OFFICIAL DOCUMENTATION

Guides for every stage.

CSAEC — Read the official English documentation for CSAEC, version 1.0, August 2026.

16 PAGES

User Guide

Installation, scans, scoring, findings, AI assistance, privacy, troubleshooting and FAQs.

Download PDF ↓
21 PAGES

Technical Guide

Architecture, technology stack, workflow, AI layer, packaging and maintenance.

Download PDF ↓
6 PAGES

Product Datasheet

Positioning, capabilities, use cases, technical summary and important limitations.

Download PDF ↓
DOCUMENTATION PATH

Choose the right level of detail.

BUSINESS USERS

Start with the User Guide

Use it to understand installation, the main interface, scan progress, score classifications, control cards, the local AI assistant, reports, privacy and troubleshooting. It explains how to read results without assuming that a high score proves security.

TECHNICAL TEAMS

Continue with the Technical Guide

Review the application layers, Python-to-interface communication, structured result contract, network components, AI architecture, local processing, reporting workflow, packaging and maintenance principles.

DECISION MAKERS

Use the Product Datasheet

Obtain a compact overview of audience, business value, capabilities, use cases, platform requirements and important product limitations before discussing licensing or deployment.

ALL READERS

Keep the limitations visible

The documents consistently position CSAEC as a preliminary assessment and decision-support product. It is not certification, continuous monitoring, automatic remediation or a substitute for specialist advice.

Recommended reading before deployment

Begin by confirming that the target workstation runs a supported 64-bit edition of Windows 10 or later. Review storage and permission requirements, especially if local AI components or network-oriented assessment modules are included in the authorised package. Organisations should identify who is allowed to install the software, run network checks, inspect results and approve corrective changes.

Before the first assessment, decide how findings will be handled. A simple process should identify the system owner, the reviewer, the person authorised to change configuration and the location where decisions are recorded. Sensitive findings can expose details about devices, services or vulnerabilities, so reports should be protected and shared only through an approved channel.

After the scan, read the overall score together with all twelve control outcomes. Document limitations, unavailable results and the assessment time. If a result suggests a material weakness, validate it before making disruptive changes. Where a control relates to backups, do not rely only on configuration evidence: restoration testing remains essential.

A small glossary of cyber terms

Attack surface
The systems, services, accounts and interfaces through which an attacker might attempt access.
Endpoint
A user or business device such as a workstation or laptop connected to an organisation's environment.
Exposure
The degree to which a service, device or weakness is reachable or accessible to potential threats.
False positive
A finding that appears to indicate a weakness but is not applicable after validation.
False negative
A weakness that exists but is not detected by the assessment.
Hardening
The process of reducing unnecessary functionality and applying secure configuration.
Least privilege
Giving users and services only the access needed for their authorised role.
Ransomware
Malware intended to deny access to data or systems, commonly accompanied by an extortion demand.
Security posture
The current condition of an organisation's controls, exposures, preparedness and ability to respond.
Vulnerability
A weakness that may be exploited to affect confidentiality, integrity or availability.
TURN DOCUMENTATION INTO PRACTICE

Use the guides as part of onboarding.

New users should read the installation and interface sections before their first scan. Technical owners should review architecture, component availability and local-processing boundaries. Managers and procurement teams should understand product positioning, commercial licensing and the distinction between software and professional services.

A short internal procedure can reference the relevant guide sections, identify who may run assessments and define how reports are protected. Review the procedure whenever the authorised build, Windows environment, network scope or business use changes.