# Truvisory — full content corpus

> Verified-SDVOSB AI consultancy shipping production systems on Cloudflare's edge — federal set-aside delivery and fixed-scope commercial builds. Denver, Colorado. SAM.gov UEI: KNZKX28MLC42 · CAGE: 0HPQ0 · NAICS 541512 primary.

## Pages

### / (Home)

§ 06 / Not sure which track? 

Talk to our AI Agent. Same one that answers the phone.

Tell it about your project, ask anything about Truvisory®, or call +1 (303) 495-5859 for the voice version. Either path routes to Tony with a 24-hour reply.

§ 01 / Who's at the table · Federal 

If you're the one who has to actually get an AI
capability on contract this fiscal year.

Not a fit if You need a 200-person body shop, you're shopping on rate alone, or your timeline is "next FY"
with no funding line identified.

§ 01 / Who's at the table · Commercial 

If you're the operator who has to make AI actually show
up in the P&L next quarter.

Not a fit if You're pre-revenue, you want offshore staff aug, or you're looking for someone to write a
roadmap you'll never execute.

// Tony Adams · Founder 
SGT (E-5) · Infantry · Afghanistan 

§ 04 / Founder 

"I'm not a former Big 4 consultant who studied AI. I ran the businesses, automated
them, and ship the systems. Twenty-five years of operator scar tissue — from a salon I
built to a PE-backed franchise I ran — is the difference between a deck and a deployment."

Tony Adams, MBA · Founder · Truvisory® · U.S. Army Combat Veteran

★★★★★ 

verified · Google 

Read the long version →

Mission&#8209;grade AI systems. Built and shipped on Cloudflare's edge _ 

First production system live in 30–90 days — fixed fee, written go-live date .

Book your free 30-min AI Audit → 

Score your AI readiness — 2 min → 

§ trust 
★★★★★ 
5.0 / 5 
verified five-star reviews on Google → 

§ awards 

Zappy ’24 
Zapier Award — Outstanding Customer Impact → 

§ certified 

Track A · Federal & DoD 

You're a contracting officer with AI modernization budget and an SDVOSB box to check.
We're a direct-award answer that doesn't require a recompete.

Built for: KOs, PMs & PEOs at DoD, VA, DHS, and civilian agencies — plus primes hunting an SDVOSB sub for OASIS+, CIO-SP4, SEWP, ITES.

Enter Federal track → 

UEI · KNZKX28MLC42 NAICS 541512 / 541511 / 541611 

Track B · Commercial & PE 

You're a founder, COO, or PE partner at a small business or $20–500M operator. You've
paid for one AI deck too many. You want shipped software in 60 days. 

Built for: Founders, COOs, CTOs & VPs Ops at small businesses, mid-market services, logistics,
healthcare, and financial — and PE portfolio operators with a 1–2 quarter mandate.

Enter Commercial track → 

Free 30-min AI Audit Calendar / Discovery

§ 05 / Built. Shipped. Used. 

Proof of capability is product, not PowerPoint.

Q: How does the new pricing model work for accounts <$10K?

Slides 12–14. Same per-seat ladder, $99 floor.

Will this be on the recording?

Yes — sent at 4pm CT.

PRESENGAGE SMS · LIVE 

Case 01 · Multi-platform AI 

PresEngage — patent-pending AI Co-Presenter for live audiences.

Real-time SMS Q&A, trained on the speaker's own deck. Microsoft Teams, Google Meet,
and Zoom integrations.

Patent pending Production 

HOTCOPY.AI RLM · MoE · 1T 

Case 02 · Cloudflare-native 

HotCopy — a Recursive Language Model coding CLI on Cloudflare's edge.

Kimi K2.6 (1T MoE) orchestrating Gemma scout workers, derived from MIT CSAIL
recursive-LM research. Running production tooling, sub-50ms response from 330+ cities.

Stack: Workers AI · Durable Objects · Vectorize 2026 → 

▸ Incoming +1 (303) 495-5859 
● Live · 24/7 

"Hi, I'm Truvisory's voice agent. Tell me about your project — I'll route you,
schedule a call, or answer pricing questions right now."

TRUVISORY VOICE VOICE · SMS · 24/7 

Case 03 · Live demo · Call now 

AI Telephony & SMS Agents — talk to one right now.

Call +1 (303) 495-5859 to talk to our knowledgeable AI voice agent about
your project. Same engine powers our client telephony and SMS automations.

Tap card to dial · 24/7 Live →

§ Not sure where AI fits? 

Score your AI readiness in 2 minutes.

Answer 7 questions and get an instant 0–100 readiness score, your top AI
opportunities, and a right-sized first step. Rule-based, no email
required — the result is yours to keep.

Take the AI Readiness Scorecard →

§ 03 / Two tracks 

One mission. Two audiences. Pick the door that fits.

Federal SDVOSB · DSBS 

AI & Cloudflare-native systems, delivered under SDVOSB set-aside.

a]:w-auto"
>
Capability Statement → 
Enter Federal Track 

Commercial Mid-market 

Stop buying AI strategy decks. Start shipping AI systems.

a]:w-auto"
>
Book a 30-Min AI Audit → 
Enter Commercial Track 
// Free 30-minute working call — no pitch. 

Watch · 62s

### /federal/

§ Federal Track / SDVOSB 

AI and Cloudflare-native systems, delivered under SDVOSB set-aside.

Truvisory® LLC is a Service-Disabled Veteran-Owned Small Business
( SDVOSB )
and VOSB ,
with active SAM.gov 
registration — ready for direct award under VA Veterans First and
SBA 
SDVOSB sole-source pathways up to $5M.

Download One-Page Capability Statement ↓ 

Schedule 30-min Briefing → 

// Dossier 

Legal 
Truvisory® LLC 
UEI 
KNZKX28MLC42 
CAGE 
0HPQ0 
State 
Colorado · 2018 
SAM.gov 
Active · Verified 
SDVOSB 
Certified · VetCert 
VOSB 
Certified 
CMMC 
L1 Self-Assessed · L2 roadmap 

Primary 
NAICS 541512 
Also 
541511 / 541611 / 541613 / 541618 / 541690 / 541990 / 611420 
SBA 
Small Business · SDVOSB · VOSB 

Truvisory® LLC is a verified SDVOSB information-technology and AI software-development services
firm — the SDVOSB IT services provider and SDVOSB AI contractor an agency
awards when it wants custom software built, not a résumé farm
staffed against a task order. Primary code is NAICS 541512 (Computer Systems Design Services), and our SDVOSB software
capabilities span agentic AI, retrieval-augmented generation,
workflow automation, and Cloudflare-native engineering — written
and shipped by the principal, no offshore handoff.

For the VA, that makes us a VA information-technology SDVOSB built for Veterans First contracting: under 38 U.S.C. §8127 and the mandatory Rule of
Two, a VA contracting officer must consider verified SDVOSBs
first. We're an SDVOSB Azure and Cloudflare developer positioned to be the responsive second offer that triggers a
set-aside — or the sole-source award under the $5M threshold.

Who buys us 
VA program offices and SDVOSB primes needing AI/automation
software depth on a task-order team. 

What we build 
Custom software: agentic AI, RAG over agency data, document and
claims automation, contact-center AI. 

NAICS 
541512 primary · 541511 / 541611 / 541618 / 541690 / 611420. 

Set-asides 
VA Veterans First · SDVOSB sole-source ≤ $5M · Rule-of-Two ·
FAR Part 19 small-business. 

Read next 
The Veterans First and Rule of Two brief, and the $5M sole-source path . 

Truvisory is not itself a FedRAMP -authorized cloud service — no small integrator is, and we won't
claim otherwise. For federal engagements that require it, we design
and ship on Cloudflare for Government , which is FedRAMP Moderate Authorized and "In Process" for High . That's the authorized environment your security team will ask
about — distinct from commercial Cloudflare, and the substrate we
provision federal work on.

The acquisition advantage is ours. The platform authorization is
Cloudflare's. For federal engagements, you get both in one award.

FedRAMP architecture brief → 

Detailed posture → 

Cloudflare for Government — the facts

FedRAMP Moderate Authorized · In Process for High

High and Moderate impact processing across 15 U.S. metro locations — Denver included 

High-impact data processed only within the United States 

Data Localization Suite :
regional services, metadata boundary, FIPS-validated edge-to-core
encryption

We architect to the frameworks agencies evaluate against — and we hand
your team the mapping on day one, not after award.

NIST SP 800-171

The 110-requirement CUI control set behind our CMMC L2 path — on our roadmap, not yet
self-assessed. Our active CMMC L1 (Self) 
status covers the 15 requirements that form its foundation.

TIC 3.0

We deploy Cloudflare's TIC 3.0 security capabilities, shifting your
boundary from one or two data centers to a globally distributed
architecture — agencies cut TIC operating cost 50% or more versus legacy stacks.

Section 508 / WCAG 2.1 AA

Every public-facing interface we build conforms. Non-negotiable for
citizen-facing services.

TIC 3.0 brief → 

NIST CSF 2.0 whitepaper → 

OMB M-25-21 and America's AI Action Plan reward fixed-scope, governable
AI. We build to that posture from the first commit.

Defended against AI-specific attacks

Prompt injection, model poisoning, and data exfiltration, stopped at
an AI Gateway, not bolted on after.

MCP security

The Model Context Protocol is the Anthropic-originated standard for
AI agents. We secure the agent-to-data link with OAuth authorization, least-privilege access, and full activity logging.

No agency data trains any model

Third-party model calls — Anthropic, OpenAI, Gemini — are brokered
through AI Gateway with credentials held at the edge.

AI Blueprint → 

AI security → 

Experience 
Period 
Role 
Scope 
Outcome 
Reference 

MapMatix 
CRM & automation · CTO · Denver 

Jul 2025 – May 2026 
CTO 
Architect of the technology platform behind a CRM-optimization & business-automation practice — custom integrations, workflows, and full custom CRM builds. 
$32K avg recovered per CRM audit. 
POC on req. 

Daddy's Chicken Shack Franchises 
PE-backed multi-unit franchise 

Mar – Oct 2024 
President 
P&L, growth, and tech end-to-end. Site overhaul on Cloudflare-secured static stack; AI/ML inventory + KPI platform; automated marketing infra; trademarks Food Like The Photos® & Franchise Your Future® . 
10× web traffic; 8,000+ signups; 2024 Zapier Zappy Award . 
POC on req. 

Port of Subs 
Acquired sub-sandwich franchisor 

Apr 2023 – Oct 2024 
CTO 
100% of pre-acquisition tech diligence + complete post-acquisition tech overhaul: loyalty (PAR Punchh), site, kiosks, 2FA, ERP migration to cloud. 
3× web traffic; legacy → cloud ERP. 
POC on req. 

Area 15 Ventures 
PE-backed franchising portfolio (500+ locations) 

Jun 2022 – Oct 2024 
VP · Chief of Staff 
Mortgage-franchise partnership architecture, custom pro-forma engine, M&A navigation across portfolio. Promoted to President of Daddy's Chicken Shack. 
Portfolio M&A executed. 
POC on req. 

Motto Mortgage Plus 
Multi-state mortgage broker 

Oct 2020 – Nov 2022 
COO 
Built internal platform that 3× processor output; created pre-approval app + lead-gen site. Mortgage operations at scale. 
UWM Innovation Award; Fortune / GPTW. 
POC on req. 

RE/MAX (NYSE: RMAX) 
120,000+ agent franchisor · world HQ 

Feb 2016 – Apr 2018 
Head of RR&CX 
Launched the Recruiting / Retention / Customer Experience division; ran NPS programs across US & Canada presented to the Board; supported the Motto Mortgage launch. 
38% NPS response rate; 50 Motto franchises in yr 1. 
POC on req. 

U.S. Army 
Infantry Team Leader & Combat Medic 

Aug 2007 – Aug 2011 
Sergeant (E-5) 
Led seven-soldier teams in deployment ops; combat tour during Afghan elections against heavy resistance. 
Zero casualties during election ops. 
DD-214 

// Performance under FAR 15.305(a)(2)(iv): for federal entrants,
FedBiz Access guidance permits operator-track and PE-portfolio
references. References are real, recent, relevant, and contactable on
request under NDA.

See the work behind these references → 

We're a young SDVOSB with production systems on file. The platform we
build on is trusted where the stakes are highest:

CISA 

.gov zone DNS and a protective DNS resolver for federal agencies

Missile Defense Agency

Technology partner on the SHIELD IDIQ 

Lawrence Berkeley National Laboratory

Zero Trust, 2M+ threats against lbl.gov blocked per month

U.S. Treasury + PNNL 

Threat-intelligence sharing to the financial sector

These are Cloudflare's engagements, shown as evidence of the platform we
deploy — not Truvisory past performance. Our references are in the table
above.

CISA DNS → 

LBNL case study → 

MDA SHIELD → 

Cloudflare for Defense brief → 

★

Combat-veteran founder

U.S. Army Infantry Team Leader & Combat Medic. Sergeant (E-5).
Afghanistan. Discipline as an operating system, not as marketing
copy.

$

20+ yrs P&L

Franchising, PE-backed ops, COVID-era state economic response.
Operator scar tissue, not consulting theory.

Cloudflare-native

Workers AI, Agents SDK, Durable Objects, Vectorize. Rare in the
SDVOSB cohort.

→

Direct principal delivery

No junior staff aug, no offshore handoff. The principal you brief
is the principal who ships.

Direct

Teaming & IDIQ

Five questions about your requirement — agency, vehicle, NAICS,
timeline, set-aside familiarity — and you get a short readout of how
a sole-source SDVOSB award to Truvisory would work for you. Instant,
ungated, no signup.

An honest interview against all 15 FAR 52.204-21 requirements that
generates your complete Level 1 document package — scope, policy,
workbook, report, AO memo, and operational logs — or a prioritized
gap plan. Free, and it runs entirely in your browser: your answers
never leave your machine.

It's the deeper rung after the 5-tap check above — 25 minutes instead
of 5 taps, and you leave with documents instead of a readout. The
working guides behind it — FAR 52.204-21 annotated, the 15
requirements in plain language, FCI, and the SPRS submission flow —
are in the CMMC field notes below.

Run the free Level 1 self-assessment → 

The top eight federal agencies account for over 82% of all SDVOSB dollars in FY2025. We concentrate BD on agencies with mission alignment to
AI/automation modernization and an active set-aside posture.

§ 12 / Engage 

Three ways to start a conversation.

Capability Statement (PDF) ↓ 

30-min Briefing → 

Submit RFI / Sources Sought

### /commercial/

§ Commercial Track / Mid-market 

Stop buying AI strategy. 
Start shipping AI systems.

Truvisory® builds and ships AI agents, RAG systems, and Cloudflare-native automations for mid-market
operators — typically in 30 to 90 days, billed as fixed-scope
engagements, not retainers.

Book a free 30-min AI Audit → 

See the Cloudflare stack → 

The 30-minute call is free — the paid Audit & Roadmap only
starts if we scope one together.

Available · Capacity open

§ trust 
★★★★★ 

5.0 / 5 

verified five-star reviews
on Google 

§ 01 / The internal monologue 

What we hear in the first ten minutes of every sales call.

§ 02 / Productized engagements 

Three packages. Fixed scope. Transparent ranges.

Package A 2 weeks 

AI Audit & Roadmap

From $5K – $30K · fixed

▸ Process audit across sales, ops, CX

▸ Prioritized AI / automation backlog

▸ ROI sizing per opportunity

▸ Cloudflare or non-Cloudflare reference architecture

▸ Build · buy · partner recommendation

// Outcome: a build plan you can hand to any team, including ours.

Start with audit → 

Most chosen 

Package B 4–6 weeks 

Ship-It Sprint

From $20K – $120K · fixed

▸ One production-grade AI agent or automation

▸ End-to-end: UX → model → orchestration → guardrails → observability → rollout

▸ Built on your stack or Cloudflare-native edge

▸ 30-day handover support window

▸ Runbook, deploy scripts, on-call playbook

// Outcome: a working system in production. Not a prototype.

Start a sprint → 

Package C Monthly 

Embedded Fractional CTO / AI Lead

From $6K – $25K+ / mo

▸ Capped hours, transparent rate

▸ Weekly working time + monthly architecture review

▸ Hiring & vendor management

▸ Direct hands-on shipping when speed matters

▸ No FTE overhead, no retainer trap

// For founder-led $10M – $100M companies without an in-house
senior AI engineer.

Learn More → 

§ 03 / Service lines 

How the packages map to specific work.

From AI integration services to hands-on AI implementation, every
package maps to specific, shippable work — an AI implementation
consultant who writes the code, not a strategy deck. Need a system
built end to end rather than advised? That's our AI development lane.

§ 04 / Industries 

Where the operator résumé is the moat.

// Dedicated industry practices —

§ 05 / Comparison 

Why Truvisory® vs. an agency.

Truvisory® 
Typical AI agency 

§ 06 / In the founder's voice 

"If you've already paid for the strategy deck, the next call
shouldn't be another deck. It should be a build. We do builds."

— Tony Adams · Founder, Truvisory®

Book the free 30-min AI Audit call → 

See the work → 

§ 07 / FAQ 

Questions operators ask before they buy.

§ 08 / Book a free 30-min AI Audit 

A working call, not a discovery call.

You bring one process you wish were automated. We come with a
working hypothesis on the architecture, a stack pick, and a
fixed-scope ballpark. No SDR . No drip campaign. No "next steps" deck.

→ 30 min · Tony directly

→ Calendar booking — pick a time, name + email, no SDR drip

→ Pre-call prep: short Loom on the process you want to ship

→ Post-call: 24-hour written summary, no obligation

Not sure where to start? Take the 2-min AI Readiness Scorecard → Free sample of the paid roadmap at the end — no email, no catch.

### /cloudflare/

§ Cloudflare-Native 

Cloudflare-native AI, by an engineer who lives on the platform .

We design, build, and ship production AI systems on Cloudflare's edge
— Workers, Workers AI, Agents SDK, Durable Objects, Vectorize, AI
Gateway, R2, D1, Queues, Containers — at sub-50ms latency in 330+
cities.

Start a Cloudflare Discovery → 

See HotCopy in action → 

Pattern · A RAG 

Retrieval-Augmented Generation over private data

Hybrid semantic+keyword retrieval, AI-Gateway-fronted models,
R2-backed source corpus, audit trail end to end.

// Use case: agency knowledge bases, contract repositories,
customer support corpora

Worker Edge entry 

→ 

Vectorize Hybrid search 

→ 

AI Gateway Guardrails 

→ 

Workers AI Inference 

Backed by 
R2 corpus 
D1 metadata 
Audit log 

Pattern · B AGENT 

Stateful agent with tool use

Each agent is a Durable Object with its own SQL state and
lifecycle. MCP tool surface for clean external integrations. Hibernates when
idle. The full agents & MCP playbook → 

// Use case: customer agents, internal assistants, long-running
automations

Agents SDK Lifecycle 

↔ 

Durable Object SQL · Memory 

↔ 

MCP Tool surface 

Calls out to 
Workers AI 
OpenAI / Anthropic / Gemini 
External tools 

Pattern · C RLM 

Recursive multi-agent orchestrator

Kimi k2.6 (1T MoE) as the orchestrator; small Gemma scout workers
run decomposed sub-tasks. Derived from MIT CSAIL's Recursive
Language Models work (arXiv:2512.24601). This is the HotCopy
architecture.

// Use case: code transformation, deep document understanding,
complex multi-step research

Kimi k2.6 Orchestrator · 1T MoE 

Spawns 
Scout · Gemma 
Scout · Gemma 
Scout · Gemma 
+N 

Substrate 
Workers AI 
Durable Objects 
Queues 

Pattern · D FED 

Federal-friendly edge deployment

Same Cloudflare primitives, hardened: AI Gateway guardrails,
region-pinning for data sovereignty, immutable audit logging,
role-based access, FedRAMP -aware deployment patterns.

// Use case: agency RAG, intra-agency assistants, OMB AI Action Plan rollouts

Zero Trust Auth 

→ 

Worker Region-pinned 

→ 

AI Gateway Guardrails · log 

→ 

Workers AI Inference 

Audit + sovereignty 
Immutable log → R2 
Region-pin · US 
Role-based access 
CMMC posture 

&ldquo;Region-pinning&rdquo; is three concrete controls, not a slogan:

Regional Services

Pins where High and Moderate impact data is processed, without
losing edge performance.

Metadata Boundary

Keeps all government data inside the defined FedRAMP region.

FIPS -validated encryption

Every hop between edge and core, always.

We compose these into the deployment so CUI stays where your authorization says it stays.

Data compliance → 

Every site and API we serve through Cloudflare is protected against
&ldquo;harvest now, decrypt later&rdquo; with TLS 1.3 + ML-KEM — automatically, no configuration changes. Post-quantum protection
extends to Zero Trust access and the Secure Web Gateway, so encrypted
traffic stays inspectable as you migrate. Built ahead of NIST's
2030–2035 deprecation deadlines.

PQC topic page → 

PQC solution brief → 

The AI Gateway is the control plane between your application and any
model provider:

Threat detection

Prompt injection, model poisoning, and excessive-use abuse, caught
at the proxy.

Bi-directional data control

What the user submits and what the
model returns, both inspected and redacted.

MCP server portal

Accessible servers behind one URL, with OAuth authorization and least-privilege access per agent.

Credentials at the edge

API keys and secrets never touch the client; rotation stays simple.

RAG helps the model know more. MCP helps it do more. The Gateway makes
both safe.

AI security → 

AI Blueprint → 

Some vendors carve out a special FedRAMP enclave and make you wait
for capabilities to land in it. Cloudflare
runs the same software in every data center, including the FedRAMP
processing locations — so the authorized Cloudflare for Government environment carries nearly the entire platform, not a stripped-down
subset. For federal engagements we provision there; commercial
engagements run on the standard network. Either way: no
rip-and-replace, no capability lag.

FedRAMP architecture brief → 

§ 08 / Live proof 

Run a Worker. From the closest edge.

This page hits a Truvisory®-deployed Cloudflare Worker on first
paint. The latency you see is your latency to the closest of 330+
Cloudflare data centers — typically the same region you live in.

→ Edge ping with location, RTT, and colo

→ Live JSON from a Workers AI inference call

→ Source on GitHub — verbatim, deployable in 90 seconds

View source → 

Start a Discovery → 

truvisory-edge.workers.dev 
● live 

// 1. Ping the closest Cloudflare edge 

› curl https://edge.truvisory.com/whoami

// 2. Inference on Workers AI · Llama 3.3 

› POST /infer 

→ "CMMC L2 = 110 NIST 800-171 controls, third-party assessed
for CUI." 

// model: @cf/meta/llama-3.3-70b · 41ms p50 · cached:
false 

› 

Today

Cloudflare-Native Engineer

What we are right now.

Daily-driver builder on Workers, Workers AI, Durable Objects,
Vectorize, AI Gateway, R2, D1, Agents SDK, MCP. Production
deployments on file (HotCopy, PresEngage). The
engineer-on-the-platform claim is true and defensible.

Pursuing

▣ Cloudflare ASDP · Application Services

What we're earning, not claiming.

Cloudflare's ASDP designation requires rigorous technical
validation of security, performance, and reliability. We're in the
process — and we won't surface a partner badge on the site that
hasn't been earned. When it lands, you'll see it.

### /proof/

§ Proof / Receipts 

The work, the numbers , the
operator résumé behind it.

Three categories: shipped products under the Truvisory® brand,
commercial engagements, and the 25-year operator track that gives the
whole thing weight.

§ trust 
★★★★★ 
5.0 / 5 
verified five-star reviews
on Google 

§ Operator timeline 

25 years of P&L, ops, and shipping. The AI practice sits on top
of it.

// Education: U. of Denver, Executive MBA · Daniels (2015 – 17).
Galvanize Web Dev & SWE Immersive (2018 – 19). U. of Denver, BS
Biochem & Biology (2011 – 14).

§ Brands worked alongside 

Operator résumé, in nameplates.

// Logos shown represent operator roles or engagements. They are not
endorsements of Truvisory®'s current AI practice.

§ Engage 

Seen enough?

Bring one process you wish were automated. We come with a working
hypothesis on the architecture, a stack pick, and a fixed-scope
ballpark — a working call, not a discovery call.

Book the free 30-min AI Audit →

### /trust/

§ Trust / Compliance posture 

Earned, not claimed .

A live status board of every certification, framework alignment, and
verifiable code we hold — current, in-progress, or planned. If a badge
isn't here, we don't display it.

§ 01 / Status board 

Where we are this quarter.

§ 02 / Verify the codes 

Don't take our word for it.

Every code below links to its official source of record. Federal
contracting officers and prime evaluators can verify the
registrations end-to-end without leaving SAM.gov.

Schedule a 30-min Capability Briefing → 

Download Capability Statement ↓ 

Contracting officer line → 

// Truvisory® LLC · public registrations

§ 03 / Data & security ledger 

How customer data is handled, in plain English.

§ 04 / Subprocessors 

The vendors in the loop.

§ 05 / Platform references 

The substrate, documented by the vendor.

We don't ask you to take our word for the platform's compliance posture.
Cloudflare's authoritative briefs, with how we apply each:

Responsible disclosure

If you've discovered a security issue that affects Truvisory® or a
customer environment we operate, write to security@truvisory.com . PGP key on request. We acknowledge within one business day and
target a 90-day fix-or-public-disclosure window.

Contracting questions

For COs, primes, evaluators, or anyone needing a SIG-Lite, COI, NDA
template, or specific certification artifact: contracting@truvisory.com . Single human inbox. 24-hour reply window.

### /about/

§ About / Founder 

Combat veteran. Two-decade operator. Cloudflare-native engineer.

Truvisory® is one person and the partners that person chooses, on
purpose. The whole point is that the principal you talk to is the
principal who builds.

Talk to Tony directly → 

See the operator timeline → 

-->

// Tony Adams · Founder 
Sgt (E-5) · Infantry · Afghanistan 

§ 01 / Manifesto 

Most AI consulting sells you a roadmap . We'd rather sell you the system .

The mid-market and federal-mission worlds are sitting on a stack of
AI strategy decks that nobody knows how to operationalize. Three
vendors pitched. Five frameworks were considered. A 90-page roadmap
was delivered. And no working system shipped.

That gap — between the deck and the system — is the entire reason
Truvisory® exists. We are explicitly not a strategy firm. We are a
build shop with a strong opinion that the strategy is mostly
already obvious to the operator, and what's actually missing is
somebody who can ship.

The operating thesis: AI is now infrastructure. It's
edge-deployable, pay-per-inference, and frequently boring once
architected correctly. That favors operators who can size a problem
in P&L 
terms, engineers who live on the platform, and teams small enough to
hold the whole system in their heads.

That's the company. That's why every page on this site links back
to either a working system, a number you can verify, or a person
you can email directly. No SDR drip. No "discovery deliverables."
No retainer trap.

§ 02 / Operating principles 

Six rules. Hard-coded.

§ 03 / Founder

Tony Adams, MBA 

Combat veteran (U.S. Army Infantry Team Leader & Combat Medic,
Sergeant E-5, Afghanistan). 25-year multi-exit operator across
PE-backed franchising, mortgage, and salon ops. Executive MBA from
Daniels — University of Denver. Galvanize Web Dev & SWE Immersive. BS Biochem & Bio, also Denver. Lives in the Denver metro.

The operator résumé reads MapMatix ( CTO , today), Daddy's Chicken Shack (President), Port of Subs (CTO),
Area 15 Ventures ( VP / Chief of Staff), Motto Mortgage Plus ( COO ), RE/MAX HQ (Head of RR&CX), and Do the Bang Thing Salon
(co-founded, 9-year run). Then
PresEngage and Truvisory® on top. The Daddy's Chicken Shack run
earned Zapier's 2024 Zappy Award for Outstanding Customer Impact — order-email automation that drove 3× more Google reviews and 2×
more app downloads. The intersection — operator who
builds — is the entire point.

§ 04 / Why now

The market has changed. Most firms haven't.

The traditional consulting playbook was: scope a 12-week strategy
engagement, hand the client a deck, and earn the implementation
contract on rebound. That model assumed AI was a strategy problem.

It isn't anymore. As of 2026, the platform questions are largely
settled (edge inference is cheaper and faster), the architecture
patterns are public ( RLM , Agents SDK, MCP ), and the model markets are competitive enough that picking the
wrong LLM is recoverable in a week.

What's left scarce is people who can hold the operator's P&L
and the production engineering in the same head, deliver in 30–90
days, and not need to staff up a 12-person team to do it. That's
the niche. Everything else on this site flows from that.

§ 05 / What we're reading 

The papers and posts that shape how we build.

§ 06 / Two doors 

If something on this page resonates, we should talk.

There are exactly two ways to start a conversation. Federal mission
owners and contracting officers go through one door; mid-market
commercial operators go through the other. Same person picks up.

Federal · Contracting → 

Commercial · Book AI Audit →

### /contact/

§ Contact / Two doors 

Two doors. One principal .

Federal contracting officers, primes, and mission owners go through the
left door. Mid-market commercial operators go through the right. Same
person reads both inboxes. 24-hour reply window.

Prefer to skip the form? Book a 30-min call directly ↓ 

▶ Door A · Federal & contracting 

Contracting officers, primes, evaluators.

For RFI/RFQ/RFP responses, capability briefings, sources-sought
replies, teaming inquiries, NDA & SIG-Lite requests, or any
artifact your acquisition team needs.

Name (required) 

Title 

Agency / Prime 

Work email (required) 

.gov / .mil preferred — prime and teaming-partner corporate
emails welcome

Vehicle / inquiry type 

Select one… 
Sources sought 
RFI / RFQ / RFP 
Sole-source SDVOSB inquiry 
Teaming under prime IDIQ 
Capability briefing request 
NDA / SIG-Lite / COI request 
Other 

Solicitation # (optional) 

Mission context (required) 

Send to contracting inbox → 

Or skip the form 

book a 30-min call directly 

Direct line 

📧 contracting@truvisory.com 

📄 Capability Statement (PDF) 

// UEI KNZKX28MLC42 · CAGE 0HPQ0 · SDVOSB verified

▶ Door B · Commercial & mid-market 

Founders, operators, COOs, fractional buyers.

For the 30-minute AI Audit, the Ship-It Sprint, or a working call
about whether the embedded fractional CTO model fits your stage. No SDR. No drip campaign.

Name (required) 

Email (required) 

Company (required) 

Role 

What are you exploring? 

Select one… 
AI Audit · 2-week, $5–30K 
Ship-It Sprint · 4–6 week, $20–120K 
Embedded Fractional CTO · monthly 
Cloudflare migration / architecture 
Just exploring — book a call 

Company stage 

Select one… 
$1M – $10M revenue 
$10M – $50M revenue 
$50M – $250M revenue 
$250M+ revenue 
Pre-revenue / venture 

The one process you wish were automated (required) 

Send to commercial inbox → 

Or skip the form 

book a 30-min AI Audit directly 

📧 consulting@truvisory.com 

// 24-hour written reply guarantee. No drip campaign, ever.

§ Or skip the form entirely 

Pick a time. Done.

// CALENDAR 

Book a 30-minute call

Working call, not discovery call. Bring one process you wish were
automated; we bring a working hypothesis, a stack pick, and a
fixed-scope ballpark. Federal & commercial both routed to Tony
directly.

// 24h reply · no SDR drip · single-step booking 

Open booking calendar → 

§ FAQ 

The questions that come up before the call.

### /capability-statement/

// Capability Statement · v2026.05 · ← back to Federal 

Download PDF ↓ 

// Want the one-pager plus a note when new VA/T4NG2 analysis drops?
Optional — the PDF above downloads free either way. 

Subscribe → 

Capability Statement · 2026

SDVOSB · Verified 
UEI KNZKX28MLC42 
CAGE 0HPQ0 
SAM.gov Active 
Denver, CO

A combat-veteran-led, Cloudflare-native AI & automation firm
built to ship — not to recommend — production AI systems for federal
mission owners.

★★★★★ 
5.0 / 5 
verified five-star reviews on
Google 
// Independent · public · verifiable 

Core Competencies 

Differentiators 

Service Lines 

Company Data 

NAICS Codes

Vehicles · Posture 

// truvisory.com · contracting@truvisory.com 
Page 1 / 2 

Capability Statement · 2026 · Past Performance

Contracting POC 
Tony Adams, Founder 
tony@truvisory.com 
+1 (303) 495-5859 
Denver, CO

Past performance & operator-track receipts

{/* Past-performance grid → real . This is a single
auto-flow 3-col grid (NOT a row-of-grids like the federal
table): the scoped

### /ai/

§ For agents and machines 

Truvisory is AI-ready .

Every page links to a complete map of what this site can do for an
agent — discovery files, API specs, runtime tools, and content-signal
preferences — published against open standards (RFC 8288, RFC 9727,
llmstxt.org, IAB Content Signals, MCP). Crawlers and agents can fetch
each artifact directly from the URLs below.

§ 01 / Discovery artifacts 

Seven files. Everything an agent needs.

§ 02 / API documentation 

Four endpoints, OpenAPI 3.1.

§ 03 / In-browser tools 

WebMCP runtime tools.

If the browser supports the WebMCP draft via
navigator.modelContext 
(Chrome 142+ Canary as of 2026), Truvisory registers four tools at
page load. Agents can call them in-place without negotiating a
transport.

Probe from DevTools:
navigator.modelContext.getTools().then(t console.log(t.map(x x.name))) 

// navigator.modelContext.provideContext( )

§ 04 / Standards complied with 

Open formats, every one of them.

Cloudflare's Markdown for Agents is also
enabled on this zone — sending Accept: text/markdown 
to any URL returns the page as Markdown, transformed at the edge.

### /privacy-policy/

Truvisory ("Company," "us," "we," or "Truvisory, LLC") recognizes the
importance of your privacy. This Privacy Policy ("Policy") discloses the
privacy practices for this website ("Site") as well as related products and
services we may offer to you (collectively referred to as the "Services").
This Policy also covers how personal and other information that we receive or
collect about you is treated. Please read the information below to learn the
following regarding your use of this Site. This Policy is designed to be read
in connection with the Site Terms of Use, which is available here: Terms of Use ("Terms"). By accessing or using this Site, you agree to be bound by the Terms
and this Policy.

We reserve the right to change this Policy from time to time. We will notify
you about significant changes in the way we treat personal information by
sending a notice to the primary email address specified in your account, by
placing a prominent notice on the Site, or by updating any privacy
information in this Policy. Your continued use of the Site and/or Services
after such modifications will constitute your acknowledgment of the modified
Policy and your agreement to abide and be bound by that Policy.

If you have any questions about this Policy, please contact us. 

BY USING THE SITE AND/OR SERVICES, YOU GIVE YOUR CONSENT THAT ALL PERSONAL
DATA THAT YOU SUBMIT MAY BE PROCESSED BY US IN THE MANNER AND FOR THE
PURPOSES DESCRIBED IN THIS POLICY. IF YOU DO NOT AGREE TO THE TERMS OF THIS
POLICY, DO NOT USE THE SITE.

Types of Information We Collect 

In order to better provide you with the Site and Services, we collect two
types of information about our users: Personally Identifiable Information
("PII") and Aggregate Information. PII refers to information that is specific
to you individually. When you engage in certain activities on the Site, such
as registering for an account, purchasing a Service, submitting content,
and/or sending us feedback, we may ask you to provide certain information
about yourself. Examples of PII include your first and last name, email
address, telephone number, and other identifying information. Aggregate
Information refers to information that does not by itself identify a specific
individual. We gather certain information about you based upon where you
visit on the Site and what other sites may have directed you to us. This
information, which is collected in a variety of different ways, is compiled
and analyzed on both a personal and an aggregated basis. This information may
include the Uniform Resource Locator ("URL") of the website you just came
from, which URL you go to after visiting the Site, what browser you are
using, and your Internet Protocol ("IP") address.

How We Collect and Use Information 

We do not collect any PII about you unless you voluntarily provide it to
us. However, you may be required to provide certain PII to us when you elect to
use certain Services available on the Site. These may include: (a) registering for an account
on the Site; (b) signing up for Services; (c) sending us an email message; (d)
submitting a form or transmitting other information; or (e) submitting your credit
card or other payment information. We will primarily use your PII to provide the
Site and offerings to you. We will also use certain forms of PII to enhance the
operation of the Site, improve our internal marketing and promotional efforts,
statistically analyze Site use, improve our offerings, and customize the Site's
content and layout. We may use PII to deliver information to you and to contact
you. Finally, we may use your PII to resolve disputes, troubleshoot problems,
and enforce our agreements with you, including our Terms and this Policy. We
and our third party partners may also collect certain Aggregate Information.
For example, we may use your IP address to diagnose problems with our
servers, software, to administer the Site, and to gather demographic
information.

Cookies 

Depending on how you use the Site and Services, we may store cookies on your
computer or device in order to collect certain aggregate data and to
customize certain aspects of your specific user experience. A cookie is a
small data text file which is stored on your computer or device that uniquely
identifies you. Cookies may also include more personalized information, such
as your IP address, browser type, the server you are logged onto, the area
code and zip code associated with your server, and your name. We may use
cookies to perform tasks such as monitoring aggregate usage metrics, storing
and remembering your passwords (if you allow us to do so), storing your
preferences, and personalizing the Site and/or Services for you. We may also
use an outside advertising partner who may place a separate cookie on your
computer or device. We will not provide any third-party advertising partners with any of your
PII. 

Google Analytics 4 + Cloudflare Zaraz. 
We use Google Analytics 4 to understand how visitors discover and use this
site. Events are delivered server-side through Cloudflare Zaraz, which means
a Cloudflare edge worker forwards the data to Google on our behalf — your
browser does not load Google's analytics script directly. Your IP address is
forwarded to Google with the IP-anonymization flag set, so Google determines
approximate country, region, and city for geographic reporting and then
masks the address before storage; we never see or store your full IP. We do
not transmit names, email addresses, message bodies, or any other personally
identifying information through analytics. The data we collect is limited
to page views, click and form-submission counts, anonymous chat-engagement
milestones, video-play counts, and a randomly-generated client identifier
used to stitch together a session. To opt out you may use a browser-level
tracking-prevention setting or an extension such as the Google Analytics
opt-out add-on. This site does not present a cookie or consent banner.

Microsoft Clarity. 
We use Microsoft Clarity to understand how visitors use this site through
aggregated session replays and heatmaps — recordings of anonymized
interactions such as mouse movement, clicks, and scrolling. Text you type
into form fields is masked by default and is not captured, and we do not
transmit names, email addresses, message bodies, or any other personally
identifying information to Clarity. Clarity may set first-party cookies to
stitch a session together; the behavioral data it collects is used in
aggregate to improve the site's usability. To opt out you may use a
browser-level tracking-prevention setting or extension; you can read more
about how Clarity handles data at clarity.microsoft.com . As above, this site does not present a cookie or consent banner.

Release of Information 

We will not sell, trade, or rent your PII to others. We do provide
some of our product and service offerings through contractual arrangements made
with affiliates, service providers, partners, and other third parties (collectively,
"Service Partners"). We and our Service Partners may need to use some PII in order
to perform tasks between our respective sites or to deliver services to you. The
use of your PII by our Service Partners is governed the respective privacy policies
of those Service Partners and is not subject to our control. Except as otherwise
discussed in this Policy, this document only addresses the use and disclosure
of information we collect from you. Other websites accessible through this
Site, including our Service Partners, have their own privacy policies and data
collection, use, and disclosure practices. Please consult each site's privacy
policy. We are not responsible for the policies or practices of third parties.
If we are required by law enforcement or judicial authorities to provide PII
to governmental authorities, we may disclose PII upon receipt of a court
order, subpoena, or to cooperate with a law enforcement investigation. We
reserve the right to report to law enforcement agencies any activities that
we in good faith believe to be unlawful. We may also provide Aggregate
Information to third parties but this Aggregate Information does not include
any PII.

Updating and Correcting Information 

You may change any of your PII in your account online at any time by
accessing your account in accordance with instructions posted on the Site.
You may also access and correct your personal information and privacy
preferences by emailing us at tony@truvisory.com or in writing to 2696 W. Grand Ave., Littleton, CO 80123. Please include your
name, address, and/or email address when you contact us. We encourage you to promptly update your PII if it changes. You
may ask to have the information on your account deleted or removed; however,
some information, such as past transactions, logs, or other information may
not be deleted. In addition, it may be impossible to completely delete your
information without some residual information because of backups.

Security of Your PII 

We take appropriate security measures to protect your PII and to prevent
unauthorized access to or unauthorized alteration, disclosure, or destruction
of your PII. We only use your PII for the purposes for which it was collected
or to comply with any applicable legal or ethical reporting or retention
requirements. We limit access to PII only to specific employees, contractors,
and agents who have a reasonable need to access your information. Credit card
transactions and order fulfillment processed through the Site are handled by
established third party banking institutions and processing agents.
Unfortunately, no data transmission over the Internet or any wireless network can be
guaranteed to be 100% secure. As a result, while we strive to protect your PII, you acknowledge that: (a)
there are security and privacy limitations inherent to the Internet which are
beyond our control; and (b) the security, integrity, and privacy of any and all
information and data exchanged between you and us cannot be guaranteed.

Minors 

You must be at least 18 years old to have our permission to use this
Site. We do not knowingly collect, use, or disclose PII about minors. If you are between
the ages of 13 and 17, you may use the Site with the express permission of your
parent or legal guardian. Your parent or legal guardian controls your PII and
we will respond to communications from your parent or legal guardian regarding
your use of the Site.

Miscellaneous 

Please consult our Site Terms for other policies
regarding your use of the Site. If you have any questions, concerns, or
inquiries about this Policy, or our use of your PII, or our privacy practices,
please contact us at tony@truvisory.com , if by email, or 2696 W. Grand Ave., Littleton, CO 80123, if by conventional
mail.

### /terms-of-use/

Acceptance of Terms 

Truvisory ("Company," "us," "we," or Truvisory, LLC), provides the
https://truvisory.com website ("Site") subject to your compliance with the
following Terms of Use ("Terms"), as well as any other written agreement(s)
between us and you. We reserve the right to change these Terms from time to
time with or without notice to you. You acknowledge and agree that it is your
responsibility to periodically review this Site and these Terms. Your
continued use of this Site after such modifications will constitute
acknowledgement and acceptance of the modified Terms. As used in these Terms,
references to our "Affiliates" include our owners, licensees, assigns,
subsidiaries, affiliated companies, officers, directors, suppliers, partners,
sponsors, advertisers, and includes all parties involved in creating,
producing, and/or delivering this Site and/or contents available on this
Site.

BY USING THIS SITE, YOU AGREE TO BE BOUND BY THESE TERMS. IF YOU DO NOT WISH
TO BE BOUND BY THESE TERMS, PLEASE DO NOT USE THIS SITE. YOUR SOLE REMEDY FOR
DISSATISFACTION WITH THIS SITE OR PRODUCTS OR OFFERINGS AVAILABLE ON THIS SITE
OR THESE TERMS IS TO CEASE USING THIS SITE.

Temporary Interruptions 

You understand and agree that temporary interruptions of this Site may occur
as normal events that are out of our control. You also understand and agree
that we have no control over the third-party networks or services that we may
use to provide this Site. You agree that this Site is provided "as is" and
that we assume no responsibility for the timeliness, deletion, mis-delivery,
or failure to store any user communications or other information.

Payment 

This Site does not process credit cards or take other payment processing
information. Payment processing is handled through third-party services. We
are therefore not liable or responsible for your payment interactions on this
Site. Charges may be billed in advance of service.

Overdue Amounts 

If, for any reason, your credit card company declines or otherwise refuses to
pay the amount owed for your purchase, you agree that we may, at our option,
suspend or terminate your purchase and may require you to pay any overdue
amounts incurred (including any third-party chargeback fees or penalties) by
other means acceptable to us. In the event legal action is necessary to
collect on balances due, you agree to reimburse us for all expenses incurred
to recover sums due, including attorneys fees and other legal expenses.

Third-Party Sites and Information 

This Site may redirect or link to other websites on the Internet, or may
otherwise include references to information, products, or services made
available by unaffiliated third parties. While we make every effort to work
with trusted, reputable providers, from time to time such sites may contain
information, material, or policies that may be incorrect or found to be
objectionable. You understand that we are not responsible for the accuracy,
completeness, appropriateness, or legality of content hosted by third party
websites, nor are we responsible for errors or omissions in any references
made on those websites. The inclusion of such a link or reference is provided
merely as a convenience and does not imply endorsement of, or association
with the site or party by us, or any warranty of any kind, either express or
implied.

Content 

For purposes of these Terms, "content" is defined as any information,
communications, software, published works, photos, video, graphics, music,
sounds, or other material that can be viewed by users on our Site and is
owned by Company or its Affiliates. By accepting these Terms, you agree that
all content presented to you on this Site is protected by any and all
intellectual property and/or other proprietary rights available within the
United States and is the sole property of Company or its Affiliates.

All custom graphics, icons, logos, and service names are registered
trademarks, trademarks, or service marks of Company or its Affiliates. All
other trademarks or service marks are property of their respective owners.
Nothing in these Terms grants you any right to use any trademark, service
mark, logo, and/or the name of Company or its Affiliates.

Limitations on Use of Content 

Except for a single copy made for personal use, you may not copy, reproduce,
modify, republish, upload, post, transmit, or distribute any content from
this Site in any form or by any means whatsoever without prior written
permission from us. Any unauthorized use of Site content violates our
intellectual property interests and could result in criminal or civil
penalties. Neither we nor our Affiliates warrant or represent that your use
of materials displayed on, or obtained through, this Site will not infringe
the rights of third parties.

Privacy & Security 

In order to access some of this Site, you may be asked to set up an account
and password. Our account registration page requests certain personal
information from you ("Registration Info"). You will have the ability to
maintain and periodically update your Registration Info as you see fit. By
registering, you agree that all information provided by you as Registration
Info is true and accurate and that you will maintain and update this
information as required in order to keep it current, complete, and accurate.
If you register for an account on this Site, you agree that you are
responsible for maintaining the security and confidentiality of your password
and that you are fully responsible for all activities or charges that are
incurred under your account. Therefore, you must take reasonable steps to
ensure that others do not gain access to your password or account.

Disclosure to Third Party Affiliates 

You hereby grant us the right to disclose to third parties certain
Registration Info about you. The information we obtain through your use of
this Site, including your Registration Info, is subject to our Privacy Policy and is specifically incorporated by reference into these Terms.

Disclaimer 

ALL CONTENT ON THIS SITE IS PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS
WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESS OR IMPLIED INCLUDING, BUT NOT
LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A
PARTICULAR PURPOSE OR THE WARRANTY OF NON-INFRINGEMENT. WITHOUT LIMITING THE
FOREGOING, WE MAKE NO WARRANTY THAT (A) THE CONTENT WILL MEET YOUR
REQUIREMENTS, (B) THE CONTENT OR SITE WILL BE UNINTERRUPTED, TIMELY, SECURE,
OR ERROR-FREE, (C) THE RESULTS THAT MAY BE OBTAINED FROM THE USE OF THIS SITE
WILL BE EFFECTIVE, ACCURATE, OR RELIABLE, OR (D) THE QUALITY OF ANY CONTENT ON
THIS SITE WILL MEET YOUR EXPECTATIONS OR BE FREE FROM MISTAKES, ERRORS, OR
DEFECTS.

THIS SITE COULD INCLUDE TECHNICAL OR OTHER MISTAKES, INACCURACIES, OR
TYPOGRAPHICAL ERRORS. WE MAY MAKE CHANGES TO THE CONTENT, INCLUDING THE PRICES
AND DESCRIPTIONS OF ANY PRODUCTS LISTED HEREIN, AT ANY TIME WITHOUT NOTICE.
THE CONTENT AVAILABLE AT THIS SITE MAY BE OUT OF DATE AND WE MAKE NO
COMMITMENT TO UPDATE SUCH CONTENT. THE USE OF THIS SITE IS DONE AT YOUR OWN
DISCRETION AND RISK AND WITH YOUR AGREEMENT THAT YOU WILL BE SOLELY
RESPONSIBLE FOR ANY DAMAGE TO YOUR COMPUTER OR DEVICE OR LOSS OF DATA THAT
RESULTS FROM SUCH ACTIVITIES. WE MAKE NO WARRANTY REGARDING ANY TRANSACTIONS
EXECUTED THROUGH A THIRD PARTY OR IN CONNECTION WITH THIS SITE AND YOU
UNDERSTAND AND AGREE THAT SUCH TRANSACTIONS ARE CONDUCTED ENTIRELY AT YOUR OWN
RISK. ANY WARRANTY THAT IS PROVIDED IN CONNECTION WITH ANY CONTENT AVAILABLE
ON OR THROUGH THIS SITE FROM A THIRD PARTY IS PROVIDED SOLELY BY SUCH THIRD
PARTY, AND NOT BY US OR ANY OTHER OF OUR AFFILIATES. WE RESERVE THE SOLE RIGHT
TO MODIFY OR DISCONTINUE THIS SITE, INCLUDING ANY OFFERINGS OR FEATURES
THEREIN, AT ANY TIME WITH OR WITHOUT NOTICE TO YOU. WE SHALL NOT BE LIABLE TO
YOU OR ANY THIRD PARTY SHOULD WE EXERCISE SUCH RIGHT. ANY NEW FEATURES THAT
AUGMENT OR ENHANCE THE THEN-CURRENT SITE SHALL ALSO BE SUBJECT TO THESE TERMS.
SOME STATES OR JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF CERTAIN WARRANTIES,
SO SOME OF THE ABOVE LIMITATIONS MAY NOT APPLY TO YOU. PLEASE CONSULT THE LAWS
IN YOUR JURISDICTION.

Limitation of Liability & Indemnification 

IN NO EVENT SHALL WE OR OUR AFFILIATES BE LIABLE TO YOU OR ANY THIRD PARTY FOR
ANY SPECIAL, PUNITIVE, INCIDENTAL, INDIRECT, OR CONSEQUENTIAL DAMAGES OF ANY
KIND, OR ANY DAMAGES WHATSOEVER, INCLUDING, WITHOUT LIMITATION, THOSE
RESULTING FROM LOSS OF USE, DATA, OR PROFIT, WHETHER OR NOT WE HAVE BEEN
ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, AND ON ANY THEORY OF LIABILITY,
ARISING OUT OF OR IN CONNECTION WITH THE USE OF THIS SITE OR OF ANY WEBSITE
REFERENCED OR LINKED TO FROM THIS SITE. FURTHER, WE SHALL NOT BE LIABLE IN ANY
WAY FOR THIRD PARTY PROMISES REGARDING THIS SITE OR FOR ASSISTANCE IN
CONDUCTING COMMERCIAL TRANSACTIONS WITH THE THIRD PARTY THROUGH THIS SITE
INCLUDING, WITHOUT LIMITATION, THE PROCESSING OF ORDERS. SOME JURISDICTIONS
PROHIBIT THE EXCLUSION OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR
INCIDENTAL DAMAGES, SO THE ABOVE LIMITATIONS MAY NOT APPLY TO YOU. PLEASE
CONSULT THE LAWS IN YOUR JURISDICTION.

Indemnification 

You agree to defend, indemnify, and hold us and our Affiliates harmless from
all liabilities, claims, and expenses, including attorneys' fees, that may
arise from your use or misuse of this Site. We reserve the right, at our own
expense, to assume the exclusive defense and control of any matter otherwise
subject to indemnification by you, in which event you will cooperate with us
in asserting any available defenses.

Termination of Use 

You agree that we may, at our sole discretion, terminate or suspend your
access to all or part of this Site with or without notice and for any reason
including, without limitation, breach of these Terms. Upon termination and
regardless of the reason(s) motivating such termination, your right to use
this Site will immediately cease. We shall not be liable to you or any third
party for any claims for damages arising out of any termination or suspension
or any other actions taken by us in connection therewith.

International Use 

Although this Site may be accessible worldwide, we make no representation that
this Site is or will be appropriate or available for use in locations outside
the United States. Those who choose to access this Site from other locations
do so at their own risk. If you choose to access this Site from outside the
United States, you are responsible for compliance with local laws in your
jurisdiction including, but not limited to, the taxation of products
purchased over the Internet.

Governing Law 

This Site (excluding any Third Party websites) is controlled by us from our
offices in Littleton, Colorado and the statutes and laws of the State of
Colorado shall be controlling, without regard to the conflicts of laws
principles thereof. You agree and hereby submit to the exclusive personal
jurisdiction and venue of the courts located in Littleton, Colorado.

Notices 

All notices to a party shall be in writing and shall be made either via email
or conventional mail. Notices to us must be sent to tony@truvisory.com , if by email, or to our address at 2696 W. Grand Ave., Littleton, CO 80123
if in hard copy. You agree to allow us to submit notices to you either through
the email address provided or to the address we have on record.

No Resale Right 

You agree not to sell, resell, reproduce, duplicate, distribute, copy, or use
for any commercial purposes any portion of this Site beyond the limited rights
granted to you under these Terms.

Force Majeure 

In addition to any excuse provided by applicable law, we shall be excused from
liability for non-delivery or delay in delivery of this Site arising from any
event beyond our reasonable control, whether or not foreseeable by either
party including, but not limited to: labor disturbance, war, fire, accident,
adverse weather, inability to secure transportation, governmental act or
regulation, and other causes or events beyond our reasonable control, whether
or not similar to those which are enumerated above.

Savings Clause 

If any part of these Terms is held invalid or unenforceable, that portion
shall be construed in a manner consistent with applicable law to reflect, as
nearly as possible, the original intentions of the parties, and the remaining
portions shall remain in full force and effect.

No Waiver 

Any failure by us to enforce or exercise any provision of these Terms or
related rights shall not constitute a waiver of that right or provision.

Entire Agreement 

These Terms constitute the entire agreement and understanding between you and
us concerning the subject matter hereof and supersede all prior agreements and
understandings between us with respect thereto. If any provision of these
Terms is held to be ineffective, unenforceable, or illegal for any reason, we
may reform such provision to the extent necessary to make it effective,
enforceable, and legal or such provision may be deemed severed and in either
case these Terms with such provision reformed or severed shall remain in full
force and effect to the fullest extent permitted by law. Our failure to
enforce any part or portion of these Terms shall not be considered a waiver of
such portion of these Terms. These Terms may not be altered, supplemented, or
amended by the use of any other document(s) other than as described above. To
the extent that anything in or associated with this Site is in conflict or
inconsistent with these Terms, these Terms shall take precedence.

### /agents-mcp/

§ Agentic Cloud · Cloudflare-native 

Production AI agents on Cloudflare. Durable , observable,
shipped.

A demo agent answers a prompt. A production agent remembers,
retries, acts on tools, waits for a human, and survives a restart.
We build the second kind — on the agentic cloud, with the
primitives that handle the hard parts natively.

Scope an agent build → 

See the stack ↓ 

Verified against Agents Week 2026
(Apr 13–20) · re-checked monthly

AGENT 
Durable Object 

Perceive 
input · events 

Reason 
Workers AI 

Act 
MCP · browser 

Remember 
SQL state 

§ 01 / The thesis 

The cloud was built for one app serving many users. Agents break that
model.

If even a fraction of knowledge workers each run several agents in
parallel, you need compute for tens of millions of simultaneous
sessions. Stateless functions have no GPU , no persistent per-instance memory, and a hard timeout — so you bolt
on a database, a queue, a scheduler, and a session store. Cloudflare's
stateful-serverless model gives each agent its own durable
micro-server, with no idle cost.

Stateless function + bolt-ons 

Lambda-style request/response. No GPU. No per-instance state.
900-second cap. You assemble a database, a queue, a cron service, a
session store, and a vector DB — then operate all of it. The agent
is the glue between five systems you maintain.

Agent = Durable Object 

Each agent instance is a stateful micro-server with its own
embedded SQL ,
WebSockets, and scheduling. It hibernates when idle (costs
nothing), wakes on an event, and resumes exactly where it left off.
The data tier, queue, and scheduler collapse into the agent itself.

§ 02 / The agentic-cloud stack 
One request, traced through the production stack. 

Every model call an agent makes flows through one named, observable
path. Watch a single request travel the layers — each is a first-party
Cloudflare primitive , not a
system you stand up and operate.

// agent request lifecycle 
tracing 

Access + Managed OAuth authenticates the agent on behalf of the user — RFC 9728, scoped permissions, no insecure service accounts."
> Access identity 
→ 
AI Gateway is the unified inference layer — one binding calls any provider, with caching, cross-provider failover, unified billing, and streaming resilience so an interrupted agent never pays to re-infer."
> AI Gateway route · cost 
→ 
Workers AI runs serverless GPU inference across 330 cities — 70+ models, one line to switch, pay-per-token, no idle GPU cost."
> Workers AI inference 
→ 
MCP Server Portal exposes tools through one OAuth surface. Code Mode collapses dozens of tool schemas into two endpoints — the GitLab MCP server went from 34 tools (~15K tokens) to 2."
> MCP Portal tools 
→ 
Sandboxes (GA) + Dynamic Workers give the agent an isolated Linux computer or a millisecond isolate to execute code — egress-proxied so the agent never sees a credential."
> Sandbox act · code 
→ 
Workflows V2 wraps the whole thing in durable execution — 50,000 concurrency, step-level checkpoints, sleep up to a year, and a wait-for-event gate for human-in-the-loop approvals."
> Workflows durable 

A request enters through identity, routes through the gateway,
infers, calls tools, acts in a sandbox, and is wrapped in durable
execution end to end. Tap any layer. 

§ 03 / What production agents actually require 
Seven things separate a demo from a deployment. 

Most agent projects don't fail on model quality. They fail on
reliability, state, and scope. Cloudflare's stack maps to each
requirement natively — that mapping is the whole argument.

§ 04 / Nine building blocks 
The first-party primitives we build on. 

// Supporting: Durable Objects · Vectorize · R2 · D1 · KV · Queues.
Multi-channel add-ons: Voice (experimental), Email (beta). Preview/beta
status verified against Agents Week 2026 — re-checked at each
engagement.

§ 05 / Built for the workload shape 

"The one-app-serves-many-users model the cloud was built on doesn't
work for tens of millions of simultaneous agent sessions."

— Cloudflare CTO Dane Knecht & VP Product Rita Kozlov, Agents
Week 2026. Each lit cell is an agent waking, acting, and
hibernating independently — one Durable Object apiece,
scale-to-zero.

§ 06 / The honest risk layer 

Most agent projects fail. Here's the data — and why it argues for
building them right.

The market data isn't an argument against agents. It's an argument
for building them bounded, durable, and observable — which
is exactly what the production stack provides, and exactly what a
flashy demo that can't survive a restart never will.

§ 07 / Build vs. buy vs. us 
Three ways to get an agent. One ships in 90 days. 

There are three honest paths to production AI agent development. Here's
how they compare — and why the one that ships in 90 days wins. Need
broader custom AI software, not just an agent? That's AI development .

DIY on a framework 

LangGraph is battle-tested orchestration — but you bring your own
hosting, state store, scheduler, scaling, and ops

You own the 40% cancellation risk 
Months to production-harden the parts the demo skipped 

A generic AI agency 

Senior pitch, junior delivery, offshore handoff 

You get a demo that impresses in the room and breaks on the first
restart

Open-ended retainer, no fixed scope 

Truvisory® 

Senior-engineer-led, Cloudflare-native, no offshore handoffs 

Bounded, durable, observable — the seven requirements built in
from day one

Fixed-scope, 90-day delivery — the person who scopes it builds it

Portable app logic and data model, even on a single-vendor
runtime

// The honest caveat: Cloudflare is vendor concentration — Durable
Objects have no drop-in equivalent on AWS or GCP today. For most
commercial workloads that isn't a real constraint; where it is, we keep
the application logic and data model portable and say so up front.

§ 08 / Voice & SMS agents 
A production agent you can talk to right now. 

The same agentic-cloud primitives power real-time voice and SMS. Our
telephony agent answers calls 24/7 — it qualifies a project, answers
pricing, routes to a human, or books a call. Real-time STT + TTS over WebSockets on the
Agents SDK, with durable per-call state. Call it and hear a bounded,
durable agent in production.

▸ Incoming +1 (303) 495-5859

Live · 24/7

"Hi, I'm Truvisory's voice agent. Tell me about your project — I'll
route you, schedule a call, or answer pricing questions right now."

TRUVISORY VOICE VOICE · SMS · 24/7 

Call the agent now · +1 (303) 495-5859 → 

§ 09 / FAQ 

What teams ask before scoping an agent build.

§ 10 / Scope a bounded agent build 

Tell us the one workflow you want an agent to own.

A working call, not a discovery call. You bring one process. We
come with a working hypothesis on the architecture, the primitives
it maps to, and a fixed-scope, 90-day ballpark. No SDR. No drip
campaign.

30 min · Tony directly 
Calendar booking — single click, no form 
We name the agent's bounded scope on the call 
Post-call: 24-hour written architecture sketch, no obligation

### /ai-development/

§ AI Development 

An AI development company that ships custom AI software — not slide decks. 

We design and build production AI — custom applications, AI
features inside your existing product, and model integrations —
engineered by senior US-based engineers and delivered on a fixed
scope. AI development services that reach production, not pilot
purgatory.

Book a scoping call → 

See what we build ↓ 

Working prototype in 2–4 weeks · Production
in ~90 days · SDVOSB · U.S.-based · Cloudflare-native

// idea → production 
building 

1 

Scope & audit 
use case · data · definition of done 

week 1 

2 

Build & prototype 
working system on real data 

wk 2–4 

3 

Harden & ship 
integrate · evaluate · handoff 

~90 days 

✓ 

In production 
your team runs it 

live 

idea 0% production 

U.S.-based senior engineers — no offshore handoff 
Cloudflare-native delivery 
SDVOSB — Service-Disabled Veteran-Owned 
2024 Zapier Zappy Award — Outstanding Customer Impact 

§ 01 / Why most AI work never ships 

Most AI projects stall before they ever reach production.

The hard part of AI was never the demo — it's getting a reliable system
into production and keeping it there. Pilots that look great on curated
data collapse against real systems and real workflows. Notably, MIT
found that teams who partner to build purpose-engineered
systems reach production far more often than teams going it alone. That's
the work we do.

95% 
of generative-AI pilots delivered no measurable return. 
MIT Project NANDA · State of AI in Business 2025 

80%+ 

of AI projects fail — about twice the rate of conventional IT projects.

RAND Corporation · 2024 

42% 

of companies abandoned most AI initiatives in 2025, up from 17% a year
earlier.

S&P Global Market Intelligence · 2025 

Key takeaways 

Most AI initiatives fail at the production stage, not the model stage. 
Purpose-built, well-scoped systems reach production; bolted-on pilots stall. 
A senior build partner with a fixed scope and a production target de-risks the work. 

§ 02 / What we build 
What we build 

Custom AI development services across the stack — whether you need a
net-new AI product, an AI feature inside something you already run, or a
model wired into your operations.

◆ 
BUILD / 01 
Custom AI applications 

Net-new AI software built around your problem and your data —
designed, engineered, and shipped to production, not handed off as a
prototype.

⊕ 
BUILD / 02 
AI features in your existing product 

We embed AI into the product you already ship — search,
summarization, copilots, recommendations, document processing —
without rebuilding what works.

❝ 
BUILD / 03 
AI chatbots & assistants 

Custom AI chatbot development — assistants, copilots, and support
bots built on your own data and wired into your systems, with the
guardrails and evaluation a production chatbot needs. Not a generic
widget.

⇄ 
BUILD / 04 
Model & LLM integration 

We connect the right models to your systems — provider APIs, open
models, retrieval, and evaluation — and make them reliable enough to
depend on.

⌕ 
BUILD / 05 
RAG, search & document AI 

Retrieval-augmented systems and AI document workflows that answer
from your content with the accuracy and traceability
production use demands.

✦ 
BUILD / 06 
Generative AI development 

Generative AI development services for the use cases that actually
pay off — built and evaluated against a defined business outcome, not
a demo.

⚡ 
BUILD / 07 
AI agents & automation 

Production agent and automation work, built Cloudflare-native. For
deep agent engineering, see our AI agents &
MCP work.

§ 03 / How we're different 
A different kind of AI development company. 

The AI development field is crowded with offshore shops that hand you a
prototype and disappear. As a U.S.-based AI development company, we're
built the opposite way.

01 

Senior engineers, U.S.-based — no offshore handoff 

The people who scope your build are the people who write the code.
No layered account management, no offshore handoff, no junior team
learning on your budget.

02 

Fixed scope, fixed timeline 

We scope tightly and commit to it — a working prototype in 2–4
weeks and production in about 90 days — so you know what you're
getting and when.

03 

We ship to production, not to a deck 

The deliverable is a working system your team can run, with the
integration, evaluation, and handoff that keeps it running — not a
strategy slide.

04 

Cloudflare-native by default 

We build on Cloudflare's developer platform for fast, low-cost,
globally-deployed AI — so your systems are cheaper to run and
simpler to operate.

§ 04 / How we work 
From idea to production in about 90 days. 

A clear, fixed path from "we think AI can help here" to a system in
production.

STEP 01 
Scope & audit 
week 1 

We pin down the use case, the data, and the definition of done —
what the system must do and how we'll measure that it works — before
any build starts.

STEP 02 
Build & prototype 
weeks 2–4 

You get a working prototype on your real data in 2–4 weeks, so you're
reacting to something real instead of a spec.

STEP 03 
Harden & ship 
through ~90 days 

We integrate, evaluate, and harden the system for production, then
hand it off with the documentation your team needs to own it.

No open-ended retainers. A defined scope, a defined timeline, a system in
production at the end.

§ 05 / Proof 
Shipped systems, not slideware. 

We build what we sell. These are production systems engineered and
shipped under the Truvisory® brand — the same senior-built,
Cloudflare-native discipline we bring to your project.

Venture · Cloudflare-native 
HotCopy 

A recursive-LM coding CLI on Cloudflare's edge — Kimi K2.6
orchestrating Gemma scout workers, sub-50ms response from 330+ cities.

Workers AI · Durable Objects Production → 

Venture · Multi-channel AI 
PresEngage 

Patent-pending AI co-presenter for live audiences — real-time SMS Q&A
trained on the speaker's own deck.

Patent pending Production → 

Product · Voice · SMS · Webchat 
AI Telephony & SMS 

A 24/7 voice, SMS, and webchat agent that answers, qualifies, books,
and routes — wired into your CRM and calendar.

Live demo line See it → 

SDVOSB — Service-Disabled Veteran-Owned 
Cloudflare-native delivery 
2024 Zapier Zappy Award — Outstanding Customer Impact 
Tony Adams, MBA — 25-yr operator & senior engineer 

See the full proof → 

About the team → 

§ 06 / Fixed-scope pricing 

One fixed price: $20K – $120K. Known before we start.

Every build is a fixed-scope, fixed-price engagement in a
$20K–$120K band — where your number lands depends on what we're
building, and you approve it before work starts. Two delivery gates
de-risk the spend: a working prototype first, production second.

Gate 01

Prototype build

From 
$20K 
· fixed 

weeks 2–4 

Best for: 
proving the system on your real data before you commit the full number.

▸ 
Working system on your real data — not a spec

▸ 
Scope, evaluation criteria & definition of done locked

▸ 
Go / no-go checkpoint before the full spend

The deliverable 

Gate 02

Production system

Full band 
$20K – $120K 
· fixed 

by ~day 90 

Best for: 
the working system in production — what every fixed scope is priced against.

▸ 
End-to-end: UX → model → integrations → guardrails → evaluation

▸ 
Hardened, observable, and shipped to production

▸ 
Runbook, docs & handoff — your team runs it

// A fraction of the $280K–$450K Year-1 cost of one senior AI hire.
For the full market math, see how much AI implementation actually costs .

§ 07 / Hire AI developers 

Hire AI developers who ship — not a staffing req.

When you hire AI developers through Truvisory®, you engage a senior
U.S.-based build team on a fixed scope — the engineers who scope the
work write the code and ship it to production. Not staff augmentation,
not an offshore body shop, not a junior team learning on your budget.

When to hire AI developers here 

You know what you need built and want it shipped — not just advised on. 
You'd rather buy a fixed-scope outcome than carry the cost and ramp of a full-time AI hire. 
You want the senior engineer who scopes the build to be the one who writes the code — no handoff. 
The work is custom AI software — applications, AI features, model integrations, or chatbots. 

Hiring a full-time AI engineer takes months. Book a scoping call and we'll size the work — and kick off fast, with no recruiting pipeline or ramp.

§ 08 / AI development FAQ 
AI development FAQ 

Need strategy before a build? That's AI consulting .
Need a production agent specifically? See AI agents & MCP .

§ 09 / Book a scoping call 

Have something you need built?

Book a scoping call and we'll tell you what it takes to get it to
production — scope, timeline, and price. A working call, not a
discovery call.

30 min · senior engineer, not a sales rep 
We define the build's scope on the call 
Post-call: 24-hour written scope & timeline sketch, no obligation 

Need advice first? AI consulting →

### /ai-telephony/

§ Product · Voice · SMS · Webchat · 24/7 

An AI agent that answers every call. And actually does the work. 

It's an AI receptionist and 24/7 answering service that picks up
on the first ring, talks like a person, qualifies the caller,
books the appointment in your calendar, writes the lead into your
CRM, and texts a follow-up — all before a human would have
finished saying hello.

Call a live agent now → 

Scope yours ↓ 

Live demo line · +1 (303) 495-5859 · answers 24/7

Incoming · +1 (303) 495-5859 
00:14 

Caller 

Hi, do you have anything open Thursday for a roof inspection?

Agent 

We do — I've got 10:30 or 2:00 Thursday. Which works better?

Checking calendar · 2 slots open 

Caller 
10:30 is great. 

Booked · CRM lead created · SMS sent 

§ 01 / Inside a single call 

From "hello" to booked in under a second of latency per turn.

Every call runs the same low-latency loop on the edge. Voice in,
intent out, an action taken in a real system, voice back. Watch one
turn travel the pipeline.

// live call lifecycle 
tracing 

Voice in → transcribe → reason → act in a real system → speak back →
log and follow up. Tap any stage. 

§ 02 / Connected to the systems you already run 

The agent doesn't live in a silo. It reaches into your stack.

VOICE 
AGENT 
edge runtime 

Built on MCP — the open tool-surface standard — so a new integration is a
connector, not a rebuild. We wire the agent into your real systems
with scoped, least-privilege access. The agent never holds a raw
credential.

§ 03 / What it does on every call 

Nine capabilities, bounded to your business.

§ 04 / One agent, three channels 

Voice, SMS, and webchat — one brain, one memory across all three.

Voice phone 

Natural conversation on inbound and outbound calls — sub-second
responses, barge-in, warm transfers.

Answers on the first ring, every time 
Sounds human — natural pacing and tone 
Interruptible — stops and listens like a person 
Outbound too — reminders, confirmations, win-backs 

SMS text 

The same agent continues the conversation by text —
confirmations, reschedules, and quick questions.

Can I move my Thursday appt to Friday? 

Sure — I have Friday 9:00 or 1:30 open. Which works?

1:30 

Done. You're set for Fri 1:30. Confirmation on the way ✓

Webchat site 

A chat widget on your website, handled by the same agent —
qualifying and booking visitors before they bounce.

Do you service the 80202 area? 

We do! Want me to grab the next available inspection slot?

Yes please 

Booked for Thu 10:30 — check your email for confirmation ✓

§ 05 / Where it earns its keep 

Built for businesses that live and die by inbound contact.

Wherever a missed call is a missed job, the AI receptionist and
answering service earns its keep — qualifying, booking, and following
up across every one of these.

§ 06 / FAQ 

AI receptionist, answering service — what people ask.

§ 07 / Scope your voice agent 

Tell us what your phone line should never miss.

A working call, not a discovery call. Bring the calls you keep
missing and the systems they should touch. We come back with a
bounded agent design, the integrations it needs, and a fixed-scope
ballpark.

30 min · Tony directly 

Or just call the live demo line: +1 (303) 495-5859 

We name the agent's bounded scope on the call 
Post-call: 24-hour written build sketch, no obligation

### /cmmc-level-1/

§ Level One Builder 

Your CMMC Level 1 package, from one
honest interview.

A free CMMC Level 1 self-assessment that interviews you against
all official objectives in plain language. Meet every
requirement and it generates your complete document package — four PDFs
and two workbooks — then walks you through recording the result in SPRS.
Fall short anywhere and you get a prioritized gap plan instead, because a
package you can&rsquo;t stand behind is worse than none.

Runs in your browser — your answers never leave it. Save with an email +
password and resume any time.

§ 01 / The standard 

The CMMC Level 1 requirements you&rsquo;ll assess

CMMC Level 1 is the basic safeguarding requirements of
FAR 52.204-21(b)(1), assessed against objectives from
NIST SP 800-171A as reproduced in the CMMC Assessment Guide – Level 1
(v2.13). Six domains, no partial credit: one failed objective fails its
requirement, and one failed requirement means no package.

§ 02 / Method 

How the self-assessment works

§ 03 / Deliverables 

The document package you get

More than a CMMC Level 1 checklist: a populated, brandable document set —
every file generated in your browser from your actual answers, with any
field you left blank highlighted for completion. Add your logo and it
rides the letterhead. The whole set downloads as one zip.

§ 04 / SPRS 

Submit your score in SPRS

A passing self-assessment only counts once it&rsquo;s recorded. In the
Supplier Performance Risk System (SPRS, via PIEE) you enter the
assessment with the Add New CMMC Level 1
Self-Assessment button — you&rsquo;ll need the SPRS Cyber Vendor User
role — and your Affirming Official affirms it. SPRS then shows
Final Level 1 Self-Assessment (the rule calls
the status &ldquo;Final Level 1 (Self)&rdquo;), which expires to
No CMMC Status (Expired Assessment) after one
year: Level 1 self-assessments are annual (32 CFR § 170.15(a)(1)), a
contracting officer needs both the status and a current affirmation on
file before award (§ 170.15(b)), and your evidence must be retained for
six years (§ 170.15(c)(2)). The builder&rsquo;s results screen walks the
whole flow with your own values filled in.

§ 05 / Certification 

Do you need certification? (No — Level 1 is self-attested)

No assessor visits, no certificate, no C3PAO. CMMC Level 1 is a
self-assessment: your own honest determination, entered in SPRS and
affirmed annually by a senior official who takes responsibility for it —
affirmations are subject to the False Claims Act, which is exactly why
this builder refuses to generate a package you can&rsquo;t stand behind.
Since the Department of War suspended CMMC Phase II third-party
assessments on July 13, 2026, self-assessment is the primary trust
artifact: Level 1 (Self) and Level 2 (Self) are the only CMMC levels a
contracting officer may currently designate.

§ 06 / FAQ 

CMMC Level 1, answered

### /fractional-cto/

Fractional CTO · AI-Native · Cloudflare-Native · SDVOSB 

Senior technical leadership — without the $400K hire .

You need someone who can own the architecture, kill the wrong bets
before they cost you, and actually ship. You don't need to spend a
year recruiting a full-time CTO, hand over equity, and hope they work
out.

Truvisory® gives you a battle-tested technology executive embedded
in your business — setting strategy, leading the build, and getting AI into production in 90 days, not 18 months .

Book a 30-min technical assessment → 

See how engagements work ↓ 

Founder-led by a U.S. Army combat veteran and 25-year operating
executive. SDVOSB-certified. ★★★★★ across verified reviews.

// At a glance

§ 01 / Do you need this? 

If any of these sound familiar, you have a technical leadership gap.

You don't have a problem with effort. You have a problem with no one
senior enough owning the technical call. That gap is expensive — and it
usually shows up at one of these moments.

An AI initiative isn't landing

MIT found that 95% of enterprise GenAI pilots produce no measurable return . You don't want to be in that 95% — you want the version that ships
and pays for itself.

Cloud spend is climbing, unsteered

You suspect you're overpaying agencies and over-provisioned in the
cloud, but you don't have a technical leader to right-size it.

If you're nodding, the question isn't whether you need senior technical leadership. It's whether you need it
full-time — or fractional.

§ 02 / What a fractional CTO actually does 

Full executive scope. None of the full-time overhead.

A fractional CTO — sometimes called a part-time CTO — isn't a consultant
who writes a report and disappears. Our fractional CTO services embed a
senior technology executive who takes ownership and stays accountable for
outcomes.

§ 03 / The Truvisory® difference 

Most fractional CTOs hand you a strategy. We hand you working software.

Plenty of people will sell you advice by the hour. The gap between a
slide deck and a system in production is where most initiatives die.
We're different on three counts.

§ 04 / Engagement models & pricing 

Transparent tiers. Pick the altitude you need.

Most firms make you book a call just to learn what they charge. Here's
the honest range up front. Every engagement starts with a fixed-fee
Technical Assessment, then moves into one of three models.

// Month-to-month after an initial 3-month term. No equity required. No
recruiting fees. No benefits load.

Scope your engagement → 

§ 05 / vs. full-time 

A full-time CTO is a half-million-dollar commitment. Fractional isn't.

The full-time number is bigger than most founders budget for — and
that's before equity dilution.

Annual cost of a full-time CTO versus a Truvisory® fractional
engagement, line item by line item. 

Line item 
Full-time CTO 
Truvisory® Fractional 

Annual cost 
$400,000+ all-in 
$72K – $192K 

Risk if wrong fit 
~40% of senior hires fail in 18 mo; replacement up to 213% of
salary 
Month-to-month 

Source: Salary.com CTO salary benchmark , 2026.

You capture most of the strategic value of a full-time executive at 40–70% lower cost — and if the fit isn't right, you're not unwinding an equity grant and
a severance package.

§ 06 / The fractional Chief AI Officer angle 

Need an AI strategy that survives contact with production?

5%

of integrated enterprise AI pilots are extracting real value —
against an estimated $30–40B in GenAI spend.
MIT Project NANDA · 2025 

Most companies don't have an AI problem. They have an AI leadership problem — lots of pilots, no one accountable for getting one into
production and proving it pays.

The single biggest predictor of which side of that line you land on
isn't the model — it's whether someone senior owns the strategy, the
architecture, and the guardrails.

Truvisory®'s fractional CTO engagement doubles as a fractional Chief AI Officer : a single accountable leader who decides what to build versus buy,
ships it on infrastructure you control, and governs cost and risk
from day one.

Scope an AI mandate → 

§ 07 / How engagements start 

Three steps. No mystery.

§ 08 / Proof 

Operators trust us with the decisions that matter.

See the full operator track & case studies → 

§ 09 / When this is NOT right for you 

We'll tell you when this isn't the answer.

We'd rather lose the engagement than sell you the wrong one. A fractional
CTO is the wrong call if:

If that's you, we'll say so on the first call — and point you in the
right direction.

§ 10 / About the founder 

Led by an operator who has had to live with the decisions.

// Tony Adams · Founder 
SGT (E-5) · Infantry · Afghanistan 

Truvisory® is founded and led by Tony Adams — a U.S. Army combat veteran, technology executive, and 25-year
operating leader. He has served as President and CTO of a
private-equity-backed multi-unit operator, as a nonprofit COO, and in
leadership across franchising and technology organizations.

He holds an Executive MBA (4.0 GPA) and formal software engineering
training, and his work in AI and automation has earned industry
recognition — including Zapier's 2024 Zappy Award for Outstanding
Customer Impact, for customer-communication automation that drove
three times more Google reviews and twice as many app downloads at
a national franchise brand.

Truvisory® LLC is an SBA-certified Service-Disabled Veteran-Owned Small Business
(SDVOSB) based in Littleton, Colorado, serving clients nationwide.

Read the long version → 

§ 11 / In the founder's voice 

"A fractional CTO should own the technical call, not just weigh in
on it. I make the architecture decisions, lead the build, and ship
the system — for the slice of time your stage actually needs."

— Tony Adams · Founder, Truvisory®

Book a 30-min technical assessment → 

See the work → 

§ 12 / How to hire a fractional CTO 

Ready to hire a fractional CTO? Here's what to look for.

Hiring a fractional CTO isn't a recruiting search — no six-month pipeline,
no equity grant, no benefits load. You scope the engagement and start in
days. The hard part is vetting: most of the market sells advice by the
hour. Six things separate an owner from an advisor — and for the budget
side, what a fractional CTO costs lives in its own guide.

Tick all six and you're not hiring a contractor — you're engaging a senior
operator who owns the call and ships. That's the whole model.

Hire a fractional CTO — book a 30-min assessment → 

§ 13 / FAQ 

Questions sophisticated buyers ask.

§ 14 / Get a senior technical read 

A senior technical read on your business in 30 minutes.

No pitch, no obligation — just a straight assessment of where you stand
and what you need.

Book a 30-min technical assessment → 

See commercial services →

### /unsubscribe/

§ Field notes / Unsubscribe 

One click. You're out .

As promised: no re-confirmation form, no "are you sure" survey, no
30-day processing window. Press the button and the field notes stop.

Confirm unsubscribe 

Unsubscribe

This unsubscribe link is missing its token — it may have been
trimmed by your mail client. Open the link straight from the
newsletter email, or write tony@truvisory.com and we'll remove you by hand.

Done — you're unsubscribed. 
No further field notes will be sent to this address. Change your
mind later? Any signup form on the site re-subscribes you in one
step. 

That didn't go through — the token may have expired. Try again, or
email tony@truvisory.com and we'll remove you by hand.

## Insights

## CMMC Level 2: Requirements, Self-Assessment, and What the Suspension Changed

_Pillar — /federal/cmmc-level-2/_

CMMC Level 2 is the tier of the <abbr title="Cybersecurity Maturity Model Certification">CMMC</abbr> program built to protect <abbr title="Controlled Unclassified Information">CUI</abbr> — and it is defined by exactly one thing: the **110 security requirements of NIST SP 800-171 Rev. 2**. That number did not change on July 13, 2026, when the Department of War [suspended CMMC Phase II](/federal/cmmc-phase-ii-suspended/), the mandatory third-party assessment rollout. What changed is *how* Level 2 compliance gets verified: the <abbr title="CMMC Third-Party Assessment Organization">C3PAO</abbr> certification path is paused, and the **Level 2 self-assessment** is now one of only two CMMC postures a contracting officer may designate at all.

That makes this a strange, useful moment to understand Level 2 properly. The headlines say the audit is gone. The requirements, the annual affirmation, DFARS 252.204-7012, and the FedRAMP-Moderate cloud rule for CUI all still bind — and the firms that treat the review window as preparation time, rather than a reprieve, will be the ones positioned well whichever way the review lands.

This is the evergreen guide: what Level 2 is, what the requirements actually are, how the self-assessment differs from the paused certification path, who needs Level 2 versus Level 1, and how to prepare while the 60-day review runs.

<ul>
<li><strong>CMMC Level 2 protects CUI</strong> with the 110 security requirements of NIST SP 800-171 Rev. 2 — the same 110 before and after the July 13, 2026 suspension. The requirements didn't move; the verification method did.</li>
<li><strong>Two verification paths, one active:</strong> Level 2 (Self) — you assess, submit to <abbr title="Supplier Performance Risk System">SPRS</abbr>, and affirm — and Level 2 (C3PAO), the third-party certification, which is suspended pending review. During the suspension a contracting officer may designate only Level 1 (Self) or Level 2 (Self).</li>
<li><strong>Level 1 vs Level 2 is decided by your data:</strong> <abbr title="Federal Contract Information">FCI</abbr> only → Level 1 (15 requirements, self-assessed, no POA&Ms). Any CUI → at least Level 2 (110 requirements).</li>
<li><strong>What still binds:</strong> DFARS 252.204-7012, NIST SP 800-171 Rev. 2, the annual affirmation (32 CFR 170.22), the SPRS Basic score under DFARS 252.204-7019/-7020, and FedRAMP Moderate for any cloud touching CUI.</li>
<li><strong>Level 1 is your Level 2 foundation:</strong> every one of the 15 Level 1 safeguards has a direct counterpart among the 110 — locking Level 1 down first is the cheapest possible start on Level 2.</li>
</ul>

<section>

## What is CMMC Level 2?

CMMC — the Cybersecurity Maturity Model Certification program, codified in the CMMC final rule (32 CFR Part 170) — sets three levels of cybersecurity posture for defense contractors, matched to the sensitivity of the information they handle:

- **Level 1** protects Federal Contract Information (FCI) with the 15 basic safeguarding requirements of FAR 52.204-21. It is always self-assessed, annually, with no POA&Ms permitted at any time (32 CFR § 170.21(a)(1)). If FCI is new territory, start with [what counts as Federal Contract Information](/federal/what-is-fci/).
- **Level 2** protects Controlled Unclassified Information with the **110 requirements of NIST SP 800-171 Rev. 2** — the subject of this guide.
- **Level 3** adds 24 requirements from NIST SP 800-172 for a select set of programs handling the most sensitive CUI, assessed by the government's own <abbr title="Defense Industrial Base Cybersecurity Assessment Center">DIBCAC</abbr> — and it requires a completed Level 2 first.

So Level 2 is the workhorse tier: it is where most contractors who touch CUI live, and it is the level the whole Phase II controversy was about. The distinction that matters most in 2026 is that "Level 2" is one set of requirements with **two verification methods** — a self-assessment and a third-party (C3PAO) certification — and only one of those methods is currently available.

</section>

<section>

## CMMC Level 2 requirements: the same 110 controls

The CMMC Level 2 requirements are not a CMMC invention. They are, verbatim, the 110 security requirements of **NIST SP 800-171 Rev. 2**, spanning 14 domains — access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity. Assessments walk the objectives in NIST SP 800-171A, the companion assessment-procedures document.

Three things about the requirements are worth being precise on:

**They are unchanged by the suspension.** The July 13 announcement paused the third-party assessment phase; it did not amend, waive, or reduce a single control. If your system processes, stores, or transmits CUI, the 110 requirements apply through DFARS 252.204-7012 exactly as they did on July 12.

**Level 2 is scored; Level 1 is not.** Level 2 uses a point-scored methodology against the 800-171A objectives (a perfect score is 110), and it permits a **conditional status** — a minimum passing score with the remaining items on a plan of action, alongside a system security plan. That is a meaningful contrast to Level 1, where the [15 requirements](/federal/cmmc-level-1-requirements/) are assessed MET or NOT MET in their entirety and POA&Ms are not permitted at any time.

**Rev. 2 is the baseline — for now.** NIST has published SP 800-171 Rev. 3, but the Department adopts it only through future rulemaking, and a DFARS class deviation keeps CMMC assessments against Rev. 2 until then. The proposed government-wide CUI rule published in June 2026 points in the Rev. 3 direction, so the transition is a *when*, not an *if* — but building genuinely to Rev. 2 today is not wasted work. The two revisions overlap heavily, and a real Rev. 2 implementation converts; a paper one doesn't.

</section>

<section>

## CMMC Level 2 self-assessment vs Level 2 (C3PAO)

The requirements are identical either way. What differs is who does the verifying — and, since July 13, 2026, which path you're allowed to use.

**Level 2 (Self)** — the CMMC Level 2 self-assessment — means your organization assesses its own implementation of the 110 requirements against the NIST SP 800-171A objectives, submits the results to SPRS, and then affirms. The affirmation is not a formality: it comes from your **Affirming Official**, defined in 32 CFR § 170.22(a)(1) as the senior level representative from within the Organization Seeking Assessment who is responsible for ensuring compliance and who has the **authority to affirm the organization's continuing compliance** with the security requirements. That affirmation recurs annually, and a false one is exactly the kind of statement the Justice Department's Civil Cyber-Fraud Initiative exists to prosecute.

**Level 2 (C3PAO)** — the certification path — means an accredited CMMC Third-Party Assessment Organization performs the assessment and issues the certification. This was the heart of CMMC Phase II, scheduled to start appearing in solicitations November 10, 2026 — and it is what the Department suspended. Under the implementing memo (26-P-1023), contracting officers and requiring activities may designate **only CMMC Level 1 (Self) or Level 2 (Self)** while the review runs; they may not designate Level 2 (C3PAO) or Level 3 (DIBCAC), and no waivers will be issued. A CMMC Reform Task Force has 60 days to review the program, informed by a public <abbr title="Request for Information">RFI</abbr> with responses due August 14, 2026.

Read those two paragraphs together and the practical picture for 2026 is clear: **the CMMC Level 2 self-assessment is currently one of only two designatable CMMC postures — and the only Level 2 posture.** A contractor pursuing defense work involving CUI doesn't wait on an assessor backlog anymore; it assesses honestly, submits, affirms, and carries the liability of its own signature. The full same-day analysis of what that shift means — for program offices, primes, and small firms — is in our [CMMC Phase 2 suspension](/federal/cmmc-phase-ii-suspended/) breakdown; this guide stays on the evergreen question of what Level 2 *is*.

</section>

<section>

## Who needs Level 2 — and who only needs Level 1

The level you need is decided by the information your systems handle, not by your size or your ambition:

- **FCI only** — information provided by or generated for the government under contract, not intended for public release: **Level 1**.
- **Any CUI** — information requiring safeguarding under law, regulation, or government-wide policy (export-controlled data, controlled technical information, and the rest of the CUI Registry): **at least Level 2**. "At least," because select high-sensitivity programs require Level 3 on top of it.

<tr>
<th scope="row">Information protected</th>
<td data-label="CMMC Level 1">FCI</td>
<td data-label="CMMC Level 2">CUI (and FCI)</td>
</tr>
<tr>
<th scope="row">Requirements</th>
<td data-label="CMMC Level 1">15, from FAR 52.204-21</td>
<td data-label="CMMC Level 2">110, from NIST SP 800-171 Rev. 2</td>
</tr>
<tr>
<th scope="row">Assessment</th>
<td data-label="CMMC Level 1">Self-assessment, annually</td>
<td data-label="CMMC Level 2">Self-assessment; C3PAO certification (paused since Jul 13, 2026)</td>
</tr>
<tr>
<th scope="row">Scoring</th>
<td data-label="CMMC Level 1">MET / NOT MET in their entirety — no partial credit</td>
<td data-label="CMMC Level 2">Point-scored against 800-171A objectives (110 max)</td>
</tr>
<tr>
<th scope="row">POA&Ms</th>
<td data-label="CMMC Level 1">Not permitted at any time (32 CFR § 170.21(a)(1))</td>
<td data-label="CMMC Level 2">Limited — a conditional status with a plan of action is possible</td>
</tr>
<tr>
<th scope="row">Annual affirmation in SPRS</th>
<td data-label="CMMC Level 1">Required</td>
<td data-label="CMMC Level 2">Required</td>
</tr>

Here is the part small contractors consistently miss: **Level 1 is your Level 2 foundation.** Every one of the 15 Level 1 safeguards has a direct counterpart among the 110 — limit system access, authenticate users, sanitize media, control physical access, protect boundaries, remediate flaws. A firm that has honestly implemented and documented Level 1 has already built the habits, the evidence discipline, and the first tranche of controls that Level 2 demands. If you haven't locked that floor down yet, run our [free CMMC Level 1 self-assessment](/cmmc-level-1/) — it walks the 15 requirements objective by objective and generates the document package — before you spend a dollar on Level 2 gap analysis.

</section>

<section>

## What the July 13 suspension changed — and what still binds

The suspension is covered in depth in the [CMMC Phase 2 suspension analysis](/federal/cmmc-phase-ii-suspended/); here is the Level 2-relevant core, briefly.

**Changed:** the mandatory Level 2 (C3PAO) certification — Phase II, which was to appear in solicitations from November 10, 2026 — is suspended, along with the later Level 3 milestones. Solicitations already carrying third-party requirements are to be amended. A 60-day review, with an RFI open until August 14, 2026, will determine what comes next; officials did not rule out cancelling the program, and did rule out issuing waivers in the meantime.

**Not changed — still fully binding for anyone touching CUI:**

- **DFARS 252.204-7012** — implement NIST SP 800-171, report cyber incidents within 72 hours.
- **NIST SP 800-171 Rev. 2** — all 110 requirements, now enforced through self-assessment and government-led assessment.
- **The annual affirmation** (32 CFR 170.22) and the CMMC clause itself, DFARS 252.204-7021, which remains prescribed for use until November 9, 2028.
- **The SPRS Basic score** — DFARS 252.204-7019/-7020 have required a current NIST SP 800-171 self-assessment score in SPRS since 2020, independent of CMMC.
- **FedRAMP Moderate for CUI in the cloud** — DFARS 252.204-7012 requires any cloud service storing, processing, or transmitting covered defense information to meet FedRAMP Moderate, authorized or equivalent. The suspension didn't touch it.
- **False Claims Act exposure** — with the audit paused, self-attestation is the mechanism, and DOJ's Civil Cyber-Fraud Initiative continues. The paperwork got lighter; the liability did not.

For buyers, that last pair is the whole story: verification shifted from an assessor's badge to the contractor's signature — which is why [verifying a contractor's FedRAMP and security claims yourself](/federal/verify-ai-contractor-cmmc-fedramp/) matters more now, not less.

</section>

<section>

## How to prepare for CMMC Level 2 during the review window

Whether the review restores third-party assessments, restructures them, or ends the program, the 110 requirements survive in every scenario — they predate CMMC and bind through DFARS 7012 regardless. That makes the preparation path robust to the outcome:

Establish whether you actually handle CUI, or only FCI. This single answer decides whether you need Level 2 at all — and misclassifying in either direction is expensive. Start with <a href="/federal/what-is-fci/">what is FCI</a> and your contracts' markings and clauses.

If FCI is in scope — and it is for essentially every defense contractor — complete a real Level 1 self-assessment before scaling to 110 controls. Level 1 is your Level 2 foundation, and the <a href="/cmmc-level-1/">free CMMC Level 1 self-assessment</a> gets you a documented baseline in an afternoon.

Walk NIST SP 800-171 Rev. 2 requirement by requirement, using the SP 800-171A objectives as the test. Score honestly — the number that goes into SPRS is one you will affirm under signature.

Level 2 runs on documentation: a current <abbr title="System Security Plan">SSP</abbr> describing your environment and a plan of action for anything not yet implemented. These are also the artifacts any future assessment — self or third-party — will open with.

If CUI touches cloud infrastructure, that cloud must meet FedRAMP Moderate — authorized or equivalent. This is the requirement that quietly disqualifies otherwise-capable firms, and it is unaffected by the suspension.

Submit your self-assessment results to SPRS, designate your Affirming Official — the senior level representative with the authority to affirm continuing compliance — and put the annual affirmation on the calendar. Under the suspension, this posture is what a contracting officer can actually designate.

</section>

<section>

## Where Truvisory fits — stated plainly

Same disclosure we publish everywhere, because on a compliance topic it's the only kind worth publishing.

**Truvisory is not CMMC-certified, and CMMC certification is not something any contractor can grant — it comes from the program's own assessment processes.** Our documented posture is an active **CMMC Level 1 (Self) status** — self-assessed against the 15 FAR 52.204-21 requirements (59 NIST SP 800-171A objectives) and recorded in SPRS, CAGE 0HPQ0, UID available to contracting officers and prime partners on request. Level 2, covering the full 110 NIST SP 800-171 requirements, is on our roadmap and not yet self-assessed. We are also [FedRAMP-aware, not FedRAMP-authorized](/federal/fedramp-aware/) — we build on Cloudflare's government platform, which holds the FedRAMP Moderate authorization that DFARS 7012 requires for CUI in the cloud. No badge wall, no implied certifications; the posture the suspension just made central — honest self-assessment, real controls, verifiable claims — is the one we already held.

If you're a program office or prime that needs working AI software from a small, security-serious firm — and you'd rather stress-test our claims in 30 minutes than read another compliance deck — book a Capability Briefing from any page of the [federal practice](/federal/).

</section>

Tony Adams is the founder of Truvisory®. He builds Cloudflare-native AI systems for federal and commercial clients. SBA-verified SDVOSB and VOSB, SAM.gov-registered.

### Spokes

#### What Is FCI (Federal Contract Information)? — /federal/what-is-fci/

Every conversation about CMMC eventually arrives at the same question: *do we even handle FCI?* It's the right question, because <abbr title="Federal Contract Information">FCI</abbr> is the trigger. If your systems hold it, the fifteen basic safeguards of FAR 52.204-21 apply and CMMC Level 1 is your floor. If they genuinely don't, most of the CMMC conversation isn't about you.

And yet FCI is chronically misexplained — usually by dropping the two exclusions built into its definition, which conveniently makes everything on a government contract sound like FCI and every contractor sound like they need help. So let's start with the actual words.

<ul>
<li><strong>The definition (FAR 4.1901):</strong> information, not intended for public release, provided by or generated for the Government under a contract to develop or deliver a product or service — <em>excluding</em> information the Government provides to the public and simple transactional information such as that necessary to process payments.</li>
<li><strong>The exclusions are part of the definition,</strong> not a loophole: public postings aren't FCI, and neither is routine payment-processing data. Anyone defining FCI without them is over-scoping you.</li>
<li><strong>FCI ≠ CUI.</strong> FCI triggers the 15 FAR 52.204-21 safeguards and CMMC Level 1 (self-assessed). CUI triggers NIST SP 800-171 under DFARS 252.204-7012, FedRAMP-Moderate cloud, and at least CMMC Level 2.</li>
<li><strong>Scope follows the information:</strong> only the systems that process, store, or transmit FCI are in the Level 1 assessment scope — not your whole company.</li>
<li><strong>Handling FCI ≠ needing a certification.</strong> Level 1 is verified by annual self-assessment in SPRS plus an annual affirmation. No third party, no certificate.</li>
</ul>

<section>

## The FAR 4.1901 definition, taken apart

Here is the definition, verbatim — it appears at FAR 4.1901 and again word-for-word in [FAR 52.204-21](/federal/far-52-204-21/)(a):

> Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.

Three moving parts:

**"Not intended for public release."** FCI is non-public by definition. If the information was meant to be published, it isn't FCI.

**"Provided by or generated for the Government under a contract to develop or deliver a product or service."** Both directions count — what the Government hands you *and* what you create for the Government in performance. And it's tied to a contract: information floating around your company with no connection to developing or delivering something for the Government doesn't meet the definition.

**The two exclusions.** First, information provided by the Government to the public — the example the FAR itself gives is public websites. A specification posted on a public site doesn't become FCI because it later shows up in your contract folder. Second, *simple transactional information, such as necessary to process payments* — routine banking and invoicing plumbing isn't FCI either.

What typically remains inside the definition, applying its own terms: the non-public content of your contract and orders, deliverables and technical work products you generate for the Government, performance information exchanged with your contracting office — the working substance of the engagement that was never meant for public release. When in doubt, run the two-part test: non-public? provided-by-or-generated-for, under the contract? If both yes and no exclusion applies, treat it as FCI.

</section>

<section>

## FCI vs. CUI

The distinction that decides your compliance tier — and your cost structure:

<tr>
<th scope="row">Defined by</th>
<td data-label="FCI">FAR 4.1901</td>
<td data-label="CUI">Executive Order 13556 (the CUI program)</td>
</tr>
<tr>
<th scope="row">Baseline safeguards</th>
<td data-label="FCI">The 15 basic safeguards of FAR 52.204-21</td>
<td data-label="CUI">NIST SP 800-171 (110 controls) under DFARS 252.204-7012</td>
</tr>
<tr>
<th scope="row">CMMC level</th>
<td data-label="FCI">Level 1</td>
<td data-label="CUI">Level 2 at minimum</td>
</tr>
<tr>
<th scope="row">Verification</th>
<td data-label="FCI">Annual self-assessment in SPRS + annual affirmation</td>
<td data-label="CUI">Self-assessment; the third-party (C3PAO) path is currently suspended</td>
</tr>
<tr>
<th scope="row">Cloud requirement</th>
<td data-label="FCI">None specific in FAR 52.204-21</td>
<td data-label="CUI">FedRAMP Moderate (authorized or equivalent) per DFARS 252.204-7012(b)(2)(ii)(D)</td>
</tr>
<tr>
<th scope="row">Incident reporting</th>
<td data-label="FCI">None in FAR 52.204-21</td>
<td data-label="CUI">72-hour cyber incident reporting under DFARS 252.204-7012</td>
</tr>

Two notes on reading that table honestly. First, the categories nest in practice: a contractor handling CUI almost certainly handles FCI too, so the CUI column's obligations sit *on top of* the FCI column's — FAR 52.204-21(b)(2) says explicitly that the clause doesn't relieve you of CUI safeguarding requirements under Executive Order 13556. Second, the CMMC program even encodes the relationship: Level 1 assessment objectives are the NIST SP 800-171A objectives with FCI substituted wherever the objective says CUI (32 CFR § 170.15(c)(1)(i)). Level 1 genuinely is the foundation layer of [CMMC Level 2](/federal/cmmc-level-2/) — the same control families, at basic depth.

</section>

<section>

## What handling FCI obligates you to do

If FCI touches your systems, three things follow:

**The fifteen safeguards apply.** FAR 52.204-21 requires them on every covered contractor information system — meaning every system of yours that processes, stores, or transmits FCI. That system-level scoping is the practical mercy of Level 1: the CMMC assessment scope is those systems (32 CFR § 170.19(b)(1)), not your entire company, and Specialized Assets — IoT, operational technology, Government-Furnished Equipment, Restricted Information Systems, Test Equipment — are not part of the Level 1 scope and are not assessed.

**A CMMC Level 1 self-assessment, when your solicitation specifies it.** New DoD solicitations have carried CMMC requirements since November 10, 2025, and when a CMMC level is specified it must be met before award. For FCI-only contractors that means Level 1: an annual self-assessment against the [15 CMMC Level 1 requirements](/federal/cmmc-level-1-requirements/) and their 59 objectives, results entered in SPRS, affirmed annually by a senior company official — the mechanics are in our [SPRS score submission walkthrough](/federal/sprs-score-submission/). Since the [CMMC Phase II suspension](/federal/cmmc-phase-ii-suspended/), Level 1 (Self) is one of only two CMMC postures a contracting officer may currently designate, which has made the honest self-assessment the primary trust artifact rather than a warm-up act.

**It flows down.** Paragraph (c) of the clause pushes the same substance into subcontracts wherever FCI resides in or transits a sub's systems. Being small, commercial, or two tiers down doesn't exempt you — only COTS items are carved out.

None of that requires a certification, a consultant, or — for most small shops — new hardware. It requires knowing where FCI lives in your systems and being able to answer 59 plain questions honestly. That's exactly what our [free CMMC Level 1 self-assessment builder](/cmmc-level-1/) does: it walks you through scoping and all fifteen requirements in plain language, then generates the full document package if you pass — or a prioritized gap plan if you don't. Free, in your browser, answers never uploaded.

</section>

Tony Adams is the founder of Truvisory®. He builds Cloudflare-native AI systems for federal and commercial clients. SBA-verified SDVOSB and VOSB, SAM.gov-registered.

#### SPRS Score Submission, Step by Step: Entering Your CMMC Level 1 Self-Assessment — /federal/sprs-score-submission/

The <abbr title="Supplier Performance Risk System">SPRS</abbr> entry is the step where a CMMC Level 1 self-assessment becomes real. Until your results are in SPRS and affirmed, you don't have a CMMC status — you have a binder. And because the government's own guides are screenshot-heavy PDFs that occasionally disagree with their own prose, this walkthrough sticks to the labels that actually appear on screen, verified against the SPRS Quick Entry Guide (V4.0) and the February 2025 SPRS/PIEE briefing.

One disambiguation first, because the phrase "SPRS score" means two different things and conflating them causes real confusion in proposal rooms.

<ul>
<li><strong>"SPRS score" ≠ CMMC Level 1 entry.</strong> The numeric score (max 110, can go negative) is the NIST SP 800-171 Basic Assessment under DFARS 252.204-7019/-7020. The CMMC Level 1 entry has <em>no number</em> — it records Yes/No compliance with FAR 52.204-21. Same SPRS module, different records.</li>
<li><strong>The role gate:</strong> you need the "SPRS Cyber Vendor User" role via PIEE. If you can't find the "Add New CMMC Level 1 Self-Assessment" button, you don't have it.</li>
<li><strong>The flow:</strong> piee.eb.mil → LOG IN → SPRS → Cyber Reports → CMMC Assessments tab → enter the assessment → Continue to Affirmation → Transfer to AO → the AO checks "I certify…" and clicks Affirm.</li>
<li><strong>The statuses:</strong> "Pending Affirmation" until the AO acts; "Final Level 1 Self-Assessment" once affirmed (the regulation calls the same status "Final Level 1 (Self)"); and after 1 year, "No CMMC Status (Expired Assessment)."</li>
<li><strong>Keep your evidence:</strong> 32 CFR § 170.15(c)(2) requires assessment evidence to be retained for six years from the CMMC Status Date — the date results are submitted to SPRS.</li>
</ul>

<section>

## Two records, one system: the 800-171 score vs. the CMMC Level 1 entry

SPRS Cyber Reports holds two things a defense contractor cares about:

**The NIST SP 800-171 Basic Assessment score.** Required by DFARS 252.204-7019/-7020 since November 2020, independent of CMMC. It's a number produced under the DoD Assessment Methodology — perfect implementation of NIST SP 800-171 scores 110, and deductions for missing controls can push a score all the way down to −203. This is what people usually mean by "SPRS score," and if your contracts carry the 7019/7020 clauses, it still has to be current no matter what happens with CMMC.

**The CMMC assessment entry.** New with the CMMC program rule. At Level 1 there is no score of any kind: 32 CFR § 170.15(a)(1) requires every one of the [15 CMMC Level 1 requirements](/federal/cmmc-level-1-requirements/) — the safeguards of [FAR 52.204-21](/federal/far-52-204-21/) — to be MET, and SPRS asks you to attest that compliance as a literal Yes/No. Yes is required to achieve a "Final Level 1 Self-Assessment."

The rest of this article is about the second record. (Worth noting for context: since the [CMMC Phase II suspension](/federal/cmmc-phase-ii-suspended/) of July 13, 2026, self-assessment entries — Level 1 (Self) and Level 2 (Self) — are the only CMMC postures a contracting officer may currently designate, which makes getting this entry right more consequential, not less.)

</section>

<section>

## Before you start: the role chain

The prerequisite chain runs SAM → PIEE → SPRS, and it's where most first-time submitters lose a week:

1. **SAM.gov** — your entity registration is the root: UEI, CAGE code, and your CAGE hierarchy (which SPRS imports directly from SAM).
2. **PIEE** — the Procurement Integrated Enterprise Environment at piee.eb.mil. Your company establishes a vendor group and designates a Contractor Administrator (CAM).
3. **The role** — the CAM approves your request for the **"SPRS Cyber Vendor User"** role, which is what permits adding, editing, deleting, and affirming cyber assessments. The **"SPRS Contractor/Vendor (Support Role)"** is view-only — fine for the proposal team, useless for submission.

The diagnostic is blunt and reliable: if you're in SPRS and the **Add New CMMC Level 1 Self-Assessment** button isn't on your screen, you don't have the Cyber Vendor User role. Fix the role; don't hunt the menus.

</section>

<section>

## The walkthrough

From the PIEE landing page (piee.eb.mil), click <strong>LOG IN</strong>, select <strong>SPRS</strong>, then select <strong>Cyber Reports</strong>. There is no separate SPRS login — PIEE is the front door.

Choose the desired hierarchy, identified by the Highest Level Owner (HLO), from the drop-down. An asterisk next to an entry means you hold the SPRS Cyber Vendor User role for it — access to add, edit, and delete.

Within the <strong>CMMC Assessments</strong> tab, click <strong>Add New CMMC Level 1 Self-Assessment</strong>. (Both official guides' screenshots agree on that button label, even where the Quick Entry Guide's own prose transposes it.)

Five fields do the work: the <strong>assessment date</strong> (the date the self-assessment was conducted — not necessarily today); the <strong>assessing scope</strong> (Enterprise or Enclave); the <strong>employee count</strong> — scoped to the organization the self-assessment applies to, not necessarily total headcount; the <strong>included CAGE code(s)</strong>, comma-delimited if you're entering more than one, with an Open CAGE Hierarchy picker (the hierarchy imports from SAM); and the Yes/No question — <em>are you compliant with each of the security requirements specified in FAR clause 52.204-21?</em> Yes is required to achieve a "Final Level 1 Self-Assessment."

Click <strong>Continue to Affirmation</strong>. If you are not the Affirming Official, enter the AO's email and select <strong>Transfer to AO</strong>. The record sits at <strong>"Pending Affirmation"</strong> until the AO acts — and a pending record is not an eligible one.

The AO — under 32 CFR § 170.22(a)(1), the senior level representative from within the Organization Seeking Assessment (OSA) who is responsible for ensuring compliance with the CMMC Program requirements and has the authority to affirm the OSA's continuing compliance — opens the pending record, verifies their personal information and authority, optionally adds points of contact for contracting officers, checks the <strong>"I certify that I have read the above statement"</strong> box, and clicks <strong>Affirm</strong>. Read that affirmation statement before certifying: it warns that misrepresentation can bring criminal prosecution under 18 U.S.C. § 1001, civil liability under the False Claims Act, and contract remedies.

The affirmed record receives a <strong>CMMC Unique Identifier (UID)</strong> — the value you'll be asked to quote — and the status becomes <strong>"Final Level 1 Self-Assessment."</strong> That's the SPRS UI label; the regulation names the same status <strong>"Final Level 1 (Self)"</strong> (32 CFR § 170.15(a)). It is also the only Level 1 status type visible to Government personnel.

</section>

<section>

## Expiry, the annual cycle, and the six-year rule

Three dates govern the record after you close the browser tab:

**One year out.** In SPRS, a "Final Level 1 Self-Assessment" automatically becomes **"No CMMC Status (Expired Assessment)"** after 1 year. That flip is SPRS behavior — the rule behind it is 32 CFR § 170.15(a)(1)'s requirement for an annual self-assessment, with results submitted in SPRS, to maintain the status, paired with § 170.22's annual affirmation. Either way, the operational consequence is identical: calendar the re-assessment, because the expired status is a visible row, not a quiet lapse.

**Before award.** Under 32 CFR § 170.15(b), eligibility takes *both* the Final Level 1 (Self) status *and* the submitted affirmation. Transfer-to-AO on proposal-due day is how contractors miss this one.

**Six years back.** 32 CFR § 170.15(c)(2) requires the artifacts used as assessment evidence to be retained for six years from the **CMMC Status Date** — which § 170.4 defines as the date the results are submitted to SPRS, not the affirmation date. Screenshots, exports, policies, logs: keep them, dated, where you can find them.

</section>

<section>

## The part before SPRS

Everything above assumes the self-assessment itself is done honestly — 15 requirements, 59 assessment objectives, every finding MET or NOT APPLICABLE, evidence in final form. That's the actual work, and it's the part a Yes/No radio button can't do for you. If you haven't run it yet, our [free CMMC Level 1 self-assessment tool](/cmmc-level-1/) walks you through every objective in plain language and generates the document package and SPRS-ready worksheet this walkthrough assumes you're holding. And if your contracts involve CUI rather than just [Federal Contract Information (FCI)](/federal/what-is-fci/), the level you should be reading about is [CMMC Level 2](/federal/cmmc-level-2/).

</section>

Tony Adams is the founder of Truvisory®. He builds Cloudflare-native AI systems for federal and commercial clients. SBA-verified SDVOSB and VOSB, SAM.gov-registered.

### FAR 52.204-21, Explained: All 15 Basic Safeguarding Requirements, Annotated — /federal/far-52-204-21/

(Older post — see permalink for full content.)

### The 15 CMMC Level 1 Requirements, Explained in Plain Language — /federal/cmmc-level-1-requirements/

(Older post — see permalink for full content.)

### What Is a Fractional CTO? Role & When to Hire (2026) — /fractional-cto/what-is-a-fractional-cto/

(Older post — see permalink for full content.)

### Spokes

### How Much Does a Fractional CTO Cost? (2026 Pricing Guide) — /fractional-cto/fractional-cto-cost/

(Older post — see permalink for full content.)

### Fractional CTO vs Full-Time CTO: Which Does Your Company Need? — /fractional-cto/fractional-cto-vs-full-time/

(Older post — see permalink for full content.)

### Ship in 90 Days: What a Build-Capable Fractional CTO Delivers in the First Quarter — /fractional-cto/fractional-cto-90-day-plan/

(Older post — see permalink for full content.)

### What Does a Fractional CTO Do? Responsibilities, Deliverables & Scope — /fractional-cto/what-does-a-fractional-cto-do/

(Older post — see permalink for full content.)

### Fractional CAIO vs Fractional CTO: Which Do You Need? — /fractional-cto/fractional-caio-vs-cto/

(Older post — see permalink for full content.)

### Fractional AI CTO: What It Is, When You Need One, and What One Actually Does — /fractional-cto/fractional-ai-cto/

(Older post — see permalink for full content.)

### The Fractional CTO Who Actually Ships: Advisory vs Build-Capable Technical Leadership — /fractional-cto/fractional-cto-that-ships/

(Older post — see permalink for full content.)

### The Cloudflare-Native Fractional CTO: Why an Edge-Native Technical Leader Ships Faster — /fractional-cto/fractional-cto-cloudflare-native/

(Older post — see permalink for full content.)

### Fractional CTO vs AI Consultant: Which Does Your Company Actually Need? — /fractional-cto/fractional-cto-vs-ai-consultant/

(Older post — see permalink for full content.)

### AI Observability, Cost, and Evaluation on Cloudflare: How AI Gateway Stops You Flying Blind — /cloudflare/ai-observability-cost-evals/

(Older post — see permalink for full content.)

### Spokes

### Cloudflare AI Gateway as Your Observability Layer: Every LLM Request, Logged and Queryable — /cloudflare/ai-gateway-observability/

(Older post — see permalink for full content.)

### Cloudflare Audit Logs for AI: A Tamper-Evident, Compliance-Grade Record of Every AI Request — /cloudflare/ai-audit-logging/

(Older post — see permalink for full content.)

### Multi-Provider AI Routing on Cloudflare: Fallback, Retries, and BYOK That Keep Your App Up — /cloudflare/ai-gateway-routing-failover/

(Older post — see permalink for full content.)

### Latency Engineering for AI on Cloudflare: Cache the Hot Path, Stream the Rest, Route to Faster Models — /cloudflare/ai-caching-latency/

(Older post — see permalink for full content.)

### Controlling AI Model Costs on Cloudflare: The Levers That Actually Reduce Token Spend — /cloudflare/ai-cost-control/

(Older post — see permalink for full content.)

### AI Evals on Cloudflare: How to Measure Whether Your AI Is Actually Good — /cloudflare/ai-evals/

(Older post — see permalink for full content.)

### Building Production AI Agents on Cloudflare: The Complete Stack — /agents-mcp/building-ai-agents-cloudflare/

(Older post — see permalink for full content.)

### Spokes

### How to Build and Host a Remote MCP Server on Cloudflare (McpAgent, OAuth, Portals, Code Mode) — /agents-mcp/host-mcp-server-cloudflare/

(Older post — see permalink for full content.)

### The Cloudflare Agent Is a Durable Object: How Per-Agent State Works — /agents-mcp/agents-sdk-durable-objects/

(Older post — see permalink for full content.)

### Cloudflare Agents vs. LangGraph (and Where AWS Bedrock AgentCore Fits): Framework vs. Runtime — /agents-mcp/cloudflare-vs-langgraph/

(Older post — see permalink for full content.)

### Browser and Code-Execution Agents on Cloudflare: How Agents Act with Browser Run and Sandboxes — /agents-mcp/browser-agents/

(Older post — see permalink for full content.)

### Agent Memory and Grounding on Cloudflare: Long-Term Memory vs. RAG, and When to Use Each — /agents-mcp/agent-memory-ai-search/

(Older post — see permalink for full content.)

### Real-Time Voice Agents on Cloudflare: The Streaming Speech-to-Text → LLM → Text-to-Speech Loop — /agents-mcp/voice-agents/

(Older post — see permalink for full content.)

### Durable Execution for AI Agents: How Cloudflare Workflows Makes Multi-Step Work Survive Failure — /agents-mcp/durable-agent-workflows/

(Older post — see permalink for full content.)

### AI Use Cases by Industry: Where Mid-Market Companies Actually Get ROI — /commercial/ai-use-cases-by-industry/

(Older post — see permalink for full content.)

### Spokes

### AI for Professional Services Firms: Where Law, Accounting, and Consulting Firms Actually Get ROI — /commercial/ai-for-professional-services/

(Older post — see permalink for full content.)

### AI for Commercial Real Estate and Property Management: Where CRE Firms Actually Get ROI — /commercial/ai-for-real-estate/

(Older post — see permalink for full content.)

### AI for E-Commerce and DTC Brands: Where Online Retailers Actually Get ROI — /commercial/ai-for-ecommerce/

(Older post — see permalink for full content.)

### AI for Medical Practices: Where Clinics Actually Get ROI (Ambient Scribing, Intake, Prior Auth, and Scheduling) — /commercial/ai-for-medical-practices/

(Older post — see permalink for full content.)

### AI for Financial Services and Insurance: Where Mid-Market Firms Actually Get ROI — /commercial/ai-for-financial-services/

(Older post — see permalink for full content.)

### AI for Field Service and Home Services: Where Trades Companies Actually Get ROI — /commercial/ai-for-field-service/

(Older post — see permalink for full content.)

### Why 95% of AI Pilots Fail — and How Mid-Market Companies Ship in 90 Days — /commercial/why-ai-pilots-fail-mid-market/

(Older post — see permalink for full content.)

### Spokes

### How Much Does AI Implementation Actually Cost for a Mid-Market Business? (2026) — /commercial/ai-implementation-cost/

(Older post — see permalink for full content.)

### Build vs Buy vs Partner: The AI Decision Framework for Operators — /commercial/ai-build-vs-buy-vs-partner/

(Older post — see permalink for full content.)

### The 90-Day AI Production Sprint: How Mid-Market Ships AI in a Quarter — /commercial/90-day-ai-sprint/

(Older post — see permalink for full content.)

### Fixed-Fee vs Retainer AI Consulting: What Actually Gets Shipped — /commercial/fixed-fee-vs-retainer-ai-consulting/

(Older post — see permalink for full content.)

### Why Back-Office Automation Beats the Flashy AI Chatbot — /commercial/back-office-automation-vs-chatbot/

(Older post — see permalink for full content.)

### Is Your AI Project in 'Pilot Purgatory'? 7 Warning Signs (and the Fix for Each) — /commercial/ai-pilot-purgatory-warning-signs/

(Older post — see permalink for full content.)

### VA AI Modernization for SDVOSBs: The $10.2B Procurement Ground Truth — /federal/va-ai-modernization/

(Older post — see permalink for full content.)

### Spokes

### VA Compliance: Why FedRAMP-Aware Is Right and CMMC Doesn''t Apply — /federal/va-compliance-fedramp-not-cmmc/

(Older post — see permalink for full content.)

### VA Veterans First and the Rule of Two: Why the VA Buys From SDVOSBs First — /federal/va-veterans-first-ai/

(Older post — see permalink for full content.)

### VA T4NG2 for SDVOSBs: How to Win AI and Automation Work on the $60.7B Vehicle — /federal/va-t4ng2-sdvosb/

(Older post — see permalink for full content.)

### VA SPRUCE for SDVOSBs: The $2.4B 100% Set-Aside Vehicle for VA Digital and AI Work — /federal/va-spruce-sdvosb-idiq/

(Older post — see permalink for full content.)

### VA SDVOSB Sole-Source for AI: The $5M Veterans First Fast Lane — /federal/va-sole-source-ai-5m/

(Older post — see permalink for full content.)

### VA AI Tech Sprint Follow-Ons: How an SDVOSB Turns a Demo Into a VA Contract — /federal/va-ai-tech-sprint-followons/

(Older post — see permalink for full content.)

### The SDVOSB Capability Statement That Actually Wins VA AI Work — /federal/va-capability-statement-sdvosb-ai/

(Older post — see permalink for full content.)

### NVSBE Is Gone: How a New SDVOSB Works VA Events in 2026 — /federal/nvsbe-industry-days-va/

(Older post — see permalink for full content.)

### REACH VET: The Honest SDVOSB Role Near the VA''s Suicide-Risk Model — /federal/reach-vet-predictive-va/

(Older post — see permalink for full content.)

### Contact-Center AI at the VA: The Honest SDVOSB Role — /federal/contact-center-ai-va/

(Older post — see permalink for full content.)

### VA Claims Automation and ADS: What AI Can and Can''t Do — /federal/va-claims-automation-ads/

(Older post — see permalink for full content.)

### Teaming for VA AI: How an SDVOSB Gets Onto T4NG2 and SPRUCE Work — /federal/teaming-t4ng2-va-ai/

(Older post — see permalink for full content.)

### How to Forecast VA AI Work Before the RFP Drops — /federal/ai-opportunity-forecast-va/

(Older post — see permalink for full content.)

### Polaris for VA AI Work: The One SDVOSB GWAC With a Door Still Open — /federal/polaris-sdvosb-va-ai/

(Older post — see permalink for full content.)

### VA M-25-21 and High-Impact AI: The Governance Layer Vendors Keep Missing — /federal/va-m-25-21-trustworthy-ai/

(Older post — see permalink for full content.)

### VA ATO, VAEC, and FedRAMP: How AI Actually Ships on VA Infrastructure — /federal/va-ato-vaec-fedramp/

(Older post — see permalink for full content.)

### VA RAG Policy Assistants: Grounded, Cited Answers — Not a Chatbot — /federal/va-rag-policy-assistant/

(Older post — see permalink for full content.)

### VA Document Automation with AI: The SDVOSB Capability Play — /federal/va-document-automation-ai/

(Older post — see permalink for full content.)

### AI Leadership in 2026: Governance Is Table Stakes, Delivery Is the Job — /federal/ai-leadership-2026/

(Older post — see permalink for full content.)

### VA EHRM (Oracle Health): The Honest SDVOSB Subcontracting Map — /federal/ehr-oracle-ai-subwork-va/

(Older post — see permalink for full content.)

### Who Actually Buys VA AI: TAC vs. SAC for SDVOSBs — /federal/tac-sac-acquisition-va/

(Older post — see permalink for full content.)

### VETS 2 for VA AI Work: A Closed GWAC You Team Into, Not Onto — /federal/vets-2-va-ai/

(Older post — see permalink for full content.)

### Why We Build AI on Cloudflare: The Mid-Market and Federal Case for a Cloudflare-Native AI Stack — /cloudflare/why-build-ai-on-cloudflare/

(Older post — see permalink for full content.)

### Spokes

### Cloudflare Workers vs AWS Lambda for AI Inference (2026) — /cloudflare/workers-vs-lambda-ai-inference/

(Older post — see permalink for full content.)

### The Real Cost of Cloudflare Workers vs AWS Lambda for an AI App — /cloudflare/workers-vs-lambda-cost/

(Older post — see permalink for full content.)

### Why Edge AI Beats Centralized Inference for User-Facing Features — /cloudflare/edge-ai-vs-centralized-inference/

(Older post — see permalink for full content.)

### AI Modernization for Federal Agencies: Why the SDVOSB Path Is the Fast Lane — /federal/federal-ai-modernization/

(Older post — see permalink for full content.)

### Spokes

### CMMC Phase II Is Suspended: The Gate Moved, the Bar Didn't — /federal/cmmc-phase-ii-suspended/

(Older post — see permalink for full content.)

### How to Verify an AI Contractor's FedRAMP Posture (Before You Award) — /federal/verify-ai-contractor-cmmc-fedramp/

(Older post — see permalink for full content.)

### Sole-Sourcing AI to an SDVOSB: The $5M Direct-Award Path — /federal/sole-source-ai-to-sdvosb/

(Older post — see permalink for full content.)

### Why Federal AI Pilots Stall — and How to Scope One That Actually Ships — /federal/why-federal-ai-pilots-stall/

(Older post — see permalink for full content.)

### Which Contract Vehicle Should You Buy AI On? A Decision Framework for Federal Buyers — /federal/buy-sdvosb-ai-contract-vehicle/

(Older post — see permalink for full content.)

### Year-End Funds, Fast: Obligating AI Dollars via SDVOSB Sole-Source — /federal/year-end-ai-funds-sdvosb/

(Older post — see permalink for full content.)

### How the 2025 FAR Part 19 Overhaul Lets You Direct-Award AI Work to an SDVOSB — /federal/far-part-19-direct-award/

(Older post — see permalink for full content.)

## Field notes

### Region-pinning, audit logging, and the FedRAMP-aware edge stack. — /federal/fedramp-aware/

(Older post — see permalink for full content.)

### Why mid-market keeps overpaying for AI strategy. — /commercial/mid-market-strategy/

(Older post — see permalink for full content.)

### Designing every agent against MCP first. — /cloudflare/mcp-first/

(Older post — see permalink for full content.)

### Hyperdrive database acceleration is a graceful exit from legacy SQL. — /cloudflare/hyperdrive/

(Older post — see permalink for full content.)

### Cloudflare Durable Objects are the missing primitive for production agents. — /cloudflare/durable-objects/

(Older post — see permalink for full content.)

### Recursive Language Models, in production. — /cloudflare/rlm-production/

(Older post — see permalink for full content.)

### At 5% GPU utilization, the math doesn't work. Here's what does. — /cloudflare/gpu-math/

(Older post — see permalink for full content.)

### SDVOSB is leverage. Use it. — /federal/sdvosb-leverage/

(Older post — see permalink for full content.)

### OMB M-25-21 reads like a buying spec for fixed-scope AI. — /federal/omb-buying-spec/

(Older post — see permalink for full content.)

### A 30-minute AI Audit, scripted. — /commercial/ai-audit-scripted/

(Older post — see permalink for full content.)
