Why questionnaires cannot secure a supply chain
Self‑reported declarations describe intent, not reality. Evidence collected from the actual environment is the only defensible basis for trust.
Read on xchain‑scm.com →Dacerta — data and certainty. We build evidence‑based cyber technologies for defence and critical supply chains, turning what organisations claim about their security into what can be proven.
Security decisions in defence are too often made on declarations, questionnaires and assumptions. Dacerta exists to replace them with data — real evidence collected from real environments — and to turn that data into certainty: a posture that can be measured, proven and defended.
Every technology we build follows that sequence: gather the data, establish the facts, deliver certainty to the people who have to decide.
Dacerta is the parent company behind a growing portfolio of cyber technologies. Each one starts from the same conviction: security posture should be discovered from real evidence, and compliance should be demonstrated, not declared.
Our technologies serve defence establishments, their supply chains and the operators of critical infrastructure — organisations that must prove, continuously, that they and their partners are secure.
Each Dacerta technology addresses a distinct, unsolved problem in defence and supply chain security — and shares a common engine for collection, analysis and reporting.
Evidence‑based supply chain cyber governance. XCHAIN automatically performs deep, forensic analysis across a supplier's actual environment — replacing questionnaires and self‑declarations with verifiable proof of posture, breach status and compliance.
Additional Dacerta technologies are in active development, extending the same evidence‑based approach to new domains of defence and critical‑infrastructure security. They are announced on release.
The XCHAIN agent runs on the endpoints inside a supplier's environment — no installation, no admin rights. Each run seals its evidence in an encrypted file that travels to the XCHAIN‑SCM server, where the analysis engines turn it into scores, findings and a report.
Four rule‑based engines read the evidence and raise every finding they can. Then the XCHAIN AI analytics layer does two things rules cannot: it removes the false positives, and it connects evidence from different sources into the attack chains a human analyst would otherwise have to assemble by hand.
Compliance in Dacerta technologies is not a checklist. Each regulatory requirement is correlated to the forensic evidence collected from the environment — so auditors see why a control is satisfied, partially met or missing, and which collector produced the proof.
Enterprise‑grade building blocks — from collection to executive decision — shared across the portfolio so every product inherits the same depth, security and auditability.
Portable, no‑install collection for Windows and Linux. Runs without admin privileges in locked‑down and third‑party environments.
Envelope encryption from the endpoint to the analysis tier; evidence is sealed at collection and verifiable end to end.
Hardening (ECAS), breach forensics (SENTINEL), compliance and intelligence engines correlate thousands of signals into prioritised findings.
Findings mapped to NIST SP 800‑171 and defence‑sector baselines, with the underlying evidence attached to each control.
Entity‑level views across suppliers, subsidiaries and sites; vulnerability, exposure and attack‑path intelligence in context.
AI‑assisted narrative reports, dashboards and audit trails built for boards, regulators and the teams who remediate.
Every Dacerta technology follows the same disciplined pipeline — so the output is always traceable back to the evidence it came from.
Gather verifiable evidence directly from endpoints, environments and distributed entities — securely, with encryption end to end.
Layered engines correlate processes, persistence, network state, identity and configuration to reveal what is really there.
Findings are prioritised by risk and mapped to control frameworks such as NIST SP 800‑171 — evidence attached to every control.
Executive and operational reporting, AI‑assisted narrative and clear next actions for leadership, auditors and defenders.
"Trust in a supply chain cannot be declared on a form. It has to be discovered in the environment, measured against a standard, and proven with evidence."
Ministries, armed forces and prime contractors that must verify the security of every link in their chain.
Suppliers and subcontractors who need to demonstrate compliance to their customers with evidence, not paperwork.
Public bodies governing distributed agencies, vendors and programmes with strict regulatory obligations.
Energy, water, transport and telecom operators whose partners and OT environments are prime targets.
Self‑reported declarations describe intent, not reality. Evidence collected from the actual environment is the only defensible basis for trust.
Read on xchain‑scm.com →Mapping forensic findings to control families turns compliance from a paperwork exercise into a verifiable, continuously updated posture.
Read on xchain‑scm.com →Defence environments demand on‑premises and disconnected operation. Our technologies are built to run identically in the cloud or fully offline.
Request a briefing →Book a briefing with Dacerta — for defence organisations, supply chain governance teams and partners.
Briefings for defence organisations, supply chain governance teams and partners. Tell us about your environment and we will come back to you.