CNCK0NSULTAI-Truthuni0naiHackatonipIII ↗k0nsult.dev ↗ dla botówDomeny osobne, spięte siecią CNC + kernelem.
K0NSULT // ai-truth/ipIII
k0nsult.cloud / ai-truth / ipIII / global-launch / en

K0NSULT ipIII — Evidence-first Cyber & AI Incident Orchestrator. Global launch.

One evidence model that connects a finding from a scanner/pentest/SOC to evidence ready to present to the board, audit, and the regulator — in the home market (EU/PL) and in parallel in target markets (US, AU, further jurisdictions). This is the product-launch page: it shows regulatory timing, numbers from the code, and a clear MVP/ROADMAP status — without promises that evidence does not support.

How to read this page. Numbers about the product (pages, endpoints, parsers, modules, tests) are real and verifiable in /pages.json and /dev-api-reference. Everything related to regulation, deadlines, and markets is labeled decision-support — organizing material, not legal advice. Status MVP = works today and has code/test/endpoint. Status ROADMAP = planned, not yet built. ipIII does not replace scanners, SIEM, or GRC systems — it is an evidence and orchestration layer complementary to them, not a substitute.
A cyber+AI regulatory wave is hitting several markets in parallel. One evidence model is enough for all of them.

DORA, NIS2, the AI Act in the EU; SEC disclosure obligations and a patchwork of state-level AI regulations in the US; Privacy Act reform and the SOCI Act in AU — each market requires a different report format, but the same foundation: documented, time-consistent evidence of an incident and of corrective action. ipIII builds this foundation once — import → incident → evidence-package (hash) → retest → close — and configures the output (regulatory pack) for the market in which the client operates.

MODEL: findingincidentevidence-package (hash)per-market regulatory mappingBoard Pack / regulator report

Markets and regulatory timing (decision-support)

The dates and act names below are public facts as of the review date (2026-07-05), cited for information only. This is not legal advice — qualification for a specific company, sector, and factual situation is determined by the client's lawyer/DPO/law firm. Deadlines get moved (see Digital Omnibus below) — always verify the current status in the Official Journal / register applicable to the jurisdiction.

MarketKey frameworks and deadlinesipIII support status
EU
home market
DORA — Regulation (EU) 2022/2554, applicable since 17.01.2025 (operational resilience of the financial sector) · NIS2 — Directive (EU) 2022/2555, transposition into national law ongoing across member states · AI Act — prohibited practices since 2.02.2025, GPAI obligations unchanged, high-risk (Annex III, e.g., scoring/HR) postponed from 2.08.2026 to 2.12.2027 (the Digital Omnibus package, pending confirmation in the EU Official Journal) · GDPR — personal data protection, 72-hour breach notification obligation. MVP — the Legal Trigger Engine and evidence-package map to these frameworks today; see /legal-engine and /dora-tiber.
US
target market
SEC cyber disclosure rules — obligation to disclose a material cyber incident in Form 8-K (Item 1.05) for listed companies · state AI laws, e.g., the Colorado AI Act (regulation of algorithmic discrimination; effective dates have been pushed back before — verify current state-level status) · breach notification laws — data breach notification obligations vary state by state. ROADMAP — US mapping requires a dedicated regulatory pack; today available as informational material, see /global-compliance.
AU
target market
Privacy Act 1988 — reform (further tranches of amendments underway, including strengthened transparency and individual rights) · SOCI Act (Security of Critical Infrastructure Act) — cyber incident reporting obligations for critical infrastructure entities, with reporting deadlines varying by incident severity. ROADMAP — no dedicated regulatory pack yet; this market is queued for prioritization after the US.
Global
cross-cutting trend
A growing, cross-cutting obligation for documented evidence of cyber and AI incidents — regardless of jurisdiction: voluntary frameworks (NIST AI RMF, ISO/IEC 42001, ISO/IEC 27001) are increasingly becoming a reference point for regulators and auditors assessing the maturity of risk management. MVP — the evidence model import → incident → evidence-package → retest → close is by design independent of any specific framework; the regulatory pack is a configuration layer on top.

Global value — one evidence model, many markets

Claim ≤ proof, regardless of jurisdiction

The doctrine on which ipIII is built does not depend on the market: every claim has code, a test, and an endpoint, or it is explicitly labeled ROADMAP. The same evidence-package (hash, chain-of-custody) serves as the starting point for an EU, US, or AU review.

Regulatory packs — configurable per market

Mapping obligations to deadlines and form fields is a configuration layer on top of a shared incident model — not a separate system per country. EU already works (MVP); US/AU are ROADMAP, prioritized by pilot demand.

One incident definition, many recipients

The same evidence-package feeds the Board Pack for the board, the package for the auditor, and the draft regulator filing — without manually re-entering data between country-specific formats.

Complementary, not a replacement

ipIII is not a scanner, a SIEM, or a GRC system. It ingests their outputs (19 import parsers) and builds an evidence layer on top of the client's existing tool stack — in every market where the client already operates.

Numbers from the code — verifiable, not marketing

Every number below is computed at runtime from /api/ip3/ssot (an endpoint that parses the repo files on every call) — zero market estimates presented as fact. The test-suite count is a static, manually updated number (tests/ip3-*) — it has no dedicated field in /api/ip3/ssot.

243
ipIII module pages (PL)
registry /pages.json
44
/api/ip3/v1 endpoints
19
import parsers
SARIF, SBOM, secrets, cloud posture, DefectDojo, Burp, Nessus, CSV and more
69
backend modules
routes/ip3-*.js
81
test suites
unit + integration + E2E, tests/ip3-* (static count, as of 2026-07-09)
6
MCP tools
AI agent integration (read-only)

numbers (except test suites) refreshed from /api/ip3/ssot — values above are fallback (last known state); loading live…

Hardening layers in progress (status ROADMAP, see /known-limitations): OIDC/identity federation, hash-chain + evidence signing (PAdES/TSA), multi-tenant isolation (tenancy/RLS), transport mTLS.

Who the global launch is for

Financial corporations

Banks, insurers, payment institutions — under pressure from DORA (EU) and SEC disclosure (US); they need a Board Pack and evidence ready before the auditor/regulator.

Critical infrastructure operators

Energy, telecommunications, healthcare — under NIS2 (EU) and the SOCI Act (AU); they need a consistent incident register regardless of which regulator is asking.

AI system providers

Companies building/deploying high-risk systems under the AI Act (EU) and state AI laws (US); they need evidence from the model card and human oversight, not just declarations.

Cyber / pentest / MSSP firms

Teams producing findings (Burp, ZAP, Nessus, SARIF) need a layer that turns a test result into time-closed evidence — for their own clients, in any market.

Positioning — honestly

A new category, complementary to the existing stack. ipIII does not claim to be the only or the best tool on the market — we have no evidence for that and will not claim it. We position ourselves as an evidence and orchestration layer alongside the scanners (SAST/DAST/SCA), SIEM, and GRC systems the client already has.
MVP with an explicit ROADMAP, not a finished banking product. Global launch means entering several markets in parallel under a controlled pilot (PoC, synthetic data, after RoE/NDA/DPA) — not a production offer without defined scope. Elements without evidence (code+test+endpoint) are labeled ROADMAP, never presented as ready.

Frequently asked questions

Does ipIII already have complete support for all four markets (EU/US/AU/Global)?

No. EU is MVP today — the Legal Trigger Engine and evidence-package map to DORA/NIS2/AI Act/GDPR. US and AU are ROADMAP: informational material is available (/global-compliance), but a dedicated regulatory pack has not been built yet. Global launch describes direction and timing, not a finished feature set.

Is this page legal advice on DORA, the AI Act, the SEC, or the SOCI Act?

No. All information about regulations and deadlines is decision-support — organizing material for a conversation with the lawyer/DPO/law firm applicable to the client's jurisdiction and sector. Deadlines get moved (example: the postponement of AI Act Annex III via the Digital Omnibus package) and require ongoing verification.

Does ipIII replace security scanners, a SIEM, or GRC systems?

No. ipIII ingests the outputs of existing tools (19 import parsers: SARIF, SBOM, secrets, cloud posture, SIEM/CTI, DefectDojo, Burp, Nessus, CSV and more) and builds from them an evidence-package with a checksum and a decision-ready Board Pack. Detection, scanning, and risk management remain with the client's dedicated tools.

How do we start — what is the first step for a global entry?

A controlled pilot (PoC) on synthetic data, after signing Rules of Engagement, an NDA, and a DPA. Submit a request via /pilot-intake; partner terms via /partner and /partner-program.

Is this page's Polish source considered the primary version?

Yes. This English page is a translation of the Polish source as published on 2026-07-05; the Polish page remains the primary reference and is updated first. hreflang tags link both language versions, with Polish set as x-default. If the two versions ever diverge, treat the Polish original as authoritative pending a sync.

Start here

Submit a controlled pilotPoC on synthetic data, after RoE/NDA/DPA — /pilot-intake Partner & Pilot Modeentry terms for implementation partners — /partner Partner programpartner program (F13) — /partner-program Product valuewho it's for and why, numbers from the code — /wartosc-produktu
Ethical and legal boundary. ipIII is a defense and compliance (GRC/blue) tool. It does not perform unauthorized scans, exploitation, or hack-back. All regulatory mappings and market timing are decision-support, not legal advice. Pilot data is synthetic; test activity stays strictly within the boundaries of signed Rules of Engagement.

Related: known-limitations register → /known-limitations · status matrix → /status-matrix · detailed market review → /global-compliance.