B2B SaaS · building security · AI · post-quantum ready

There is no such thing as free security

tanstaafl.info is a cloud platform that brings order to building security systems: it audits existing ones against the regulatory code, helps design new ones, and watches running ones around the clock. AI finds the weak spots, and every risk gets a price in money — so decisions are made on numbers, not gut feeling.

Why “tanstaafl”?

TANSTAAFL stands for “There Ain't No Such Thing As A Free Lunch.” Robert Heinlein made the phrase famous in The Moon Is a Harsh Mistress: everything that looks free will be paid for by someone — later, and usually at a higher price.

In security this law never misses. Save on the design — pay during installation. Miss a worn-out detector — pay with downtime, a fine or a fire. A risk nobody knows about doesn't disappear; it just waits to present its bill.

The whole platform is built around this idea: every finding gets a probability and a cost of consequences. The formula R = P × C turns “everything is bad” into “here are three problems, here is what each one costs — start with the first.”

What's wrong with building security

Take any office building, warehouse or hospital. Inside there are a dozen engineered systems: fire alarm, evacuation announcement, video surveillance, access control, low-voltage networks, building automation. They were designed by one set of people, installed by another, and are maintained by a third.

As a result nobody — including the owner — knows what state all of this is actually in. An audit happens once a year, performed by the contractor who checks their own work. Reports live on paper. Nobody counts false alarms. Meanwhile designers of new buildings place hundreds of devices by hand and collect the same expert-review remarks over and over.

Existing software covers fragments of the job: some watch video, some track maintenance tickets, some check BIM models. Nobody covers the full “design → build → operate” lifecycle end to end. And nobody speaks the regulatory codebase in AI.

How it works

1 · Upload your data

A BIM model of the building (IFC) or a simple guided survey with photos — it works even for a site with no surviving documentation.

2 · AI checks it against the code

The platform verifies the systems against a machine-readable rule base. Every finding cites the exact clause — you can verify it and hold people to it.

3 · Get your risks in money

A report: a map of problems, the probability and price of each, and priorities — what to fix first. Significant decisions are confirmed by a human, not an algorithm.

A platform of five modules

M1 · Audit

MVP core

An independent check of existing systems: upload a model or fill in a survey → a findings map where every item cites a code clause and carries a probability and a price. First the things that are cheap to fix and expensive to ignore.

M2 · Design

phase 3

AI places detectors, cameras and readers on floor plans under code constraints, produces the specification and bill of materials in one click, and exports to IFC/Revit.

M3 · Monitoring

phase 2

An on-site gateway collects events from every subsystem and runs up to 72 hours without the cloud. The cloud builds a digital twin of the building, predicts failures and counts false alarms.

M4 · Quantum module

differentiator

Quantum computers will one day break today's encryption. The module inventories the cryptography on site and prepares a migration plan to post-quantum algorithms — starting with the secrets that must live longest.

M5 · Identity

phase 4

Privacy-first identity: one credential in the form factor of your choice, short-lived tokens instead of raw data, a consent center and a full log of access to personal data.

Roadmap

Timelines are indicative; each phase counts from its funding start. Calendar dates get fixed together with anchor pilots.

Phase 0 · Discovery

~1.5 months

Digitising the regulatory corpus, interviews with target roles, a clickable audit prototype, design system.

Outcome: Validated scenarios and the MVP backlog

Phase 1 · MVP “Audit”

~3.5–4 months

Portal, IFC import, rule engine (50–80 rules), findings with R = P × C, PDF reports, AI assistant citing code clauses.

Outcome: A sellable product: paid audits, first pilot clients

Phase 2 · Monitoring

~5 months

Edge gateway and protocol drivers, event core, live dashboards, maintenance base, predictive v1, mobile inspection rounds.

Outcome: Per-data-point subscription; sites under 24/7 monitoring

Phase 3 · Design + Quantum

~6 months

Generative placement, IFC/Revit export, edge video analytics, converged event correlation, the quantum module, on-prem distribution.

Outcome: Full lifecycle; entering design firms and critical infrastructure

Phase 4 · Identity & ecosystem

~8 months

Consent center and short-lived tokens, a marketplace of rules and templates, a vendor partner programme.

Outcome: A platform ecosystem with a data network effect

Contact

Project news lives in the Telegram channel; questions and discussion — in the chat. We answer personally: investors, pilot clients and team candidates alike.