Audit-Grade Decision Records for DoD Network Planning
CrestView PDS produces tamper-evident, cryptographically signed, externally verifiable decision records as the primary deliverable — not a side effect of network operations.
Decision Records as the Primary Deliverable
Everything — topology, discovery, proposals, scoring, workflow integration — serves the production of defensible decisions.
Tamper-Evident
Audit Trail
Hash-chained, signed, append-only records. Database-level triggers enforce immutability. Standalone verification tool allows independent verification without system access.
Deterministic
Optimization Engine
Ranked proposals via Pareto frontier, integer programming, and constraint propagation. Same inputs produce byte-identical output — verified across 250 test runs.
Vendor-Neutral
Multi-Vendor Support
Vendor-neutral topology model supporting Ciena, Nokia, Cisco, and Infinera equipment in a single deployment. No vendor lock-in.
Disconnected
Air-Gap Ready
Four deployment profiles: standalone, VM-native, OpenShift, RKE2. Node-count licensing via signed artifacts — no phone-home requirement.
Continuous
cATO Ready
Continuous evidence emission via OpenTelemetry. Self-attestation across 8 check types. 42 STIG controls assessed across 4 STIGs. FISMA Moderate baseline.
Human Authority
Human-Only Decisions
AI systems can submit proposals but architecturally cannot commit decisions. Enforced in code, not policy. The human planner always decides.
Performance
DISA-Scale Benchmarked
All metrics measured against a 15,000-node topology matching DISN operational scale. Memory footprint verified at 57 MB.
| Metric | Value |
|---|---|
| Topology import (15K nodes) | 181 ms |
| Pathfinding (10 hops) | 20 μs |
| Proposal generation | 469 μs |
| Audit chain throughput | 5,413 / sec |
The Capability Gap Is Structural
CrestView PDS occupies a position no existing tool does: audit-grade decision records with multi-vendor support, deterministic optimization, and air-gap operability.
| Capability | Vendor NMS | Excel + Visio | CrestView PDS |
|---|---|---|---|
| Audit-grade decision records | No | No | Yes |
| Multi-vendor topology | Single vendor | Manual | Yes |
| Deterministic optimization | Vendor-specific | None | Yes |
| Air-gap deployment | Limited | N/A | Yes |
| cATO readiness | Varies | No | Yes |
| External verification | No | No | Yes |
| Node-count licensing | Per-vendor | N/A | Yes |
Every Role in the Decision Lifecycle
CrestView PDS serves everyone who touches a network planning decision — from the planner who makes it to the auditor who reviews it years later.
Primary
Network Planner
Record decisions once, defend them forever. Deterministic optimization removes second-guessing. Keyboard-first workflows respect your expertise.
Reviewer
CAB Member
Standardized review packages with alternatives evaluated transparently. Spend 10–30 minutes approving, not hours digging for documentation.
Auditor
IG Investigator
Verify any past decision without CrestView access. Standalone verification tool. Cryptographic proof the record hasn't been tampered with.
Executor
Operations Team
Clear implementation instructions with rollback procedures. ServiceNow integration for change ticket creation. No ambiguity.
Accreditation-Ready From Day One
Built for classified enclaves. Every cryptographic, access control, and audit requirement is addressed in the architecture — not bolted on after.
- FISMA Moderate
- cATO Ready
- FIPS 140-3
- CNSA 2.0
- PQC-Ready
- NIST SP 800-53 Rev 5
- IPv6 Baseline
- STIG Compliant (42 Controls)
- PPSM Documented
11 Subsystems. Zero External Dependencies.
Built in Go for single-binary deployment. PostgreSQL for persistence. No middleware, no message queues, no microservice sprawl.
- Language: Go 1.26+
- Database: PostgreSQL 17 (Iron Bank)
- Cryptography: FIPS 140-3 / CNSA 2.0
- Secrets: Vault Enterprise
- Observability: OpenTelemetry
- Container Base: Alpine 3.20 (non-root)
- Build Pipeline: Platform One Big Bang
- Authentication: PKI / CAC / RADIUS / TACACS+
- RBAC Roles: 12 roles
- Network Posture: Read-only (never pushes config)
Deployment Profiles
- Standalone: systemd unit. Evaluation, pilot, training.
- VM-Native: Multi-tier. DISA GMS, mid-sized enterprise.
- OpenShift: Platform One environments.
- RKE2: Tactical environments.
Ready to Make Every Decision Defensible?
Node-count tier licensing. 90-day evaluation at no cost for up to 100 nodes. OTA, GSA Schedule (pending), and direct contract vehicles available.