Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
Home/Government

State, local & public sector

Deployment sovereignty is the requirement,
not the differentiator

Public sector security teams are asked to monitor continuously, respond within defined windows, and produce a record for an auditor, usually with a headcount that has not moved in five years, and often with data that cannot go to a vendor cloud.

The gap

Three constraints that rule out the obvious answer

Headcount is fixed

Agencies and municipalities cannot solve alert volume by hiring. The queue grows with every new system brought online, and the team does not.

Data cannot always leave

Criminal justice, health, benefits and utility data carry residency constraints that a managed multi-tenant cloud cannot always satisfy, regardless of the vendor's certifications.

The record is the deliverable

An auditor, an inspector general or a council committee will ask what was done about a specific event on a specific date. "The system flagged it" is not an answer that survives that conversation.

The mechanism

Run it inside your own boundary, keep every decision

The same platform runs as managed SaaS, inside your own cloud account, or entirely on-premises with open-weight models and no outbound network calls. The analysts, the pipeline and the audit trail are identical in all three; only the inference target changes.

That means a sovereignty requirement does not cost you capability, and does not put you on a stripped-down build with its own release cadence and its own bugs.

What we can put in a proposal, verbatim

  • SOC 2 Type II certified
  • Deployable on AWS GovCloud, which is FedRAMP High authorized infrastructure
  • Deployable fully on-premises with no outbound network calls
  • Row-level tenant isolation and per-tenant encrypted credentials
  • No automated response action without human approval
  • Control mapping across NIST CSF, ISO 27001, SOC 2, PCI-DSS, HIPAA and CMMC
  • Full decision replay on every verdict

Each of those is worded to survive the scrutiny it invites. We will confirm any of them in writing, and we will send an engineer rather than a sales engineer to the technical evaluation call.

Procurement

Easy to buy, easy to pilot

Intruex is the original manufacturer and developer of the Intruex SOC Platform, which means there is no reseller in the chain and no ambiguity about who owns the technology on a contract document.

We work as a subcontractor to primes, as a technology partner on teaming arrangements, and through cooperative vehicles where one applies. A pilot scoped to a single system is often the fastest path: connect one alert source, run it for a month, and read the record it produces before anyone writes a larger requirement.

Bring us an alert you already know the answer to

Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.