Which systems belong in which tier, what the buyer gets, and what they do not get.
See PAINPOINT_TIER_MATRIX.md for painpoint-level minimum tier gating. See TIER_GATING_RULES.md for tier boundary enforcement rules.
Anyone evaluating the stack. Developers, security researchers, curious engineers.
- Cannot verify claims without access (PP-006)
- Technical proof does not automatically sell (PP-014)
- This repo (painpoint-to-system map)
- Public README files and claim boundaries
- Published test counts and methodology descriptions
- Clear understanding of what each system does
- Claim boundary awareness (what is and is not claimed)
- Pointers to where proof artifacts live
- Source code
- Proof bundles
- Receipts or evidence files
- Operational access
- Money: Free evaluation saves wasted sales cycles
- Reputation: Honest claim boundaries build trust before any purchase
- Data: No data exchanged at this tier
Small teams, solo founders, early-stage operators who need basic governance proof.
- Operational memory gets lost (PP-004)
- Operators cannot debug the system (PP-011)
- Benchmark claims are hard to trust (PP-007)
- Persistent Operational Memory (basic)
- Truthpacks (read-only verification)
- CTLM Engine (basic retrieval)
- Persistent memory across sessions
- Basic proof verification capability
- Reproducible benchmark results
- Enforcement receipts
- Hash-chained audit trails
- Claims Safety Engine
- Fleet governance
- Custom policy evaluation
- Money: Reduced rework from lost context
- Reputation: Consistent decisions across sessions
- Data: No context loss between sessions
Teams that need to prove their governance to buyers, auditors, or internal stakeholders.
- We cannot prove what the AI did (PP-001)
- Governance is only policy theater (PP-003)
- Buyer cannot verify claims (PP-006)
- Runtime failure gets hidden (PP-005)
- Compliance language can create legal risk (PP-012)
- SAR Guardian (enforcement + receipts)
- Prestige-Forge (proof engine)
- Truthpacks (full bundle generation)
- Claims Safety Engine
- ChessClock (event spine)
- Hash-chained enforcement receipts
- Proof bundles with SHA-256 manifests
- Claims safety verdicts (SAFE_TO_SAY / AT_RISK)
- Temporal event logging
- Buyer-verifiable evidence packs
- Fleet governance
- Custom policy engine
- OEM/white-label rights
- Source code access
- Money: Faster audit prep, fewer compliance failures
- Reputation: Provable governance replaces promises
- Data: Tamper-evident evidence chain
Teams running controlled deployments that need continuous governance and fleet awareness.
- Fleet nodes can drift or go rogue (PP-009)
- Policy drift can destroy trust (PP-010)
- Operational memory gets lost (PP-004)
- Runtime failure gets hidden (PP-005)
- Everything in Professional
- FleetSim Trust Plane
- PolicySourceEngine
- CTLM Engine (full)
- Persistent Operational Memory (full)
- Fleet heartbeat monitoring and drift detection
- Policy pack integrity verification
- Full operational memory with retrieval
- Severity ladder and distress pulse handling
- OEM/white-label rights
- Source code access
- Custom module development
- Money: Early drift detection in controlled deployments helps reduce expensive incident risk
- Reputation: Rogue nodes caught before damage in governed scope
- Data: Receipt-backed fleet state visibility inside simulation scope
Organizations with regulatory-readiness requirements, external auditors, or buyer due-diligence obligations.
- All painpoints above
- Security work is hard to package safely (PP-008)
- Compliance language can create legal risk (PP-012)
- A good system still needs a clear buying path (PP-013)
- Everything in Operator
- BountyPipeline Sidecar
- EU AI Act Readiness (article mapping)
- OpenClaw Governed Agents
- Voidlock (execution cages)
- Full stack governance review
- Regulatory-readiness article-to-evidence mapping
- Agent execution cages with capability attenuation
- Security evidence packaging with chain-of-custody
- Shareable proof reports for third parties
- OEM/white-label rights
- Source code ownership
- Exclusive licensing
- Money: Reduced regulatory penalty risk, faster governance review cycles
- Reputation: Evidence-mapped regulatory-readiness (not compliance certification)
- Data: Receipt-backed governance trail from agent to audit for covered paths
Platform vendors who want to embed Razorglint governance into their own products.
- Their customers need governance proof and they cannot build it themselves
- Platform trust requires embedded proof infrastructure
- Selected modules from the stack, embedded under the buyer's brand
- Integration support for the buyer's existing systems
- Embeddable governance modules
- Integration guidance
- Co-branding rights for selected components
- Full source code ownership
- Right to resell as standalone product
- Modification rights without agreement
- Money: Build-vs-buy savings — years of R&D avoided
- Reputation: Embedded proof infrastructure enhances platform trust
- Data: Governance layer protects platform and end-user data
Organizations that need exclusive or semi-exclusive rights in a specific vertical or geography.
- Competitive differentiation through governance infrastructure
- Regulatory compliance in regulated industries (finance, healthcare, defense)
- Negotiated subset or full stack
- Exclusive deployment rights within defined scope
- Defined exclusivity window
- Priority support and roadmap input
- Custom integration engineering
- Ownership of IP
- Rights outside agreed scope
- Modification rights without agreement
- Money: First-mover advantage in governed AI within their vertical
- Reputation: Exclusive governance capability as market differentiator
- Data: Strongest governance evidence density available
Acquirers who want to own the technology outright.
- Need to own, not license, governance infrastructure
- Strategic acquisition of proof-producing capability
- Full source code and IP transfer for negotiated assets
- All documentation, test suites, and proof artifacts
- IP ownership
- Full source code
- Right to modify, deploy, and sublicense
- Anything excluded from the acquisition agreement
- Ongoing development commitment (unless separately contracted)
- Money: Own the asset instead of paying recurring license
- Reputation: Full control over governance claims
- Data: Complete sovereignty over the technology