs. Enterprise) The Primitive (evk-sdk): Released under Apache-2.0. The core verify() primitive will remain free and open-source forever. We believe trust requires transparency and independent auditability. The Orchestration (evk-enterprise): A commercial offering designed for organizations that require high-throughput, compliance-grade orchestration, and SIEM/SOAR integration.
  2. Enterprise Value Proposition We do not sell "AI that detects evil." We sell deterministic proof that every artifact has been accounted for. CISOs purchase our platform for the peace of mind provided by: Multi-node Orchestration: Horizontal verification capable of handling millions of bundles per day with SLA-backed performance. Compliance Automation: Cloud-native API hooks that provide signed attestations for SOC2, S3/Datadog integration, and immutable audit logging. Non-Repudiation: Tamper-evident ledgers (backed by Postgres/Trillian) that provide auditors with absolute proof of chain-of-custody.
  3. Commercial Tiers Starter ($2K/mo): Ideal for mid-market; includes 10 nodes, REST API access, and 90-day audit retention. Pro ($10K/mo): For large enterprises; includes unlimited nodes, SAML/SCIM, Sigstore signing, and 7-year immutable ledgers. Airgap (Custom): On-premise, FIPS-compliant deployments for government and defense.
  4. The "Boring" Infrastructure Strategy Our architecture prioritizes reliability over complexity: [ S3/GCS ] -> [ evk-api ] -> [ Kafka ] -> [ evk-worker x N ] -> [ Postgres Ledger ] This modular approach ensures the OSS SDK remains pristine, while the enterprise layer provides the necessary scaling, signing, and ledgering infrastructure required for enterprise-grade compliance.
  5. 90-Day Go-To-Market Roadmap Days 1–30: Launch evk-sdk v0.1.0. Secure 5 Incident Response firms for free POCs to stress-test the engine against 1M+ real-world bundles. Days 31–60: Launch private beta of /v1/verify. Convert POC partners to commercial contracts based on drift-detection efficacy. Days 61–90: Utilize internal compliance data to achieve SOC2 Type II alignment. Target 3x enterprise contracts to validate the $100K/yr Pro tier.

Log in or sign up for Devpost to join the conversation.