Prototype for simulated field testing. Results are investigative leads for a person to review. They are never legal determinations.

CPIT

SOW traceability

Each requirement in the Statement of Work for RFQ 19AQMM26Q0468, with what this prototype already shows and what belongs to the contract period of performance. Status is stated conservatively.

Demonstrated: 9 Partly demonstrated: 4 Contract task: 4
Requirements matrix
Select a row's evidence link to see it in the app.
SOWRequirementStatus
§1, Task 3Training data includes Ukraine and at least one other country restricted under 19 CFR §12.104g

Ukraine (CBP Dec. 24-16) plus Egypt, Peru, Greece, China, Cambodia, each checked against the eCFR §12.104g table.

Demonstrated
§1, Task 4Standalone application, not connected to DoS or other USG systems or networks

Static bundle. Inference, index and audit all run on the device. CSP connect-src 'self'. Works offline after first load.

Demonstrated
§1, Task 4Enough scope, functionality and traceability of outputs for simulated field testing

Screening workflow, held-out test samples with hidden labels, hash-chained audit trail with export.

Demonstrated
Task 3Use CC0 training data where possible; record data sources and sharing arrangements

75% of designated-category images are CC0 or public domain; per-source inventory with licence terms.

Demonstrated
Task 3Vet each object; standardise metadata; normalise and vectorise images

Keyword and licence guards, automated image screen, manual review log, near-duplicate removal, SHA-256 fingerprints, embeddings.

Demonstrated
Task 3No non-public DoS or USG information in the training data

Every record is from a public open-access collection, with its source URL retained.

Demonstrated
Task 4Technical specifications: model architecture, data inputs, performance benchmarks

Model card; held-out top-1 86%, top-3 95%; model-selection study.

Demonstrated
Task 4Governance specifications: data handling, chain of custody, trustworthy AI

Data-handling spec, per-event custody fields, NIST AI RMF mapping, human disposition required.

Demonstrated
Task 4Security specifications and extensibility to FedRAMP

Standalone safeguards are in place, and an NIST SP 800-53 family mapping for a hosted phase is documented. Authorisation itself is out of scope.

Partly demonstrated
Task 4At least 90% test coverage of contractor-developed code

100.0% line coverage on domain logic (scoring, evaluation, audit, corpus), enforced in CI. UI component tests are planned for the contract build.

Partly demonstrated
Task 4Free of medium/high vulnerabilities; SCA, static and dynamic scanning at each deployment

SCA (npm audit) and static lint run on every build; see the scan results. A commercial SAST service and DAST are added under the QAP.

Partly demonstrated
Task 4Government Purpose Rights in prototype, model and data; contractor may commercialise

Only permissively licensed model weights (MIT) and open-licensed data are used. A research-only model was rejected for this reason.

Demonstrated
Task 5Internal testing, validation and performance testing

Held-out benchmark with calibration, ablations and latency. Field-image testing is a contract activity.

Partly demonstrated
Task 1Kickoff, Project Management Plan with risk register, monthly reports

Delivered within 15 days of award.

Contract task
Task 2Stakeholder engagement: CHC, CHCC, law enforcement, CPEOC, cultural institutions

Validates scope, user workflows and the training and testing plan.

Contract task
Task 6Simulated field testing and CPEOC concordance

The audit export and test-set mode are built to capture concordance and user feedback.

Contract task
Tasks 7–8Final Assessment Report and final briefing

The Governance, Evaluation and Corpus pages are working drafts of its technical sections.

Contract task