PDF
Product Overview -- Early AdopterEarly AccessDenseDefense | DenseAIArmour

DenseAIArmour

The AI-usage surface your last assessment never looked at. Your people are already using AI assistants, and the vendor keys they hand those assistants tend to sit in plaintext on the same machines you just had assessed. DenseAIArmour is the DenseDefense suite's answer to that surface. In active development -- this is an overview of what it is for, not an API reference.

Early Adopter -- in active developmentRead-only by design -- it changes nothing on your systemsNot assessed != passed -- the honest-reach doctrineAPI reference published at general availability

What this document is

StatusDenseAIArmour is an Early-Adopter capability, in active development. There is no shipping public REST API yet, so an API reference would be premature. This page is a product overview: what it is for and where it fits.
Scope of claimsThis overview describes purpose and intent. It does not assert current capability -- nothing here should be read as a claim that the product finds, scans, or reports on your environment today.
What comes nextFull API documentation will be published at general availability. Until then, contact us for early access to help shape the surface before it ships.

1 | What DenseAIArmour is

DenseAIArmour is the DenseDefense suite's AI-usage assessment capability. Compliance assessments were designed for a world of servers, shares, and endpoints. They were not designed for the assistants your people now type into every day -- and the credentials those assistants are handed to do their work. DenseAIArmour exists to bring that surface into the same honest, evidence-first posture the rest of the suite already holds.

It is being built as a read-only capability: its purpose is to look and report, never to change anything on the systems it looks at. That is a deliberate design choice, not a limitation to be lifted later.

This is an overview of a product in active development. It describes what DenseAIArmour is for. It is not an API reference, and nothing here is a claim that the product performs any of these functions on your environment today.

2 | What it is for

Your people are already using AI assistants, and the vendor keys they hand those assistants tend to sit in plaintext on the same machines you just had assessed. DenseAIArmour is aimed squarely at that gap: the AI-usage surface that a traditional CMMC or 800-171 assessment simply never looked at.

The surface it is being built to bring into view includes:

SurfaceWhy it matters
Local model endpointsAn AI model running on a workstation is a service on your network like any other -- and one your last assessment did not enumerate.
Agent configurationsThe assistants and agents your people wire up define what an AI can reach and act on. Their configuration is part of your real attack surface.
Credentials at restThe vendor keys handed to those assistants often live in plaintext beside the work they touch -- exactly the exposure the rest of the suite is built to surface.
The AI vendor organizationThe account and organization behind the assistant carry their own settings and posture, outside the boundary an on-host scan alone can see.
Positioning only. Each row above states an intended area of coverage for a product in active development, not a shipped feature list. Coverage, names, and behavior may change before general availability.

3 | The honest-reach doctrine

DenseAIArmour is being built to hold the same line the whole DenseDefense suite holds: a clean result you cannot trust is worse than no result at all. Where the product cannot reach a part of the surface, the design intent is to mark that part not assessed rather than quietly report it as passed.

This matters most for AI usage, because AI reachability is a vantage: what one collection point can see is not the whole picture, and a network view can call a host clean while missing what only a host-local view would show. The doctrine is to be explicit about the edge of what was reached, so an assessor is never handed a false all-clear.

"Not assessed, not passed" is the same principle that governs the rest of the suite's evidence: report what was reached, name what was not, and never let a gap in reach read as a clean bill of health.

4 | Where it fits in the suite

DenseAIArmour is one product in the DenseDefense suite, alongside the compliance engine that scans and remediates your Windows and Linux fleet against CMMC Level 2 / NIST 800-171, the offensive console that proves exposures are real, and the evidence-and-custody layer beneath them. DenseAIArmour extends that same posture to a surface the others were never built to cover: how AI is actually used across your environment.

The intent is that AI-usage findings live in the same honest, evidence-first frame as everything else the suite reports -- so a shop that has assessed its fleet can also account for the AI its people brought in, rather than leaving that surface uninventoried and unspoken-for.

DenseAIArmour reads; by design it changes nothing on your systems. It is meant to add visibility to your posture, not to act on your hosts.

5 | Status & what comes next

DenseAIArmour is an Early-Adopter capability, in active development. There is no shipping public REST API today, which is why this is an overview and not an API reference -- publishing an interface reference for a surface still being shaped would be a promise the product is not yet ready to keep.

Everything in this overview describes purpose and direction for a product in active development. Treat any capability named here as not available today for planning purposes, and confirm current status against the build you are offered.