Enterprise Kansas City
Growing the Kansas City innovation economy and the companies, jobs and talent that come with it.
QuantaSeek® is the one platform for building your dedicated control plane for physical and virtual identity and access management, from drones to vehicles to gates. Automate trusted identity across your entire enterprise, with defense-grade continuous authentication that runs at the edge, in the cloud, or fully air-gapped.
A 5U rackmount system that pairs GPU-accelerated LLM inference with Lewis Rhodes Labs' ExtremeSearch® neuromorphic search. It reads raw bytes directly, so analysis that used to take hours or days returns in seconds, and every answer is grounded in your own data through a retrieval-augmented core.
Every layer shares one identity control plane. What QuantaSeek® finds in your data and what the Adaptive Risk Engine sees in every session feed one live score that decides, second by second, whether access stays open.
Threats don't respect the line between a badge reader and a login screen. SOFTwarfare.AI ties people, non-human identities, places, systems, and autonomous machines into one verified, intelligent fabric, so your team sees what's happening, knows who is behind it, and responds in real time.
Fuse cameras, full-motion video, sensors, access control, logs, and machine telemetry into one live operating picture with QuantaSeek® and its QuantaSight™ module.
Zero Trust Identity® continuously correlates who and what is acting, across humans, machines, and locations, not just once at the door or the login.
AI and policy score risk in real time and surface the handful of events that matter out of thousands of feeds. Your operators make the call.
Step up authentication, lock a door, end a session, or dispatch a team from one command layer, with every action tied to a verified identity.
See physical security command and control · Securing AI agents? See agent identity and access · See next-generation C2 identity
Vendor-neutral by design. We work with the cameras, sensors, identity providers, and systems you already own, in cloud, hybrid, on-premises, or fully air-gapped environments. No rip-and-replace. The AI watches everything so your people can focus on what matters, and a human always stays in the loop.
"Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location."
NIST SP 800-207
"Authentication and authorization (both subject and device) are discrete functions performed before a session to an enterprise resource is established."
NIST SP 800-207
"Federal agencies SHALL require their staff, contractors, and partners to use phishing-resistant authentication to access federal information systems."
NIST SP 800-63B-4
Technology alone doesn't hold the line. Every deployment comes with a team led by veterans of Army Special Operations and the Ranger Regiment, who help you design, integrate, and tune your control plane around your sites and your mission.
Talk to our teamDelivered from our Kansas modular edge data centers, so mid-market operators get continuous identity without building a security operation.
Automated playbooks that step up, lock down, or escalate the moment identity and context don't line up, with every action logged to a verified identity.
Assessments, deployment, and ongoing optimization through our mission support agreement, built around the systems you already run.
One verified identity for every person, machine, and autonomous system, whether it's badging through a gate, driving onto an installation, flying a mission, or logging into a console. The same control plane decides access in both worlds, and the same risk engine watches both.
No. PangaeAPI® connects the systems you already own, including legacy directories, video management systems, OT networks, and decades-old defense protocols, without custom code.
Yes. QuantaSeek®, QuantaSight™, and Zero Trust Identity® run fully air-gapped on appliances at the edge. Nothing phones home, and your data and video stay inside your facility.
AI correlates signals, scores risk, and isolates the events that matter across thousands of feeds and logs. Policy you define decides the response, and your operators always keep the final call.
Through Carahsoft on NASA SEWP V, ITES-SW2, NASPO ValuePoint, OMNIA Partners, E&I and The Quilt, or directly under our SBIR Phase III sole-source authority. See contract vehicles.
A Kansas-built Secure AI Ops company, founded on a Special Operations mindset and proven with the U.S. Army, Navy, and Air Force. We protect defense, critical infrastructure, banking, and manufacturing, and we invest in the communities we defend.
Build your dedicated control plane for physical and virtual identity. Start with one site and scale to every installation, plant, branch, and fleet.
Attackers no longer need your password. They steal the session token after MFA succeeds and walk in as you. Zero Trust Identity keeps checking biometric, behavioral, device, and network signals for the entire session, and closes it the moment the risk crosses your policy line.
The chart shows a real pattern we defend against: a clean login, normal work, then a hijacked session token replayed from a new device.
Dashed red line is the policy threshold. Response options include step-up, re-authentication, de-authorization, or termination, with a human in the loop or fully automated.
Defense proved the platform. Energy, finance, and critical infrastructure buy the same hardened stack at commercial terms, quoted through World Wide Technology, Carahsoft, and Google Cloud Marketplace.
Isolated SCADA and remote pipelines. Continuous identity down to the operator console, no cloud dependency.
Energy solutionsPetabytes of transaction logs searched in seconds. Session theft stopped before a wire goes out.
Finance solutionsDDIL-ready identity and AI for warfighters, primes, and the 220,000-company defense industrial base.
Defense solutionsUtilities, manufacturing, and healthcare. Legacy systems wrapped in phishing-resistant, continuous authentication.
Infrastructure solutionsYour existing partners can quote us today. Commercial buyers can draw down Google Cloud commitments, and agencies use pre-negotiated Carahsoft vehicles.
Spend your final 180 days of service on a team built by veterans, building identity and AI capabilities for the mission you just left.
Explore SkillBridgeSOFTwarfare.AI is American-owned and American-built, with a team of veterans and engineers who never stopped serving. Every line of code we write protects the warfighters, workers, and communities that keep this country free.
We build capabilities to defend the American way of life. That way of life lives in classrooms, gyms, small towns and the families of those who serve, so we invest there too. It is the part of our work we value most.
Bring a sample of raw logs or telemetry. We run it on an air-gapped appliance in front of your team.
An industrial 5U AI Ops appliance that searches petabytes of raw data in seconds, answers in plain language, and never phones home.
Large language models are powerful readers and slow searchers. Traditional SIEM and data lake pipelines must parse and index everything before anyone can ask a question, which costs hours to days and a lot of storage. In disconnected environments, the index often never gets built at all.
QuantaSeek® moves the search into hardware. Lewis Rhodes Labs' ExtremeSearch® processor, modeled on how the brain filters signal from noise, scans raw bytes at line rate and hands only relevant material to the GPU-hosted model. The retrieval-augmented core then grounds every answer in your own verified records, with citations back to the source bytes.
Logs, sensor telemetry, PCAP, documents, test data, and video metadata. No schema, no index.
ExtremeSearch® and FPGA hyper-indexing pull matches from petabytes on low-power processing units.
On-appliance models correlate the filtered evidence and draft an answer.
Answers tie back to source records. Analysts trust the result the first time.
The 5U configuration sold through World Wide Technology and Carahsoft. Final bill of materials is confirmed per order.
| Form factor | Industrial 5U, 19-inch rackmount. Ruggedized transit-case variant for forward deployment. |
|---|---|
| Host compute | Intel® Xeon® server platform |
| AI inference | GPU-accelerated on-appliance LLM with retrieval-augmented generation core |
| Search acceleration | Lewis Rhodes Labs ExtremeSearch® neuromorphic processing; Intel Agilex® FPGA hyper-indexing on PCIe 4.0 |
| Processing units | 30W neuromorphic units, a fraction of GPU-only power draw |
| On-board storage | 64 TB NVMe per node, fully encrypted |
| Data scope | Petabyte-scale federated search across attached and networked stores |
| Connectivity | Fully air-gapped operation supported. No cloud back-haul required. |
| Identity | Zero Trust Identity® control plane built in, with continuous verification for operators, services, and AI agents |
| Deployment modes | Tactical edge (portable, DDIL), enterprise (scalable, multi-tenant), hybrid (on-prem plus cloud) |
Complex analysis compressed from hours or days to seconds, on data no one had time to index.
Low-power neuromorphic filtering means fewer GPUs, less cooling, and less rack space per question answered.
Grounded retrieval removes the hallucination tax. Every answer points to its source.
Run disconnected. Your data stays in your facility, your jurisdiction, your classification level.
Choose a lens, ask the question the way you'd ask an analyst, and QuantaSeek® answers from your own data in seconds. The Data Provenance panel shows exactly which records the neural search surfaced, so every answer can be checked.
Cyber-physical signal intelligence, IoT telemetry, finance, claims, video. The lens tunes how QuantaSeek® reads your data.
Here: five devices under active attack, with timestamps and anomalous values, found in raw telemetry that was never indexed.
Every claim traces to the source record the neural processing unit retrieved. No black box, no hallucination tax.
ISAAC fuses AIS maritime tracks, IoT devices, cyber events, and MITRE ATT&CK® techniques onto a single area of interest. Alerts, recommended actions, confidence, fabric health, and ranked courses of action sit side by side, so operators move from detection to decision without switching tools.
AIS spoofing, a Modbus injection pattern, and MITRE T1595 active scanning linked into one picture.
"How I found this": the lens, dataset, and chunks behind every conclusion.
Ranked options for the operator to select. The human decides; QuantaSeek® shows the work.
QuantaSight adds real-time video to everything QuantaSeek® already searches. It ingests live full-motion video from fixed cameras, UAS and ISR platforms, vehicles, and body-worn cameras, then correlates what it sees with verified identities in Zero Trust Identity®.
Search and correlate feeds across sites and partner networks without backhauling every stream to one place. Video stays where it's captured.
Match a person at the gate, the door, or the flightline to the same identity logging in at the console, so one policy governs both.
AI watches thousands of feeds at once and isolates the moments that matter, so operators stay sharp instead of staring at monitors.
Ask for the vehicle, the person, or the event, and get grounded answers with the timestamped clip as the source.
Runs on the QuantaSeek® appliance at the tactical edge, with no cloud dependency and no video leaving your facility.
Works with the cameras and video management systems you already run.
Correlate historian data, PLC logs, badge readers, and camera events across a pipeline network in one question, without routing OT data outside the plant.
Search raw transaction and access logs in seconds to link account takeover, mule activity, and privileged misuse across systems.
Discover and correlate technical documents, test data, sensor feeds, and logistics records across command-and-control environments.
No. QuantaSeek® reads raw data where it lands. You can optionally build persistent hyper-indexes for repeated queries.
No. The models, search engine, and identity control plane all run on the appliance. Hybrid mode is available if you want it.
Every person, service account, and AI agent authenticates through Zero Trust Identity and is re-verified throughout the session. Access is scoped by persona and data classification.
Through World Wide Technology for enterprise accounts, Carahsoft for public sector vehicles, or directly. List price is $1,000,000 per appliance with a required 20% annual support agreement.
Continuous, phishing-resistant authentication for every human, machine, and AI agent that touches compute. Verified at login, and every second after.
Layered multimodal biometrics with liveness detection: face, retina, iris, palm, voice, and fingerprint. Passwordless desktop login and SSO. Behavioral analytics score the session continuously, so the credential stops being an attack surface.
The encrypted integration backbone. Connects modern IdPs, legacy directories, OT systems, and decades-old defense protocols without custom code. It's why deployments take weeks, not quarters.
A zero trust engine for agentic AI. Agents get identities, scopes, and continuous re-verification, and their data access is governed at the edge.
Most organizations run physical access and digital access as two separate worlds, and attackers live in the gap between them. Zero Trust Identity® closes it. The same verified identity opens the door, unlocks the workstation, and authorizes the API call, and the same Adaptive Risk Engine watches all three.
When QuantaSeek® and its QuantaSight™ module add video and sensor context, a badge used in Kansas City while the same account logs in from overseas isn't two unrelated alerts. It's one high-risk identity, stopped in real time.
Employees, contractors, warfighters, and visitors, verified with layered biometrics bound to the person.
Service accounts, API keys, and workloads, governed with the same continuous scrutiny as people.
Drones, robots, vehicles, and agents that act on your behalf, each with a verifiable identity and a policy.
Doors, gates, SCIFs, control rooms, and racks, where location becomes part of every access decision.
A live 1–100 score for each identity, from geolocation, behavioral biometrics, device fingerprint, SIEM and SOC data, threat feeds, and behavioral analytics.
Granular, rule-based access modeled on firewall rules, so operators read policies the way they already think. Adaptive policies, session management, and ML anomaly detection.
Step-up authentication, re-authentication, de-authorization, or session termination. Human in the loop or fully automated.
Employees, contractors, operators, and warfighters, with biometrics bound to the person rather than a phone or token.
Workloads, services, PLCs, and devices, identified by fingerprint and re-verified mid-session. Machine identities now outnumber humans by roughly 109 to 1.
Agents authenticate, move laterally, and touch data. We give each one an identity, a scope, and a joiner-mover-leaver process.
Share, segment, and protect information across organizations and domains without losing control of who sees what.
Remove redundant accounts across enterprise and tactical directories.
Enforce minimum necessary access across organizational boundaries.
Enforce zero trust while working alongside external identity providers.
Integrate tactical systems with SIPRNet initiatives as DoD requirements evolve.
Support large multinational deployments as users and resources grow.
Cloud, on-premises, air-gapped, and DDIL, on the same policy model.
Cloud identity providers were built for a connected human workforce. Our market starts where that architecture ends.
| Capability | Cloud IAM (Okta, Ping, Entra) | Machine identity vendors | New agentic AI security | SOFTwarfare.AI |
|---|---|---|---|---|
| Phishing-resistant human MFA | Yes | Partial | No | Yes |
| Machine and workload identity | Partial | Yes | Partial | Yes |
| AI agent identity and governance | Partial | Partial | Yes | Yes |
| Air-gapped and DDIL operation | No | No | No | Yes |
| Legacy OT, ICS, and defense protocols | No | Partial | No | Yes |
| Edge AI data fusion on owned hardware | No | No | No | Yes |
| Continuous session-long re-verification | Partial | No | Partial | Yes |
Identity and AI for nuclear plants, pipelines, and the SCADA, ICS, and OT networks that can't tolerate cloud latency or depend on a back-haul link.
Pipelines, well pads, refineries, and substations run on isolated control networks and decades-old protocols. Shared operator logins and vendor remote access are common, and a cloud-dependent MFA prompt is useless when the satellite link drops. Investigations mean pulling historian data, PLC logs, and camera footage by hand.
| Recommended bundle | QuantaSeek® 5U + Zero Trust Identity Mission edition |
|---|---|
| Deployment | On-prem, air-gapped control network |
| Identities | Operators, engineers, vendors, PLCs, gateways, AI agents |
| Program alignment | Designed to support NERC CIP, ISA/IEC 62443, and TSA pipeline security programs |
| Starting investment | $1,000,000 appliance + $200,000/yr support, plus $8.75 per operator per month |
Broad enough to fit your environment, specific enough to start a pilot next month.
Continuous biometric verification for reactor operators and shift turnover, with walk-away locking on every console.
Verified technician access at unmanned sites over satellite or cellular links, with no cloud dependency.
Identity that works on rigs and well pads when back-haul is intermittent or gone.
Time-boxed, scoped maintenance sessions that expire automatically.
QuantaSeek® correlates historian data, PLC logs, badge events, and video in seconds.
Physical and digital access governed together at substations, solar, and wind farms.
Illustrative screen with sample data.
Fence sensors, cameras, gates, and badge readers feed the same command layer that protects your control systems. An intrusion at the perimeter steps up access to the OT network automatically.
Your firm is sitting on its biggest edge: decades of client, claims, and transaction data nobody has time to read. QuantaSeek® turns all of it into answers in seconds, and Zero Trust Identity® makes sure the only people asking are the ones who should be.
CRM notes, call transcripts, statements, claims files, and emails hold the signals. Most of it never gets searched.
The firm that spots the liquidity event, the at-risk household, or the fraud ring first keeps the assets.
Account takeover, deepfake voice, and session hijacking now bypass MFA and move money in minutes.
SEC Reg S-P, FINRA, NYDFS Part 500, GLBA, and state insurance data security laws all expect strong, auditable access controls.
For RIAs, multi-family offices, and asset managers scaling through acquisition, the data from every advisor, custodian, and tuck-in firm lives in different systems. QuantaSeek® searches all of it at once, without a data warehouse project first.
| Household | Advisor | AUM | 90-day flow | Signal | Risk |
|---|---|---|---|---|---|
| HH-20417 | Team North | $11.4M | -18.2% | Business sale closing Q4 | High |
| HH-08862 | Team Plaza | $6.9M | -14.7% | ACATS request, 2 accounts | High |
| HH-31190 | Team North | $4.2M | -12.9% | Inheritance, new beneficiary | Medium |
| HH-17755 | Team Lakes | $3.1M | -12.1% | 401(k) rollover at old employer | Opportunity |
Illustrative screen with sample data. Not investment advice.
Illustrative screen with sample data.
Carriers, MGAs, and brokers win on underwriting precision and claims speed. Both depend on reading more data, faster, than the next carrier.
| Cluster | Claims | Shared entity | Paid + reserved | Pattern | Priority |
|---|---|---|---|---|---|
| C-01 | 23 | Roofing contractor + 1 payee account | $1.84M | Policies under 6 months, same photo metadata | Refer SIU |
| C-02 | 11 | Public adjuster | $0.92M | Loss outside storm path per radar | Refer SIU |
| C-03 | 8 | Contractor invoice template | $0.41M | Identical line items, different addresses | Review |
| C-04 | 6 | Repeat claimant | $0.18M | Third claim in 24 months | Monitor |
Illustrative screen with sample data.
Correlate trades, chats, email, and voice in seconds for market-abuse and off-channel reviews.
Ask plain-language questions across filings, transcripts, and internal research without sending data to a public model.
Continuous verification on trading desks and admin consoles, with walk-away locking on shared terminals.
| Recommended bundle | Zero Trust Identity® Enterprise edition + QuantaSeek® for advisory, fraud, claims, and SOC teams |
|---|---|
| Deployment | Google Cloud tenant, on-prem, or hybrid |
| Procurement | Google Cloud Marketplace ↗, eligible to draw down existing Google Cloud commitments |
| Frameworks | SEC Reg S-P, FINRA, NYDFS Part 500, GLBA Safeguards Rule, NAIC Insurance Data Security Model Law, PCI DSS v4.0 |
| Starting investment | $5.75 per user per month; QuantaSeek® $1,000,000 + 20% annual support |
Continuous assurance for warfighters, platforms, installations, and the defense industrial base, in contested and disconnected networks, now with real-time full-motion video identity.
Our engineering is led by retired Special Operations and Army leadership, including a JSOC and JCU tactical edge network engineer. We build for the environment where networks fail and adversaries are already inside.
| SBIR status | Phase III, sole-source direct award authority under 15 U.S.C. § 638(r)(4) |
|---|---|
| Army vehicle | PEO C3N contract W15P7T-25-C-0003, expandable by task order |
| Contract vehicles | NASA SEWP V, ITES-SW2, NASPO ValuePoint via Carahsoft. All vehicles |
| Identifiers | CAGE 970S2, UEI XY86SLF9NCK7, NAICS 513210 |
| Recommended bundle | Zero Trust Identity® Mission edition + QuantaSeek® tactical configuration with QuantaSight™ and Federated ICAM |
Decision advantage starts with knowing that every actor on your network is who, and what, it claims to be. SOFTwarfare.AI brings high-assurance, continuous authentication to all three identity classes on the modern battlefield, and keeps working when the network is contested, degraded, or gone.
Layered biometrics bound to the person, paired with CAC and PIV credentials.
UAS, loitering munitions, tactical vehicles, sensors, and hypersonics, each with an attested identity.
Mission agents that search, summarize, and recommend on a commander's behalf.
QuantaSeek® edge nodes form an encrypted, identity-bound mesh across the battlespace. Every packet, video frame, and query is tied to a verified identity as it flows through PangaeAPI® secure integrations back to command and control.
Nodes cache, verify, and decide locally, then synchronize when the link returns. The mesh degrades gracefully instead of failing closed.
Every exchange is mutually authenticated and encrypted end to end, so a captured node or spoofed feed can't inject trusted data.
PangaeAPI® connects mission systems, legacy protocols, and coalition networks without custom code or new attack surface.
At the command post, QuantaSeek® turns petabytes of raw sensor data, full-motion video, intelligence reports, and logistics records into grounded answers in seconds. Commanders ask questions in plain language, see every answer tied to its source, and weigh AI-generated courses of action.
Nothing executes without a verified human decision. Every query, recommendation, and order is authenticated by Zero Trust Identity® and recorded for after-action review.
The side that observes, orients, decides, and acts faster wins. SOFTwarfare.AI accelerates every stage of the loop while keeping every step verified.
QuantaSight™ and the data mesh fuse live FMV, sensors, and signals into one picture.
QuantaSeek® correlates petabytes of raw data in seconds, with every source cited.
Generative AI frames courses of action. The commander chooses.
Orders flow to verified warfighters, platforms, and agents only.
Mapped to MITRE ATT&CK® and the MITRE D3FEND™ countermeasures SOFTwarfare.AI implements.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T1078 Valid Accounts | D3-MFA Multi-factor Authentication | Continuous biometric and credential verification, so stolen credentials don't grant mission access. |
T1557 Adversary-in-the-Middle | D3-ET Encrypted Tunnels | Mutually authenticated, identity-bound links across the mesh. |
T1550 Use Alternate Authentication Material | D3-ANCI Authentication Cache Invalidation | Tokens are re-verified continuously and invalidated the moment risk changes. |
T1621 MFA Request Generation | D3-MFA Multi-factor Authentication | No push prompts to fatigue. Verification is passive and continuous. |
T1528 Steal Application Access Token | D3-CRO Credential Rotation | Short-lived, task-bound credentials for platforms and agents. |
T0859 Valid Accounts (ICS) | D3-NI Network Isolation | Platform and OT access segmented and brokered through verified identity. |
Broad enough to fit your environment, specific enough to start a pilot next month.
Federated ICAM and QuantaSight™ at entry control points.
Identity decisions made locally when the link is gone.
Attested identities for unmanned and manned platforms.
QuantaSeek® correlates FMV, SIGINT, and reports at the edge.
Evidence and phishing-resistant MFA for primes and suppliers.
Scoped, human-approved agents for planning and analysis.
Illustrative screen with sample data.
Fence sensors, cameras, gates, and badge readers feed the same command layer that protects your control systems. An intrusion at the perimeter steps up access to the OT network automatically.
Federated ICAM (identity, credential, and access management) extends one trusted identity across installations, forward sites, agencies, and coalition partners, with credentials that are issued, verified, and revoked in one place and honored everywhere. QuantaSight™, a module of QuantaSeek®, ingests real-time full-motion video and feeds it straight into Zero Trust Identity® for physical and digital identity and access management.
UAS and ISR feeds, gate and perimeter cameras, and vehicle and body-worn video, across every site.
People, vehicles, and platforms matched to federated ICAM identities and credentials in Zero Trust Identity®.
The Adaptive Risk Engine scores each actor across the physical and digital domains at once.
Open or deny the gate, the SCIF door, the flightline, and the network session from one policy.
U.S. intelligence consistently names China, Russia, North Korea, and Iran as the leading nation-state cyber threats. They target identities, infrastructure, and the defense industrial base every day, well below the threshold of armed conflict. Continuous, verified identity is how we deny them the easy way in.
Utilities, manufacturing, healthcare, and education share the same problem: essential systems, mixed-age technology, and identities no one is governing.
Continuous operator verification and vendor access control on isolated control networks, with QuantaSeek® for event reconstruction.
Secure identity cloud for manufacturers, delivered from our Kansas modular edge data centers, with CMMC-driven pull from defense primes.
Passwordless biometric login for shared clinical workstations, and walk-away session locking that protects patient data.
Treatment plants, wells, reservoirs, and pump stations spread across an entire service area, run by lean teams on a mix of modern cloud tools and legacy SCADA. SOFTwarfare.AI was built for exactly that.
A phished email or compromised office login should never become a path to the plant. Every crossing between office and control networks is verified, and PangaeAPI® protects OT hardware without rewiring it.
Technicians and contractors reach wells, plants, and reservoir sites from wherever the work is. BioThenticate® verifies the person, not a password that can be shared or stolen, and every vendor session is scored continuously.
Main breaks, storms, and wildfire response can't wait on a password reset. Passwordless biometric login is faster than typing, and verification keeps working when the cloud can't be reached.
Legacy SCADA that can't speak SAML or MFA gets the same protection as cloud apps. Integrates with your existing directory and identity provider rather than replacing it, deployed in weeks.
QuantaSeek® correlates SCADA historians, alarms, badge events, and work orders in seconds to reconstruct an incident or plan maintenance.
Access controls and monitoring that support America's Water Infrastructure Act risk and resilience assessments, emergency response plans, EPA and CISA water-sector guidance, and NIST SP 800-82.
SOFTwarfare.AI operates modular edge data centers near Wichita and in Great Bend, Kansas, including a cyber range. Mid-market organizations get identity as a managed service, delivered by MSP and MSSP partners, without building a security team from scratch.
Broad enough to fit your environment, specific enough to start a pilot next month.
Badge, gate, and relay-console access tied to one verified identity.
Continuous verification for dispatchers and gas controllers.
One identity layer across city IT, utility SCADA, and public works.
Mutual-aid crews verified fast without shared credentials.
Governed access to meter data and head-end controls.
Delivered from our Kansas edge data centers for small and mid-sized utilities.
Illustrative screen with sample data.
Fence sensors, cameras, gates, and badge readers feed the same command layer that protects your control systems. An intrusion at the perimeter steps up access to the OT network automatically.
Keep production running and adversaries off the plant floor, with continuous identity for every operator, engineer, vendor, and machine touching your OT network.
HMI and engineering workstations are shared across shifts, so a single password tells you nothing about who changed a setpoint.
Integrators and OEMs connect in to maintain equipment, often with standing credentials that never expire.
Defense primes now require phishing-resistant MFA and auditable access across their supply chain, down to Tier 3 suppliers.
| Recommended bundle | Zero Trust Identity® Enterprise edition + QuantaSeek® with QuantaSight™ |
|---|---|
| Deployment | On-prem, air-gapped OT enclave, or hybrid |
| Frameworks | NIST SP 800-171, CMMC 2.0, ISA/IEC 62443 |
| Procurement | WWT, Carahsoft, or direct |
Broad enough to fit your environment, specific enough to start a pilot next month.
Biometric login and walk-away locking on shared line workstations.
Phishing-resistant MFA and evidence for Tier 1 to Tier 3 suppliers.
QuantaSeek® traces a defect across MES, historian, and QA records in seconds.
Every robot and autonomous vehicle carries a verifiable, revocable identity.
CAD files and process recipes accessible only to verified engineers.
Brokered, time-boxed access for equipment vendors.
Illustrative screen with sample data.
Fence sensors, cameras, gates, and badge readers feed the same command layer that protects your control systems. An intrusion at the perimeter steps up access to the OT network automatically.
Adversary techniques from MITRE ATT&CK®, paired with the MITRE D3FEND™ countermeasures SOFTwarfare.AI puts in their path.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T0859 Valid Accounts (ICS) | D3-MFA Multi-factor Authentication | Continuous biometric verification means a stolen password isn't enough to operate the line. |
T0822 External Remote Services (ICS) | D3-NI Network Isolation | Vendor sessions are scoped, time-boxed, and brokered, never standing. |
T0886 Remote Services (ICS) | D3-ANET Authentication Event Thresholding | Abnormal remote session patterns trigger step-up or termination. |
Verify every driver, operator, crane, vehicle, and cargo system moving through your network, from the gate to the dispatch console.
Drivers, contractors, and vehicles cross gates constantly, and credential checks are still manual and point-in-time.
Automated cranes, yard trucks, and drones need identities and policies just like people do.
Terminal operating systems, rail signaling, and fleet telematics share networks with corporate IT.
| Recommended bundle | QuantaSeek® with QuantaSight™ + Zero Trust Identity® Enterprise edition |
|---|---|
| Deployment | Edge appliances at terminals and yards, hybrid to HQ |
| Frameworks | TSA security directives, NIST CSF 2.0, NIST SP 800-207 |
| Procurement | WWT, Carahsoft, or direct |
Broad enough to fit your environment, specific enough to start a pilot next month.
QuantaSight™ matches driver, truck, and container to the manifest at the gate.
Continuous verification for dispatchers and signal maintainers.
Driver-to-vehicle binding and verified telematics.
Badge, door, and system access for ramp, fuel, and maintenance crews.
Every handoff tied to a verified identity from ship to rail to truck.
Machine identities and policies for autonomous equipment.
Illustrative screen with sample data.
Adversary techniques from MITRE ATT&CK®, paired with the MITRE D3FEND™ countermeasures SOFTwarfare.AI puts in their path.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T1078 Valid Accounts | D3-MFA Multi-factor Authentication | Phishing-resistant, continuous authentication for dispatch and control consoles. |
T1133 External Remote Services | D3-NI Network Isolation | Brokered, scoped access for carriers, brokers, and maintenance vendors. |
T1539 Steal Web Session Cookie | D3-ANCI Authentication Cache Invalidation | Session tokens are re-verified continuously, so a stolen cookie goes stale in seconds. |
Fast, passwordless access for clinicians and airtight protection for patient data and research IP, verified continuously on every shared workstation.
Clinicians share carts and nursing-station PCs dozens of times a shift, and walk away still logged in.
Stolen credentials and MFA fatigue remain a leading path into hospital networks.
Infusion pumps, imaging systems, and lab equipment run legacy software that can't speak modern identity.
| Recommended bundle | Zero Trust Identity® Enterprise edition, with QuantaSeek® for research and SOC teams |
|---|---|
| Deployment | On-prem, Google Cloud tenant, or hybrid |
| Frameworks | HIPAA Security Rule, HHS 405(d) HICP, NIST CSF 2.0 |
| Procurement | WWT, Google Cloud Marketplace, or direct |
Broad enough to fit your environment, specific enough to start a pilot next month.
Clinicians into the EHR in seconds, locked when they walk away.
Biometric verification for dispensing cabinets and e-prescribing.
Legacy devices brought under one identity policy through PangaeAPI®.
On-premises search across trial and research data, tied to verified identities.
QuantaSeek® finds denials patterns across payer remits and notes.
Biometric verification for password resets and admin sessions.
Illustrative screen with sample data.
Adversary techniques from MITRE ATT&CK®, paired with the MITRE D3FEND™ countermeasures SOFTwarfare.AI puts in their path.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T1621 Multi-Factor Authentication Request Generation | D3-MFA Multi-factor Authentication | Biometric verification replaces push approvals, eliminating MFA fatigue. |
T1078 Valid Accounts | D3-ANET Authentication Event Thresholding | Behavioral risk scoring catches the credential used by someone else. |
T1110 Brute Force | D3-AL Account Locking | Passwordless login removes the password attackers try to guess. |
Phishing-resistant, continuous identity for state agencies, school districts, universities, and public safety, bought on the contracts you already use.
Agencies and districts defend thousands of users with a handful of IT staff.
911 centers, courts, and law enforcement systems need access that works even when the network doesn't.
Advanced authentication requirements now reach every user of criminal justice information.
Zero Trust Identity® is live on Google Cloud Marketplace, bringing user identity, device posture, attribute-based access control, and just-in-time access to agencies, schools, and public safety, with purchasing through Carahsoft on the contracts you already use.
| Recommended bundle | Zero Trust Identity® Enterprise edition, managed or self-hosted |
|---|---|
| Deployment | Managed from Kansas, on-prem, or hybrid |
| Frameworks | CJIS Security Policy, NIST SP 800-63B, CISA ZTMM |
| Procurement | NASPO, OMNIA, E&I, The Quilt via Carahsoft |
Broad enough to fit your environment, specific enough to start a pilot next month.
Phishing-resistant, continuous MFA for every state employee and contractor.
Passwordless login for staff and protected admin consoles.
Research enclave protection and campus physical-digital access.
Verified access to case management and evidence systems.
Continuous verification for election officials and systems.
Identity that keeps working when networks degrade.
Illustrative screen with sample data.
Adversary techniques from MITRE ATT&CK®, paired with the MITRE D3FEND™ countermeasures SOFTwarfare.AI puts in their path.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T1566 Phishing | D3-MFA Multi-factor Authentication | Phishing-resistant authentication means a captured password can't be replayed. |
T1557 Adversary-in-the-Middle | D3-ET Encrypted Tunnels | Cryptographically bound sessions defeat proxy-based credential theft. |
T1078 Valid Accounts | D3-ANET Authentication Event Thresholding | Anomalous use of legitimate accounts is flagged and stepped up in real time. |
One identity for the technician at the rack, the engineer in the network core, and the automation touching both.
Network engineers and automation hold keys to cores, routers, and customer environments.
Whoever can reach the rack can often reach the data, and badge logs live in a different system.
APIs, service accounts, and orchestration tools now outnumber people many times over.
| Recommended bundle | Zero Trust Identity® Mission edition + QuantaSeek® with QuantaSight™ |
|---|---|
| Deployment | On-prem, per-site edge appliances |
| Frameworks | NIST SP 800-207, SOC 2, ISO 27001 |
| Procurement | WWT or direct |
Broad enough to fit your environment, specific enough to start a pilot next month.
Physical entry and console login tied to one identity.
Continuous verification for NOC engineers and privileged sessions.
Verified technician access at unmanned cell sites.
Governance for the machine identities that run the network.
QuantaSeek® searches raw network and access data on premises.
Identity for distributed edge nodes and network functions.
Illustrative screen with sample data.
Adversary techniques from MITRE ATT&CK®, paired with the MITRE D3FEND™ countermeasures SOFTwarfare.AI puts in their path.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T1078 Valid Accounts | D3-MFA Multi-factor Authentication | Privileged access requires continuous, phishing-resistant verification. |
T1528 Steal Application Access Token | D3-CRO Credential Rotation | Short-lived, bound tokens for automation and agents limit what a stolen token can do. |
T1556 Modify Authentication Process | D3-PH Platform Hardening | Hardened, tamper-evident authentication paths across the fleet. |
AI agents now read your data, call your APIs, and act on your behalf. Zero Trust Identity® gives every agent a verifiable identity, least-privilege access, and a human who answers for it, from the enterprise to the tactical edge.
Teams spin up agents and connect them to data and tools faster than security can inventory them.
Agents often run on a person's session or a long-lived API key, with far more access than the task needs.
When an agent acts, most logs can't say which agent, for which person, under what authority.
Find every agent, tool connection, and MCP server in your environment.
Give each agent its own identity and a named human owner.
Delegate narrow, task-scoped permissions on behalf of a verified user.
Score agent behavior continuously and step up when it drifts.
Route consequential actions to a human for asynchronous approval.
Kill an agent's access instantly, everywhere, with a full audit trail.
| Identity types | Humans, service accounts, workloads, AI agents, autonomous platforms |
|---|---|
| Authorization | Delegated, scoped, time-bound, revocable |
| Approvals | Asynchronous human approval with biometric step-up |
| Integration | PangaeAPI® connects IdPs, tools, APIs, and MCP servers |
| Deployment | Cloud, on-prem, or fully air-gapped |
SOFTwarfare.AI is built against the frameworks federal agencies, the defense industrial base, and critical infrastructure operators are measured by: NIST zero trust and digital identity guidance, MITRE ATT&CK®, and MITRE D3FEND™.
"Zero trust assumes there is no implicit trust granted to assets or user accounts based solely on their physical or network location."
NIST SP 800-207, Zero Trust Architecture
"Authentication and authorization (both subject and device) are discrete functions performed before a session to an enterprise resource is established."
NIST SP 800-207, Zero Trust Architecture
"Federal agencies SHALL require their staff, contractors, and partners to use phishing-resistant authentication to access federal information systems."
NIST SP 800-63B-4, Digital Identity Guidelines
Every session verified before and during access, for users, devices, workloads, and agents, with no trust granted by network location.
Phishing-resistant, cryptographic authentication with layered biometrics, designed for the highest authenticator assurance.
Access control and identification and authentication controls mapped for CMMC Level 2 and 3 and federal systems.
D3FEND organizes defensive techniques into seven tactics. Zero Trust Identity® and QuantaSeek® contribute across all of them.
| ATT&CK technique | D3FEND countermeasure | SOFTwarfare.AI capability |
|---|---|---|
T1566 Phishing | D3-MFA Multi-factor Authentication | Phishing-resistant, passwordless biometric authentication |
T1110 Brute Force | D3-AL Account Locking | No passwords to guess; adaptive lockout on anomalous attempts |
T1111 Multi-Factor Authentication Interception | D3-MFA Multi-factor Authentication | Verification bound to the person and device, not an interceptable code |
T1621 Multi-Factor Authentication Request Generation | D3-ANET Authentication Event Thresholding | No push prompts; abnormal request volume triggers lockdown |
T1557 Adversary-in-the-Middle | D3-ET Encrypted Tunnels | Cryptographically bound, mutually authenticated sessions |
T1539 Steal Web Session Cookie | D3-ANCI Authentication Cache Invalidation | Continuous re-verification makes stolen session tokens worthless |
T1528 Steal Application Access Token | D3-CRO Credential Rotation | Short-lived, task-bound tokens for workloads and AI agents |
T1078 Valid Accounts | D3-UAP User Account Permissions | Least-privilege, just-in-time access with behavioral risk scoring |
MITRE ATT&CK® is a registered trademark and D3FEND™ is a trademark of The MITRE Corporation. Mappings describe how SOFTwarfare.AI capabilities address each technique; they are not an endorsement by MITRE.
Verified identity for every operator, ground station, satellite, and link, from the mission control room to low Earth orbit.
Whoever sits at a satellite operations console can task, move, or disable a national asset.
Hundreds of satellites and ground terminals each need an identity that can be verified and revoked.
Jamming, spoofing, and intermittent contact make cloud-dependent authentication a liability.
How identity flows from orbit to the operations floor.
| Recommended bundle | Zero Trust Identity® Mission edition + QuantaSeek® tactical configuration |
|---|---|
| Deployment | Ground stations, operations centers, air-gapped enclaves |
| Acquisition | SBIR Phase III sole-source authority; NASA SEWP V and ITES-SW2 via Carahsoft |
| Frameworks | NIST SP 800-53, SP 800-207, CNSSI 1253 |
Broad enough to fit your environment, specific enough to start a pilot next month.
Continuous biometric verification at every mission console.
Mutual authentication between ground systems and spacecraft links.
Verified access to controlled technical data.
QuantaSeek® searches telemetry and test data in seconds.
Physical and digital access governed together on the range.
Phishing-resistant access for the aerospace supply chain.
Illustrative screen with sample data.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T1078 Valid Accounts | D3-MFA Multi-factor Authentication | Continuous biometric verification at every mission console. |
T1557 Adversary-in-the-Middle | D3-ET Encrypted Tunnels | Mutually authenticated, identity-bound ground-to-space links. |
T1133 External Remote Services | D3-NI Network Isolation | Brokered, scoped access for contractors and partner operators. |
Get the right information to the right officer in seconds, and prove that only the right officer could reach it. CJIS-aligned identity and real-time intelligence from the patrol car to the crime center.
The FBI CJIS Security Policy requires multi-factor authentication for access to criminal justice information, including in the field.
Body cams, LPR, CCTV, and drones generate more video than any team can watch.
MDTs and station workstations change hands every shift, and passwords get shared.
How SOFTwarfare.AI connects the field, the crime center, and systems of record.
| Recommended bundle | Zero Trust Identity® Enterprise edition + QuantaSeek® with QuantaSight™ |
|---|---|
| Deployment | On-prem at the crime center, in-vehicle, or hybrid |
| Frameworks | FBI CJIS Security Policy, NIST SP 800-63B, NIST SP 800-207 |
| Procurement | NASPO ValuePoint, OMNIA Partners via Carahsoft ↗ |
Broad enough to fit your environment, specific enough to start a pilot next month.
Biometric, passwordless access in the vehicle, locked when the officer steps out.
Find every sighting of a vehicle across LPR, CCTV, and body cam in seconds.
Analysts verified continuously while viewing live feeds and CJIS data.
Every access, export, and redaction tied to a verified identity.
Verified pilots and machine identities for DFR programs.
Federated identity honored across departments and jurisdictions.
Illustrative screen with sample data.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T1078 Valid Accounts | D3-MFA Multi-factor Authentication | A shared or stolen password can't open CJIS data. |
T1566 Phishing | D3-MFA Multi-factor Authentication | Phishing-resistant authentication for every officer and analyst. |
T1539 Steal Web Session Cookie | D3-ANCI Authentication Cache Invalidation | Continuous re-verification makes stolen sessions useless. |
Every fence sensor, camera, gate, badge reader, and drone feeds one command layer. SOFTwarfare.AI turns thousands of signals into a few verified alarms, tells you who is behind each one, and orchestrates the response in seconds, from the plant fence line to the nuclear protected area.
Adversaries test the fence, the badge reader, and the network together. Most sites still watch them on separate screens, run by separate teams, with alarms nobody has time to verify.
Wind, wildlife, and weather trigger nuisance alarms all night. Real intrusions hide in the noise.
Video, access control, perimeter detection, and OT monitoring each run their own console.
A camera can see a person. It can't tell you whether they're allowed to be there.
Vendor-neutral by design: we connect the cameras, fence sensors, access control, and video management systems you already own.
The layered physical protection model security teams already use, accelerated by AI and anchored in verified identity.
Fence, buried, radar, and camera analytics fused into one alarm, with context.
Gates, barriers, and doors lock by policy the moment an alarm is confirmed.
QuantaSight™ verifies what the camera sees; QuantaSeek® says what else is connected.
Guards, drones, and robots dispatched from one command layer with live video.
Every alarm, decision, and action tied to a verified identity for after-action review.
AI does the watching across thousands of feeds so your operators stay sharp for the alarms that matter. Policy handles the first moves. People make the call.
Illustrative timeline.
Remote, unmanned sites spread across hundreds of square miles, where every alarm has to be assessed and answered in seconds, even with a degraded link.
Protected and vital areas, layered access, and armed response. Every door, badge, and control-room session tied to one verified identity.
Smaller footprints and fewer on-site staff mean automated detection and remote assessment carry more of the security load.
The fence, the gate, and the PLC are one attack surface. Physical intrusion alarms step up access to OT systems automatically.
Unmanned sites protected with perimeter sensing, camera verification, and verified crew access.
Perimeter to rack: fence, lobby, mantrap, cage, and console under one policy.
Pair the platform with SOFTwarfare.AI mission support. Our team helps you integrate every sensor, tune alarm policy to your sites, and build response playbooks around your guard force, drones, and local law enforcement.
Cameras, access, perimeter, and autonomous assets correlated before an alarm reaches your queue.
Policy-driven playbooks that coordinate people, drones, and lockdowns the moment identity and context line up.
Assessments, sensor placement, integration, and tuning built around your threat and operating model.
| ATT&CK technique | D3FEND countermeasure | How we stop it |
|---|---|---|
T0859 Valid Accounts (ICS) | D3-MFA Multi-factor Authentication | Control-room access requires continuous biometric verification, stepped up during any physical alarm. |
T0822 External Remote Services (ICS) | D3-NI Network Isolation | Remote access to security and OT systems is brokered and locked by policy during incidents. |
T1078 Valid Accounts | D3-ANET Authentication Event Thresholding | A badge or login that doesn't match presence, video, or schedule is flagged in real time. |
We sell through the channels our customers already trust, and build on silicon and research partners who push the edge.
WWT account teams can quote QuantaSeek® 5U appliances and Zero Trust Identity user blocks inside standard enterprise proposals for energy, defense, and financial services clients, with solution datasheets for each vertical.
Public sector access through Carahsoft's reseller network and contract vehicles, including NASA SEWP V, ITES-SW2, NASPO ValuePoint, OMNIA Partners, E&I and The Quilt. Government, military, and education buyers acquire on pre-negotiated terms. View contract vehicles
Visit the SOFTwarfare microsite at Carahsoft opens in new window ↗
Zero Trust Identity® is live on Google Cloud Marketplace. Commercial customers procure inside their Google Cloud account and apply eligible spend to existing commitments, and public sector customers can transact through Carahsoft. Commercial Google Workspace deployments are live.
View Zero Trust Identity® on Google Cloud Marketplace opens in new window ↗
A reseller agreement supporting an active Fortune 500 security motion.
LRL's ExtremeSearch® processor is integrated into QuantaSeek®, offloading raw-data search so the language model receives only relevant evidence.
QuantaSeek® is architected on Intel: Xeon compute, Agilex FPGA hyper-indexing, and Intel accelerators, carrying sovereign AI into markets a GPU cloud can't serve.
A multi-year sponsored research agreement that feeds our AI and identity roadmap.
Simple economics, protected deals, and a founding-partner offer for MSPs and MSSPs.
On license and subscription for registered deals, with added margin protection in RFP and competitive bid situations. Unregistered deals receive 30% off MSRP.
$100 per qualified deal registration and $500 per qualified customer meeting, plus 3% of net on purchase orders.
On your first 50 qualified opportunities, for identity delivered as a managed service from our Kansas edge data centers.
One appliance price. Three identity editions. Every capability in an edition is included, with no add-ons for adaptive risk, device posture, or integrations.
Per appliance, one-time
20% of license, billed annually from commissioning
| 3-year total | $1,600,000 |
|---|---|
| 5-year total | $2,000,000 |
Priced per human identity per month, billed annually. Machine and AI agent identities are priced as a fixed fraction of the same rate, so every quote uses one number.
20% of the edition rate. Workloads, services, devices, and PLCs.
40% of the edition rate. Each agent gets its own identity, scope, and lifecycle.
25-user minimum. Okta carries a $1,500 annual minimum and PingOne for Workforce a 5,000-user minimum.
| Identity units | Rate multiplier |
|---|---|
| 25 to 999 | List |
| 1,000 to 4,999 | 10% off |
| 5,000 to 24,999 | 20% off |
| 25,000 and above | 30% off |
| Term | Rate multiplier |
|---|---|
| 1 year | List |
| 2 years | 5% off |
| 3 years, prepaid or annual | 10% off |
Identity units = human users + (machines × 0.2) + (agents × 0.4). Volume and term multipliers stack. Partner discounts apply to the resulting MSRP.
The same math our sales team and partners use. Copy the quote code into your deal registration or Google Cloud private offer request.
Competitor figures use published per-user list prices for the closest comparable tier as of September 2026, including Okta's $1,500 annual floor and Ping's 5,000-user minimum. Negotiated discounts vary.
| Need | SOFTwarfare.AI | Cisco Duo | Okta Workforce | PingOne for Workforce |
|---|---|---|---|---|
| MFA, passwordless, SSO | $2.75 Essentials | $3 Essentials | $6 Starter | $3 Essential (SSO), $6 Plus for MFA |
| Risk-based, adaptive authentication | Included from $2.75 | $6 Advantage | $14 Core Essentials and up | $6 Plus |
| Air-gapped and DDIL operation | $8.75 Mission | Not offered | Not offered | Self-managed software, by quote |
| Minimum commitment | 25 users | None published | $1,500 per year | 5,000 users |
Zero Trust Identity is transactable on Google Cloud Marketplace at the same list prices shown here. Purchases bill through your Google Cloud account and eligible spend can count toward your existing Google Cloud commitment, so there's no new vendor onboarding or budget cycle.
Your quote code maps directly to the offer.
Onboarding links your Google Workspace and IdP.
Founded in 2017 in Kansas City, SOFTwarfare.AI pioneered multimodal biometric authentication and now leads identity for the AI era, across defense and commercial markets. Building like allies, thinking like adversaries.
SBIR Phase I, II, and III programs paid for research and hardening.
Proven in command and control, Space Operations control rooms, and tactical edge networks.
NIST 800-series and CMMC alignment become commercial credentials as regulators adopt the same language.
The same platform serves finance, energy, healthcare, and critical infrastructure.
Ten issued U.S. patents in three families, with our founder named as inventor on each.
Four patents, including our ninth: continuous authentication integrated into the Zero Trust Identity platform for air-gapped and enterprise missions.
Three patents.
Patented AI techniques for analyzing cyber telemetry at scale.
Pioneered the multimodal biometric authentication market in 2017. Inventor on all SOFTwarfare patents. 20+ years in cybersecurity across power and healthcare infrastructure.
Retired CW-4, JSOC and JCU. Tactical edge network engineer for U.S. Army Special Operations Command. CSfC architect at CACI.
Leads finance, capital strategy, and investor relations as SOFTwarfare.AI scales across defense and commercial markets.
27-year career with six combat deployments. Commanded 3rd Ranger Battalion and 2nd Stryker BCT. 11th Director of the School of Advanced Military Studies.
Former head of consulting services at Cerner, leading 150+ associates across delivery and deployment.
Registered patent attorney with 14 years of corporate counsel experience in B2B SaaS and M&A.
| SBIR status | Phase III, sole-source authority under 15 U.S.C. § 638(r)(4) |
|---|---|
| Originating award | Phase I W51701-24-C-0210 under ASA(ALT) |
| Army vehicle | PEO C3N, W15P7T-25-C-0003 |
| Vehicles | NASA SEWP V and ITES-SW2 through Carahsoft, plus NASPO ValuePoint, OMNIA Partners, E&I and The Quilt for state, local and education. See every vehicle |
| CAGE and UEI | 970S2, XY86SLF9NCK7 |
Headquarters in Prairie Village, Kansas, in the Kansas City metro. AI modular edge data centers near Wichita and in Great Bend, Kansas, where we also operate a cyber range. Allied relationships with Australian and U.K. defense leadership under the AUKUS framework.
Work with usAmerican-owned continuous authentication for government, education, and critical infrastructure, on federal, state, local, and cooperative vehicles through Carahsoft, the Master Government Aggregator®.
Point-in-time MFA stops at the login. Adversary-in-the-middle attacks, session hijacking, and push fatigue happen after it. Zero Trust Identity keeps verifying for the whole session.
A built-in Adaptive Risk Engine watches behavioral biometrics, device health, and geolocation in real time, then steps up or ends a session the moment risk crosses a threshold.
Engineered for NIST 800-series controls and the Optimal stage of the CISA Zero Trust Maturity Model, with automated, real-time response.
Wraps phishing-resistant MFA around mission-essential applications that don't speak modern identity protocols, in cloud, on-prem, or fully air-gapped, without rip-and-replace.
Domestic provenance and supply-chain security for the U.S. military, the intelligence community, and essential-service providers.
SBIR Phase III sole-source authority under 15 U.S.C. § 638(r)(4), and an active Army PEO C3N contract, W15P7T-25-C-0003.
Carahsoft's reseller network and pre-negotiated terms mean agencies buy through vehicles their contracting officers already know.
| Vehicle | Contract number | Period |
|---|---|---|
| NASA SEWP V Government-wide acquisition contract for federal agencies | NNG15SC03B / NNG15SC27B | Through Jan 31, 2027, option years available |
| ITES-SW2 Army IT Enterprise Solutions, Software 2: COTS software, services, and hardware | W52P1J-20-D-0042 | Through Aug 30, 2030 |
| Vehicle | Contract number | Period |
|---|---|---|
| E&I Cloud Solutions and Services Available in all 50 states for education, state, and local purchasing | EI00063-2021MA | Through Mar 31, 2031 |
| The Quilt Software and services cooperative for Quilt research and education members | MSA-05012019F | Through May 2, 2028 |
| Vehicle | Contract number | Period |
|---|---|---|
| OMNIA Partners, Cobb County GA Technology products, solutions, and services for OMNIA members | 23-6692-01 | Through Apr 30, 2027, option years available |
| OMNIA Partners, Region 4 Software solutions and services for OMNIA members | R240303 | Through Dec 31, 2027, option years available |
Available for state, local, and education purchasing in 29 jurisdictions, including our home state of Kansas. Hover a state for its contract number.
| Vehicle | Contract number | Period |
|---|---|---|
| State of Florida State, local, and higher education (OMNIA-based) | 43210000-23-OMNIA-ACS | Through Apr 30, 2028 |
| Fairfax County, VA OMNIA-based | 4400012235 | Through Apr 30, 2027 |
| Orange County, CA (RCA) OMNIA-based | RCA-017-25010020 | Through Dec 31, 2027 |
| Washington Suburban Sanitary Commission OMNIA-based | 48531 | Through Apr 30, 2027 |
| Clark County School District, NV OMNIA-based | JU 25-16 | Through Apr 14, 2027 |
| Dallas ISD, TX OMNIA Region 4-based | 207331 | Through Dec 31, 2027 |
| Frisco ISD, TX OMNIA-based | 23-6692-01 | Through Apr 30, 2027 |
| Richardson ISD, TX OMNIA-based | R240303 | Through Dec 31, 2027 |
Contract details as listed on Carahsoft's SOFTwarfare contracts page. Confirm current terms with Carahsoft before ordering.
Quotes, contract questions, and ordering for every vehicle above.
| SOFTwarfare@carahsoft.com | |
| Phone | (703) 871-8548 |
| Fax | (703) 871-8505 |
| Microsite | carahsoft.com/softwarfare |
For sole-source actions under SBIR Phase III authority, or to scope a pilot on your data.
| SBIR status | Phase III, 15 U.S.C. § 638(r)(4) |
|---|---|
| Originating award | W51701-24-C-0210 (ASA(ALT)) |
| Army contract | PEO C3N, W15P7T-25-C-0003 |
| CAGE / UEI | 970S2 / XY86SLF9NCK7 |
SOFTwarfare.AI is part of the Department of War SkillBridge program. Transitioning service members can spend their final months of service working alongside our team, building the technology that defends the American way of life.
You already know how to operate under pressure, protect what matters, and lead people. That's exactly what this work needs.
We're a mission-focused team of veterans, ML engineers, and security leaders. Our leadership includes a retired Army Special Operations chief warrant officer and a retired Ranger battalion commander, so the language, the pace, and the standards will feel familiar.
SkillBridge lets eligible service members train with an industry partner during the last 180 days of service while still receiving military pay and benefits. With your command's approval, you join our team full time, learn the business, and leave with real experience and a network that's invested in your success.
Fill out the short form below. No resume required yet.
A member of our team will reach out to learn your goals, timeline, and skills.
We'll help with the paperwork your unit commander needs to authorize participation.
Work on real programs in Kansas City, Great Bend, or remote, with a clear path to employment.
Our open Proposal + Capture Fellow role: shape federal pursuits, write winning proposals, and learn government business development.
Identity security, zero trust architecture, and the Great Bend cyber range.
Deploying QuantaSeek® appliances and modular edge data centers in the field.
Technical demos, pilots, and integrations with defense and enterprise customers.
Keeping federal programs on schedule, on budget, and on mission.
Finance, contracts, logistics, and the work that keeps a growing company running.
Takes about five minutes. Your information goes only to our recruiting team.
Not eligible for SkillBridge, or already separated? Apply anyway. We hire veterans at every stage of transition.
Your application has been received, and a member of our team will be in touch. Welcome to the next chapter.
The American way of life isn't an abstraction. It's a Kansas classroom, a Saturday game, a scholarship for a Gold Star family, a blood drive, a small town that gets its next employer. We build the technology that protects it, and we show up for the people who make it.
Capability without character is just capability. We intend to build both.
SOFTwarfare is a Kansas company built on a Special Operations mindset: protect the mission, protect the team, never stop. Every day we protect identities, networks and critical infrastructure against adversaries who don't take days off. But we have never believed the mission ends at the edge of a network.
A nation is only as strong as its communities. Every student who finds a path into technology, every young athlete who finds a mentor, every military family that gets a hand up, and every rural town that gains a new generation of jobs makes America harder to defeat. That is why community partnership is not a line item for us. It is the part of our work we value most.
Standing behind service members, veterans, first responders and the families who carry the cost of their service.
Students, athletes and future engineers in our own backyard, from Shawnee Mission classrooms to the University of Kansas.
Bringing high-tech infrastructure and skilled jobs to Kansas City, Great Bend and rural communities across the state.
Health, disaster readiness and resilience. The same instinct that drives our security work, applied to our neighbors.
We are proud to stand with these organizations. Each one strengthens the communities we are building to protect.
Growing the Kansas City innovation economy and the companies, jobs and talent that come with it.
Strengthening rural communities across the heartland, the same communities our edge infrastructure is built to serve.
Investing in the students in our own backyard and the next generation of Kansas technologists and defenders.
Our partner in bringing modular edge data center and cyber range capacity, and the skilled jobs around it, to central Kansas.
Supporting the University of Kansas and the research, scholarships and talent pipeline that keep Kansas competitive.
Mentorship on and off the court. Our team is proud to wear the jersey and show up for the players.
Educational scholarships for the spouses and children of fallen and disabled service members and first responders.
Disaster relief, blood services and support for military families. Resilience is a mission we share.
Fighting heart disease and stroke, and training more people in CPR, so our communities are healthier and ready to respond.
Building faith, character and leadership in coaches and athletes across Kansas and beyond.
Some of our favorite days aren't spent in a SCIF or a data center. They're spent in a gym, wearing the jersey alongside the players.
As SOFTwarfare.AI grows, our community commitment grows with it. That's a promise to our partners, our team and the people we serve.
Community organizations, schools and veteran service groups: we'd like to hear what you're building.
Partner names and logos are trademarks of their respective organizations and are shown to recognize our community relationships.
Tell us what you're protecting. A solutions engineer will set up a session on your data, in your environment if needed.
7301 Mission Road, Suite 141
Prairie Village, KS 66208
Enterprise: World Wide Technology. Public sector: Carahsoft, SOFTwarfare@carahsoft.com, (703) 871-8548. Self-service: Google Cloud Marketplace.
Register deals and apply for MSSP founding-partner economics through the partner team.
Tell us a little about you. We'll follow up on the platform, a pilot on your data, or whatever you're exploring.
Thanks. Our team will be in touch shortly.