CAIRNS
Enterprise architecture, governed by construction

The architecture repository that proves its answers.

Cairns turns the documents and systems of record you already have into one governed architecture model, keeps it current as they change, and proves every answer back to its source. A cairn is the marker a party leaves so the next one finds the way. That is what your architecture information should do for every initiative that follows.

The problem it is built for

Architecture truth does not live in architecture tools. It lives in design documents, board minutes, spreadsheets and diagrams that drift out of date the week they are written. The structured systems hold what they hold; the documents hold what everyone actually decided. Conventional platforms assume the repository is fed from structured sources and kept honest by stewards, so every new initiative starts with the same discovery and validation exercise, billed again.

Cairns starts from the other end. It ingests the documents as well as the systems, pins every source, and keeps the model current as the corpus changes. Restatements are shown, never overwritten.

300
applications at demonstration scale
4,000
configuration items, each pinned to its source row
1,000
controls across ISM, Essential Eight, PSPF
44
sources pinned with sha256 in the demonstration build

Four planes

01Ingestion and grounding

Connectors for the systems of record, and governed ingestion of the design corpus: Word, PowerPoint, Visio, minutes. Extraction resolves against the metamodel; ambiguous or conflicting material goes to a review queue, never silently in.

02Repository

A governed model of applications, capabilities, data, technologies, controls, risks, decisions and roadmaps. Declarative metamodel, versioned branches for target states, every element carrying its provenance pin.

03Governed AI

Natural-language query and assistance over the repository. Deterministic screening before any model call. Answers cite their sources or refuse. Figures are computed, never written by a model. Open-weight models inside your boundary; model choice is configuration.

04Insight and adoption

Role-appropriate views for architects, contributors and consumers. The consumer cohort never sees a modelling notation: they ask questions and get cited answers, or they read dashboards built for their role.

Proof, not slideware

The figures below are captured from the running demonstration build on a fully synthetic estate at the scale of a Commonwealth regulator. The same build is what we bring to a demonstration. Every record is synthetic; every element traces to a pinned source.

Document change detection showing a waiver revocation and a superseded design decision
Fig. 1. Sight of design assets as they evolve. Two documents changed between ingests: a waiver revocation in board minutes and a superseded design decision. Diffs carry before-and-after hashes; both versions are retained; affected records are queued for review. Below, three business-managed applications found in documents but absent from the CMDB, queued for registration.
Natural-language query answered with citations
Fig. 2. A cited answer. Which applications run technology that reaches end of support within 18 months? Answered from pinned records, joined to capabilities and custodians. Figures are computed from the repository, never written by a model.
The platform refusing a question it has no source for
Fig. 3. A refusal. A question the sources cannot answer is refused, and the refusal is logged to the audit spine. The fix, when the question matters, is a source, and the platform says which kind.
Technology portfolio and obsolescence view
Fig. 4. Technology lifecycle position. Computed from pinned CMDB rows. Missing dates route to the enrichment queue rather than being guessed: 726 of 4,000 configuration items in the synthetic estate.

Narrated rehearsals

Two short recordings of the running build, narrated end to end. The narration is synthetic; the live demonstration carries a human presenter. Every figure in them is computed from pinned sources.

The full figure set, including the estate dashboard, TIME portfolio quadrant, remediation roadmap and the AI register, is in the demonstration annex. Better: walk the trial yourself.

AI you can defend

This control layer is not new for the product. It has been hardened over more than two years and 500,000-plus automated review cycles, and it runs in production today in Commonwealth-facing services.

Security and sovereignty

PositionDetail
DeploymentIn-tenancy, or Hosting Certification Framework Certified Assured hosting in Australian regions. Provider, region, tenancy and isolation disclosed.
Data sovereigntyAll data, backups, logs, metadata and AI processing remain within Australian regions or inside your boundary.
IdentityMicrosoft Entra ID federation, MFA, SCIM provisioning, role and attribute-based access on least privilege.
AssuranceControls designed against the ISM, PSPF and Essential Eight. Workload assessment up to full IRAP is scoped into implementation, with the assessor-facing evidence pack shipped with the platform.
AuditHash-chained audit spine with signed checkpoints; verification you can run without us.
ExitFull export of data, models, metadata and configuration in documented formats. Exit costs you your own effort and nothing else.

Contact

The demonstration build is public and self-guided. For a walkthrough, a demonstration against your scenarios, or the full response annex, write to us.