Live audit proof

Every finding carries the configuration value that produced it.

A compliance report is only worth what an assessor can verify. TITAN AI runs all nine license tiers against the live estate, records the exact property value that triggered each finding, captures the configuration of every resource it read, and states plainly what it did not examine. The result is a document that survives cross-examination rather than one that summarizes a scan.

Nine tiers, one estate, separate results

Each license tier authorizes a different set of agents, so the same environment produces different coverage depending on what an organization has licensed. Rather than describe that difference, the report demonstrates it: every tier is executed in full and reported in its own tab, showing which agents ran, how many findings each produced, and what the narrower tiers could not see. A prospective customer can therefore judge what a tier is worth before buying it.

Observed, never assumed

A detector fires only when a live property demonstrates the condition it describes, and the report prints that property beside the finding. Nothing is inferred from a template, a previous assessment or a naming convention.

Configuration captures

The security-relevant configuration of every resource is recorded as read and sealed with a cryptographic hash, so an assessor can confirm the evidence in the report is byte-identical to what was collected.

A stated scope boundary

What was not assessed is published as prominently as what was. Areas requiring directory permissions, log history or third-party connectors are named explicitly, because absence of a finding is not evidence of compliance.

The questions an assessor actually asks

Host assessment is traditionally a screen-share: an administrator types configuration queries one at a time while an assessor watches. TITAN AI runs the same eleven questions across every server automatically and returns the verbatim console output for each, alongside a pass or fail judgement. Windows and Linux results are presented separately, because their evidence differs even where the control does not.

Answered on every host

Host identity, system clock and timezone, authorized time source, network path, remote administrative access policy, cryptographic module policy, transport protocol versions, credential caching and password ageing, anonymous and null-session access, memory protection, and the running service inventory.

Returned as evidence, not summary

Each answer shows the command that produced it and the raw text it returned. Assessors are trained to distrust a verdict without its output, so the output is what the report contains.

Connected, disconnected, or entirely offline

Regulated estates are frequently unreachable by design. TITAN AI separates collection from analysis so the assessment does not depend on connectivity. Where the platform API is available, collection is automatic. Where it is not, the estate is exported once inside the enclave and the full nine-tier analysis runs afterwards with no network access and no API calls of any kind — producing the identical report, because the analysis was never the part that needed the network.

The auditor package itself is a single self-contained file. It carries no external stylesheet, script, font or image, so it renders from removable media on an isolated workstation, and its navigation works with scripting disabled entirely — a routine condition on assessor desktops and one that silently breaks conventional dashboards.

Findings, fixes and who performs them

Every finding is published with its severity, the framework citation behind it, the observed evidence, a written recommendation, and the exact remediation command. Each is then routed by blast radius. Corrections the remediation engine can safely reverse are marked as such and still require approval before they run. Anything touching firewall rules, ports, identity, connectivity or data deletion is routed to the customer's own service-management platform with an implementation and backout plan, for a human to approve, perform and close. Findings with no safe automated path are raised for human investigation rather than quietly closed.

The report states the split as a number, so an organization can see exactly how much of its remediation burden is automated and how much remains human work.

What the package contains

For the assessor

An architecture diagram of the estate as collected, severity and coverage charts, per-tier findings with evidence, per-host question results with console output, resource configuration captures with integrity hashes, and the scope boundary.

For the record

The same content as a Word document, a machine-readable findings file, a run record describing what executed and for how long, and an integrity manifest covering every artefact in the package.