EcoWealth×Inter-Con Security Dedicated Provisioner · Proposal

A proposed dedicated provisioner · for an internal conversation · unlisted

EcoWealth as Inter-Con's always-on efficiency provisioner: here's what we'd run for you from day one.

A security company runs on one thing: proof others can trust without taking your word for it. That's the one thing EcoWealth builds: verifiable, tamper-evident proof (funded, photo + GPS + method-verified, on-chain-settled receipts and a durable anti-forgery anchor, live on Base mainnet today), run as a dedicated, always-on provisioner pointed at Inter-Con's two highest-leverage surfaces: the authenticity of your own communications and the proof-of-service your clients and government contracts already demand. Below: the day-one efficiency plan, the evidence behind it, and a working demo in your own navy.

✎ A proposal, warm and internal, not a cold pitch, and not a claim we already work with you. Brandon works in security at Inter-Con, so this is a conversation he can open inside the company. EcoWealth is an independent party proposing to run this; everything here was gathered passively from public pages and DNS, and Inter-Con's estate is competently built (credited in the brief). See the disclaimer on every page.
The whole thing, plainly Inter-Con's email can be spoofed today (no enforcement on the anti-spoofing record), and a client can't check a guard tour or incident report without just trusting Inter-Con's word. We'd run both fixes as a standing, dedicated worker: free to see working, nothing needs your systems to start. The one ask: a short internal conversation about which surface to point it at first.

The through-line: one primitive, two fronts

Phishing is a verification failure. A guard tour, a site attendance log, an incident report is proof-of-work-done. Both are the same question, can a recipient confirm this is real without trusting the sender?, and EcoWealth answers it with one mechanism.

Front A · Trust & authenticity

A genuine Inter-Con message a recipient, or their AI, can verify is real, so a scam can't impersonate the company whose business is trust.

= tamper-evident anchor + machine-verifiable mark

Front B · Proof of work done

A guard tour or incident report settled with photo + GPS + method proof into a replayable receipt a client or government auditor can verify independently.

= the same anchor, pointed at operations

What your dedicated provisioner runs

If Inter-Con brings EcoWealth in as its dedicated provisioner, this is the aggressive, specific plan: a standing Opus worker pointed at one company, shipping felt efficiency on a clock, keeping the workforce, RMS, and GSOC doing what they already do best, faster and more verifiably. Nothing here needs Inter-Con systems access to start; each step deploys on EcoWealth infrastructure first.

Week 1 · comms

Make Inter-Con's own mail un-spoofable

  • Publish /.well-known/security.txt: a real report/verify channel for suspected impersonation.
  • Move DMARC p=none → quarantine → reject: the monitoring data is already flowing to Proofpoint, so the step is safe to make now.
  • Stand up a verifiable-message mark for staff security-awareness notices (demo, Front A).
Felt efficiencyA spoof of @icsecurity.com stops being deliverable, and staff stop guessing whether an internal email is real: fewer spoofable emails, day one.

Month 1 · operations

Proof-verified tours on one client site

  • Run one site's overnight tours + incident reports through the EWP packet: photo + GPS + method-template → tamper-evident on-chain receipt.
  • Runs alongside RMS, the same officers, the same posts, adding a verifiable layer, not replacing the system.
Felt efficiencyThat client's monthly audit resolves on evidence they verify themselves: SLA and coverage disputes settle faster, on proof, not a report to trust.

Quarter 1 · growth

RFP legibility + audit trail at scale

  • Publish agent-legible capability / certification / sector data (llms.txt + structured schema + agent card).
  • Extend the tamper-evident proof trail across more sites: clients and government contracting officers verify performance directly.
Felt efficiencyAn RFP-answering AI returns Inter-Con accurately, with a citation; re-competes are won on proof, not paperwork: legible where buyers now look first.

One dedicated Opus provisioner, pointed at Inter-Con. After the first quarter it keeps running on a loop: new sites onto the proof trail, comms authenticity maintained, capability data kept current as an RFP-ready asset, so Inter-Con stays legible, verifiable, and ahead of a sector that hasn't done this yet.

The value exchange · what the provisioner brings vs. what it needs to start

What your provisioner brings

  • A tamper-evident authenticity layer: a machine-verifiable mark any Inter-Con notice can carry, so a recipient or an AI confirms it's genuine and a forgery fails closed.
  • The Ecological Work Protocol: funded, proof-verified (photo + GPS + method), on-chain-settled, receipted work packets: exactly the shape of a guard tour, patrol log, or incident report.
  • An Agent Kit: llms.txt, agent card, and MCP tools (the interface an AI assistant calls to use a service correctly), that makes Inter-Con's capabilities, sectors, and certifications legible and callable by any buyer's or auditor's AI.

What it needs to start

  • A short internal conversation, Brandon can open it, about where a verifiable-proof layer helps most: comms authenticity, client-facing proof-of-service, or procurement legibility.
  • Fifteen minutes to feel the efficiency, a cited capability answer and a proof an auditor can check themselves, before any commitment. The whole point is that it's felt, not pitched.
  • Nothing requiring Inter-Con systems access to see it work. Every demo runs on EcoWealth infrastructure first.

Three documents, one story

Six findings: full inline proof in the brief

1

The verifiable-trust gap. Inter-Con's DMARC is published but set to p=none, monitor-only, no enforcement, so a spoof of @icsecurity.com isn't hard-blocked, and genuine mail rides third-party domains (Mailchimp, Salesforce) a recipient can't verify at a glance. Phishing is a verification failure; the trust company has the sharpest reason to close it. DNS-evidenced

2

Zero hardening headers on a security brand's own site. HSTS, CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy: all six absent. curl + browser

3

Capabilities, sectors & certifications aren't machine-legible. Every page carries only Yoast's default graph; zero Service/Offer schema; the certification page is logo-only with empty alt. A gov/enterprise buyer's AI can't represent Inter-Con from structured data. rendered DOM

4

Proof-of-operations is trust-me, not verify-me. Inter-Con already runs a real proprietary RMS + GSOC (credited), but a client or auditor can't independently verify a tour or incident without trusting Inter-Con's own system. their copy + gap

5

No structured procurement front door. The Sales page renders zero form elements; contact routes through generic cards. No machine-navigable RFP/capability-statement intake. forms = 0

6

Real climate disclosure, PDF-only. Inter-Con publishes a TCFD report (Dec 2025), but it's a 349 KB PDF buried in the footer, with no structured or proof-verified, on-chain outcome layer beneath the number. 200 · application/pdf

The hand-off

Point your dedicated provisioner at one surface, comms authenticity, and Week 1 is already spec'd.

This isn't a web-vendor pitch, and it needs no system access to begin. It's a standing efficiency worker for Inter-Con: comms an AI can confirm are genuine, service records a client or government auditor can verify without taking your word for it, and capability data legible where buyers now look first, the same tamper-evident proof, live on Base today. Give the word and Week 1 ships; the brief and the demo show exactly what it looks like.

The proof rail, as open agentic commerce

Put one agent on-chain today

A guard tour, a patrol log, an incident report is proof-of-work-done, exactly the shape of a work packet. The same tamper-evident rail is a live endpoint any assistant can exercise. No account with us, no API key, no sales call. Here is the whole path.

1

Fund it a few cents. Give any AI agent, Claude, GPT-class, Llama, or your own, a Base wallet holding a few cents of USDC. That's the whole setup.

2

Point it at the endpoint. The work-packet program answers HTTP 402 with a standard x402 (a web-native way for AI agents to pay per use) payment schema; the agent signs a USDC authorization and pays $0.10. A runnable client with a dry-run default is published at vealth.net/recipes.html.

3

Get a verifiable packet. Back comes a bounded, proof-verified work packet, and every step the agent took (payment, settlement) is an on-chain receipt an auditor can replay, forever. The EWP contract is live on Base mainnet; workId 14 settled the first packet end-to-end.

Why this isn't scary

The agent cannot do anything invisible here. Every action embeds its own receipt: permanent, public, verifiable. That is more accountability than most enterprise software offers, not less, exactly what a security business sells.

The bet

Inter-Con already runs a real proprietary RMS + GSOC, and AI competence is scaling. What this rail adds is proof a client or government auditor can verify without trusting your system, the same tamper-evident receipt, exercisable today for $0.10. Being early costs an afternoon; being late just means Inter-Con's real performance stays something clients have to take on trust instead of something they can verify.

The one concrete ask: have one agent make one $0.10 call and settle a single proof-of-service packet into a receipt an auditor can replay, on EcoWealth infrastructure, no Inter-Con systems access.

Provisioned by EcoWealth · Digital Provisioning Protocol · provenance‑sealed