TensorOne for Government · Federal · State · Local

You're not running one hypervisor. You're running three. What's watching all of them?

Agencies don't migrate off one virtualization platform onto another. They run several at once, for years: VMware (Broadcom) beside Nutanix, OpenShift beside KVM, AWS on the side. Each platform has its own control plane, its own logging format, and its own security model. EDR covers none of them, and a single-platform tool covers a fraction of the estate. TensorOne watches that layer across all of them from one console: behavioral detections mapped to MITRE ATT&CK, multi-stage correlation that reconstructs a kill chain instead of alerting on each step alone, and a response playbook for what it finds. Nothing is installed on a hypervisor to do it.

It is also how the coverage gets funded. The same edge filter that feeds the detections drops up to 99% of datacenter log volume before your SIEM bills for it, and what that removes from the ingest line is usually enough to pay for the detections outright.

SDVOSB

Service-Disabled Veteran-Owned Small Business. SBA VetCert certification in progress.

Founded and run by two veterans, of the U.S. Army and the U.S. Marine Corps. Status is stated here exactly as it stands and will be updated the day it changes, not before.

NAICS 541519 · 541512 · 541990 Software developed in the United States
33 OF 62
Federal agencies with a measurable virtualization estate bought two or more platforms in the same two-year window
12 BOUGHT THREE
Three platforms, three control planes, three logging formats, one security team
1 BOUGHT FOUR
The estate a single-platform tool was never going to cover

Source: public federal contract records, FY2025–26.

Several platforms, at once

A migration is a decade. The blind spot is the whole time.

A hypervisor can snapshot, clone, or wipe every workload it runs, and no endpoint sensor can live on it. That is true on every platform in the estate, and government estates hold several: the VMware (Broadcom) clusters that run the systems of record, the Nutanix or OpenShift footprint that arrived with a modernization program, the KVM hosts under a lab or a legacy application, and the AWS account beside them. Each is a separate place an intruder can stand below the floor your EDR is standing on.

Control plane

Each platform has its own

vCenter, Prism, the Kubernetes API, libvirt, the AWS console. Five different places to log in, five different privilege models, five different ways to take a snapshot of a domain controller with memory included.

Logging format

Each platform has its own

hostd and vpxd syslog, Prism audit records, Kubernetes events, libvirt journal lines, CloudTrail JSON. None of them share a schema, and a rule written for one says nothing about the others.

Security model

Each platform has its own

Roles, service accounts, and hardening settings that do not map to each other. The person who knows the vSphere lockdown modes is usually not the person who knows the ClusterRole bindings.

EDR covers none of them, and a single-platform tool covers a fraction of the estate. TensorOne collects from all of them into one console, with one inventory and one set of detections that know which platform each event came from.
How government buys TensorOne

Three paths. None of them is a dead end.

A buyer who wants this should not have to invent a way to buy it. These are the paths that exist today, stated concretely, with the one that is still in progress marked as such.

01 · Through a reseller

On a vehicle you already hold

Most agencies buy TensorOne through a reseller they already hold a contract vehicle with. The vehicle types we can be bought under:

  • GSA Multiple Award Schedule, through a partner's schedule
  • NASA SEWP, through a partner's contract
  • Agency blanket purchase agreements the reseller already holds

We work with agency-specific resellers. If your incumbent isn't one of them yet, we'll work with them rather than ask you to change vendors.

02 · Direct, below the SAT

Simplified acquisition

Purchases under $350,000 use FAR Part 13 simplified acquisition procedures. Micro-purchases under $15,000 can go on a government purchase card.

A first deployment can be scoped to fit either: one collector, one site, a defined host count, and the console on your own infrastructure. The seven-day assessment tells you what that scope should be before anything is quoted.

03 · SDVOSB set-aside or sole source

Once certified

SBA VetCert certification is in progress. Once it is issued, TensorOne becomes eligible for SDVOSB set-aside and sole-source awards under the thresholds your contracting officer already knows.

We will confirm the status in writing the day it changes. Until then, paths 01 and 02 are the ones that exist, and we would rather say so than have you plan around a status we do not yet hold.

Hold a vehicle we haven't named? Tell us which. We will work with the reseller you already use.
Deployment & authorization posture

Everything stays inside your boundary. Including the console.

This is the part of the product that matters most to an authorizing official, so it gets a full section rather than a pricing bullet. Every statement below is about the on-premises configuration that government deployments get by default.

01

The collector runs entirely inside your boundary

One virtual machine you own, on infrastructure you control. Hypervisors and management appliances send it syslog passively; it polls each platform's management API read-only for inventory and configuration state. Nothing is installed on a hypervisor: no agents, no VIBs, no kernel modules, no change window on the hosts themselves.

It never reads guest memory, guest disks, datastore contents, or application data. It receives what the platform already logs and reads what a read-only role already exposes.

02

The console is on-premises by default

For government deployments the console runs inside your network. It is the default configuration, not a paid upgrade. Telemetry, detections, evidence, inventory, and analyst notes stay on your infrastructure, under your access controls, on your retention schedule. No customer telemetry leaves your network.

03

FedRAMP and GovRAMP: why that path doesn't apply here

FedRAMP and GovRAMP authorize cloud service offerings. An on-premises deployment is not a cloud service offering, so the FedRAMP path does not apply to it. We state that as a fact about scope and nothing more: TensorOne holds no FedRAMP or GovRAMP authorization, and in this configuration there is no cloud service to authorize.

What governs instead is your own assessment and authorization process for software you operate. The security review pack below is written to feed it.

04

Air-gapped operation, stated honestly

Once running, an on-premises deployment needs no outbound connection. The collector talks to your console and to nothing else. Detection content is compiled into each software release rather than pulled from a live feed, so an isolated deployment receives new detections the way it receives any other update: as a versioned release you carry in on your own media, on your own schedule, with a checksum to verify before you install it.

Two limits today, so nobody discovers them during an install. The standard installer fetches container images over the network, so a fully disconnected first install is staged with us during scoping rather than run from a single command. And the optional AI features that explain an alert's evidence call a third-party model API; they are off by default for every tenant and stay off on an isolated network.

05

Read-only, and documented before you grant anything

Every management API account is a named read-only role on its platform: the vSphere Read-only role, the Prism Viewer role, the Kubernetes view ClusterRole, a read-only libvirt connection, an IAM policy limited to reading CloudTrail. The complete list, one page per platform, is at /permissions/ and is sent before anything is provisioned.

06

Silence is a detection

The obvious move against a passive collector is to stop feeding it. Expected volume and heartbeat are tracked per host, so a source that goes quiet raises an alert instead of leaving a gap, including when someone turns syslog off.

Platform coverage

Five sources. One console. Depth stated per platform.

Collection, inventory, and exposure matching run across every platform below at the same time. Behavioral detection content does not run uniformly across them, and the table says where it is deepest rather than implying it is everywhere.

PlatformWhat is collectedDetection depth
VMware vSphere / ESXiBroadcom · vCenter and ESXi hosts vCenter event stream and ESXi host syslog (hostd, vpxd, vmkernel, auth). Read-only vSphere API for inventory, host hardening settings, sessions, and installed extensions. Deepest behavioral content
Nutanix AHVPrism Central and Element Prism syslog and audit records. Read-only Prism API (Viewer role) for hosts, virtual machines, storage containers, and alert policies. Collection · inventory · growing
Red Hat OpenShiftOpenShift Virtualization · KubeVirt Kubernetes events. Read-only ServiceAccount bound to the view ClusterRole plus get/list/watch on KubeVirt resources. No Secrets, no exec. Collection · inventory · growing
KVM / libvirtqemu:///system, read-only Host syslog and journal. Read-only libvirt connection for domain inventory and host capabilities. Collection · inventory · growing
AWS CloudTrailManagement events, scoped by account and region CloudTrail management events through a read-only IAM role. No management actions, no data-plane object reads. Collection · inventory · growing

Behavioral detection content is deepest on vSphere and ESXi, where most government estates still anchor their systems of record. On the other four platforms you get collection, live inventory, exposure matching, and a behavioral rule set that is smaller today and growing. Before you buy, we will tell you which detections apply to which platform in your estate, in writing.

Compliance & security review

"Aligned" and "attested" are different words. We use them differently.

Aligned means the architecture maps to a control framework. Attested means an independent auditor has said so. We will tell you which is which before you ask, and the review pack below is what we send before a buyer has to request it.

Compliance status, stated accurately
SOC 2 not yet attested CMMC 2.0 aligned HIPAA aligned Data residency your premises
  • SOC 2 is not yet attested. An audit is in preparation; until a report exists we will not describe ourselves as SOC 2 anything.
  • CMMC 2.0 and HIPAA alignment means our controls map to those frameworks. It is not a certification and not an attestation.
  • FedRAMP and GovRAMP do not apply to an on-premises deployment, as stated above. We hold neither and do not claim either.

Anything not on this list, we do not hold. Ask and you will get a plain answer.

Security review pack · sent before you ask
  • Read-only service account permission listOne page per platform. The exact role, what it reads, and what it can never do.
  • Data flow diagramWhat is collected, where it stays, and what leaves. In the on-premises configuration the last box is empty, and the diagram shows that.
  • Section 889 representationCovered telecommunications equipment and services, represented in the form your contracting officer expects.
  • Country-of-origin / Trade Agreements Act statementThe software is developed in the United States.
  • Software bill of materials (SBOM)For the collector and the console, per release.
  • SOC 2 statusStated as it is on the day we send it. Today: not yet attested.

The permission list is already public at /permissions/. The rest arrives with the assessment scope.

Who you would be working with

Two veterans who spent their careers inside the government they now sell to.

The detections come from people who spent years on the offensive side of national-security networks, and the company is run by people who have worked inside U.S. government facilities at home and abroad. Here is exactly who that is.

James Ball
James Ball
Founder · Director of Security
U.S. Army veteranNational Security Agency · 8 years

Eight years at the National Security Agency in Computer Network Operations (CNO), working on Exploitation Analysis. Designed the TensorOne platform from the ground up; owns detection engineering and security operations. The detections on this page were written from the side of the work that spent years staying invisible at this layer.

Sean Byrd
Sean Byrd
Director of Strategic Engagement
U.S. Marine Corps veteranU.S. government facilities · 20 years

Decorated U.S. Marine Corps veteran with nearly two decades designing security protocols for U.S. government agency facilities at home and abroad. At TensorOne, owns growth and engagement strategy, which for this audience means the reseller relationships and the purchase paths on this page.

How you start

Seven days of your logs. No purchase order.

Before anyone talks about a vehicle, we measure what your datacenter layer is actually producing and what is already sitting in it. Nothing is installed on a hypervisor, nothing leaves your network, and the report is yours whether or not you go further.

You

Point syslog at one VM inside your boundary

A single configuration line on your hosts, reversible in seconds. No agents, no VIBs, no kernel modules, no change window on the hypervisors themselves. The collector stays in your network for the whole assessment.

Us

Seven days, then a written report

Your real ingest volume by platform, what it costs at your SIEM's rate, the share we would filter, and anything already anomalous in that telemetry. Measured on your estate, never an average from ours.

Then

You decide with your own numbers

If the report is not compelling, we part ways and you keep it. If it is, we scope a first deployment to fit whichever purchase path above you prefer, and quote it against figures from your estate.

No cost, no procurement, no commitment. The assessment is a measurement, not a trial.
Capability statement

What's watching all of them?

One page, built to circulate: what TensorOne does, what it runs on, how to buy it, and where every certification actually stands. Print it, or send the link to the person who holds the vehicle.

Questions from a contracting officer or an ISSO go to hello@tensorone.cloud. Reply within one business day.