Parent company of XCHAIN‑SCM — evidence‑based supply chain security, selected for use by Israel's defense establishment.
Company Technologies How it works Engines & AI Regulation Platform Approach Sectors Contact XCHAIN‑SCM ↗
Defence technology group

Deep Discovery.
Absolute Compliance.

Certainty about yoursuppliers.endpoints.controls.supply chain.evidence.

Dacertadata and certainty. We build evidence‑based cyber technologies for defence and critical supply chains, turning what organisations claim about their security into what can be proven.

Evidence, not questionnaires Cloud, on‑prem or air‑gapped Built for defence supply chains
Dacerta — Deep Discovery. Absolute Compliance.
Evidence streamLIVE
    94+Forensic collectors in the XCHAIN endpoint agent
    110NIST SP 800‑171 controls with evidence‑backed mapping
    4Analysis engines — ECAS, SENTINEL, Compliance, Intelligence
    3Deployment models — cloud SaaS, on‑premises, air‑gapped
    Defence‑grade by designEngineered for environments where assumptions are not acceptable.
    Evidence over declarationsAnalysis of the actual environment — processes, registry, logs, network, identity.
    Compliance you can defendFindings mapped to control frameworks such as NIST SP 800‑171 — not paperwork.
    DATA
    Data
    +
    CERTAINTY
    Certainty
    =
    DACERTA
    The name
    What Dacerta means

    Data and certainty. That is the whole idea.

    Security decisions in defence are too often made on declarations, questionnaires and assumptions. Dacerta exists to replace them with data — real evidence collected from real environments — and to turn that data into certainty: a posture that can be measured, proven and defended.

    Every technology we build follows that sequence: gather the data, establish the facts, deliver certainty to the people who have to decide.

    Company

    A technology company for the hardest security questions in defence.

    Dacerta is the parent company behind a growing portfolio of cyber technologies. Each one starts from the same conviction: security posture should be discovered from real evidence, and compliance should be demonstrated, not declared.

    Our technologies serve defence establishments, their supply chains and the operators of critical infrastructure — organisations that must prove, continuously, that they and their partners are secure.

    Deep discoveryForensic‑depth collection and analysis across endpoints, environments and distributed entities.
    Absolute complianceEvery finding tied to a control, every control backed by evidence that auditors and regulators can verify.
    Deployable anywhereCloud SaaS, on‑premises or fully air‑gapped — the same engine, wherever the data must stay.
    Built by practitionersDesigned with the people who assess, audit and defend defence supply chains every day.
    Technologies

    One company. A portfolio of evidence‑based security technologies.

    Each Dacerta technology addresses a distinct, unsolved problem in defence and supply chain security — and shares a common engine for collection, analysis and reporting.

    Flagship technologyXCHAIN‑SCM
    In production

    Evidence‑based supply chain cyber governance. XCHAIN automatically performs deep, forensic analysis across a supplier's actual environment — replacing questionnaires and self‑declarations with verifiable proof of posture, breach status and compliance.

    ECASHardening assessment — how resilient the environment actually is.
    SENTINELBreach detection & forensics — traces of compromise and post‑incident artifacts.
    COMPLIANCE ENGINEReal findings mapped to NIST SP 800‑171 control families.
    INTELLIGENCE LAYERCross‑supply‑chain correlation, risk patterns and decision support.
    No installationNo admin privilegesWindows & Linux forensicsEncrypted evidenceAI‑assisted reportingCloud · On‑prem · Air‑gapped
    Visit xchain‑scm.com
    PortfolioWhat's next
    In development

    Additional Dacerta technologies are in active development, extending the same evidence‑based approach to new domains of defence and critical‑infrastructure security. They are announced on release.

    Technology 02 — undisclosed
    Technology 03 — undisclosed
    Request an early briefing →
    How it works

    From the supplier's computers to a defensible report.

    The XCHAIN agent runs on the endpoints inside a supplier's environment — no installation, no admin rights. Each run seals its evidence in an encrypted file that travels to the XCHAIN‑SCM server, where the analysis engines turn it into scores, findings and a report.

    Agents run on the supplier's computers, encrypted evidence files travel to the XCHAIN-SCM server, engines analyse them and a report is produced. SUPPLIER ENVIRONMENT · AGENT RUNS ON EACH ENDPOINT ENCRYPTED XCHAIN‑SCM · ANALYSIS ECAS SENTINEL NIST AI 4 ENGINES · CORRELATION · SCORING REPORT · DASHBOARD SUPPLIER 14 82 ECAS SCORE NIST 800‑171 · P1–P4
    1
    Agent runs on endpointsWorkstations, laptops and servers inside the supplier's network. 94 forensic collectors, executed in place.
    2
    Evidence sealed & sentEach result is envelope‑encrypted at the endpoint and delivered to the server — cloud, on‑prem or via offline transfer.
    3
    Engines analyseECAS, SENTINEL, the Compliance Engine and the AI layer correlate every signal into prioritised findings.
    4
    Report & dashboardScores, P1–P4 findings and NIST SP 800‑171 mapping — for the supplier, the customer and the auditor.
    Engines working together

    Rules find everything. AI decides what matters.

    Four rule‑based engines read the evidence and raise every finding they can. Then the XCHAIN AI analytics layer does two things rules cannot: it removes the false positives, and it connects evidence from different sources into the attack chains a human analyst would otherwise have to assemble by hand.

    Evidence sources
    Processes
    Registry
    Network
    Event logs
    Identity
    Drivers & files
    Rule‑based engines
    ECASHardening rules
    SENTINELBreach & forensics rules
    COMPLIANCENIST 800‑171 controls
    CORRELATIONMulti‑stage patterns
    XCHAIN AI analytics
    AI analytics layer
    Reasoning over evidence
    Idle
    −0 findings suppressed as false positives — legitimate signed drivers, known admin tooling, benign scheduled tasks.
    Output
    Rule findings
    0findings
    ECAS
    SENTINEL
    Compliance
    Correlation
    PERSISTENCE → EXECUTION3 sources · 4 findings0.94
    CREDENTIAL → LATERAL3 sources · 3 findings0.88
    EVASION → BYOVD2 sources · 3 findings0.86
    0raw evidence signals
    0rule‑based findings
    after AI false‑positive reduction
    correlated attack chains
    Regulation workspace

    Every requirement, tied to the evidence that proves it.

    Compliance in Dacerta technologies is not a checklist. Each regulatory requirement is correlated to the forensic evidence collected from the environment — so auditors see why a control is satisfied, partially met or missing, and which collector produced the proof.

    0%
    0evidenced
    0partial
    0gap
    Evidence · agent collectors
    Requirements · NIST SP 800‑171
    Evidence‑backed, not declaredEach control links to the exact collector output, host and timestamp behind it.
    Gaps are explicitWhere no evidence exists the control is marked as a gap — never assumed compliant.
    Framework‑agnosticThe same evidence maps to NIST SP 800‑171, RM2 and further frameworks as they are added.
    Platform capabilities

    A common engine beneath every Dacerta technology.

    Enterprise‑grade building blocks — from collection to executive decision — shared across the portfolio so every product inherits the same depth, security and auditability.

    01 / COLLECTION

    Endpoint forensics agent

    Portable, no‑install collection for Windows and Linux. Runs without admin privileges in locked‑down and third‑party environments.

    02 / PIPELINE

    Encrypted evidence pipeline

    Envelope encryption from the endpoint to the analysis tier; evidence is sealed at collection and verifiable end to end.

    03 / ANALYSIS

    Layered analysis engines

    Hardening (ECAS), breach forensics (SENTINEL), compliance and intelligence engines correlate thousands of signals into prioritised findings.

    04 / COMPLIANCE

    Control‑framework mapping

    Findings mapped to NIST SP 800‑171 and defence‑sector baselines, with the underlying evidence attached to each control.

    05 / INTELLIGENCE

    Supply chain correlation

    Entity‑level views across suppliers, subsidiaries and sites; vulnerability, exposure and attack‑path intelligence in context.

    06 / DECISION

    Executive & operational reporting

    AI‑assisted narrative reports, dashboards and audit trails built for boards, regulators and the teams who remediate.

    Approach

    From raw evidence to decisions leadership can defend.

    Every Dacerta technology follows the same disciplined pipeline — so the output is always traceable back to the evidence it came from.

    Collect

    Gather verifiable evidence directly from endpoints, environments and distributed entities — securely, with encryption end to end.

    Analyse

    Layered engines correlate processes, persistence, network state, identity and configuration to reveal what is really there.

    Score & map

    Findings are prioritised by risk and mapped to control frameworks such as NIST SP 800‑171 — evidence attached to every control.

    Decide

    Executive and operational reporting, AI‑assisted narrative and clear next actions for leadership, auditors and defenders.

    "Trust in a supply chain cannot be declared on a form. It has to be discovered in the environment, measured against a standard, and proven with evidence."

    Dacerta — operating principle
    Sectors

    Where the cost of an assumption is highest.

    Defence & aerospace

    Ministries, armed forces and prime contractors that must verify the security of every link in their chain.

    Defence supply chain

    Suppliers and subcontractors who need to demonstrate compliance to their customers with evidence, not paperwork.

    Government

    Public bodies governing distributed agencies, vendors and programmes with strict regulatory obligations.

    Critical infrastructure

    Energy, water, transport and telecom operators whose partners and OT environments are prime targets.

    Perspectives

    How we think about defence supply chain security.

    Governance

    Why questionnaires cannot secure a supply chain

    Self‑reported declarations describe intent, not reality. Evidence collected from the actual environment is the only defensible basis for trust.

    Read on xchain‑scm.com →
    Compliance

    NIST SP 800‑171 for defence suppliers — proving it, not filing it

    Mapping forensic findings to control families turns compliance from a paperwork exercise into a verifiable, continuously updated posture.

    Read on xchain‑scm.com →
    Deployment

    Air‑gapped by default: the same engine where data cannot leave

    Defence environments demand on‑premises and disconnected operation. Our technologies are built to run identically in the cloud or fully offline.

    Request a briefing →

    See what is really there.

    Book a briefing with Dacerta — for defence organisations, supply chain governance teams and partners.

    Contact

    Talk to Dacerta.

    Briefings for defence organisations, supply chain governance teams and partners. Tell us about your environment and we will come back to you.

    ResponseWe typically respond within two business days.
    XCHAIN‑SCM product enquiriesxchain‑scm.com ↗

    By submitting you agree to be contacted by Dacerta regarding your enquiry. No marketing lists.