Skip to content
EternaEdge

Markets · Defense Industrial Base

Insider threat, foreign ownership, and cleared travel — one record, ready for review.

Cleared contractors hold the technology foreign intelligence services want, and they are approached through people, ownership structures, and suppliers — not only networks. The facility security officer (FSO) and the insider threat program senior official (ITPSO) carry the insider threat program, travel and contact reporting, and foreign ownership, control, or influence (FOCI) disclosures with a small team. EternaEdge is designed to detect targeting during reconnaissance and to keep the program record current as the work happens.

Built for the FSO · the ITPSO · counsel & compliance · program managers at primes and suppliers

Scroll
01 · Problem

Cleared industry is targeted through people, ownership, and suppliers — not only networks.

An approach arrives as a résumé, a conference contact, a web-form inquiry, an expert-outreach email, or an investment offer. Each one looks ordinary in the one system that saw it.

The FSO and the ITPSO run the insider threat program, suspicious contact and foreign travel reporting, and FOCI disclosures across a records tool, an inbox, and a spreadsheet. Evidence for the self-inspection and the Defense Counterintelligence and Security Agency (DCSA) security review under the National Industrial Security Program Operating Manual (NISPOM) is rebuilt when the review is scheduled, not kept as the work happens.

Compliance-records systems keep the record of clearances, visits, and containers. Targeting shows up somewhere else — in contacts, travel, ownership, and access. Endpoint-first monitoring watches one domain, while cleared industry is approached across several. The stack a program assembles today — one tool for travel, one for records, one for cyber feeds, and a spreadsheet for the insider threat program — leaves the pattern for the ITPSO to find by hand.

Detection built around events starts after the loss. Detection built around intent starts where the adversary does: beneath the contract, in the ownership, suppliers, and people the program depends on.

For the FSO · the ITPSO · security leadership · counsel & compliance · HR & procurement vetting

Beneath the contract

  1. 01 Prime contract

    The program, the technology it protects, and the clauses that flow down with it.

  2. 02 Your facility

    Cleared personnel, the insider threat program, and the reporting the FSO owns.

  3. 03 Subcontractor

    Flow-down obligations, shared drawings, and people your program did not hire.

  4. 04 Sub-tier supplier

    Components and access two contracts removed — seldom screened, seldom visible.

  5. 05 Beneficial owner

    The controlling interest behind the entity, where foreign ownership, control, or influence surfaces.

FOCI indicator · foreign ownership interest surfaced

Screening for any entity, at any tier: sanctions · politically exposed persons (PEP) · adverse media.

Ownership, suppliers, personnel — one picture, audit-ready.

32 CFR Part 117

NISPOM obligations, and how the platform supports them.

The NISPOM is codified at 32 CFR Part 117; the Cybersecurity Maturity Model Certification (CMMC) program is the contract's separate cyber obligation. Every obligation below stays with the contractor. The platform is designed to support the work and keep the record — nothing here assesses, approves, or files on the program's behalf.

Support comes from OBSIDIAN — Counterintelligence, FORGE — Investigations, and PATHWAY — Travel Security, standing on APEX — Platform Foundation, so a report, a travel notice, an access anomaly, and a vetting result resolve to the same person or program and are scored together.

Obligation

Insider threat program — gather, integrate, and report (32 CFR 117.7(d))

Designed to support

OBSIDIAN Guard correlates access, travel, cyber, and open-source signals against role and mission sensitivity. At threshold, a FORGE case opens with the entity timeline already assembled.

The human role

The ITPSO and the working group of security, HR, IT, and legal make every determination.

The record it leaves

Why the alert fired, who reviewed it, and what was decided — on the audit trail.

Obligation

Suspicious contact, foreign contact, and adverse information reporting

Designed to support

FORGE Intake guides the report, assigns a platform access tier, and routes it to the right queue. Intake reports are signals too: they can corroborate OBSIDIAN assessments.

The human role

The FSO decides what is reportable and remains the reporting official.

The record it leaves

Each report, its routing, and its disposition, timestamped.

Obligation

Foreign travel reporting and defensive briefings (Security Executive Agent Directive 3, SEAD 3)

Designed to support

PATHWAY Risk tiers the trip and schedules the workflow — brief, pre-brief, or pre-brief plus debrief — with live intelligence in every briefing.

The human role

Counterintelligence staff conduct the pre-briefs and debriefs; the FSO reports from the record.

The record it leaves

Notices, briefings, debriefs, and in-travel events on the traveler's record.

Obligation

FOCI awareness and disclosure (Certificate Pertaining to Foreign Interests, SF 328)

Designed to support

OBSIDIAN Check maps beneficial ownership, screens sanctions, politically exposed persons, and adverse media, and flags FOCI indicators as audit-ready reports.

The human role

Counsel and security prepare disclosures. DCSA makes FOCI determinations and prescribes mitigation.

The record it leaves

Indicator reports designed to help prepare for review.

Obligation

Self-inspection and security review evidence — NISPOM- and CMMC-aligned

Designed to support

FORGE Chain keeps program records hashed, tamper-evident, and exportable with authentication — assembled as the work happens, not at review time.

The human role

The FSO signs the self-inspection; the reviewers review. The platform supplies the record.

The record it leaves

A complete audit trail with authenticated export.

Obligation

Supplier, teaming-partner, and key-hire vetting

Designed to support

OBSIDIAN Check maps hidden ownership structures and screens sanctions, politically exposed persons, and adverse media, with counterintelligence red flags called out in an audit-ready report.

The human role

HR, procurement, and counsel make the trust decision.

The record it leaves

An audit-ready vetting report per entity.

Alignment, not assessment. EternaEdge supports NISPOM- and CMMC-aligned compliance programs; it does not assess the facility, file to any government system, or stand in for the FSO as the reporting official. Our security posture is described on the security page.

OBSIDIAN · Guard and Shield

Insider threat management for cleared defense contractors.

Designed to support the gather, integrate, and report elements of the insider threat program under 32 CFR 117.7(d), and to keep the evidence current for the self-inspection rather than reconstructing it for the review.

Every cleared contractor maintains an insider threat program under 32 CFR 117.7(d), with an ITPSO who gathers, integrates, and reports relevant information across security, HR, IT, and legal. The working-group record — what was gathered, how it was integrated, what was reported — is kept in FORGEas the work happens. Training for newly appointed program personnel follows the cognizant security agency’s designated curriculum; the platform references those training records, it does not deliver the training.

Looks inward

OBSIDIAN Guard — behavioral analytics across domains

Behavioral baselines for the cleared workforce, with anomalies correlated across access, travel, cyber, and open-source signals and weighed by role and mission sensitivity: a badge anomaly for a program manager on a sensitive effort is not the same as one in the mailroom. At threshold, a FORGE case opens with the entity timeline already assembled.

Human role

Insider threat analysts review, direct inquiries, and make every determination. Guard surfaces and organizes; people decide.

Guard is not an endpoint agent. It does not record screens or keystrokes; it correlates signals the organization already governs.

Looks outward

OBSIDIAN Shield — program protection and targeting early warning

Shield maps what you protect to who wants it: programs and technologies linked to the collection priorities of the actors that target them, with indicators watched across open sources, cyber, and travel. Supply-chain exposure and foreign dependencies surface beside the program they threaten.

Human role

Program protection leads and counterintelligence officers validate warnings and choose countermeasures.

Shield is not a supply chain illumination service or a program protection plan generator. It answers the counterintelligence question: who is targeting the chain, and through whom.

OBSIDIAN · Check

FOCI risk analysis before the review.

Vetting with beneficial-ownership depth — for hires, suppliers, teaming partners, and investors — delivered as audit-ready reports with counterintelligence red flags called out.

OBSIDIAN Check maps beneficial ownership and hidden corporate structures, screens against sanctions, politically exposed persons, and adverse media, and flags foreign ownership, control, or influence indicators. Counsel and security prepare disclosures, and prepare for the security review, with the picture already assembled instead of assembling it under a deadline.

The trust decision stays human. DCSA makes FOCI determinations and prescribes mitigation instruments; the platform does not clear FOCI, mitigate it, or file the SF 328. Indicator reports are designed to help prepare for review.

Why now: a proposed Defense Federal Acquisition Regulation Supplement (DFARS) rule would extend beneficial-ownership and FOCI disclosure to a wider set of contracts. It has not been finalized. Read the dispatch: Foreign-ownership vetting is coming to unclassified contracts.

Beneficial ownership
Hidden corporate structures mapped to the controlling interest
Sanctions · PEP · Adverse media
Screened for every entity you are about to trust
FOCI indicators
Flagged with counterintelligence red flags called out
Audit-ready report
One report per entity, prepared for disclosure and review

LUCID · Grid, Horizon, Pulse

Open-source early warning for the programs you protect.

Counterintelligence-aware open-source intelligence (OSINT), not brand monitoring: who is targeting the program, what is destabilizing the regions where cleared personnel travel, and what campaigns are forming.

LUCID — OSINT Awareness runs collection continuously across 150+ agents and 50+ languages, with no analyst tasking and no shift gaps. What reaches the security team is a product, not a feed: relevance-scored, correlated to personnel, assets, and travel through APEX, and summarized for action. Critical alerts arrive in under 30 seconds.

Targeting indicators feed OBSIDIAN Shield; live intelligence feeds every PATHWAY briefing; an event that implicates a protected program can open a FORGE case. Analysts steer collection priorities and act on alerts. Correlation and routing are automatic; judgment is not.

LUCID Grid

Autonomous collection across regions, domains, and languages, with campaign and influence-operation detection.

LUCID Horizon

Continuous country and regional risk scoring, with executive briefings generated on demand from live intelligence.

LUCID Pulse

Critical alerts relevance-scored and correlated to the personnel, programs, and travel they concern.

FORGE · Intake, CaseOps, Chain

Evidence assembled continuously, not at inspection time.

Where every report, inquiry, and case becomes an auditable record. EternaEdge supports NISPOM- and CMMC-aligned compliance programs by keeping that record current as the work happens.

FORGE — Investigations turns the reporting the program already does into the evidence a review expects: a guided front door, cases that open at threshold, and a hashed, tamper-evident chain that ends in authenticated export.

The front door

FORGE Intake

Guided reporting for foreign contacts, suspicious contacts, security incidents, and ethics matters — each report assigned a platform access tier and routed to the right queue. A low-friction path encourages reporting; reviewers receive complete, triaged reports.

Human role

The FSO decides what is reportable and remains the reporting official.

The case backbone

FORGE CaseOps

Cases open automatically at risk thresholds or from an Intake report, organized around the people, programs, and entities involved, with the full intelligence picture attached.

Human role

Investigators run the investigation; CaseOps removes the administrative drag.

The defensibility layer

FORGE Chain

SHA-256 evidence hashing, tamper detection, a complete audit trail of every access and transfer, and authenticated export for oversight, inspector general review, and legal proceedings. Complete auditability — integrity is automatic rather than procedural.

Human role

Investigators and counsel rely on the record; the platform makes it provable.

Inspection-prep tooling organizes the binder; the platform is designed to keep the evidence current all year. Classification inside FORGE means platform access-control tiers. The platform files nothing to any government system — the FSO reports from the record.

STRATUM · Watch, Vector, Signal

Cyber threat intelligence with counterintelligence context — not a SIEM replacement.

Not a security information and event management (SIEM) replacement or a vulnerability scanner. It sits above the controls you already run under DFARS 252.204-7012 and National Institute of Standards and Technology (NIST) Special Publication 800-171, and answers the question they were not built to answer: what does this digital activity mean for our programs, our people, and our contracts?

STRATUM — Cyber Threat brings counterintelligence context to the digital domain: the actors that target your programs, the exposure they can see from outside the perimeter, and the point where a cyber signal and a personnel signal describe the same risk.

STRATUM Watch

Threat actors mapped to your programs with attribution confidence, campaign correlation, adversary-forum monitoring, and early warning for reconnaissance against the facility.

STRATUM Vector

Attack surface mapping and shadow-IT discovery, with exposure prioritized by mission impact rather than raw vulnerability counts.

STRATUM Signal

The cyber-insider nexus: digital anomalies correlated with travel and access patterns, corroborating OBSIDIAN — raising or reducing confidence with every new signal.

Cyber analysts tune priorities and decide response postures; every determination about a person stays with the insider threat working group. STRATUM is not a CMMC assessment or documentation tool, and it does not host the data those controls protect. For the campaign that named the defense industrial base a priority target, read A decade inside the routers: the FSB advisory and the defense industrial base.

PATHWAY · Brief, Risk, Beacon

SEAD 3 foreign travel and foreign contact reporting, as a workflow instead of an inbox.

Foreign travel and foreign contact reporting run as a scheduled workflow with the record attached, instead of an inbox thread the FSO reconstructs at review time.

PATHWAY — Travel Security is designed to run the defensive foreign travel briefing workflow that supports Security Executive Agent Directive 3 (SEAD 3) reporting for cleared personnel: briefings generated from live intelligence, risk tiers that decide the workflow, and a record the FSO reports from.

Risk tier

The workflow it decides

Low

Briefing delivered automatically; no analyst engagement.

Security leadership tunes the thresholds.

Medium

Pre-travel briefing scheduled automatically.

Counterintelligence staff conduct the pre-brief.

High

Pre-brief and a mandatory post-travel debrief, both scheduled on the calendar.

Counterintelligence staff conduct both; the FSO reports from the record.

Every briefing carries foreign-intelligence targeting context beside the destination picture, and is designed to save 2–4 analyst-hours per traveler. Beacon reassesses risk by location while the traveler is away, and an emergency SOS opens a FORGE case on activation; the security team responds with the context already attached.

Foreign contact and suspicious contact reports go through FORGEIntake, and the record of notices, briefings, debriefs, and in-travel events stays with the traveler. The FSO remains the reporting official; the platform does not file on the FSO’s behalf. Supports ISO 31030 compliance programs.

Continuous vetting runs in the government’s own personnel-security systems; EternaEdge does not connect to or replace them. The platform is continuous-evaluation-aligned: it keeps the program’s own record of self-reports, foreign contacts, foreign travel, and inquiries current between government checks.

AI FORCE

Governed automation, with the human role stated.

In development: four assistants designed to work across every module, so a small security office can keep a program-wide record without adding staff.

AI FORCE — Autonomous Intelligence Assistants is the assistant layer. Sentinel is designed to monitor every governed source around the clock. Oracle is designed to correlate signals and deliver briefings on demand. Scribe is designed to keep case documentation current and chain-of-custody aware. Guide is designed to support compliance guidance in the flow of work. The FSO, the ITPSO, and counsel stay in command: every consequential step routes to a person for decision, and every automated action is logged.

AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.

150+
LUCID collection agents
50+
LUCID languages
<30s
LUCID critical alerts
2–4
PATHWAY analyst-hours saved per traveler
03 · Outcome

The record the review expects, kept as the work happens.

Early warning

Designed to detect targeting during the adversary's reconnaissance phase — an approach to a cleared engineer, an ownership change at a supplier, a credential exposure on a program portal — while there is still time to intervene.

Defensible action

Human-in-the-loop controls on every consequential step. The ITPSO determines, the FSO reports, counsel decides trust — and the record shows what was detected, what automation did, and who approved it.

Audit-ready record

The record the review expects, kept as the work happens: complete audit trails with authenticated export for the self-inspection, the security review, and oversight. Supports NISPOM- and CMMC-aligned compliance programs.

FAQ

Frequently asked questions.

Every determination, disclosure, and report remains the contractor's own.

What is the defense industrial base?

The defense industrial base is the worldwide industrial complex that researches, designs, produces, delivers, and maintains military weapons systems, subsystems, and components — the primes, their subcontractors, and the sub-tier suppliers beneath them. Cleared contractors within it operate under the National Industrial Security Program and 32 CFR Part 117, with the Defense Counterintelligence and Security Agency (DCSA) as the cognizant security agency for most facilities. EternaEdge serves the security offices of those contractors: the facility security officer, the insider threat program senior official, counsel, and the security team.

Does using EternaEdge satisfy NISPOM or CMMC requirements on its own?

No product does. NISPOM compliance is assessed at the cleared facility by the cognizant security agency, and CMMC assesses organizations, not software. EternaEdge supports NISPOM- and CMMC-aligned compliance programs: it is designed to support the gather, integrate, and report elements of the insider threat program in 32 CFR 117.7(d), to keep reporting and training records current, and to assemble evidence for the annual self-inspection and the security review as the work happens. The program remains yours. Policy, legal review, and every determination stay with the ITPSO, the FSO, and counsel.

Is EternaEdge CMMC compliance software?

No. EternaEdge is not a CMMC assessment, system security plan, or NIST SP 800-171 documentation tool, and it is not a hosting environment for controlled unclassified information (CUI). Safeguarding obligations under DFARS 252.204-7012 and the CMMC program's phased rollout remain the contractor's own program of record, with dates subject to rulemaking. STRATUM adds cyber threat intelligence with counterintelligence context that complements the controls you already run. It is not a SIEM replacement or a vulnerability scanner.

What does FOCI risk analysis in OBSIDIAN Check cover?

OBSIDIAN Check maps beneficial ownership and hidden corporate structures, screens against sanctions, politically exposed persons, and adverse media, and flags foreign ownership, control, or influence indicators. Results arrive as audit-ready reports with counterintelligence red flags called out, so security and counsel can prepare disclosures and the security review with the picture already assembled. DCSA makes FOCI determinations and prescribes mitigation instruments; the platform does not clear FOCI, mitigate it, or file the SF 328. A proposed DFARS rule would extend beneficial-ownership and FOCI disclosure to a wider set of contracts; it has not been finalized.

How does the platform support SEAD 3 foreign travel and foreign contact reporting?

PATHWAY generates pre-travel briefings from live intelligence, including foreign-intelligence targeting context, and applies risk tiers that decide the workflow: low, a brief; medium, a pre-brief; high, a pre-brief plus a mandatory debrief. In-travel monitoring reassesses risk by location, and an emergency SOS opens a FORGE case automatically, so the security team responds with the context already attached. FORGE Intake captures foreign contact and suspicious contact reports and routes them, and the record of notices, briefings, and debriefs stays with the case. The FSO remains the reporting official; the platform does not file on the FSO's behalf.

Is OBSIDIAN a user activity monitoring agent?

No. OBSIDIAN is not an endpoint agent and does not record screens or keystrokes. It correlates signals the organization already governs — access records, travel, cyber telemetry, and open-source information — scores them against role and mission sensitivity, and opens a case at threshold. The ITPSO and the working group of security, HR, IT, and legal make every determination, and the audit trail shows why an alert fired and who acted on it. That design supports the legal, civil-liberties, and privacy policies that 32 CFR 117.12 requires program personnel to be trained on. Policy and legal review remain with the contractor.

How does continuous vetting under Trusted Workforce 2.0 fit?

Continuous vetting runs in the government's own personnel-security systems, DISS and NBIS; EternaEdge does not connect to or replace them. The platform is continuous-evaluation-aligned: it keeps the program's own record of self-reports, foreign contacts, foreign travel, and inquiries current between government checks, so the FSO is not reconstructing a year of activity from an inbox when a reportable event, a self-inspection, or a security review arrives. Reporting decisions and eligibility determinations remain with the FSO and the government.

Where does the platform run, and what data is it designed for?

Deployment options, data residency, and authorization questions are worked through with a platform architect before any commitment is made, and our security posture is described on the security page. The platform is designed for insider threat program records, vetting workflows, travel workflows, and open-source intelligence. EternaEdge makes no accreditation or authorization claims, and it does not position the platform as a system for national-security information of any kind. Classification inside FORGE refers to platform access-control tiers, never to government classification.

Security posture 

Keep the program record current between reviews.

Tell us how your facility security program is organized — who holds the FSO and ITPSO roles, where reports land today, and which review is next. A platform architect will map the architecture — one platform foundation, five product pillars, one assistant layer — to your obligations.

 All markets