Engagement flow

From security claims to verifiable evidence.

ArcticScore scopes the collection with the deal team, checks stated controls against connector, scanner, and on-prem evidence, shows which claims the connected sources can and cannot verify, and delivers a signed bundle with an offline verifier.

Engagement isolation

A dedicated instance for each engagement

ArcticScore runs each engagement in a dedicated single-tenant instance with its own customer data volume. Collection mode and approved outbound services are agreed during scoping. The deployment:

  • keeps customer records separate from other engagements;
  • collects through agreed Microsoft 365 / Entra ID or Google Workspace connections, supported scanner exports, and an optional outbound-only on-prem collector for directory, virtualization, and backup evidence;
  • records the approved services used during the engagement, including RFC 3161 timestamp authorities.

Data isolation and integrity

Per-customer isolation. Each engagement uses a dedicated container instance on its own data volume. There is no multi-tenant database, no shared volume, no pooled customer data. Each assessment’s evidence lives on that instance alone.

Collection. The engagement uses agreed directory connectors, supported scanner exports, and — where in-network evidence is needed — an outbound-only collector agent that polls out over HTTPS, listens on nothing, and leaves credentials on site. A coverage map shows, claim by claim, which connected sources can verify what and what remains unchecked. The technical review package documents the approved sources, data flow, and outbound services before collection begins.

Integrity. The final evidence bundle includes a signed manifest and an external RFC 3161 timestamp. The public verification materials ship with the bundle so a recipient can check integrity offline.

Delivery. The exported bundle contains the scope, scored findings, contradiction record, supporting evidence references, integrity proofs, and any optional certification artifacts completed for the engagement.

What the target’s IT team can review

Single-tenant isolation

One firm per container, on a dedicated data volume. No cross-client storage, no shared multi-tenant database.

Localhost-only port

The application binds to 127.0.0.1 only. It is never exposed directly to the network — reachable solely through the host reverse proxy where TLS terminates.

Memory-capped

Each tenant is hard-capped so an OOM in one instance cannot take down the host. Resource isolation is by design, not by courtesy.

Verification materials ship with the record

The bundle includes the public materials needed to check its signature and timestamp without calling ArcticScore.

Integrity controls

Evidence chain and tamper detection

The evidence chain is designed so a recipient can check the delivered bundle’s integrity independently and offline, without calling ArcticScore.

Tamper-evident record

Evidence events are linked so later alteration is detectable. At export, the delivered files and the record state are committed to a signed manifest.

RFC 3161 timestamp anchoring

An external RFC 3161 authority timestamps the record state. The included token can be checked against the authority’s public certificate rather than ArcticScore’s system clock.

Digital signature

The complete bundle is digitally signed. The public verification material ships inside it, allowing the included verifier to check the signature offline.

Linked evidence history

Each recorded event commits to the prior state. The shipped verifier checks that the delivered history and signed manifest still agree, making later alteration detectable.

The standalone verifier

Every bundle ships with a readable verifier and plain-English instructions. A recipient can inspect it before running it offline. The public description stays at the buyer-relevant boundary:

  1. Declared files. The delivered contents agree with the bundle’s signed declaration.
  2. Record integrity. The linked evidence history remains internally consistent.
  3. Signature and timestamp. The included public material validates the signature and external timestamp.
  4. Optional artifacts. When certification materials were completed, the verifier checks that the declared files are present and unchanged.

The verifier reports pass, fail, or unverified and does not silently accept an incomplete record. It runs offline without connecting to ArcticScore.

Five-step engagement

What happens from scope to delivery

1

Pre-deployment review

The target’s security team reviews the single-tenant model, collection plan, approved connectors, and outbound services before the engagement begins.

2

Deployment

The target and deal team approve the collection plan. ArcticScore provisions the dedicated instance and agreed connectors, then ingests supported scanner exports. Detailed deployment settings are available for technical review.

3

Assessment run

The engagement work typically spans several days of collection and review. The instance collects evidence, cross-references stated controls against it, grades required documentation element by element against per-control rubrics, and produces findings classified by deal materiality. No human at ArcticScore touches the target’s infrastructure during the run.

4

Output review & delivery

The IT team exports the evidence bundle from the instance. They run the shipped standalone verifier to confirm integrity. They deliver the bundle to ArcticScore (at their discretion) for the scoring deliverable and report generation.

5

Post-engagement

The evidence bundle is the permanent record, re-verifiable at any time with the shipped verifier and no involvement from ArcticScore. On a post-remediation re-run, fix claims are adjudicated against fresh evidence — a repaired finding earns a machine-verified certificate, and a claim the new evidence contradicts is recorded as exactly that. The instance is torn down on the engagement schedule — no lingering access credentials are required for verification.

Risks we explicitly address

Cross-client leakage

Single-tenant container on a dedicated volume. One firm’s data per instance.

Approved data flow

Sources and outbound services are documented during technical review before collection begins.

Evidence tampering

The signed, timestamped record makes alteration detectable by the shipped verifier.

Independent checks

Public verification material ships with the bundle for offline signature and timestamp checks.

Reduced vendor dependence

The recipient can re-check bundle integrity without a continuing connection to ArcticScore.

Durable record

The timestamp token and public verification material remain with the delivered bundle.

Review our full deployment package.

The deployment package, single-tenant run model, and the verifier that ships inside every bundle are available for pre-engagement review. Contact our security team to walk through the architecture with your IT stakeholders.

Request deployment package