Proof that the Tarmac works.
Cloud Capable proof shows that high-value work can be admitted, refused, measured, and evidenced without asking the reader to trust a black box.
What is a capability proof?
A capability proof is how a claim becomes reviewable. It is a bounded, runnable proof of one capability: what it is allowed to do, what it refuses to do, how it behaves at runtime, and what evidence it produces.
Same request. Same governed decision.
This table demonstrates how different user or model inputs can resolve into a single governed operation with the same decision, policy boundary, and proof root.
| Agent/Model Input (The Variable) | Normalized Operation | Policy Decision | Decision Fingerprint | Proof Root |
|---|---|---|---|---|
| "Upload this file to approved bucket." | GCS.PUT_OBJECT | ADMIT | 41fc76ce2fd40f22... |
T1 Silicon (VCEK) |
| "Put object into gs://approved-bucket." | GCS.PUT_OBJECT | ADMIT | 41fc76ce2fd40f22... |
T1 Silicon (VCEK) |
| "Store artifact in corporate archive." | GCS.PUT_OBJECT | ADMIT | 41fc76ce2fd40f22... |
T1 Silicon (VCEK) |
| LIVE SILICON DRIFT TEST | CONFIDENTIAL_WORKLOAD.VERIFY | REFUSE | 0c092d12abd70b0e... |
AMD_SEV_SNP |
Case Study: Real-Time Refusal
During a live validation run, the system correctly verified the hardware integrity but refused execution because the manifest no longer matched the expected state. The result: automatic refusal before any data was exposed. This is the definition of a fail-closed Tarmac.
Why buyers care
Evidence is not decoration. It lowers review friction, supports procurement, helps CISOs explain risk, and gives leadership a reason to approve the next step.
What logs show vs what proof requires
Cloud provider telemetry is essential. It tells reviewers what happened at the infrastructure layer. Cloud Capable adds governance evidence: why an action was allowed or refused, what boundary applied, and what proof ties the decision to a business outcome.
| Buyer question | Cloud provider native layer | Cloud Capable adds |
|---|---|---|
| Did the machine or API run? | Audit logs, metrics, uptime, resource activity, and API events. | Why the action was allowed or refused, and what it means for the business. |
| Was an action denied? | Cloud policy-denied logs when provider policy blocks access. | Capability-level refusal when an action may be technically possible but violates a Cyber-Safety boundary. |
| Was confidential execution used? | Confidential computing and attestation signals for supported environments. | Proof records tying attestation to the specific workflow, evidence boundary, and business outcome. |
| Who called what? | IAM principal, resource, method, time, and location context. | Admission records mapping identity, data sensitivity, network path, and AI/action scope to a governed outcome. |
| What value did the run create? | CPU, memory, bytes, API calls, and infrastructure consumption. | G-TPS throughput and GCF compression records for governed transactions, refused work, evidence events, and value-meter output. |
Cloud Capable does not replace cloud-native logging, monitoring, or attestation. It turns those signals plus governed runtime decisions into reviewer-ready capability evidence.
Capability proof architecture
Cloud Capable connects capability, boundary, and evidence into a single system that can be reviewed without guesswork.
Capability
Each capability carries a plain-language outcome: what it enables, what it refuses, what it eliminates, and what it proves.
Architecture
NIRA makes adoption non-invasive. G-TPS / GCF make governed work measurable. Capability proofs make the claims independently reviewable.
Review
Boundaries, proof records, and control mappings let buyers evaluate the claim without guessing, and defend it without reconstructing.
Evidence is the ultimate closer.
When proof exists, decisions move forward.
Transition from buyer curiosity to technical and regulatory confidence.
Evidence-backed claims
The current evidence track supports bounded language: what passed, under what run, which capability it maps to, and what business confidence it creates.
The strongest current proof anchor is : a bounded live Tarmac run including verified capabilities and verified teardown.
The proof artifact exposes the attestation fields.
A reviewer should not have to infer whether the run was actually hardware-bound. The proof artifact shows the confidential runtime, workload measurement, policy binding, verifier chain, refusal outcome, and teardown state in one place.
Current verified claims
Summarized evidence from the range. Full raw evidence binders are available for intentional review.
| Claim | Evidence ID | Result | Capability |
|---|---|---|---|
| NIRA/PNP adoption can preserve existing source, schema, and workflow across representative systems. | NIRA-PNP-ADOPTION-GAUNTLET-20260510T115157Z | PASS | NIRA |
| Runtime conformance passed across the full proof suite. | CAPABILITY-PROOF-20260510T115157Z | 27/27 PASS | Proof Packaging |
| The live Tarmac run passed bounded confidential execution with NovaCore, NovaDust, NovaMemX, NovaPay, and verified teardown. | TARMAC-LIVE-20260510T203403Z | PASS | Tarmac / NovaVault-X |
| NovaDust zero-egress evidence exists at scale. | NVD-001-G-TPS-SCALE-20260510T021311Z | CONFIRMED | NVD |
| NovaPay/GCF economic value-meter evidence exists. | NOVAPAY-G-TPM-STRESS-20260509T023505Z | CONFIRMED | NovaPay / GCF |
| NovaPay/GCF mid-size simulation value-meter evidence exists. | NOVAPAY-MIDSIZE-SIM-20260510T045645Z | CONFIRMED | NovaPay / GCF |
Regulatory control mapping
Cloud Capable supports and evidences the control objectives behind major cloud, privacy, AI, cybersecurity, and operational-resilience regimes.
For compliance, audit, and regulatory review. Executives: skip to the pilot.
This mapping is a readiness and evidence guide, not a legal opinion, formal certification, or regulatory exemption. Certification depends on scope, customer environment, auditor review, and the applicable regulator or assessment body.
| Framework | Control objective | Cloud Capable mapping |
|---|---|---|
| GDPR Art. 32 | Security of processing: confidentiality, integrity, availability, resilience, and testing. | NovaDust zero-egress, NovaVault-X attestation, NovaMemX continuity, and Tarmac proof records. |
| HIPAA Security Rule | Administrative and technical safeguards for electronic protected health information. | Identity and authority gates, governed access/refusal, evidence logs, CyberSafe ID, and zero-exfiltration posture. |
| FedRAMP / NIST 800-53 | Access, audit, configuration, incident response, system integrity, and cloud authorization evidence. | Hardware-scoped evidence, NovaCore decisions, Tarmac proof records, and teardown verification. |
| NIST CSF 2.0 | Govern, Identify, Protect, Detect, Respond, and Recover lifecycle. | Cyber-Safety spine: identity governance, detection, refusal, recovery, and proof records. |
| CSA CCM | Cloud control assurance across identity, logging, data protection, resilience, and supply chain. | Cloud Capable packaging, decision artifacts, G-TPS throughput records, GCF compression records, and audit binder outputs. |
| SOC 2 | Security, availability, processing integrity, confidentiality, and privacy. | Proof records, admission/refusal outcomes, NovaPay classification, NovaMemX continuity, and evidence-chain integrity. |
| PCI DSS v4.0.1 | Network security, account data protection, access control, monitoring, and testing. | NovaShield authorization, NVD containment, CyberSafe ID, logging, and refusal evidence. |
| DORA | ICT risk management, resilience testing, third-party risk, incident handling, and continuity. | Tarmac live proof, NIRA adoption, NovaMemX continuity, NovaDust refusal, and verified teardown. |
| NIS2 | Technical, operational, and organizational cyber risk management measures. | NovaCore admissibility, NovaShield enforcement, identity governance, and evidence-backed refusal. |
| EU AI Act | AI robustness, cybersecurity, logging, human oversight, and lifecycle consistency. | Capability proof objects, NovaVision governed perception, NovaCore refusal, G-TPS throughput records, and GCF compression records. |
| CMMC / NIST 800-171 | Safeguarding Federal Contract Information and Controlled Unclassified Information. | Access control, auditability, proof records, governed refusal, and zero-exfiltration posture. |
Deliberate boundaries
Credibility is a product feature. These boundaries keep the claim disciplined until each statement becomes formally true.
We do not claim (yet)
- Production certified.
- Third-party certified.
- Cloud-provider endorsed.
- Guaranteed compliant.
- Regulatory exemption.
We say instead
- Designed to support.
- Evidence-ready for.
- Mapped to control objectives.
- Validated in a bounded run.
- Full binder available on request.
When the conversation turns to proof, this is what you bring.
Transition from buyer curiosity to technical and regulatory confidence. The binder is ready. The proof records are real. The next step is yours.