The tools, checklists and briefs we actually use in the field.
Everything on this page is free to open and free to cite. Score your own exposure, audit your own trust boundaries, and read how the architecture held in real deployments — before you talk to anyone here.
AI Governance Assessment
Fifteen questions across the five AI SAFE² pillars. Returns your AI Sovereignty Maturity Score on the S0–S4 scale. No call required.
Open →Engineered Certainty Assessment
The full prevention-posture review: where your architecture enforces control deterministically, and where it only hopes to.
Open →Cloud CNAPP Assessment
A cloud posture gap score across ASPM, CSPM, Kubernetes identity, and runtime workload protection.
Open →Risk Recalculator
Run your own numbers against the CVSS formula and see how conventional scoring misranks the exposure that actually breaches you.
Open →USCG Readiness Checker
Where your fleet stands against the USCG cybersecurity-plan mandate before the July 2027 deadline.
Open →MCP Trust-Boundary Audit Checklist
Every trust boundary a Model Context Protocol server exposes, and what to verify at each one before you connect an agent to it.
Open →Five Eyes Gap Controls
The ten controls missing from joint five-nation AI security guidance — the ones an adversary reaches for first.
Open →AI Agent Readiness Brief
What has to be true before an agent touches production: identity, bounded authority, reversibility, and evidence.
Open →Maritime OT Brief
Why flat vessel networks fail under conventional security tooling, and what offline-capable prevention has to do instead.
Open →Beyond Human-in-the-Loop
Human review is a scaling failure, not a control. What replaces it at machine speed — and why authority must be cryptographic.
Open →MCP Design Risk
The MCP exposure is a design decision, not a bug. What that means for anything you connect to it today.
Open →Pelorus Maritime Deployment
Prevention architecture deployed across vessel networks with intermittent connectivity, and the compliance evidence it produced.
Open →Pelorus Deployment Blueprint
The full maritime and OT implementation blueprint: sovereign, fail-closed operational assurance for vessels.
Open →MCP Server Audit
What a public MCP scan cannot see, and what a real trust-boundary audit surfaced instead.
Open →Hermes Sovereign Runtime
Four criticals and three CVEs found before production — the find, file, fix, verify process run in public.
Open →The Five Eyes AI Security Gap
A gap analysis against joint five-nation guidance, and the controls the alliance left out.
Open →CVSS Is Mathematically Obsolete
We ran the formula. The before-and-after math showing how CVSS misranks AI-era risk.
Open →About the resource library
Is everything here free?+
Yes. Every tool, checklist, brief and use case on this page is free to open and free to cite with attribution. Some downloads ask for a work email so we can send you the updated version when the underlying framework changes.
What is the difference between the Resource Library, the Research Hub, and CSI Intelligence?+
This library holds the practical instruments — things you run, fill in, or hand to your team. The Research Hub holds the analysis and the published frameworks. CSI Intelligence is the live archive of every article and brief as it publishes.
Which resource should I start with?+
If you have AI in production, start with the AI Governance Assessment — eight minutes to a scored baseline on the S0–S4 maturity scale. If you are connecting agents to tools, start with the MCP Trust-Boundary Audit Checklist. If you operate vessels, start with the USCG Readiness Checker.
Run the tools first. Book the call second.
Score your exposure with no sales conversation attached. When you want the architecture behind the score, we are here.