
Platform
How RedMesh moves from authorized scope to reviewable proof
RedMesh combines Navigator workflow controls with distributed Ratio1 Edge Node execution: operators define authorized work, monitor task state, inspect findings, retain evidence references, and prepare selected records for Proof-of-Test attestation when configured.
Product workflow
Navigator workflow: scope, monitor, review
These Navigator views use seeded lab data to show implemented interface states. They are not a customer deployment or a dated live multi-node result.
Define an authorized task
The operator selects a task type, names the engagement, defines the target boundary, and confirms authorization before creation.
- Evidence shown
- Navigator task setup and authorization review

Monitor work by task state
The operations view separates active, continuous, completed, and stopped work so operators can inspect progress and exceptions.
- Evidence shown
- Navigator operations dashboard with seeded task data

Inspect findings and worker evidence
Task detail brings scope, worker activity, findings, timeline, and report actions into one review surface.
- Evidence shown
- Navigator task detail with seeded findings

Core platform components
Coordination Layer
Schedules approved workflows and assigns validation work to participating Ratio1 Edge Nodes across one or more vantage points, keeping execution aligned with the scope you define.
Asynchronous Distributed Execution
Edge Nodes run authorized workflows asynchronously and report progress and results back to the coordination layer as they complete.
ChainStore & ChainDist
Run metadata and results are stored and distributed via ChainStore and ChainDist, forming the backbone of RedMesh's evidence coordination pipeline.
R1FS Evidence Flows
Evidence artifacts can be captured through R1FS into decentralized encrypted storage, producing retained references for governance and review.
Core Features
Everything RedMesh does
Four capabilities work together: recurring validation, tamper-evident attestation, distributed vantage points, and integrations that fit your existing stack.
Recurring Validation
Move from point-in-time testing to recurring proof
RedMesh repeats authorized, controlled, low-noise validation workflows, including black-box PT/VA and authenticated web/API gray-box checks, so drift can be reviewed between annual or quarterly engagements.
A complement to human pentesting
RedMesh does not replace your pentest team or established scanners. It runs the same classes of authorized checks continuously, surfacing drift and regressions for human review between engagements.
Scoped and authorized by you
Every run executes against scope you define and authorize. Humans review significant findings before they're treated as confirmed.
Evidence-first results
Each run produces timestamped evidence, with Proof-of-Test attestation for selected records, so results can support remediation tracking and review.
Evidence & Proof
Proof-of-Test records for recurring assurance
Run metadata, results, and evidence hashes are captured in tamper-evident archives, with on-chain Proof-of-Test attestation for selected validation records.
Tamper-evident by design
Evidence archives are tamper-evident by design, and attestation records - blockchain-anchored - make it possible to detect if evidence has been altered after the fact.
Built for governance workflows
Attested run records feed directly into governance reporting, remediation tracking, and service-delivery evidence for CSPs and MSSPs.
Not a replacement for authorization
Attestation proves what ran and what was found - it does not grant or imply authorization. Scope and authorization remain human-controlled.
Distributed Execution
Validate from participating Edge Node vantage points
A single scanning location only sees what that location can see. RedMesh distributes approved validation work across participating Ratio1 Edge Nodes in your deployment, including multi-region vantage points where provisioned.
Reduce single-source blind spots
Geographic and network-path differences mean a target can look different depending on where a check originates. Multiple vantage points reduce that blind spot.
Coordinated, not duplicated
RedMesh's coordination layer schedules and deduplicates work across nodes, so vantage diversity doesn't mean redundant noise.
Useful for distributed environments
Especially valuable for organizations with multi-region infrastructure, multi-cloud footprints, or edge deployments - multi-region coverage scales with how many Edge Nodes are provisioned in your deployment.
Ecosystem
RedMesh evidence fits into the tools you already run
Findings, evidence, and attestation records are designed to flow into your existing CTI, SOC, vulnerability management, and compliance workflows - not to create a new silo.
CTI and graph platforms
Feed validated findings into threat intelligence and graph-based asset/risk platforms for correlation with other signals.
SOC and vulnerability management
Push results into SIEM/SOC tooling and vulnerability management pipelines so remediation tracking happens where your team already works.
AI analysis, storage, and compliance
Evidence is structured for optional AI-assisted analysis under human review, long-term evidence storage, and compliance/GRC reporting.
How it works
- 01
Define and authorize scope
You define the systems, checks, and schedule RedMesh is authorized to run against.
- 02
Coordinate across the Edge Node mesh
RedMesh's coordination layer assigns checks to Ratio1 Edge Nodes across one or more vantage points.
- 03
Execute distributed, asynchronous workflows
Nodes run authorized workflows asynchronously, reporting progress and results back to the coordination layer.
- 04
Capture and attest evidence
Results, run metadata, and evidence references are captured through ChainStore and R1FS, with Proof-of-Test attestation.
- 05
Review, remediate, and integrate
Findings and evidence flow to your team and integrated tools for review, remediation, and reporting.
Assurance lanes
Executive assurance
Give CEOs, boards, CFOs, GCs, and executive committees a recurring proof rhythm for continuity, supplier trust, customer assurance, and board reporting.
Provider-managed B2B2B
Help MSSP, MSP, CSP, PT/VA, legal, regulatory, and digital-compliance providers package RedMesh as a managed assurance service line.
Board assurance pilot
Start with one executive-visible system, supplier interface, API estate, or exposure set and produce baseline, remediation, and retest evidence.
Direct enterprise operation
Let mature internal teams operate RedMesh directly for recurring validation, internal CTI workflows, API assurance, and evidence collection.
Compliance evidence support
Support NIS2, CRA, and DORA-oriented programs through evidence collection and recurring validation without claiming automatic compliance.
Supplier assurance
Apply authorized validation to supplier interfaces, third-party-connected systems, and customer assurance evidence requests.
How RedMesh compares
Frequency
- RedMesh
- Recurring workflows, including continuous programs
- Traditional PA/VA
- Periodic (e.g. annual)
- Automated Scanners
- Periodic or continuous, single-source
Vantage points
- RedMesh
- Multi-region Edge Nodes
- Traditional PA/VA
- Single engagement scope
- Automated Scanners
- Single scan location
Evidence
- RedMesh
- Tamper-evident, blockchain-anchored
- Traditional PA/VA
- Written report
- Automated Scanners
- Scan output / report
Human oversight
- RedMesh
- Authorize scope, review findings and any AI-assisted analysis
- Traditional PA/VA
- Full manual execution
- Automated Scanners
- Configuration only
Best for
- RedMesh
- Recurring assurance evidence between engagements
- Traditional PA/VA
- Deep manual exploration
- Automated Scanners
- Known-vulnerability sweeps