A Microsoft-first foundation
Core connects Entra and Sentinel records to identities, assets and incident timelines. Captured payloads retain their source timestamps, hashes and provenance alongside separately normalised records.
THE 170TARV PLATFORM
When an MSP faces a serious cyber incident, 170tarv brings together the people, events, affected customers, evidence, decisions and obligations that explain it.
Least-privilege vendor APIs collect source records.
Raw payloads remain unchanged, with hashes and provenance.
Linked timelines connect identities, assets, customers and decisions.
Export manifests support checks for changes after capture.
The public website holds no customer evidence or privileged sessions. Customer users access their organisation in the authenticated app. Staff operations have a separate authentication boundary. Integration activation and commercial entitlements remain managed by 170tarv.
ONE CONNECTED INCIDENT RECORD
Core connects Entra and Sentinel records to identities, assets and incident timelines. Captured payloads retain their source timestamps, hashes and provenance alongside separately normalised records.
Blackbox adds ConnectWise PSA and NinjaOne RMM relationships to map potential downstream scope. Reconstruction distinguishes confirmed impact, suspected findings and questions that still need evidence.
Command brings leadership the current picture. Incident Command connects evidence, actions and decisions. Assurance links controls and obligations. Workspace Admin brings service health, billing and governed requests together.
Core provides signed readiness reports. Blackbox adds evidence-backed reconstruction, customer-impact assessment, decision rationale and an uncertainty register. Each report carries a 170tarv verification code.
Blackbox can use a configured external AI service to draft summaries, identify gaps and organise findings with evidence citations. Drafts remain subject to human review before becoming official signed report content.
Tenant isolation, role permissions and separate customer/staff authentication protect access. Audited containment controls can pause high-risk operations while preserving records for investigation and recovery.
THE NAME. THE PURPOSE.
The name draws on tarv, a Scandinavian word with Germanic roots associated with need, requirement, welfare and best interests. Its usage spans Danish, Norwegian and historical Swedish.
For example: when an MSP needs to explain a serious incident, 170tarv brings the preserved evidence, customer scope and human decisions together into a record that can be verified.
Service updates, incident communications and planned maintenance.
Follow the capture, hash, provenance and verification chain.
Understand website enquiries and customer evidence processing.
Review acceptable use, managed service boundaries and contract terms.
See exactly what this public site stores in your browser.
Review access boundaries and responsible reporting guidance.
Explore two quote-led plans with annual contracts.
Cryptography can demonstrate that evidence has not changed after capture. It cannot prove that the upstream system was truthful or complete. Human assessment remains essential.