the honest FAQ

The objections, at full strength.

Written the way the person raising them would put it, not the way that makes them easy to answer. Where the honest answer is “correct”, it says correct.

0100 about the method

“Why should I believe a policy you generated?”

“An agent is not touching our production.” — it does not. The first two weeks are read-only: configuration and flow exports, ingested in your tenant, nothing written back. Beyond that, every change is a proposal through one write path, and the sensitive ones wait for a named human. There is no mode in which the system widens policy on its own.
“Your zero-false-positive number is lab-only.” — correct. It is measured on controlled topologies and labelled as a lab figure everywhere it appears. What transfers is not the number but the protocol that produced it: your ops author the held-out set, we never see it, and the same gate that passed can be shown going red on a seeded defect. Your numbers come from your estate, in the first two read-only weeks.
“Vendors already do microsegmentation.” — they do, and most of them learn least privilege from observed traffic. That scores perfectly on the window it watched and silently blocks the failover, the nightly batch and the 3am break-glass, because those were never in the window. The difference here is not policy generation; it is that the policy is scored against traffic it never saw before it is allowed near enforcement.
“How do you not drown in telemetry?” — by not keeping the records. Flows are classified in flight at the edge and discarded; what persists is a verdict ledger that grows with the square of your role count, not with your flow count, plus a hash commitment per discarded window so the ledger is provably a summary of the stream actually seen. The long answer is on the product page.

0200 about your estate

“Our network does not look like your demo.”

“We run VMware and OpenStack, not just Kubernetes.” — half the value never touches Kubernetes. The estate map, the public-IPv4 ledger, the firewall rule report and the retire-or-keep proposals are computed from read-only config and flow exports alone. An estate with zero Kubernetes still gets the first two weeks' deliverables. Stated plainly: enforcement on hypervisor and fabric substrates is roadmap, not product, and an estate that is almost entirely non-Kubernetes with no growth platform is a genuine bad fit — we would rather say so in week zero.
“We don't run Cilium everywhere.” — Themis is a verification layer above whatever already enforces, not a replacement for it. Router and firewall configuration is read as it really is; where a cluster does enforce, policy compiles to it; where nothing does, the output is the gap list and the proposal. The engine's job is to hold enforcement against declared intent, whoever performs the enforcement.
“IPv6 will break things.” — which is why nothing in the first weeks changes an address. The audit is read-only, the plan is reversible, and the transition case is simplification rather than renumbering: a strands-nothing check is a reachability proof run before anything is written. One deployment detail we publish rather than discover in production: encapsulated mode costs 40 bytes of path MTU, and an unset ingress MTU black-holes TCP without a PMTUD rescue. It is an explicit step in the plan, not a surprise.
“What data do you actually need?” — roughly thirty minutes of exports: a manifests dump where clusters exist, a flow export, an edge firewall configuration, and the public-IP inventory. No install, no agent, no workshops. Raw flows never leave your site.

0300 about the company

“And who exactly are we depending on?”

“You are one person.” — true, and no sentence makes it false — so the offer is built to make the dependency not matter. The substrate is upstream open source that outlives any startup; the custom surface is a small, dependency-free Python codebase your security team can read in an afternoon, running under credentials you issue and revoke, with no network egress. Every artifact it produces — maps, ledgers, scorecards, evidence packs — keeps working whether or not this company does.
“Not now — attention is the scarce resource.” — which is why the entry costs about thirty minutes and no engineer-hours. Weeks one and two run entirely from exports you produce once; effort starts in week three only if the week-two numbers, computed from your own estate, justify it. The deliverable is input to the compliance work you are already doing, not a project competing with it. And if thirty minutes is too much, that is worth both of us learning in week zero rather than week four.
“What happens if we stop?” — kill criteria are published before the engagement starts and either side can invoke them. Everything produced stays with you. The audit is read-only, so there is nothing to roll back; where policy was enforced on a slice, removal is a single delete.

If a question here is missing, it is worth an email — we would rather answer it than have it decided silently.

e000 End.DT6 deliver

See it against your own kit.

30–60 minutes. Read-only. We compare your declared intent to what is actually running, and hand back the gap list.

Nothing is installed to have this conversation.

See it on your estate — read-only