INVENTORY TRUST LAYER

Trust your inventory before you build on it.

An assessment is only as good as the inventory under it. Aurithm validates every file — provenance, tampering, reconciliation, migration-specific anomalies — and produces a confidence score before any analysis runs.

What you get

Four-dimension confidence, before any sizing runs.

Tool provenance

Verifies the inventory tool version against a maintained allowlist. Flags unknown versions, warns on builds with known concerns, blocks compromised builds.

Tampering detection

Checks for formula cells in data ranges (indicates Excel editing), column-order deviations, missing expected tabs, version mismatches. Machine-generated exports have predictable structure — deviations are signals.

Internal consistency

Reconciles main inventory tab against detail tabs. Every VM should appear consistently. Mismatches, orphan rows, or conflicting values reduce structural confidence.

Migration-specific anomalies

CD/DVD media attached (blocks live migration), orphan snapshots, infrastructure VMs mixed with tenant workloads, value mismatches between tabs. These are migration hygiene issues, not data errors.

Why this matters

In May 2025, a tampered build of a popular inventory tool was briefly distributed. Assessment platforms had no way to detect it.

Aurithm's Trust Layer turns that class of risk into a first-class concern. Confidence is scored across four dimensions: Structural (reconciliation health), Anomaly (impact of detected issues), Temporal (export freshness), and Provenance (tool version trustworthiness). The composite is the minimum across dimensions — a pristine provenance tier cannot hide badly anomalous inventory. Below threshold, Aurithm enters diagnostic mode: all four scores visible, full anomaly ledger, reconciliation statistics, targeted recommendations. Downstream modules can still run (architects may want to see the numbers) but every output carries a 'computed against low-confidence inventory' banner.

Scope

What it does — and what it doesn't.

It does
  • Validates tool provenance against a maintained allowlist
  • Detects tampering signals (formula cells, column-order drift, missing tabs)
  • Reconciles main inventory against detail tabs, VM by VM
  • Flags migration-specific anomalies (CD/DVD, snapshots, infra/tenant mix)
  • Produces a four-dimension confidence score with explicit minimum composition
It doesn't
  • Repair your inventory — it tells you what to re-export
  • Block assessment runs outright — you acknowledge, then proceed
  • Replace change management — it surfaces hygiene issues, not governance
Who uses this
Operations leadsAcknowledging inventory posture before assessment goes to stakeholders.
Cloud architectsUnderstanding why downstream numbers look off.
Security teamsCatching supply-chain tampering on ingest.
Delivery partnersConfirming the inventory they were handed is trustworthy.

Validate your inventory before you build on it.

Four-dimension confidence scoring runs silently on every upload. See exactly what your data is made of.

Request access