The platform
An infrastructure-trust platform, end to end
SAUTERA™ reads the posture of every device, decides what to do about it, acts to fix it, proves what happened, and improves over time. Fourteen named engines do the work — here are the nine that tell the story.
The SAUTERA Witness sensor
One sensor. Installed or agentless.
The SAUTERA Witness sensor reads a device's vitals and immune signals and vouches for them. It runs two ways — you choose per estate.
Installed (push)
A signed binary reads vitals and immune signals locally and pushes them over a signed channel. Windows and Linux ship today.
Agentless (pull)
Remote collection over SSH, WMI/WinRM, and SNMP — for hosts and network devices where nothing gets installed.
What it observes
Patch currency, AV/EDR presence and currency, host firewall, disk encryption, exposed listening surface, known CVEs, lifecycle/EOL status, and the vitals (CPU, memory, disk, uptime). Trust is concluded from what is observed — never assumed.
The lifecycle
Detect → Decide → Act → Prove → Improve
Every device flows through the same closed loop. Improve feeds the next Detect, so the score is always current.
- 01
Detect
What's broken?
Read the vitals and the immune signals of every device — patch currency, encryption, exposed surface, known CVEs — and turn them into a trust score you can act on.
- 02
Decide
What needs me?
Surface the sickest infrastructure first and produce the trust decision — allow, degrade, restrict, or remediate — with the sign-off chain a regulated estate requires.
- 03
Act
What's being done?
Push the approved fix as a signed, reversible change — then re-collect and check our own work. Closed-loop remediation, human-gated where it must be.
- 04
Prove
Show me proof.
Write a tamper-evident record of what was found, decided, and done — audit-grade evidence a third party can trust, mapped to the framework you report against.
- 05
Improve
Are we getting better?
Trend each device's recovery over time so you can show the trajectory — not just today's snapshot — to your board, your auditor, and your customers.
Agentic AI
Two AI agents do the reasoning — not a table of static rules
Most posture tools score a device by checking its values against a fixed threshold table. SAUTERA's two agentic-AI marks reason about each device instead. TELESCOPE reads live telemetry in context to catch what changed; PARACLETE weighs the result and advocates the fix. Both ship in the platform today and are proven in the lab — the agents reason and recommend, a human approves, and SENTINEL enforces.
TELESCOPE
Step 1 · DetectThe anomaly-detection agent
Reasons about what changed on a device — not just whether a value crossed a line.
TELESCOPE reads a device's live telemetry against its own history and uses LLM reasoning to flag anomalies, version drift, configuration tampering, and breach signals. It doesn't stop at a threshold match — it weighs the change in context and emits an adjusted predictive-risk score into VIGIL, so the trust score reflects what a seasoned analyst would actually notice.
Shipped and lab-proven. Its reasoning runs on your configured LLM provider.
A TELESCOPE finding
- Device
- win-sql-03
- Signal
- Config drift + anomalous listening surface
- Reasoning
- TLS 1.0 re-enabled and RDP (3389) newly exposed to the subnet since last collection — inconsistent with this host's 90-day baseline.
- Risk signal
- Elevated — predictive risk raised, emitted to VIGIL
Illustrative output
PARACLETE
Step 5 · DecideThe remediation-advocate agent
Recommends the fix — with its reasoning and evidence — for a human to approve.
Given a device's trust state and the drift TELESCOPE surfaced, PARACLETE uses LLM reasoning to produce a structured remediation recommendation: a recommended action, an urgency, a written rationale, and the evidence behind it. It advocates to a human approver — it never enforces on its own.
Advocates; does not enforce — SENTINEL enforces the decision once a person approves. Shipped and lab-proven; reasoning runs on your configured LLM provider.
A PARACLETE recommendation
- Device
- win-sql-03
- Recommendation
- DEGRADE · urgency: high
- Rationale
- Unsupported TLS re-enabled on a database host with an exposed RDP surface; trust band dropped to Untrusted.
- Evidence
- TELESCOPE drift finding · CVE match · last-known-good config
- Approval
- advocates to a human approver · enforced by SENTINEL on approval
Illustrative output
Shipped in the platform and proven in the lab · the agents' reasoning runs on your configured LLM provider · humans approve every change
For your AI agents
Your AI agents can call SAUTERA's trust engine
SAUTERA's VIGIL infrastructure scoring and ARBITER trust decisions are exposed as Model Context Protocol (MCP) tools — so an AI agent you run can ask SAUTERA for a live infrastructure-trust verdict on a device and act on it, the same way it reaches any other tool.
Design-partner preview · authenticated and tenant-scoped per partner · exposes the trust verdict, not the mechanism behind it.
Under the hood
The Nine Marks
The narrative spine of the platform. Each mark owns one job in the loop; together they take a device from a raw signal to a proven, enforced trust decision.
VIGIL
DetectReads device posture and produces the trust score.
TELESCOPE
DetectSpots version drift, config tampering, and breach patterns.
EMCS
DetectComposes the score across lifecycle, risk, energy, availability, and modernization.
BEACON
Detect · ProveTriages the fleet worst-first and writes the permanent evidence record.
ARBITER
DecideMakes the call: allow, degrade, restrict, deny, or remediate.
PARACLETE
DecideRecommends the fix — with rationale, evidence, and urgency.
SENTINEL
DecideEnforces the access decision across network, cloud, and endpoint.
COMMAND
DecideRuns the sign-off chain so irreversible changes get a human gate.
AMEND
Act · ImproveRe-scores after the fix and closes the loop only when the device truly recovered.
Five further engines — VIE, DRIFTMATRIX, ENVOY, AEGIS, and CHANNEL — complete the closed loop: version intelligence, trend analysis, signed dispatch, ZT attestation, and the in-band conveyance layer (CHANNEL) that SAUTERA Edge is being built on. Fourteen in all, no phantom engines.
SAUTERA Edge — on the roadmap
Carry the trust verdict in-band, at the moment of access
A score only matters if it changes what happens at the moment of access. SAUTERA Edge is the in-band runtime mode of our CHANNEL conveyance — designed to carry the infrastructure-trust verdict (allow, degrade, restrict, deny) on the request itself, so a failing host is acted on as it asks for access rather than flagged in a report afterward.
Where it stands — honestly
Today, every trust verdict is already signed and attested on the evaluation response (out-of-band). Carrying that verdict in-band on the wire — and enforcing it at a network policy point — is the next step: the conveyance design is in progress.
Verdict signed + attested today · in-band enforcement on the roadmap
Prove
Compliance evidence on demand
Every finding, decision, and fix is written to a tamper-evident record and mapped to the controls you report against. When the auditor asks, you export the package — you don't run a fire drill.
- ▪SOC 2 (CC families)
- ▪NIST CSF
- ▪ISO 27001
- ▪FedRAMP-aligned
Reporting against a specific mandate? See how this works for CMMC compliance, or find the unsupported hosts in your fleet with a free EOL exposure scan.
BEACON — the triage board
BEACON surfaces your fleet worst-first, so the sickest infrastructure gets attention before it becomes an incident — and writes the permanent Trust Delta Record that the evidence package is built from.
Coverage too low to conclude? The band reads Unknown — an honest insufficient-data state, never a confident guess.
Straight talk
What ships today — and what doesn't
We sell trust, so we hold ourselves to the same standard. Here is the honest line between what runs today and what is on the roadmap.
What SAUTERA does today
- ✓Continuous collection and trust scoring on Windows and Linux — installed sensor or agentless (SSH / WMI / SNMP).
- ✓The full VOUCH loop in the lab: detect, decide, act with signed reversible remediation, prove with an audit record, and improve over time.
- ✓Compliance evidence packages mapped to SOC 2, NIST CSF, ISO 27001, and FedRAMP-aligned controls.
- ✓The Complete Trust Decision — identity trust (Zero Trust) combined with infrastructure trust (SAUTERA) at the point of access.
- ✓An automated ITA Completeness Audit — your SAUTERA deployment scored on demand against the 7 ITA v1.0 completeness criteria, with a remediation plan. It measures whether your ITA implementation is complete; it confers no credential and does not assess your Zero Trust programme.
- ✓VIGIL infrastructure scoring and ARBITER trust decisions callable by your own AI agents as Model Context Protocol (MCP) tools — in design-partner preview.
On the roadmap — and we say so
- →macOS and mobile sensors (Windows and Linux ship today).
- →Turnkey one-click integrations to third-party tools (the signed-dispatch path is live; most connectors are still maturing).
- →Automated CVE-to-patch authoring (remediation payloads are authored today, not yet auto-derived).
Put it on your fleet.
Start free on up to 10 devices, or book a walkthrough with the team.