A deliberate path into your environment.

Start with a bounded evaluation. Prove the complete organism before expanding its senses.

Prepare the trust boundary.

Choose an approved AWS account and region, a supported immutable image, private networking, HTTPS ingress, PostgreSQL, encrypted storage, and secret-management controls. The buyer owns the account, data, identity policies, retention, and operating access.

Configure Hermes and any model destination deliberately. Start with least-privilege AWS and GitHub sensors and a synthetic organisation. Broader Microsoft, engineering, and threat-intelligence coverage should follow an explicit integration-readiness review.

Prove a journey, not a process.

Run migrations and licensing preflight before admitting traffic. Observe a known change, retrieve its evidence through an authorized interface, restart the service, and verify that the same genome state survives.

Then follow an IAM mutation through investigation, notification, human response, independent remediation verification, and immune memory. Verify backups and restore, inspect logs for secrets, and record the exact image digest and deployment evidence.

Public instructions, explicit readiness.

The public deployment repository is the handoff for buyer-facing templates and runbooks. Its README and release status determine what is available; a repository existing does not mean a Marketplace offer or an AWS apply has been verified.

Upgrade tests must preserve PostgreSQL state. Destructive teardown must require explicit confirmation and verify only stack-owned resources were removed. Never run a template against an unapproved account merely because a local plan succeeded.

Open the buyer-facing repository.

Check its readiness and release notes before using any deployment material.

Deployment repository