THONIS SYSTEMS · STATED LIMITS

What we do not do.

Most of this you would find out eventually — in a questionnaire, on a call, or three weeks into procurement. It is cheaper for both of us if you find it out now. Nothing below is softened, and every limit restates one published elsewhere on this site. What is left at the end is the part we do claim.

Things we will never claim.

01

We never sign, attest, or approve

A named reviewer inside your organisation holds every consequential authority: assertions, exceptions, risk acceptance, attestations, and anything sent outside. The software records who decided and what they decided it against. It does not decide.

02

No assessor, certification body, or buyer has accepted our output

Nothing produced here is certification, assessment, authorization, or endorsement. A package states that it is not approved rather than implying consent, and building a package is not delivery — nothing has been sent, received, or accepted.

03

Referencing a framework is not being certified under it

NIST SP 800-207, SP 800-218 and CISA Secure by Design inform how the products are built. They do not mean THONIS or any Dextra product is assessed, certified, compliant, authorized, or endorsed under them.

04

We hold no FedRAMP authorization, SOC 2 report, or ISO certification

If a page ever implies otherwise, that page is wrong and we want to know. THONIS Systems is a small company; the honest position is that these are not held today.

Things that are not true yet.

01

The public demonstrations run on synthetic records

Every tenant, person, buyer, question and evidence record in the published product views was created by a seeding script for that capture. No customer, engagement or production data appears in any of them.

02

Product views show mechanics, not a customer outcome

They demonstrate a complete synthetic case with human authority and the material boundaries visible. They do not demonstrate customer deployment, production identity, external-system integration, official conformance, or recipient acceptance.

03

Integrations are designed, not connected

Production integrations, customer-specific compliance, operational authorization and accepted results all require implementation and evidence in your environment. Nothing on this site should be read as an existing connector to a system you run.

04

Sentinel is a software prototype

It supports signed proposal checks, deterministic policy, attributable approval and a tamper-evident local trail. It does not prove hardware flight, airworthiness, field use, production interoperability, certification, or operational authorization. Lethal and payload-release functions are outside the product charter entirely.

Things no software should do.

01

Software cannot supply the judgement

Deciding whether an answer is adequate, whether a risk is acceptable, or whether a claim can be made to a buyer is a human act with consequences attached. The product moves the known work and stops where judgement starts — deliberately, and visibly in the interface.

02

A hash proves modification, not truth

A recomputed digest can reveal that something changed and support reconstruction. It does not prove identity, authorship, source truth, legal authority, or compliance. We use it for exactly what it establishes.

03

We will not invent coverage we cannot support

Where a corpus has not been declared, the product reports that rather than a completeness figure. Where conformance is not established, it says so on the screen. A zero that is true is worth more than a number that is not.

What is left after all of that.

Evidence is getting cheaper to produce and harder to trust. More of what reaches a reviewer was generated rather than observed, and the person who signs is still the person answerable for it. Producing evidence faster does not close that gap. It widens it.

What closes it is being able to reconstruct the decision: which named person accepted which artifact, at which version, against which requirement — and having that acceptance reopen the moment any of those change, instead of standing on a state that no longer exists. That is the product.

It does not investigate. It does not decide what matters. It does not write your answers. It keeps custody around the people who do, and it tells you when a decision has quietly gone stale.

If you want the work done for you, the sections above already say we are the wrong vendor. If you need to show later how a decision was reached and whether it still holds, that is this.

If a page on this site contradicts this one, this one is right.

Tell us which page and we will correct it. If a limit here rules us out for what you need, that is a useful answer too, and it costs you one message rather than a procurement cycle.

Ask about a limit