The engine can run inside your perimeter. The interface is yours.

There are contexts where data cannot leave: sovereignty, contract, sector regulation. The appliance exists for those — collector, engine, and encrypted weights in a licensed binary, executable in the partner's environment. It is an integration component, not a shelf product: whoever licenses it builds the end experience.

01The problem

Embedding cryptographic exposure measurement into a product, a consulting operation, or an environment where data cannot travel — without building the model and calibration from scratch.

What is at stake

  • Building your own model requires a calibration base that only exists with collection at scale.
  • Sending client data outside the perimeter is unworkable under a share of contracts.
  • A score computed with a bespoke methodology is not comparable to anyone's sector ruler.
  • Integrating an engine requires a stable data contract, not an API that changes every release.
02Evidence

The appliance uses the same collector employed in GWK's at-scale collection and the same calculation engine — it is not a reduced version. What packaging adds is protection: compiled code, encrypted weights, and licensing, so the model can run outside GWK infrastructure without exposing the calibration.

The appliance uses the same collector employed in GWK's at-scale collection and the same calculation engine — it is not a reduced version. What packaging adds is protection: compiled code, encrypted weights, and licensing, so the model can run outside GWK infrastructure without exposing the calibration.

Source
GWK packaging architecture
Date
July 12, 2026
Population
Same collector and engine as the operational run
Coverage
Public collection and local calculation; optional declarative layer, when the integrator supplies it.

Limitation: The appliance is in internal use and licensed by contract, case by case. There is no general availability, price list, or self-service.

03What is in the package

A binary and a data contract. Everything above that — screen, flow, authentication, report — is built by whoever integrates.

Collector

Internal use

The same public collection module used in at-scale runs.

Calculation engine

Internal use

Score, dimensions, contributors, coverage, and mode, on GWK's ruler.

Protected weights

Internal use

Encrypted calibration: the model runs without the parameters being readable.

License and structured outputs

Internal use

Execution contract and raw plus calculated output in a stable format.

04What the integrator receives

Components and documentation. The product layer is the partner's responsibility, and that division is the appliance's very definition.

  • A binary compiled for the agreed environment.
  • An execution license with defined scope and term.
  • A versioned input and output data contract.
  • Raw collection output and calculated engine output.
  • Integration and operation documentation.
  • A technical channel for integration questions.

What it depends on

  • A licensing agreement — there is no open distribution.
  • An execution environment defined and validated with GWK.
  • A product layer built by the partner: interface, authentication, flow, and presentation.
05What the appliance is not

The costliest confusion here would be selling an integration component as a finished product. The binary calculates; it does not serve a business user.

Observed

Public collection saw

  • The same public surface that at-scale collection observes.

Calculated

The IEQ engine derived

  • Score, level, dimensions, and contributors.
  • Coverage and the calculation mode applied.

Declared

The organization reported

  • An optional declarative layer, when the integrator supplies it.

Inferred

The model estimated

  • Sector priors applied in the absence of a declaration.

Out of scope

Other evidence decides

  • A portal, dashboard, or business-user interface.
  • A public API or general availability of the product.
  • A managed service, end-user support, or delegated operation.
  • Access to the model's weights, parameters, or internal rules.

What this comparison is measured against

Cutoff date
July 12, 2026
Run
producao_324k_20260712
Population
316,911 companies
Sectors
15 sectors in the engine taxonomy
Anonymity floor
K = 30

Limits of the comparison

  • The ruler is a static reference base, not a continuous measurement: there is no automatic update between one run and the next.
  • Comparison is always against anonymous aggregates, never against another organization's individual result.
  • A public-mode result does not compare to a complete-mode result, because the two readings start from different kinds of evidence.

Boundary

Where measurement ends

Adequacy programNot implemented

Measurement ends at: the technical change in the environment. Measuring exposure does not reduce it: reduction requires changing configuration, replacing certificates, switching negotiation policy, or migrating libraries — work carried out by the organization's own teams and suppliers.

This readout delivers

  • Collection and calculation executable inside your perimeter.
  • Results on the same ruler GWK uses.
  • Protection of the calibration while the model runs elsewhere.

After the change, GWK

  • Re-collects public signals and recalculates IEQ on the same ruler, when contracted to do so.
  • States scope, mode, coverage, and run for both measurements, so the difference is interpretable.
  • Attributes the observed effect only to the scope actually changed and verified.

Not included

  • Executing the change: GWK does not alter the client's configuration, certificates, or infrastructure.
  • Deployment, assisted operation, or change management.
  • An adequacy program: it exists as a GWK engineering project, not as a contractable capability.

Start from the integration case

Describe the environment, the expected volume, and the product layer you intend to build on top. Licensing is discussed case by case, with technical scope before commercial scope.