Knox Blockchain Federal Compliance

DealMatcherApp.com — Bonis Systems LLC

Company Information

Legal Entity Bonis Systems LLC UEI R2BPJDC5CBA3 NAICS 541511 — Custom Computer Programming Services FinCEN Registered (BSA E-Filing) SAM.gov Registration In Progress Location San Antonio, TX

Knox Blockchain Architecture

Knox is the immutable audit and compliance backbone powering all Bonis Systems products. Every transaction, deal match, and AI decision is cryptographically hashed (SHA-256) and recorded on-chain.

PhaseTechnologyStatusDescription
Phase 1 Local Chain (SQLite + SHA-256) DEPLOYED Immutable append-only ledger with cryptographic hash chaining. Every block references prior block hash.
Phase 2 Google Blockchain Node Engine READY Enterprise-grade managed blockchain nodes on Google Cloud. Hyperledger Fabric integration point.
Phase 3 Hyperledger Fabric PLANNED Permissioned enterprise blockchain with smart contracts for multi-party deal verification and federal audit trails.

NIST SP 800-53 Control Mapping

26 security controls mapped to DealMatcher's AI deal-matching and procurement platform. Each control is implemented or scheduled for implementation.

Control IDControl NameImplementation
AC-2Account ManagementRole-based accounts (admin, investor, vendor) with approval workflows
AC-3Access EnforcementJWT authentication with role-based API route guards
AC-6Least PrivilegeAPI endpoints scoped to user role; admin routes require admin JWT claim
AC-7Unsuccessful Logon AttemptsRate limiting on auth endpoints; lockout after repeated failures
AC-17Remote AccessTLS 1.3 enforced on all connections; HTTPS-only in production
AU-2Event LoggingKnox Blockchain records all deal matches, AI decisions, and user actions
AU-3Content of Audit RecordsEach Knox block contains timestamp, action type, actor ID, SHA-256 hash, and parent hash
AU-6Audit Record ReviewAdmin dashboard with filterable audit log; exportable for federal review
AU-9Protection of Audit InfoKnox ledger is append-only; blocks cannot be modified or deleted
AU-11Audit Record RetentionAll Knox blocks retained indefinitely; 7-year minimum for federal compliance
IA-2User IdentificationUnique user IDs with email verification; bcrypt password hashing
IA-5Authenticator Managementbcrypt (12 rounds) password storage; no plaintext credentials
IA-8Non-Org User IDExternal vendor/investor accounts with UEI and SAM.gov cross-reference
SC-8Transmission ConfidentialityTLS 1.3 for all data in transit; HSTS headers enforced
SC-12Cryptographic Key ManagementEnvironment-variable key storage; no keys in source code
SC-13Cryptographic ProtectionSHA-256 for Knox hashing; bcrypt for passwords; AES-256 for data at rest
SC-28Protection of Info at RestEncrypted database storage; sensitive fields encrypted at application layer
CM-2Baseline ConfigurationDocker containerized deployments; Cloud Run managed infrastructure
CM-6Configuration SettingsEnvironment-based configuration; no hardcoded secrets; .env separation
CM-8System Component InventoryPackage.json dependency tracking; automated vulnerability scanning
RA-5Vulnerability Monitoringnpm audit on CI/CD; dependency version pinning
SI-2Flaw RemediationAutomated CI/CD pipeline with pre-deploy security checks
SI-4System MonitoringCloud Run metrics; application-level health checks at /api/health
SI-10Information Input ValidationServer-side input validation on all API endpoints; SQL injection prevention via parameterized queries
PL-2Security PlansThis compliance document; BAA template; capability statement maintained
PS-6Access AgreementsBAA required for all business associates handling deal data

Knox Blockchain Products

Three production platforms powered by Knox Blockchain, each with full audit trail and federal compliance capability.

DealMatcherApp.com

AI-powered deal matching and procurement platform with Bruce AI agent. Matches investors to commercial opportunities using machine learning scoring, SAM.gov verification, and Knox audit trails.

AI Matching Knox Ledger Bruce AI SAM.gov

HealthAgentCare.com

HIPAA-compliant health management platform with AI-powered care coordination. 60+ AI tools, smart forms, Rx scanning, and PHI scrubbing. Knox blockchain for audit compliance.

HIPAA PHI Scrubber AI Tools Knox Ledger

TerraVaultHQ.com

B2B hemp and cannabis marketplace with seed-to-sale tracking, Metrc/BioTrack integration, Cannaverse 3D experience, and Knox blockchain for compliance chain-of-custody.

Seed-to-Sale Metrc Cannaverse Knox Ledger

© 2026 Bonis Systems LLC. All rights reserved. This document is provided for federal compliance review purposes.

Generated: