The fastest way to verify physical hardware resilience instead of paper checklist compliance. 45-second passive inspections with contractual warranty leverage before final invoice sign-off.
An integrated family of open-source standards, field audit tools, and executive playbooks designed to make physical security verification actionable and reproducible.
A standardized taxonomy mapped directly to MITRE ATT&CK tactics, specifying deterministic binary verification thresholds.
Offline-capable inspection switchboard that generates executive invoice hold notices during physical site walks.
Focused, step-by-step physical test execution procedures with prerequisites, pass/fail rules, and remediation clauses.
A 4-step contractual strategy for CISOs to hold final contractor milestone payments until latent hardware defects are remediated.
Select observed field states during your site walk. The engine compiles an executive CISO Vendor Warranty Notice formatted for immediate invoice hold enforcement.
An independent APCAF Quality Assurance inspection identified latent hardware installation deficiencies. In accordance with standard contractual warranty terms, final invoice retainage is placed on hold pending zero-cost vendor rectification.
| Vector ID | Observed Defect | Contract Standard Required | Remediation Spec |
|---|
• Remediation Plan: Integrator must submit written rectification schedule within five (5) business days.
• Re-Inspection: A 45-second APCAF QA re-inspection will verify full 'Hardened' status prior to invoice release.
How security executives convert physical QA findings into zero-cost contractor repairs before final invoice clearance.
Add the 1-sentence passive testing authorization to engagement letters to establish zero-liability consent.
Auditor inspects RFID encryption, door margins, and link pulses without disrupting site operations.
Regulator gets the compliance PASS. CISO gets the technical Warranty Defect Punch List.
CISO holds contractor retainage payment until hardware is upgraded under warranty at $0 client budget.
Direct mapping between APCAF hardware specifications and global compliance standards.
| APCAF ID | Attack Vector | Hardened Specification | ISO 27001:2022 | PCI DSS v4 |
|---|---|---|---|---|
| PHY-T1001 | Unencrypted RFID Harvesting | AES-128 / DESFire EV3 Smartcards | Control A.7.2 (Physical Entry) | Req 9.2.1 (Access Controls) |
| PHY-T1002 | Mechanical Latch Manipulation | Continuous Steel Astragal (Gap ≤ 3.2mm) | Control A.7.4 (Monitoring) | Req 9.1.1 (Perimeter Security) |
| PHY-T1003 | REX Sensor Blind Activation | Directional PIR Deflector Shrouds | Control A.7.4 (Monitoring) | Req 9.1.1 (Perimeter Security) |
| PHY-T1004 | Unauthenticated Network Tap | Port Shutdown / 802.1X NAC | Control A.7.4 & A.8.20 | Req 9.1.2 (Network Drops) |
Zero lockpicks, zero destructive tools. The entire APCAF kit fits in a pocket.
Dual-frequency reader to verify whether credentials transmit encrypted AES containers or unencrypted UIDs.
Pocket gauge to measure door frame gaps and verify NFPA/IBC tolerances (≤ 3.2mm margins).
Non-packet-transmitting dongle to verify whether perimeter network drops broadcast active link states.