Home / Services
Four services. One workforce.

We build your Digital Employee.
Then we run, govern, and defend it.

TrueNorth Quantum delivers four discrete but tightly-coupled services. Build is a one-time, five-week engagement that produces a production-ready Digital Employee. Run, Govern, and Defend are continuous services that keep that DE operating, compliant, and secure for as long as it serves your organisation.

Build once. Operate forever.

Our service model maps to two dimensions: when the work happens (one-time vs. continuous) and how it's purchased (included with the platform vs. optional add-on).

01 · Build & Deploy

The five-week build engagement.

Every Digital Employee TNQ deploys is purpose-built — there is no shrink-wrap DE. The Build service is a structured engagement spanning six phases, producing fifteen named artifacts, gated by five client sign-off milestones. The target is M5 Go-live in approximately five weeks from SOW signature, with day-for-day adjustments if either side runs behind. Throughout the build, the Governance AI is trained in parallel with the DE itself — not bolted on at the end.

Phase 1
Discovery & Scoping
Week 0
→ M1 Discovery sign-off
Phase 2
Design & Specification
Weeks 1–2
→ M2 Spec lock
Phase 3
Build & Train
Weeks 2–3
→ M3 Build complete
Phase 4
Integration & Testing
Weeks 3–4
→ M4 Pilot pass
Phase 5
Supervised Rollout
Week 4–5
→ M5 Go-live
Phase 6
Live Operation
Week 5+
→ Ongoing services
The eighteen artifacts produced
All version-controlled · Ledger-anchored
Phase 1
Phase 2
Phase 3
Phase 4
Phase 5
Phase 6
TNQ-DE-01
Discovery Brief
TNQ-DE-04
DE Role Specification
TNQ-DE-07
DE Build Manifest
TNQ-DE-10
End-to-End Test Report
TNQ-DE-13
Shadow-Run Log
TNQ-DE-16
DE Identity Certificate
TNQ-DE-02
Candidate Role Profile
TNQ-DE-05
Policy-as-Code Definition
TNQ-DE-08
Governance Training Corpus
TNQ-DE-11
Red-Team Findings
TNQ-DE-14
Pilot Performance Pack
TNQ-DE-17
Live Audit Ledger Feed
TNQ-DE-03
Risk Tier Assessment
TNQ-DE-06
Data & Access Plan
TNQ-DE-09
Behavioural Baseline
TNQ-DE-12
UAT Sign-off Package
TNQ-DE-15
Go-Live Readiness Memo
TNQ-DE-18
Quarterly Review Pack
Five client sign-off milestones — no phase begins without written acceptance
M1
Discovery sign-off
Role + scope locked. Risk tier assigned.
M2
Spec lock
Policy boundary signed. Data plan agreed.
M3
Build complete
DE assembled. Baseline established.
M4
Pilot pass
UAT signed. Red-team findings remediated.
M5
Go-live
DE in production. Platform billing begins.
What the engagement produces

A fully-governed Digital Employee, ready for production.

Five weeks. Three swimlanes running in parallel. Eighteen versioned artifacts. One DE in production at the end — with a Governance overseer that was raised on the same training corpus.

The Build engagement is delivered under the Development Services Statement of Work (TNQ-COMM-02), attached as Exhibit A to the Platform-as-a-Service Agreement. Fees are milestone-billed: a portion at SOW signature, then successive payments at M1 through M4. Final acceptance is M5, at which point Platform Fee billing begins.

Three TNQ-named roles run the engagement: an Engagement Lead (single point of accountability), a Governance Lead (owns the risk classification, policy-as-code, and overseer training), and a DE Architect (owns the build, tool integration, and testing). Four client-side roles are required: an Executive Sponsor, Operational Owner, Technical Counterpart, and Risk/Security Officer.

Tier-calibrated

Scaled to the risk

Engagement intensity and required controls calibrated to the Risk Tier assigned in Phase 1. Tier 4 engagements include external red-team and additional client signatures.

Parallel governance

Trained alongside the DE

The Governance AI overseer is not added at the end. It is trained on the same role specification, in parallel, in Phase 3 — making behaviour-bound governance an architectural property.

Acceptance-gated

No phase begins without sign-off

Each milestone has named, specific written acceptance criteria. Silence beyond 5 business days constitutes acceptance — predictability for both parties.

Ledger-anchored

Every artifact, signed

Every deliverable is version-controlled and anchored to the audit ledger. The engagement record becomes the operating record from Phase 6 forward — no handoff loss.

02 · Platform Operations

The platform that runs everything.

Once a Digital Employee enters Phase 6 (Live Operation), TNQ runs the entire underlying platform on a 24/7/365 basis. Platform Operations is the always-on service that hosts the DE, runs the Governance AI overseer, operates the Quantum-Proof Foundation, maintains the immutable audit ledger, and applies security patches and platform upgrades. Everything in this section is included with the Platform Fee subscription — no add-on, no per-seat licensing, no separate hosting bill.

What's continuously operated

Hosting, identity, ledger, and uptime — always on.

The same Northern Shield infrastructure that has, for years, been the reference monitor for carrier-grade enterprise environments. Now operating your AI workforce on dedicated tenant infrastructure.

Platform Operations is governed by clause 2.2 of the PaaS Agreement, which enumerates exactly what is bundled into the Platform Fee. The Client's Digital Employees, Governance AI instances, Client Data, and audit ledger entries are deployed on infrastructure dedicated to the Client — not co-mingled with other clients' workloads.

The service is calibrated by Risk Tier (per the TNQ-DE-03 Risk Tier Assessment): a Tier 4 deployment is operated to higher uptime targets and more frequent retraining cadences than a Tier 1. SLAs are documented in Schedule C of the PaaS Agreement.

Dedicated hosting

Single-tenant by default

Your Digital Employees and Governance AI run on infrastructure dedicated to your organisation. No multi-tenant noise. No noisy-neighbour risk.

Intelligence Layer

Four-tier hierarchy operated

Master Session → Governance Agent → Architecture Agent → Worker Agents. Continuously operated. Type-theoretic boundaries enforced at every layer.

Quantum-Proof Foundation

PQC everywhere, always

Post-quantum cryptography across transport, storage, and audit ledger. Warm / Cold / Frozen custody tiers continuously available. FIPS 140-2 Level 3 HSM.

Immutable audit ledger

Every action, forever

Every prompt, tool call, governance decision, and outcome — anchored to the blockchain audit ledger. Two years of full-fidelity history by default; longer on request.

Platform upgrades

Patching, on us

Security patches, platform upgrades, dependency updates, model improvements — managed by TNQ on a documented change-control cadence. No customer maintenance windows.

Standard support

Business-hours response

Standard support included with the Platform Fee. Documentation, training materials, configuration assistance, and Master Portal user administration.

What's included with Platform Operations
Status
DE hosting + Governance AI hosting (dedicated tenant)
✓ Included
Intelligence Layer 24/7 operation
✓ Included
Quantum-Proof Foundation + immutable ledger
✓ Included
Baseline monitoring + ledger feed access
✓ Included
Patches, upgrades, dependency management
✓ Included
Standard business-hours support
✓ Included
24/7 SOC + agent-aware threat detection
+ CyberDefense add-on
03 · Governance & Compliance

Continuous surveillance of every action.

Launching a Digital Employee in production is not the end of the governance work — it is the start. The Governance & Compliance service is the continuous oversight regime that watches every action the DE takes, detects drift before it becomes incident, packages evidence for auditors and regulators, and adjusts policy boundaries as the role evolves. This service is included with the Platform Fee subscription — because we believe deploying an AI agent without continuous governance is the same as deploying it without governance at all.

What surveillance looks like

The overseer is always watching.

The Governance AI trained in Phase 3 is not deployed and forgotten. It evaluates every prompt, every tool call, every decision — in real time, at machine speed, with the formal authority to halt an action before it executes.

The Governance & Compliance service operates on three time scales: per-action (the overseer evaluates every decision before it executes), per-day (drift detection runs continuously against the behavioural baseline established in Phase 3), and per-quarter (governance board reviews authority adjustments, policy updates, and regulatory mapping).

The frequency of every surveillance activity is calibrated by Risk Tier. A Tier 1 DE has a daily summary review; a Tier 4 DE has per-action human approval. The Oversight Cadence Table in the Risk Tier Assessment (TNQ-DE-03) defines exactly what cadence applies to each Digital Employee.

Per-action evaluation

Policy gate in microseconds

Every action evaluated against the compiled policy-as-code before execution. Forbidden actions blocked. Approval-required actions escalated. Authorised actions proceed and are signed.

Drift detection

Compared to baseline

Live behavioural patterns continuously compared to the baseline established in Phase 3. Deviation thresholds trigger alerts. Pattern shifts trigger human review.

Audit ledger curation

Regulator-ready evidence

The immutable ledger captures every action. TNQ packages, indexes, and prepares ledger excerpts for auditor review, regulatory disclosure, or insurance underwriting on demand.

Policy adjustment

Authority that evolves

As trust accrues, authority can be expanded; as risk surfaces, authority can be tightened. Every adjustment is a versioned change to the policy-as-code with formal approval.

Quarterly governance board

Recurring review

Every quarter, TNQ delivers the Quarterly Review Pack (TNQ-DE-18) — drift summary, KPI performance, exception review, authority recommendations. Joint Client and TNQ review.

Regulatory mapping

Evidence per regime

For each applicable regulation (GDPR, HIPAA, EU AI Act, SOC 2, sector-specific), TNQ maintains the artifact-to-clause mapping that demonstrates compliance — produced as a side-effect of operation.

04 · CyberDefense Monitoring · Optional

Defending the AI workforce itself.

The Governance service prevents your Digital Employee from doing the wrong thing on purpose. CyberDefense Monitoring is the layer that prevents external actors from manipulating, exfiltrating from, or impersonating your DE. It is an optional add-on under the PaaS Agreement (Schedule B), priced as a percentage of monthly Platform Fees with a fixed minimum. Once elected, it scales automatically as your workforce grows.

What 24/7 SOC looks like

The same SOC discipline, now defending AI.

CyberDefense is not bolted on as a separate tool. It is woven into the Northern Shield's operational fabric — the same SOAR loop that monitors infrastructure at carrier-grade scale across the most demanding enterprise environments, now tuned to defend agent-shaped workloads.

The CyberDefense Monitoring service covers the new threat surface that an AI workforce creates: prompt injection, credential abuse, lateral movement through DE tool access, model poisoning, output manipulation, and impersonation of cryptographic identity. Traditional endpoint and identity tools do not see these attack patterns; the TNQ SOC is purpose-built to recognise them.

The service operates as a continuous SOAR loop: Monitor → Analyse → Plan → Execute → Assess → Adjust. Threat detection ML runs against the audit ledger in real time. Severity-1 incidents trigger autonomous containment (suspending the DE under a documented run-book). Lower-severity events route through ChatOps to your on-call team.

24/7 SOC

Eyes on the workforce

Continuous human-supervised monitoring of every DE in production. Tuned alert thresholds. Coverage across all time zones and shifts.

Agent-aware detection

Threat models for AI

ML-driven detection specifically tuned for AI-agent threat patterns. Prompt injection. Jailbreak attempts. Tool-call abuse. Model manipulation. Identity spoofing.

SIEM federation

Plays with your stack

Federates with Splunk, Elastic, IBM QRadar, ArcSight, Microsoft Sentinel, and others. Bidirectional. We don't replace what works — we extend it.

SOAR automation

Response at machine speed

Autonomous incident response under documented run-books. DE suspension authority. ChatOps escalation. Replay-from-ledger forensics in one click.

Incident response

Expert human backstop

TNQ incident-response analysts engage for any severity-1 event. Communication plan execution. Coordination with client security and legal. Post-mortem package delivered.

Insurance-grade evidence

Underwriter-ready records

Quantitative incident telemetry packaged for cyber-policy underwriting and renewal cycles. Insurance partnerships via Gallagher. The audit ledger is the evidence underwriters want.

Commercial structure: aligned to value.

We do not charge for the build until value starts. The Platform Fee subscription does not begin until your Digital Employee enters production at M5. You only pay for a DE that is actually doing work for you.

Onboarding fee · one-time, milestone-billed
Value starts here — M5 Go-live
Monthly subscription · per active Digital Employee
Build & Deploy

Phases 1–4. Five weeks typical. Milestone-billed (20% SOW signature, then 15/20/20/25% at M1–M4). Final invoice at M4 acceptance.

Platform + Governance subscription

Begins at M5 Go-live. Per active Digital Employee, monthly in advance. Includes Platform Operations and Governance & Compliance — bundled, never separate.

Optional CyberDefense Monitoring
Priced as a percentage of monthly Platform Fees, with a fixed minimum. Scales automatically as your DE workforce grows. Elected by countersigning Schedule B — at any time during the term.

Build, operate, govern, defend.
One platform. One contract.

A 30-minute discovery call. We map a candidate role, classify the risk tier, scope the build, and tell you what your first DE could look like in production — including which services are bundled and what the monthly economics look like.