Trust Codex · public demo
See the whole program before you talk to anyone.
Northwind Defense Components is a fictional aerospace parts maker with CUI drawings, a partly hardened enclave and an assessment coming. Everything below is its Trust Codex tenant, read-only, no sign-in, synthetic data run through the real code.
Every page in the demo carries a synthetic-data banner. The download is rate-limited.
Seven stops, in assessment order
01
The company and its number
Northwind Defense Components, a fictional aerospace parts maker mid-journey. Its SPRS score is computed by the real scorer from the evidence on record, not typed in.
Open the overview →02
The System Security Plan
Versioned sections with control narratives that cite evidence by hash. This is the document an assessor reads first.
Read the SSP →03
All 110 controls
Every NIST SP 800-171 requirement resolved to its assessment objectives, each MET, NOT MET or N/A with the evidence that justifies it.
Browse the controls →04
One control, end to end
Control 3.13.16 (CUI at rest) failed a monitoring run, became a POA&M, was fixed, and the regenerated evidence closed it. The whole loop is on one page.
Walk 3.13.16 →05
The POA&M
Open items with milestones, each marked eligible or not under 32 CFR 170.21, and the one that closed with dual sign-off.
Open the POA&M →06
The evidence ledger
Evidence as metadata: run id, path, SHA-256, freshness. Three items are about to expire, which is what the dashboard would nag about.
See the evidence →07
The assessor package
The ZIP a C3PAO would receive the night before: SSP, SCTM, POA&M, evidence index, asset inventory, responsibility matrix, attestations.
Download the package →
Questions people ask first
- Is any of this real?
- No. Northwind Defense Components is fictional, every person and host is invented, and the evidence is metadata with synthetic hashes. The scoring, the objective resolution, the POA&M rules and the package export are the real code paths, run on the synthetic data.
- Why can I see it without signing in?
- Because a buyer should be able to inspect the product before a sales call. The demo tenant is read-only and pinned to the fictional organization at the middleware; nothing you do there changes anything, and no real tenant is reachable from it.
- What would my version look like?
- The same screens with your controls, your evidence flowing in weekly from EnclaveWatch in your vault, and your assessor package one click away. That is the Vault + EnclaveWatch + Trust Codex tier on the market.