tandmm

RESILIENCE THROUGH CONTROL

Control what connects.
Know how AI is used.

Physically isolate critical network connections and use evidence of actual AI activity to guide access, governance and investment.

Led by former federal technology executives and healthcare leaders who understand the systems your mission depends on.

WHY NOW

Attackers and AI models are already reaching systems they were never meant to reach.

Detecting the threat is only part of the response. You need the ability to cut its access.

01 / PHYSICAL NETWORK CONTROL

When the work ends, the connection shouldn’t stay open.

Powered byGoldilock

Only when needed.
Only for as long as needed.

Move from continuous connectivity to approved connection windows, with physical isolation between them, where your operations allow.

A vendor finishes maintenance. A data transfer completes. But the connection remains available. If credentials are stolen or access controls fail, an attacker can use that opening to reach critical systems, disrupt operations, or spread into other connected environments.

Firewalls and access policies are the locks. Security monitoring tools are the cameras. A data diode makes the doorway one-way. Physical isolation removes the doorway between approved uses. Your existing controls stay in place; you gain control over whether the connection exists at all.

Goldilock FireBreak provides on-command network isolation at the physical layer. Connect selected network links only when needed, and only for as long as needed. Between approved uses, those links are physically disconnected.

THE PHYSICAL DIFFERENCE

A policy controls traffic.
A physical break removes the path.

Conceptual illustration
Logical controls compared with physical isolationThe upper path stays physically connected through access controls and monitoring. The lower path adds FireBreak, with a visible physical gap before the critical network. Use the button below to illustrate an approved connection window. SOFTWARE / LOGICAL CONTROLSGOLDILOCK LAYER 1 PHYSICAL CONTROL ExternalsystemCriticalnetworksegmentExternalsystemCriticalnetworksegment Access controlsMonitoringPath remains connected24x7 connectivity means24x7 exposureAccess controlsMonitoringExposure window you control PHYSICAL GAP CONNECTED

Software / logical controls

External system
Access controls
Monitoring

Path remains connected

Critical network segment

24x7 connectivity means 24x7 exposure

Goldilock Layer 1 physical control

External system
Access controls
Monitoring
Physical gapGoldilockConnected
Critical network segment

Exposure window you control

Physically isolated. The selected path is disconnected.

Explore an approved connection window, then close the connection.

Your access controls and monitoring stay in place. Physical isolation adds control over whether the selected connection exists.

Put physical control to work.

Start with operations.

Identify essential connections and operational dependencies before selecting a segment to isolate.

Design the right boundaries.

Define approved connection windows and how your team authorizes access.

Put control into practice.

Test physical isolation and operational continuity in a scoped pilot before expanding deployment.

Request a Disconnect Demo →

ONE APPROACH TO CONTROL

Every connection is a decision.

Control starts with knowing what your operations depend on. For critical networks, that means deciding which connections should exist and when. For AI, it means understanding actual use, access and ownership so you can decide what to approve, expand or stop. We help you turn those decisions into practical controls that support your mission.

Know what is connected. Decide what is allowed. Put control into practice.

02 / TANDMM AI VISIBILITY BASELINE

Know how AI is actually being used.

TANDMM's AI Visibility Baseline shows leadership how AI is used across public tools, personal accounts, enterprise platforms, cloud AI and agents.

Uncover shadow AI, meaning AI use outside approved tools or accounts. Use the evidence to approve useful applications, address sensitive-data exposure, assign responsibility and direct investment.

60 days. Actual usage data. Coverage defined by the systems and telemetry included in your engagement.

YOUR AI ENVIRONMENT

People & teams
ApplicationsPublic tools
Enterprise platforms
Personal accounts
Models & agentsCloud AI
Internal initiatives
Agentic activity
Connected tools & dataSystems · Data sources · MCP services
TANDMMAI Visibility BaselineObserved activity + available business data
VisibilityKnow the activity
SecurityExamine exposure
ValueDirect investment

Conceptual map. Connections and activity are identified where the relevant telemetry is available.

Build on what you have.

Keep your existing security stack.

We build on supported security, identity and cloud telemetry, adding AI-specific visibility where needed. Collection and coverage are agreed before deployment.

WHAT YOU RECEIVE

Evidence your team can use.

Receive seven deliverables at the end of 60 days, with observed findings clearly distinguished from gaps needing investigation.

01

Enterprise AI Inventory

Applications, models, agents, MCP services and major AI assets observed during the engagement.

02

AI Usage & Adoption Baseline

Who is using AI, where adoption is happening, and the business objectives indicated by observed use and customer context.

03

AI Access & Exposure Map

Where AI intersects with sensitive information, connected tools, systems and data within supported coverage.

04

AI Ownership & Accountability Register

Owners of sanctioned AI capabilities, validated with your team, and areas where accountability is unclear.

05

AI Spend & Value Baseline

Available licensing, adoption and token-consumption data, potential duplication, and use cases showing evidence of value.

06

AI Control & Visibility Gaps

Differences between observed behavior and approved tools, enterprise accounts, policies or intended controls.

07

Executive Action Plan

A prioritized view of what to expand, consolidate, control, investigate or stop.

A snapshot of three areas your Baseline can examine.

SAMPLE FINDINGS

AI Visibility Baseline

Illustrative report
47AI tools in use
118Licenses with no recorded use
23Potential data exposures
4Agents flagged for review
Explore the sample findings

AI tools discovered

6 approved41 not approved

WHAT THE NUMBERS SHOW

More AI than IT approved.

47 AI tools in use. IT approved 6.

Approval statusTools
Approved6
Not approved41

What to reviewWhich tools should be approved, restricted, or retired.

Paid AI licenses

312paid licenses
194 with recorded use118 with no recorded use

Usage over the last 60 days

WHAT THE NUMBERS SHOW

Paid for. No recorded use.

312 paid AI licenses. 118 with no recorded use in the last 60 days.

38%of paid licenses with no recorded use
Rounded from 118 of 312

What to reviewWhich licenses can be reassigned or removed before renewal.

Findings to investigate

23
Potential data exposuresPrompts flagged for possible sensitive customer information.
4
Agents flagged for reviewAgent activity identified for further investigation.

Separate findings. These counts are not a risk score.

WHAT THE NUMBERS SHOW

Know what needs attention.

23 prompts flagged for possible sensitive customer information. 4 agents flagged for further investigation.

What to reviewInvestigate flagged activity, confirm agent ownership, and review access requirements. Where findings indicate unnecessary access to critical systems, assess whether physical isolation is appropriate.

Usage evidenceLicense utilizationRisk findings

Illustrative baseline findings, not a live product screen. Results depend on your observed activity, available data and agreed coverage.

A FIXED-DURATION ENGAGEMENT

Your AI baseline in 60 days.

01 / DEPLOY

Establish visibility.

Agree on scope and data handling, then establish collection through supported infrastructure.

02 / OBSERVE

Build the evidence.

Collect actual usage data and validate the findings with your team.

03 / UNDERSTAND

Find what matters.

Identify meaningful patterns and investigate findings in their operational context.

04 / ACT

Make informed decisions.

Review the findings together and agree on priorities for action.

Continue if useful.

The paid Baseline stands on its own. Your findings and data are yours to keep, whether or not you continue. Implementation, ongoing visibility and managed governance are optional, separately scoped services.

PRACTICAL QUESTIONS

Know what to expect.

We already have a web proxy or Microsoft Purview. What does the Baseline add?

We review your existing coverage and identify unanswered questions across AI providers, accounts, agents and business data. The Baseline adds AI-specific context where evidence is missing, building on reporting you already trust.

What needs to be deployed?

No security-tool replacement is required. Supported gateways include Zscaler, Netskope and Palo Alto Prisma Access. A lightweight endpoint client can add visibility where needed. Deployment depends on compatibility and agreed scope.

Can it cover cloud AI, agents and MCP services?

Supported telemetry can reveal models, agent interactions, MCP services and tools agents report access to. Cloud logs and OpenTelemetry can add evidence, including in supported Amazon Bedrock deployments. Observed or reported access is not a complete permissions audit.

Does the Baseline enforce controls or disconnect network connections?

No. It provides evidence and an action plan. Your team decides which controls to implement through a separate engagement. Findings may inform a network assessment, but the services do not automatically trigger one another.

Does it measure value as well as risk?

Yes. It examines available adoption, licensing, token-consumption and use-case data to identify duplication and candidates for expansion. Business value is validated with your team, not inferred from activity alone.

How is captured AI data handled?

We agree on collection, access and retention before work begins. Our platform supports tenant isolation, configurable retention and customer-controlled encryption keys. GovCloud deployment is available where appropriate.

Your data is not used to train the underlying platform’s AI models, and platform administrators cannot view it in clear text. We confirm the protections and configuration that apply to your environment during scoping.

Know what to expand.
Know what to control.
Know what to stop.

Build Your AI Baseline
Powered byPortal26

Portal26 supplies AI telemetry, security and value analytics. TANDMM scopes the engagement, interprets the evidence and delivers your Baseline.

INDUSTRIES

Built around your mission.

The right controls depend on what you operate, the information you hold, and the people you serve.

Critical Infrastructure

Maintain essential operations while controlling access to critical systems. Design physical isolation around the connections your operations need, and establish an AI Visibility Baseline to understand observed AI use and sensitive-data exposure.

Water · Energy · Ports & Maritime · Healthcare

Government

Establish an AI Visibility Baseline to understand how tools and agents are being used across your organization. Use the findings to guide approved use, accountability and investment while protecting the systems and information public services depend on.

Federal · State · Local & Municipal

Tribal Nations

Exercise sovereign control over your networks and how AI is used across tribal operations. Your AI Visibility Baseline provides evidence to guide those decisions. We agree on data collection, access, retention and deployment region before work begins. Your findings and data are yours to keep. The Tribe decides.

Tribal Government · Healthcare · Utilities · Gaming

Public Safety

Protect the systems and sensitive information that emergency response, investigations and court operations depend on. Control critical network connections and use your AI Visibility Baseline to guide approved AI use, access and accountability.

Police · First Responders · State DOJs · Courts · AG Offices

ABOUT TANDMM / HOW WE DELIVER

From evidence to working controls.

TANDMM helps organizations build resilience through control of critical networks and AI use. Our experience running federal and healthcare systems grounds our work in the demands of essential operations and sensitive data. Physical Network Control governs selected connections. The AI Visibility Baseline establishes the evidence for decisions about AI use, ownership, exposure and investment.

Start with the service you need. The AI Visibility Baseline stands on its own; implementation and ongoing support are scoped separately.

01

Understand.

Understand your critical systems and operational dependencies. For AI, establish a baseline of observed activity and available business data, with coverage gaps made clear.

02

Design.

Use the findings to define priorities, appropriate controls and a practical plan around your operational needs.

03

Implement.

Put agreed controls and governance decisions into practice through a separately scoped implementation engagement.

04

Support.

Maintain and review those controls as your environment changes, with optional technical support, ongoing AI visibility and managed governance.

People

Evan Lee

Evan Lee

Co-Founder & CEO

Evan brings more than 25 years of commercial and federal technology experience, including service as CTO and CIO of the PCAOB, CTO of HHS OIG, and Chief of Solutions Architecture at DHS. He has also helped systems integrators achieve nine-figure growth in federal business.

LinkedIn ↗
Bryan Wempen

Bryan Wempen

Co-Founder & President

Bryan brings more than 25 years of healthcare and technology leadership. At TANDMM, he connects customer needs with the company’s services and leads growth and market strategy.

LinkedIn ↗
Casey Johnson

Casey Johnson

Chief Solutions Officer

Casey led the Digital Services Center effort at FDA and served as an enterprise architect for the Army’s ServiceNow program. A former CTO for national security at ICF and CTO at Unqork, he has also helped win more than $500 million in contract value.

LinkedIn ↗

Advisors

George Rivera

George Rivera

Executive Advisor, Tribal Nations

George served the Pueblo of Pojoaque for more than two decades as Lieutenant Governor and Governor, leading the development of Buffalo Thunder Resort & Casino. His experience spans tribal governance, economic development, and cultural preservation. An accomplished sculptor, his work is held in the Smithsonian’s National Museum of the American Indian.

Quinton DuBose

Quinton DuBose

Advisor, Maritime & Critical Infrastructure

Quinton brings 20 years of U.S. Coast Guard experience in port operations, emergency management, and cyber risk. He advises government and maritime leaders on cybersecurity, incident response, and critical infrastructure resilience.

LinkedIn ↗

GET STARTED

Make control part of your operations.

See physical network control in action, find out how AI is being used across your organization, or start with a conversation about both.

See physical control in action.

Live demonstration · 60 minutes

See how a network connection can be physically disconnected and restored for an approved need. Explore where this fits your operations, with the option of a 30 to 60 day pilot on a selected network segment.

Request a Disconnect Demo

Know how AI is actually being used.

AI Visibility Baseline · 60 days

Build a real-world view of observed AI usage, ownership, exposure, spend and value. Use supported existing telemetry where possible and add AI-specific visibility where needed.

Receive tangible baseline deliverables and an executive action plan. Continue with ongoing visibility and managed governance if useful.

Build Your AI Baseline

Not sure where to start?

Working session · 60 minutes

Walk through your critical systems, network connections, and AI use with our team. We will help you decide which step makes sense first.

Book a Working Session

Resilience through control.

GET IN TOUCH

Start a conversation.

Tell us what you need. Our team will follow up with you.

Verification characters

* Required. We use these details to respond to your inquiry. Please do not include sensitive or confidential information.

Prefer email? MissionSuccess@tandmm.ai