Defense Compliance Summary
Leighton Dynamica, operating through Leighton Avant-Garde Haus and subsidiaries like Xerataus IQX, is committed to delivering innovative AI and technology solutions exclusively for government use, with a focus on defense applications. As a small, agile entity, we prioritize compliance with U.S. Department of War (DoW) regulations to ensure secure, ethical, and reliable services. Our compliance framework is designed to support Federal Acquisition Regulation (FAR) and Defense Federal Acquisition Regulation Supplement (DFARS) requirements, enabling us to handle Controlled Unclassified Information (CUI) and position for classified contracts.
We are actively pursuing opportunities as a defense contractor, with self-attested readiness for CMMC Level 2 as of December 2025. Below is a high-level overview of our compliance posture. Detailed documentation, including System Security Plans (SSP) and Plans of Action & Milestones (POA&M), is available under NDA for qualified partners, primes, or government contracting officers.
Key Compliance Commitments
- Cybersecurity and CUI Safeguarding: Implemented NIST SP 800-171 Rev. 2 controls (110/110 addressed or on 180-day POA&M, per current DoW Class Deviation). This includes access controls, system monitoring, and incident response plans with 72-hour reporting to the DoD Cyber Crime Center (DC3) as required by DFARS 252.204-7012. Rev. 3 gap analysis complete for future transition.
- CMMC Readiness: Self-attested at Level 2 in the Supplier Performance Risk System (SPRS), making us eligible for CUI-handling contracts under CMMC 2.0 Phase 1 (effective November 2025). Preparing for Phase 2 (November 2026) with third-party certification by a Certified Third-Party Assessment Organization (C3PAO).
- AI Risk Management: Aligned with the NIST AI Risk Management Framework (AI RMF) 1.0 and the Artificial Intelligence Strategy for the Department of War (January 9, 2026), emphasizing objectively truthful AI, rapid deployment, and no ideological tuning. Our AI development lifecycle incorporates assessments for bias, reliability, explainability, and human oversight, ensuring trustworthy systems for defense applications.
- Export Controls: Compliant with U.S. Export Administration Regulations (EAR) and International Traffic in Arms Regulations (ITAR) for technology, software, and data exports. End-user certificates required for ITAR-controlled items.
- Supply Chain Security: Rigorous supplier screening to prevent counterfeit parts, with transparency and flow-down requirements per DFARS 252.246-7007 and NIST SP 800-171 Rev. 2.
- Small Business Utilization: As a small disadvantaged business, we prioritize subcontracting with other small entities in line with FAR Part 19.
- Anti-Corruption and Ethics: Adherence to the Foreign Corrupt Practices Act (FCPA), prohibiting bribery and ensuring ethical practices in all operations.
- Incident Response and Reporting: Established plans for rapid detection and response, including coordination with DoW channels.
- Classified Information Handling Aspirations: Positioned for Facility Security Clearance (FCL) under the National Industrial Security Program Operating Manual (NISPOM, 32 CFR Part 117). We seek sponsorship via DD Form 254 for contracts involving classified data, with personnel ready for clearances.
Certifications and Affirmations
- SPRS Affirmation: Annual compliance affirmed as of February 2026.
- Badges:
Next Steps for Collaboration
We are registered in SAM.gov and eager to engage in DoW opportunities, including small business set-asides. For detailed compliance artifacts, capability statements, or to discuss potential partnerships/sponsorships, contact us at contact@oneleighton.cloud. We welcome RFIs, RFPs, or DD Form 254 sponsorships to advance toward classified work.
Last Updated: February 6, 2026
The following terms (“IQX/AI Program Terms”) supplement the Master Subscription Agreement and Terms of Service (each, respectively and as applicable, the “Agreement”) between you and Xerataus IQX, L.AgH LLC (“A1MX, Leighton Avant-Garde Haus, Leighton Dynamica, Leighton IQX, Xerataus IQX) and apply to and govern your participation in the A1MX, Leighton IQX, and Xerataus IQX early access program that provides AI-enabled features and functionality to program participants (“IQX/AI Program”). All defined terms in these IQX/AI Program Terms shall have the same meaning as in the Agreement. The applicable Agreement (including our Privacy Policy) is incorporated by reference and will control for any provisions not addressed in these IQX/AI Program Terms.
Improvement of Services
Artificial intelligence and machine learning models can improve over time to better address specific use cases. We do not and will not permit third parties to use your Content or Customer Data to improve or train their AI models. We do not and will not use your Content or Customer Data to improve or train our models unless you give us express permission to do so.
Additional Processing Instruction
To the extent your Input contains Customer Personal Data (as that term is defined in the Data Process Addendum), you instruct Xerataus IQX to process the Customer Personal Data for the additional Business Purpose of providing the A1MX functionality and Output. You acknowledge that for the purposes of your participation in the A1MX, Leighton IQX Program(s) and your use of Xerataus IQX, Xerataus uses additional subprocessor(s) to provide the Xerataus IQX functionality.
Data Security
We implement reasonable technical, administrative, and physical safeguards to protect Customer Personal Data and Content, in line with NIST SP 800-171 and DFARS 252.204-7012. These include:
- Encryption of data in transit (e.g., TLS 1.3) and at rest.
- Access controls, including role-based authentication and multi-factor verification.
- Regular vulnerability assessments, penetration testing, and security audits.
- Incident response plans, including breach notification within 72 hours as required by GDPR or state laws (e.g., NC data breach notification).
- Data minimization: We collect only necessary data and retain it for as long as required for service provision, contract fulfillment, and legal obligations (e.g., up to 6 years post-contract for audit purposes under DFARS).
- In the event of a security incident, we will notify affected users and cooperate with investigations. Users must report suspected breaches to contact@leightondynamica.cloud. We aim for CMMC Level 1 certification for handling CUI.
For cross-border data transfers, we use Standard Contractual Clauses (SCCs) or equivalent mechanisms to ensure adequate protection.
The following terms (“IQX/AI Program Terms”) supplement the Master Subscription Agreement and Terms of Service (each, respectively and as applicable, the “Agreement”) between you and Xerataus IQX, L.AgH LLC (“A1MX, Leighton Avant-Garde Haus, Leighton Dynamica, Leighton IQX, Xerataus IQX) and apply to and govern your participation in the A1MX, Leighton IQX, and Xerataus IQX early access program that provides AI-enabled features and functionality to program participants (“IQX/AI Program”). All defined terms in these IQX/AI Program Terms shall have the same meaning as in the Agreement. The applicable Agreement (including our Privacy Policy) is incorporated by reference and will control for any provisions not addressed in these IQX/AI Program Terms.
Definitions
For the purposes of these Terms, the following definitions apply:
- AI Model or Foundation Model: Any machine learning model, including large language models or generative AI, used in Xerataus IQX or A1MX to process Inputs and generate Outputs.
- Customer Personal Data: Any information relating to an identified or identifiable individual, as defined under applicable data protection laws (e.g., GDPR, CCPA).
- Sensitive Personal Data: Categories of Customer Personal Data that require heightened protection, such as health, biometric, or financial data, as defined under applicable laws.
- Content or Customer Data: Includes Inputs, Outputs, and any data provided by users, as defined in the Agreement.
- Subprocessor: A third-party entity engaged by Leighton Avant-Garde Haus or Xerataus IQX to process Customer Personal Data, as listed in the Subprocessing List.
- High-Risk AI Use: Applications of AI that could significantly impact individuals’ rights, safety, or opportunities, such as automated decision-making in employment or legal contexts.
- CUI (Controlled Unclassified Information): Information requiring safeguarding under U.S. federal regulations, including DFARS 252.204-7012.
- Export-Controlled Items: Technology, software, or data subject to U.S. export laws, including EAR (Export Administration Regulations) or ITAR (International Traffic in Arms Regulations).
Participation and Termination
Xerataus IQX may suspend or terminate your access to or use of any Xerataus IQX programs at any time. The Xerataus IQX Program(s) Terms will automatically terminate upon the release of a generally available version of any Xerataus IQX program(s) or upon notice of termination by Xerataus IQX. You acknowledge IQX or A1MX is under no obligation to make Xerataus IQX generally available and may never do so. Further, upon Xerataus IQX becoming generally available, you acknowledge that continued access and use of any Xerataus IQX feature may be subject to your agreement to pay additional fees. We reserve the right to modify or terminate the IQX/AI Program, the IQX/AI Program Terms, or your use of Xerataus IQX, to limit or deny access to Xerataus IQX or A1MX and/or participation in the Xerataus IQX Program(s), at any time, in our sole discretion, for any reason, with or without notice and without liability to you. You may discontinue your use of Xerataus AI and/or your participation in the Xerataus IQX Program(s) at any time by disabling any Xerataus IQX or A1MX feature.
Nature of AI
You may provide input to be processed by Xerataus A1MX or IQX (“Input”), and receive output generated and returned by the Xerataus A1MX or IQX based on the Input (“Output”). Input and Output are your Content or Customer Data, as applicable. You will ensure that your Input and use of the Xerataus IQX will not violate any applicable law. You are solely responsible for the development, content, operation, maintenance, and use of your Content and Customer Data.
AI Risk Management
In accordance with the NIST AI Risk Management Framework and DoD AI Ethical Principles, we implement measures to manage risks associated with AI systems, including Xerataus IQX and A1MX. These include:
- Validity and Reliability: AI models are tested for accuracy and performance, but Outputs may contain errors or hallucinations. Users must verify Outputs for critical applications.
- Safety and Security: We employ safeguards such as encryption, access controls, and regular audits to prevent unauthorized access or data leaks. Users agree not to input sensitive data without prior review.
- Transparency and Explainability: We provide information on how AI models function where feasible. Outputs include disclaimers on probabilistic nature.
- Fairness and Non-Discrimination: Models are monitored for bias; users must not use AI in ways that perpetuate discrimination (e.g., based on race, gender, or other protected characteristics).
- Privacy: Data processing minimizes collection and uses anonymization where possible.
- Human Oversight and Accountability: High-risk uses require human review. We maintain accountability through incident reporting and audits.
- Environmental Impact: We optimize resource use to reduce the carbon footprint of AI training and inference.
Users acknowledge these risks and agree to use Xerataus IQX responsibly. For high-risk activities, implement human oversight and comply with applicable laws.
Ethical AI Use
We adhere to ethical principles including those from the U.S. Executive Order on Safe, Secure, and Trustworthy AI and DoD Responsible AI Strategy. Prohibited uses include:
- Developing AI for weapons, unlawful surveillance, or discriminatory purposes.
- Generating content promoting violence, disinformation, or illegal activities.
- Processing data in violation of privacy laws or without consent.
We reserve the right to monitor usage and terminate access for violations. Users indemnify us for ethical breaches arising from their use.
IP
You agree that, as between you and us, we own all legal rights, title and interest in and to the Xerataus IQX/AI Programs, such as A1MX, or any and Parent Company, Leighton Avant-Garde Haus’ Properties, which includes all intellectual property rights, and except for the license provided herein, no other rights or permissions to any of present or future Xerataus IQX is granted. Nothing herein gives you a right to use any of our trade names, trademarks, service marks, logos, domain names, and other distinctive brand features. Except to the extent permitted by law, you may not modify, distribute, prepare derivative works of, reverse engineer, reverse assemble, disassemble, decompile or otherwise attempt to decipher any code in connection with Xerataus IQX and/or any other aspect of Xerataus IQX technology, except as permitted by us.
You grant us a non-exclusive license to use your Inputs for service provision only; ownership remains yours.
Export Controls Compliance
All technology, software, and data provided through Xerataus IQX or A1MX may be subject to U.S. export control laws, including the Export Administration Regulations (EAR) administered by the U.S. Department of Commerce and the International Traffic in Arms Regulations (ITAR) administered by the U.S. Department of State.
You represent and warrant that:
- You will not export, re-export, or transfer any Export-Controlled Items without obtaining required licenses or approvals.
- You are not located in, or a national of, a country subject to U.S. embargoes (e.g., Cuba, Iran, North Korea, Syria).
- You will not use our services for prohibited end-uses (e.g., military, nuclear, missile, or chemical/biological weapons development).
- You comply with all applicable U.S. and international export laws.
Violations may result in termination of access and reporting to authorities. We reserve the right to deny service to ensure compliance. For questions, contact contact@leightondynamica.cloud.
Additional Use Provisions
You may not use A1MX (i) to develop foundation models or other large scale models that compete with Xerataus IQX; (ii) to mislead any person that Output from the Services was solely human generated; (iii) to generate spam, content for dissemination in electoral campaigns, use the Services in a manner that violates any applicable laws or technical documentation, usage guidelines, or parameters; or (iv) process sensitive personal data as that term is understood under applicable data protection law. You acknowledge that due to the nature of machine learning and the technology powering Xerataus AI, Output may not be unique and the Services may generate the same or similar output to Xerataus IQX or a third party. Xerataus IQX uses technology provided by our Parent Company (Leighton Avant-Garde Haus, LLC) to provide Xerataus IQX. You may not use Xerataus IQX in a manner that violates any Leighton Avant-Garde Haus Policy, including any other Legal Agreements.
Improvement of Services
Artificial intelligence and machine learning models can improve over time to better address specific use cases. We do not and will not permit third parties to use your Content or Customer Data to improve or train their AI models. We do not and will not use your Content or Customer Data to improve or train our models unless you give us express permission to do so.
Additional Processing Instruction
To the extent your Input contains Customer Personal Data (as that term is defined in the Data Process Addendum), you instruct Notion to process the Customer Personal Data for the additional Business Purpose of providing the A1MX functionality and Output. You acknowledge that for the purposes of your participation in the A1MX, Leighton IQX Program(s) and your use of Xerataus IQX, Xerataus uses additional subprocessor(s) to provide the Xerataus IQX functionality.
Data Security
We implement reasonable technical, administrative, and physical safeguards to protect Customer Personal Data and Content, in line with NIST SP 800-171 and DFARS 252.204-7012. These include:
- Encryption of data in transit (e.g., TLS 1.3) and at rest.
- Access controls, including role-based authentication and multi-factor verification.
- Regular vulnerability assessments, penetration testing, and security audits.
- Incident response plans, including breach notification within 72 hours as required by GDPR or state laws (e.g., NC data breach notification).
- Data minimization: We collect only necessary data and retain it for [specify period, e.g., as long as required for service provision or legal obligations].
- Employee training on data protection and compliance.
LIMITS ON LIABILITY
IN NO EVENT SHALL XERATAUS OR ITS AFFILIATES BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL OR INCIDENTAL LOSS, EXEMPLARY OR OTHER DAMAGES RELATED TO THESE AI PROGRAM TERMS OR YOUR PARTICIPATION IN THE XERATAUS AI PROGRAM WHETHER DIRECT OR INDIRECT, HOWEVER CAUSED AND BASED ON ANY THEORY OF LIABILITY, AND WHETHER OR NOT WE HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
Copyright and License Policy
© 2026 Leighton Avant-Garde Haus LLC. All Rights Reserved.
© 2026 Xerataus IQX, L.AgH LLC. All Rights Reserved.
© 2026 Leighton Dynamica. All Rights Reserved.
Leighton Avant-Garde Haus, a North Carolina Private Limited Liability Company, and all of its subsidiaries (including entities referred to as “Leighton Avant-Garde Haus,” “The Leighton Haus,” “Xerataus,” “Leighton AgH,” “L.AgH,” or “Leighton Dynamica”) respects the intellectual property rights of others and expects its users, employees, and partners to do the same.
This Policy applies to ownership, employees, and private members under Non-Disclosure Agreement for investors. It supplements the internal Copyright Use and Ownership Policy and complies with applicable laws, regulations, grants, or contracts governing copyrighted works.
All files, information, and content contained in this website (https://leightonavantgardehaus.github.io/), our internet properties portfolio, and associated services are copyrighted by Leighton Avant-Garde Haus LLC, Leighton Dynamica, and/or its subsidiaries. They may not be duplicated, copied, modified, redistributed, published, or adapted in any way without our express written permission.
Our website, properties, and services may contain service marks, trademarks, logos, words, and graphics belonging to us, our affiliates, or other companies. Use of these does not constitute any right or license to reproduce or use them without prior written permission from Leighton Avant-Garde Haus LLC or Leighton Dynamica.
The copying, redistribution, use, or publication of any content from our website or services is strictly prohibited. Access and use do not grant any ownership rights to our content.
In appropriate circumstances, we may disable or terminate accounts of users who repeatedly infringe copyrights or other intellectual property rights.
In accordance with the Digital Millennium Copyright Act of 1998 (DMCA; full text available at http://www.copyright.gov/legislation/dmca.pdf), Leighton Avant-Garde Haus and Leighton Dynamica will respond expeditiously to claims of copyright infringement on our website or services.
If you are a copyright owner (or authorized to act on behalf of one), report alleged infringements by providing a DMCA Notice of Alleged Infringement to our Designated Copyright Agent at contact@leightondynamica.cloud. Upon receipt, we will take appropriate action, including removal of challenged material.
Enforcement of this policy supports our commitment to ethical innovation in defense and AI technologies. For questions, contact contact@leightondynamica.cloud.
Last Updated: February 4, 2026
© 2026 Leighton Avant-Garde Haus LLC, Leighton Dynamica, and Subsidiaries. All Rights Reserved.
Unauthorized reproduction or distribution of this content is prohibited.
Contact: contact@oneleighton.cloud