Affirmation Snapshot
The environment frozen, hashed and timestamped on the day your senior official signs. Everyone else sells the score. We seal the date.
SHA-256 · RFC 8785 · Verify at scrutexity.com/verify/9f2c4a
Every year an officer at your company signs a NIST SP 800-171 affirmation under False Claims Act liability. Your assessor needs defensible evidence behind that signature. We produce it: a read-only harvest of your Microsoft and Windows configuration, sealed and dated, and a record you can replay when someone asks what was true.
Engagements start at $7,500 for a 10-day scoping sprint, credited in full toward year one. No login to your tenant is required to start.
Assessing on behalf of clients? Scrutexity for assessment organizations
Merkle root
9f2c4a71b8e05d3612ff8a94c7d0b1e63a5f8c2d94e17b60aa3f5c81d2e94b70
Illustrative sample, not customer data. Reconstructable for any date the record covers.
DFARS 252.204-7012 REQUIREMENT:
"Annual affirmation of compliance by a Senior Official of the company."
The IT Director does not sign the SPRS score.
The CISO does not sign the SPRS score.
The President, CEO, or CFO signs it under penalty of perjury and False Claims Act liability.
Scrutexity is not built for the IT Director.
It is built to protect the signature of the Senior Official.
In July 2026 the Department of Defense suspended CMMC Phase II. Requiring activities may designate self-assessment only.
DFARS 252.204-7012 did not move. Neither did the 110 controls, the SPRS posting requirement, or the annual affirmation signed by a senior official of your company.
The risk did not disappear. It relocated onto one signature, with nothing standing between it and the Department of Justice.
United States v. LOGZONE, June 2026
$507,144
Settled with the Department of Justice under the False Claims Act. The case was built on self-assessed SPRS scores.
DOJ Office of Public Affairs[ COMPARATIVE EVIDENCE WEIGHT ]
| Metric | Standard GRC Dashboard | Scrutexity Affirmation Seal |
|---|---|---|
| Format | Web UI / Screenshot | RFC 8785 Canonical JSON |
| State | Ephemeral (Updates live) | Frozen (Immutable) |
| Verification | Vendor API Claim | SHA-256 Cryptographic Hash |
| FCA Admissibility | Hearsay | Contemporaneous Record |
| Protects | IT Budget | Senior Official Signature |
The environment frozen, hashed and timestamped on the day your senior official signs. Everyone else sells the score. We seal the date.
SHA-256 · RFC 8785 · Verify at scrutexity.com/verify/9f2c4a
Every drift event, who was notified, when it was closed, sealed in order. What sinks a contractor is rarely non-compliance. It is knowing and doing nothing.
// GOOD FAITH LEDGER : APPEND ONLY : ILLUSTRATIVE SAMPLE
[2026-05-12T14:02:00Z] SEAL GENERATED. MFA: ENFORCED. FIPS: ENFORCED.
[2026-06-09T09:14:22Z] DRIFT DETECTED. Control 3.5.3 (MFA) disabled on legacy tenant.
[2026-06-09T09:14:23Z] NOTIFICATION DISPATCHED to CFO & Outside Counsel.
[2026-06-11T11:00:00Z] REMEDIATION VERIFIED. MFA re-enforced. Ledger closed.
Append only · ordered · signed
Implementation statements generated only from harvested configuration, each citing the hash it came from. A statement with nothing behind it does not get written.
Citation enforced at compile time
A signed token your prime verifies without an account and without seeing anything underneath. Alter one field and it stops verifying.
ECDSA P-256 · JWS
Configuration telemetry can prove 6 of 110 controls. The rest turn on scope, policy, process and judgement. Every one of them returns HUMAN_REVIEW_REQUIRED and deducts its full weight.
Run the engine against a flawless environment and it recovers 18 of the 313 points in play. The score lands at -185.
A vendor claiming to automate 110 controls is describing something the standard does not permit. Ask them which controls their engine refuses to score.
For five years, RPOs and C3PAOs have assessed the DIB by taking screenshots of Microsoft Entra ID and pasting them into Word documents.
A screenshot proves nothing. It has no timestamp, no chain of custody, and no cryptographic proof of origin. It is easily forged and easily dismissed.
Scrutexity replaces the screenshot with the hash. We do not capture the UI. We harvest the API, canonicalize the payload, and seal the Merkle root.
Resolved deterministically
Refused · routed to human review
One year of Affirmation Defense is roughly six percent of the LOGZONE settlement, and that settlement did not include counsel.
$7.5k
One time. Credited in full against year one.
$30k
Per year.
Twenty minutes. We will tell you which controls apply to an enclave rather than your whole company.
Contact Sales