§ Capability statement

Capability Statement.

The work we perform, the deployment shapes we support, and the controls we build around private agent systems. Twelve platform capabilities. Four deployment shapes. One evidence package your examiner can accept.

In plain terms: a teaming-packet-ready statement of what we do, where it runs, and how it passes an audit.

Canall.ai, Inc. forward-deploys private agent platforms for teams that need AI to operate inside real security, policy, and procurement constraints.

We are a Delaware C-corporation, foreign-registered in Virginia and headquartered in Henrico County (greater Richmond). The platform — twelve capabilities, four deployment shapes, the same agent library across all four — is built and in production use. The cut that produces a company this size is the founder's combination: enough platform-engineering depth to have designed the product personally, and enough experience of regulated data environments to know what an examiner asks for.

“The deliverable at the end of a deployment is not only a working system — it is an evidence package the customer hands to their examiner.”

The twelve capabilities.

An agentic platform-for-platforms requires twelve components. A customer building this themselves builds all twelve and then staffs their maintenance indefinitely. The table below is the build-versus-buy argument in its entirety — all twelve are built and in production use.

#CapabilityCanall implementation
01Multi-model abstractionAny LLM, any provider — frontier, open-weight, on-host, or sealed. Swap per agent without rewriting it.
02Cost and loop guardrailsBudgets enforced before tokens are spent. Depth and time bounded per agent, per task, per tenant.
03Secrets managementSecrets broker — the agent never sees the key. Scoped tokens, brokered access.
04Observability and tracingEnd-to-end traces with span-level cost and latency. Every run traced and replayable.
05Evaluation harnessEvals plus a tuning arena, built in. Accuracy measured on your golden tasks, not a vendor benchmark.
06Policy and governancePolicy enforced at the runtime, not in application code. RBAC plus OWASP agentic hardening.
07Deployment portabilityHosted, VPC, on-premises, or air-gapped. Same platform, four perimeters.
08Skill and connector librarySnap-in skills, extended with each engagement. The accumulated library is the asset.
09Human-in-the-loop surfacesApproval surfaces as a first-class primitive. A reviewer signs before it lands.
10Sandboxed executionPer-session isolation with controlled egress. Containers per run.
11Agent design and deployment loopDesign, configure, evaluate, deploy. The loop is the product.
12A team to maintain all of itOne platform, one team, forward-deployed. The Standing Account keeps it fitting.

Why it survives an audit.

The capabilities above are engineering. What follows is why a risk officer signs — the six controls that make a private agent platform defensible at the perimeter your examiner expects.

  • Nothing leaves unless approved. Egress is an explicit allow-list, not a default. In air-gapped configurations there is no egress path at all.
  • The agent never holds credentials. The secrets broker issues scoped, brokered access; a compromised or misbehaving agent cannot exfiltrate a key it never possessed.
  • Every run is traced and replayable. Span-level traces with cost and latency produce an audit trail that answers which model processed which data, when, under whose authority.
  • Outputs carry their sources. Citation-grounded generation means each assertion points back to the passage that supports it. The system reports when the record does not answer the question rather than guessing.
  • Accuracy is measured, not asserted. The evaluation harness runs against your own golden tasks, producing documented performance on your data rather than a vendor benchmark on someone else's.
  • Policy is enforced at runtime. RBAC plus OWASP agentic hardening, with policy evaluated by the runtime rather than trusted to application logic.

The commercial translation: the deliverable at the end of a deployment is not only a working system but an evidence package — trace samples, eval results on the customer's tasks, policy configuration, and access model — that the customer hands to their examiner or auditor.

Company & procurement facts.

Legal entity Canall.ai, Inc. — Delaware C-corp, foreign-registered in Virginia
Headquarters Henrico County, Virginia (greater Richmond)
Founder & CEO Mark Avallone — 20+ yrs engineering leadership, regulated/data-intensive enterprises (3E, S&P Global, SNL Financial); MBA, College of William & Mary
Hardware partner Richmond-based, SWaM-certified hardware partner
Virginia SWaM / SBSD Filed, pending award TBD
SOC 2 / ISO 27001 Pursuing — Type I first; Type II window to follow
StateRAMP / FedRAMP Target — on customer pull
Contract vehicles None held; cooperative or state-term vehicle is a named objective
NAICS code(s) TBD
PSC code(s) TBD
UEI TBD
CAGE TBD
SAM.gov entity TBD
Street address & geo TBD

Codes marked TBD are pending founder/ops input and will be populated as registrations and certifications complete. We will not list a certification we have not been awarded.

Where it runs.

Four deployment shapes. One platform, one agent library, one license. The perimeter is a risk-model decision, not a re-platforming one — and an upgrade between shapes is a configuration change, not a migration.

Questions we hear.

What does Canall.ai deliver?
A forward-deployed private agent platform. Twelve platform capabilities — multi-model abstraction, cost and loop guardrails, secrets broker, observability and tracing, evaluation harness, policy and governance, deployment portability, skill and connector library, human-in-the-loop surfaces, sandboxed execution, agent design and deployment loop, and a team to maintain all of it. All twelve are built and in production use.
Where does the platform run?
Four shapes, one platform: Hosted, Customer VPC, On-premises, or Air-gapped. The agent library and license are identical across all four — pick the perimeter that matches your risk model. For air-gapped work there is no outbound path at all.
How does it survive an audit?
Six controls: egress is an explicit allow-list, not a default; the agent never holds credentials (a secrets broker does); every run is traced and replayable; outputs carry their sources (citation-grounded); accuracy is measured on your tasks, not asserted; access is controlled and policy is enforced at runtime. The deliverable at the end of a deployment is an evidence package the customer hands to their examiner.