We join the prime contractor's team, and the prime builds the record into what it delivers.
Programs and oversight bodies reach PacSpace through the contractors who deliver them. We work as a subcontractor under the prime.
One record, checked from both sides.
The program
A record of what its AI did that it can check itself, without asking the contractor for it each time.
The prime
An answer to oversight that doesn't need a data call, and a way to show its own records are intact whenever someone asks.
Five steps, from evaluation to handover.
Evaluation starts unclassified, on the platform as it stands.
The prime's team writes a test record with no controlled information in it, changes a copy, and checks it the way the program would.
The technical approach names the record.
What the delivered system writes, who checks it, and how. We write that part with the prime's capture team.
The record is fitted to the program's systems.
The kinds of entries the program needs, and where its systems write them.
The delivered system writes each action as it happens, and PacSpace commits it.
The program office, its test organization and its inspector general can each check the record from a link the operator shares, or with the open-source checker on their own machines.
The record stays checkable when the contract changes hands.
The next contractor and the government can still check any copy of a record the last one committed.
The operator writes the record, whoever runs the system, the prime or the agency. It still chooses what to write, the same limit every log has. What it gives up is changing the record afterward. If writing stops, the gap shows: the records on either side put a start and an end on it.
Five things a proposal can point to.
A check the agency runs itself
Where a contract must let the agency regularly monitor and evaluate an AI system, the agency monitors from a record it checks itself, with no data call each time.
Where a system must protect audit information from modification, the record gives that integrity a check anyone can run. The system's assessor decides what it satisfies.
A record that outlasts the contract
Contractors keep records available for audit for three years after final payment. Any copy kept still checks against what was committed, after final payment and through a recompete.
A prototype project can go forward when “at least one nontraditional defense contractor or nonprofit research institution” participates “to a significant extent”. PacSpace has performed no Department of Defense contract, so it meets the statute's definition. The agency decides what counts as significant.
PacSpace is not a compliance product and doesn't make a system compliant or authorized. What a record satisfies on a given system is for the program, its assessor and its counsel. OMB's two memos do not cover AI used as a component of a National Security System. The scope of each rule
A record committed under one administration is checkable in the next; a record committed by a contractor is checkable after the contract ends.
The seals live on the proof layer, infrastructure no party controls, PacSpace included, and the checker is open source. Don't trust us, trust the math. The verification survives the company.
Sources
- OMB, M-25-22, “Driving Efficient Acquisition of Artificial Intelligence in Government”, Apr 3, 2025.
- NIST, SP 800-53 Rev. 5, AU-9, Protection of Audit Information.
- NIST, SP 800-171 Rev. 2, 3.3.8.
- 32 CFR 170.14, CMMC Level 2.
- FAR 4.703, as revised in the FAR overhaul.
- 10 U.S.C. 4022(d), prototype projects.
- 10 U.S.C. 3014, nontraditional defense contractor.
- FAR 19.109, as revised in the FAR overhaul, Sept 2026.
- FAR 52.219-9, as revised in the FAR overhaul, Sept 2026.
Bring the case you think breaks it.
We would rather be evaluated by use than by description. Talk to us and we'll put you in a live environment: commit a record, do your best to change it, then check it yourself, with us out of the loop. The change shows.
The record must exist.