DR and compliance evidence your audit committee can defend.

Read-only capture, recovery runbooks, framework gap reports, and a witness bundle any examiner can re-derive — fixed fee, 4–6 weeks

Every engagement includes

Discovery & documentation

  • Validated inventory and L2 / L3 topology map
  • Cross-tier dependency map

Recovery runbooks & DR analysis

  • RTO/RPO matrix and prioritized gap analysis
  • Recovery runbooks ordered by the dependency map

Compliance

  • Automated compliance reports for every supported framework
  • Reproducible witness bundle

Fixed fee · 4–6 weeks

Read-only capture · no production changes

Advisory, not formal attestation

For security & compliance leaders

Regulators and audit committees want evidenced disaster-recovery readiness — not narrative-only deliverables, stale runbooks, or spreadsheet inventories that rot before the next cycle. MKDC captures what is actually running and packages defensible artifacts on a fixed-fee, 4–6 week calendar.

CISO · Head of Risk · IT Compliance · Internal Audit

Audit evidence with a reproducible trail

You sponsor engagements when a DR audit or examiner cycle creates budget and urgency — and when operational teams cannot fully explain the estate they run. MKDC ships the artifact set audit committees ask for: inventory and topology grounded in read-only capture, not interviews alone.

  • Validated inventory — VMs, hosts, network devices, storage arrays
  • L2 and L3 topologies and a cross-tier dependency map
  • RTO/RPO matrix and prioritized gap analysis
  • Recovery runbooks ordered by the dependency map
  • Automated compliance reports for every supported framework
  • Reproducible witness bundle — any third party can re-derive every conclusion
  • Board-ready executive summary

What we deliver

Discovery & Documentation

Ground truth from read-only capture

Read-only API capture from management planes — vCenter, network controllers, storage, OOB — into a single normalized model your audit committee can trace to source evidence. Cross-vendor checks validate the dependency map end-to-end before anything is published. Authenticated read-only access; no agents on production workloads.

  • L2 and L3 network topologies
  • Compute and storage inventory — VMs, hosts, network devices, arrays
  • Cross-tier dependency map validated end-to-end
  • Guided follow-ups to document intent and use — critical services, application ownership, and site delineation

Recovery runbooks & DR analysis

Recovery documentation tied to validated estate state

Generated RTO/RPO matrix, prioritized gap analysis, and recovery runbooks ordered by the dependency map — evidence your committee can defend in a DR audit, not a managed failover or recovery service. Fixed fee, 4–6 weeks.

  • RTO/RPO matrix and prioritized gap analysis
  • Recovery runbooks ordered by the dependency map
  • Board-ready executive summary
  • Reproducible witness bundle — re-derive every conclusion

Compliance

Audit-ready compliance reporting

Automated gap analysis and evidence mapping for FFIEC BCM, SOC 2 CC9, SOX ITGC, HIPAA contingency, and HHS 405(d) HICP — per-framework reports plus a cross-framework index with consolidated gap analysis across frameworks.

  • Board-ready executive summary
  • Per-framework gap analysis and evidence mapping
  • Cross-framework index for overlapping controls
5 supported audit frameworks
  • FFIEC BCM Booklet
  • SOC 2 — Common Criteria 9 (Risk Mitigation / BCM)
  • SOX ITGC (recovery + change-management subset)
  • HIPAA Security Rule §164.308(a)(7) Contingency Plan
  • HHS 405(d) HICP — Resilience subset

Subset mapping per framework — full control catalogs in the engagement SOW.

How we're different

Audit committees usually compare four alternatives. Each solves part of the problem; none ships the full artifact set from one read-only capture pass.

Manual DR consulting

Interview-driven plans and narrative deliverables

What buyers often have

We will workshop with teams, run a BIA, and write recovery plans.

Where it stops

PowerPoint decks and spreadsheets that describe intent — not what is actually running. Findings decay; re-verifying means re-engaging consultants.

MKDC

Read-only API capture from management planes records what is running today. Runbooks are ordered by a validated dependency map. A reproducible witness bundle lets you or any third party re-derive every conclusion without calling us back.

Discovery & mapping tools

Live dependency maps and CMDBs you operate

What buyers often have

We already have a dependency map or asset registry.

Where it stops

Traffic-flow inference or a registry you must populate and keep current. Mapping-only — no audit-grade runbooks, framework gap reports, or one-shot evidence pack.

MKDC

Authenticated read-only access to hypervisor, switching, storage, and OOB management APIs — no agents on production workloads. Cross-tier validation before publish. Bundled runbooks, compliance reports, and a witness bundle in one fixed-fee engagement.

BCM / resilience platforms

Planning software your teams maintain

What buyers often have

We have a business continuity platform.

Where it stops

Customer-populated planning SaaS — exercises, notifications, and program workflows, but not automated capture of your operational data center.

MKDC

We capture the estate once via read-only management APIs and ship defensible artifacts timed to your audit cycle — inventory, topology, runbooks, and framework reports in a single witness bundle.

Compliance automation

Cloud compliance workflows and control monitoring

What buyers often have

We use a SOC 2 or GRC automation platform.

Where it stops

Policy templates, integration evidence, and continuous control tests — built for cloud-native SaaS, not heterogeneous on-premises infrastructure state.

MKDC

Compliance reports bound to captured infrastructure evidence — topology, dependencies, and recovery posture from your operational estate, not paperwork alone.

Why one bundled engagement

Discovery, recovery runbooks, and compliance reports are derived from the same validated capture pass. Splitting them would produce inconsistent artifacts — runbooks disconnected from the map, compliance gaps without estate evidence. One engagement, one witness bundle, fixed fee, 4–6 weeks.

Why our deliverables are defensible

Manual consulting ships narrative decks and spreadsheets. Neither survives the next audit cycle unchanged. Ours does — by design. Automated capture and report generation at scale, not staff-hours consulting.

Infrastructure evidence

Estate snapshot excerpt

Validated inventory and dependencies from read-only capture — the operational baseline your audit committee can trace to source evidence.

Compliance reporting

Compliance gap excerpt

Per-framework gap analysis with evidence pointers — what the audit committee reviews, not narrative-only slides.

The witness bundle

Every engagement ships a reproducible artifact set: a complete normalized snapshot of your infrastructure state, all per-vendor source captures, validation logs, and an integrity manifest. The customer — or any third-party reviewer — can re-derive the conclusions independently.

  • Independent verification without re-engaging us
  • Reproducible evidence trail

What your team adds

Capture documents what is running. Your operational teams document why it matters — the context only they hold. We structure follow-ups so compliance reviewers and platform teams can enrich the documentation over time instead of starting from scratch each cycle.

  • Critical services, application ownership, site delineation
  • Ships as part of discovery and documentation deliverables

Vendor coverage

We capture hypervisor, network, storage, and adjacent control planes across the vendor surfaces that drive US enterprise data centers. Supported today or shipping soon:

Hypervisor

  • VMware vSphere
  • Microsoft Hyper-V (alpha)
  • Nutanix AHV

DC switching / WAN edge

  • Cisco NX-OS, IOS-XE, IOS-XR
  • Arista EOS
  • Juniper Junos / cRPD
  • Nokia SR Linux

Server / OOB

  • Cisco UCS
  • Dell iDRAC
  • HPE iLO via Redfish

Firewall

  • Palo Alto Networks
  • Fortinet
  • Cisco ASA / FMC

Load balancer

  • F5 BIG-IP (roadmap)
  • Citrix ADC (roadmap)

Storage / backup

  • NetApp ONTAP
  • Pure FlashArray
  • Dell EMC PowerStore
  • Veeam

HCI / DDI / fabric

  • Cisco ACI
  • Microsoft DDI
  • (Infoblox, Commvault landing later)

Estate not on the list? Tell us. Surfaces outside current coverage inform our vendor roadmap directly — and when coverage is partial, we label what's captured and what's not in every deliverable.

The founders

Two infrastructure veterans with decades of operating mission-critical infrastructure — one at hyperscale, one at multi-region regulated estates with documented business-continuity execution.

Chong Yan

Chong Yan

Co-founder & Systems Architect

  • 12+ years systems architecture — enterprise integrations and large-scale operational platforms
  • Confluent Solutions Architect for Azure / Dell enterprise accounts
  • Product Owner, Riot Global Server Manager 2.0 — global fleet and deployment infrastructure
  • Prior platform engineering at Gaikai and Singularity 6
Tim Flechtner

Tim Flechtner

Co-founder & Infrastructure Leader

  • 25+ years infrastructure leadership — multi-region data centers and business-continuity execution
  • TradeLink CIO — US, UK, Europe, and India; defined and executed the business-continuity plan
  • Disney Director of Integration & Test; prior infrastructure leadership at Riot Games and Chef
  • Bare-metal data-center and network operations in regulated environments

Frequently asked questions

Common questions from security and compliance leaders who sponsor engagements and evaluate MKDC on a first call.

What's included in an engagement?

One bundled engagement — not à-la-carte. Discovery and documentation, recovery runbooks & DR analysis, and compliance ship together in 4–6 weeks. You receive validated inventory, L2/L3 topology, a cross-tier dependency map, RTO/RPO analysis, recovery runbooks, automated compliance reports for every supported framework, a board-ready executive summary, and a reproducible witness bundle any third party can use to verify our conclusions.

Which compliance frameworks do you support?

We ship automated compliance reports with subset mapping per framework for: FFIEC BCM Booklet; SOC 2 — Common Criteria 9 (Risk Mitigation / BCM); SOX ITGC (recovery + change-management subset); HIPAA Security Rule §164.308(a)(7) Contingency Plan; HHS 405(d) HICP — Resilience subset. Each engagement includes per-framework gap analysis, a cross-framework index, and evidence bound to the captured estate in the witness bundle. Full control catalogs are scoped in the SOW.

Who should sponsor an engagement?

Security and compliance leaders: CISOs, Heads of Risk, IT Compliance leaders, and Directors of Internal Audit — typically when a calendared DR audit or regulatory cycle creates budget and urgency. Platform teams provide access and validate output during the engagement; MKDC scopes and delivers the audit artifact set your committee needs.

Our operational documentation does not match what is running — can you help?

Yes — that gap is why security and compliance leaders engage us before an audit cycle. We map what is actually running via read-only capture — networks, compute, storage, and dependencies — and deliver validated inventory, topology, and a dependency map tied to recovery runbooks and framework gap reports. Your operational teams fill in business context through guided follow-ups we structure for them.

How do you document an estate when runbooks and topology are stale?

Read-only capture from management APIs — vCenter, switches, storage, OOB — not interviews alone. MKDC normalizes that into inventory, L2/L3 topology, and a cross-tier dependency map validated before publish. Your operational teams document intent — what is critical, who owns it — through guided follow-ups we structure for them.

We have stale runbooks and Visio diagrams — can you replace them with something current?

Yes. We capture what is running today and generate recovery runbooks ordered by the dependency map — not a copy of outdated docs. You get RTO/RPO analysis, gap findings, and runbooks tied to validated infrastructure state, plus a witness bundle so the next audit cycle starts from evidence, not narrative.

Can you resolve production vs. non-production for audit scope?

We document what is running and how it connects from read-only API capture. Labeling production workloads, application ownership, and business criticality requires context your operational teams hold. We structure follow-ups so they can enrich the map with the labels auditors need — instead of guessing under exam pressure.

What if our vendor mix isn't fully covered?

We run a short qualification conversation before any SOW. Estates with partial coverage receive a reduced-fee engagement with every deliverable clearly labeling what was captured and what was not. Estates outside current coverage go on a wait-list — and inform our vendor coverage roadmap directly.

Do you change anything in production?

No. Capture is read-only via authenticated access to management APIs only — vCenter, network device APIs, storage controllers, OOB — with no agents installed on production workloads. Zero production interruption is a core requirement of how we built the product, not a best-effort claim.

We already have discovery or CMDB tooling — do we still need MKDC?

Often yes, for different reasons. Discovery tools and CMDBs give you ongoing maps you operate day to day. MKDC delivers audit-grade capture in one engagement: cross-tier validation, recovery runbooks, automated compliance reports, and a reproducible witness bundle. We complement daily ITSM when the gap is audit documentation — not when you only need a live dependency dashboard.

When is MKDC not the right fit?

Mapping-only with no approaching audit or compliance cycle. Cloud-native SOC 2 where there is no operational data center to capture. A need for formal attestation signatures or facilitated DR tabletop exercises today — we ship advisory documentation; we do not attest or facilitate tests.

Why are discovery, runbooks, and compliance bundled?

Runbooks and compliance reports are derived from the same validated capture. Splitting the pillars would produce inconsistent or non-reproducible artifacts — runbooks disconnected from the dependency map, compliance gaps without estate evidence. One fixed-fee engagement, 4–6 weeks, one witness bundle.

Where is our data stored during the engagement?

Captures and credentials live in a dedicated engagement environment for the duration of the project. Retention, credential rotation, and data-handling terms are documented per customer in the SOW.

How is liability structured?

Engagements are signed under a Master Services Agreement with a fixed-scope SOW. Liability is capped at the engagement fee. We carry $5–10M aggregate Errors & Omissions coverage, bound before any signed engagement.

Is this a formal attestation?

Initial engagements ship as advisory, not formal attestation, until our credential and partner-attestation chain (ISO 22301 Lead Auditor, CISA, or boutique-attestation partner) lands. The witness bundle is independently re-derivable today regardless of attestation posture — that is the entire point.

Ship audit-ready documentation before your next DR cycle.

Schedule an intro to discuss your estate, frameworks, and audit timeline. Scope, deliverables, and qualification details are in the FAQ below.