Water · 2026
Attackers locked operators out of water system controls in at least seven states, forcing manual operations and boil water notices.
Source: Reuters ↗RESILIENCE THROUGH CONTROL
Physically isolate critical network connections and use evidence of actual AI activity to guide access, governance and investment.
Led by former federal technology executives and healthcare leaders who understand the systems your mission depends on.
WHY NOW
Detecting the threat is only part of the response. You need the ability to cut its access.
01 / PHYSICAL NETWORK CONTROL
Move from continuous connectivity to approved connection windows, with physical isolation between them, where your operations allow.
A vendor finishes maintenance. A data transfer completes. But the connection remains available. If credentials are stolen or access controls fail, an attacker can use that opening to reach critical systems, disrupt operations, or spread into other connected environments.
Firewalls and access policies are the locks. Security monitoring tools are the cameras. A data diode makes the doorway one-way. Physical isolation removes the doorway between approved uses. Your existing controls stay in place; you gain control over whether the connection exists at all.
Goldilock FireBreak provides on-command network isolation at the physical layer. Connect selected network links only when needed, and only for as long as needed. Between approved uses, those links are physically disconnected.
THE PHYSICAL DIFFERENCE
Path remains connected
24x7 connectivity means 24x7 exposure
Exposure window you control
Physically isolated. The selected path is disconnected.
Explore an approved connection window, then close the connection.
Your access controls and monitoring stay in place. Physical isolation adds control over whether the selected connection exists.
Identify essential connections and operational dependencies before selecting a segment to isolate.
Define approved connection windows and how your team authorizes access.
Test physical isolation and operational continuity in a scoped pilot before expanding deployment.
ONE APPROACH TO CONTROL
Control starts with knowing what your operations depend on. For critical networks, that means deciding which connections should exist and when. For AI, it means understanding actual use, access and ownership so you can decide what to approve, expand or stop. We help you turn those decisions into practical controls that support your mission.
See what AI touches. Decide what AI can do. Control what AI can reach.
02 / TANDMM AI VISIBILITY BASELINE
TANDMM's AI Visibility Baseline gives leadership a real-world view of AI across the organization, from public AI tools and personal accounts to enterprise platforms, cloud AI, agents and connected services.
You cannot make sound decisions about AI you cannot see. The Baseline gives your team evidence to approve useful applications, address sensitive-data exposure, assign responsibility and direct investment. Those decisions become the foundation for ongoing AI governance and control.
60 days. Actual usage data. Coverage defined by the systems and telemetry included in your engagement.
YOUR AI ENVIRONMENT
Conceptual map. Connections and activity are identified where the relevant telemetry is available.
Keep your existing security stack.
We use supported security, identity and cloud telemetry where possible, add AI-specific visibility where needed, and make coverage gaps explicit. We agree on usable sources and additional collection before deployment.
WHAT YOU RECEIVE
Seven tangible outputs, grounded in observed activity and available data. Each distinguishes findings from gaps that need further investigation.
Applications, models, agents, MCP services and major AI assets observed during the engagement.
Who is using AI, where adoption is happening, and the business objectives indicated by observed use and customer context.
Where AI intersects with sensitive information, connected tools, systems and data within supported coverage.
Owners of sanctioned AI capabilities, validated with your team, and areas where accountability is unclear.
Available licensing, adoption and token-consumption data, potential duplication, and use cases showing evidence of value.
Differences between observed behavior and approved tools, enterprise accounts, policies or intended controls.
A prioritized view of what to expand, consolidate, control, investigate or stop.
SAMPLE FINDINGS
Illustrative baseline findings, not a live product screen. Results depend on your observed activity, available data and agreed coverage.
A FIXED-DURATION ENGAGEMENT
Scope the environment and data handling. Use supported existing infrastructure and add visibility where needed.
Collect real usage data to identify patterns, rather than relying on interviews or assumptions.
Examine adoption, exposure, ownership, duplication, risk, spend and value.
Review the baseline and prioritize what to expand, consolidate, control or investigate.
The paid baseline stands on its own. You can then choose ongoing visibility, managed governance and supported controls as your needs evolve.
PRACTICAL QUESTIONS
It provides important evidence about web activity. The Baseline adds AI-specific context around supported applications, accounts, models, agents, connected tools, use cases, licensing, exposure and value. Existing proxy telemetry can contribute to the baseline rather than be replaced.
We start by reviewing what your existing tools already cover. If questions remain across AI providers, cloud services, developer tools or business data, we scope the additional evidence needed. The aim is to close useful gaps, not duplicate reporting you already trust.
No replacement is required. Supported secure web gateways include Zscaler, Netskope and Palo Alto Prisma Access. A lightweight endpoint client is available where additional visibility is needed. The collection approach depends on compatibility and the agreed scope.
Supported telemetry can reveal observed models, agent interactions, MCP services and tools agents report access to. Cloud logs and OpenTelemetry can provide additional evidence in supported deployments, including Amazon Bedrock scenarios. Observed or reported access is not a complete permissions audit.
No. AI findings can inform a separate network assessment to determine where physical isolation fits. Your team decides which controls to implement. The services do not automatically trigger one another.
The Baseline gives your team evidence to define approved AI use, assign ownership, address exposure and prioritize investment. It includes an executive action plan. Implementing governance changes and providing ongoing managed governance are separate follow-on services.
No. The Baseline also examines adoption, licensing, token consumption, duplication and use cases where evidence is available. Usage helps identify candidates for expansion; business value is validated with your team, not inferred from activity alone.
We agree on what data is collected, who can access it, and how long it is retained before work begins. Our platform supports tenant isolation, configurable retention and customer-controlled encryption keys. GovCloud deployment is available where appropriate.
Your data is not used to train the underlying platform’s AI models, and platform administrators cannot view it in clear text. We confirm the protections and configuration that apply to your environment during scoping.
The standard AI Visibility Baseline is a 60-day engagement. It concludes with the baseline deliverables and an executive action plan. Ongoing visibility, governance and supported controls are optional.
Start with the AI questions your current reporting cannot answer.
Portal26 provides enterprise AI telemetry, AI security and value analytics that enable the TANDMM service. TANDMM scopes the engagement, interprets the evidence and delivers the baseline.
INDUSTRIES
The right controls depend on what you operate, the information you hold, and the people you serve.
Maintain essential operations while controlling access to critical systems. Design physical isolation around the connections your operations need, and establish an AI Visibility Baseline to understand observed AI use and sensitive-data exposure.
Water · Energy · Ports & Maritime · Healthcare
Establish an AI Visibility Baseline to understand how tools and agents are being used across your organization. Use the findings to guide approved use, accountability and investment while protecting the systems and information public services depend on.
Federal · State · Local & Municipal
Exercise sovereign control over your networks and how AI is used across tribal operations. Your AI Visibility Baseline provides evidence to guide those decisions. We agree on data collection, access, retention and deployment region before work begins. Your findings and data are yours to keep. The Tribe decides.
Tribal Government · Healthcare · Utilities · Gaming
Protect the systems and sensitive information that emergency response, investigations and court operations depend on. Control critical network connections and use your AI Visibility Baseline to guide approved AI use, access and accountability.
Police · First Responders · State DOJs · Courts · AG Offices
ABOUT TANDMM / HOW WE DELIVER
TANDMM helps organizations build resilience through control of critical networks and AI use. Our experience running federal and healthcare systems grounds our work in the demands of essential operations and sensitive data. Physical Network Control governs selected connections. The AI Visibility Baseline establishes the evidence for decisions about AI use, ownership, exposure and investment.
Start with the service you need. The AI Visibility Baseline stands on its own; implementation and ongoing support are scoped separately.
Understand your critical systems and operational dependencies. For AI, establish a baseline of observed activity and available business data, with coverage gaps made clear.
Use the findings to define priorities, appropriate controls and a practical plan around your operational needs.
Put agreed controls and governance decisions into practice through a separately scoped implementation engagement.
Maintain and review those controls as your environment changes, with optional technical support, ongoing AI visibility and managed governance.

Co-Founder & CEO
Evan brings more than 25 years of commercial and federal technology experience, including service as CTO and CIO of the PCAOB, CTO of HHS OIG, and Chief of Solutions Architecture at DHS. He has also helped systems integrators achieve nine-figure growth in federal business.
LinkedIn ↗
Co-Founder & President
Bryan brings more than 25 years of healthcare and technology leadership. At TANDMM, he connects customer needs with the company’s services and leads growth and market strategy.
LinkedIn ↗
Chief Solutions Officer
Casey led the Digital Services Center effort at FDA and served as an enterprise architect for the Army’s ServiceNow program. A former CTO for national security at ICF and CTO at Unqork, he has also helped win more than $500 million in contract value.
LinkedIn ↗Executive Advisor, Tribal Nations
George served the Pueblo of Pojoaque for more than two decades as Lieutenant Governor and Governor, leading the development of Buffalo Thunder Resort & Casino. His experience spans tribal governance, economic development, and cultural preservation. An accomplished sculptor, his work is held in the Smithsonian’s National Museum of the American Indian.
Advisor, Maritime & Critical Infrastructure
Quinton brings 20 years of U.S. Coast Guard experience in port operations, emergency management, and cyber risk. He advises government and maritime leaders on cybersecurity, incident response, and critical infrastructure resilience.
LinkedIn ↗GET STARTED
See physical network control in action, find out how AI is being used across your organization, or start with a conversation about both.
Live demonstration · 60 minutes
See how a network connection can be physically disconnected and restored for an approved need. Explore where this fits your operations, with the option of a 30 to 60 day pilot on a selected network segment.
Request a Disconnect DemoAI Visibility Baseline · 60 days
Build a real-world view of observed AI usage, ownership, exposure, spend and value. Use supported existing telemetry where possible and add AI-specific visibility where needed.
Receive tangible baseline deliverables and an executive action plan. Continue with ongoing visibility and managed governance if useful.
Build Your AI BaselineWorking session · 60 minutes
Walk through your critical systems, network connections, and AI use with our team. We will help you decide which step makes sense first.
Book a Working SessionResilience through control.