Veteran-owned • Accountable by design

Accountability is the operating system.

eTrepid helps defense contractors, regulated organizations, and government buyers turn cybersecurity, compliance, technology operations, and governed AI into bounded work with named owners, reviewable evidence, and human authority.

FoundedMarch 2, 2010
LeadershipFounder-led
Primary focusGRC, CMMC, and secure operations
Business recordVeteran Owned Small Business

Our origin

Move forward without fear—because the work is governed.

eTrepid was founded in 2010 around a practical service idea expressed in its name: reduce the uncertainty that keeps organizations from using technology with confidence.

Service shaped the company

Founder Thomas R. Blandford III built eTrepid around preparation, reliability, clear authority, and responsibility for the outcome—not simply the tool.

The mission expanded with the risk

As technology became inseparable from contracts, regulated data, security obligations, and AI-enabled work, eTrepid evolved from practical IT delivery into an integrated security, GRC, evidence, and governed-operations partner.

Company evolution

The same service ethic, applied to a wider operating system.

Foundation

Practical technology

Make systems understandable, dependable, and useful to the people responsible for the business.

Operations

Managed service

Turn support, change, configuration, vendors, and lifecycle work into an accountable operating rhythm.

Security

Managed defense

Connect identity, cloud, monitoring, response, continuity, and remediation instead of treating them as isolated tools.

Governance

GRC and CMMC

Translate obligations into scope, owners, implementations, evidence, exceptions, review, and sustained readiness.

Next system

Governed AI

Help organizations adopt AI with approved purpose, data and system boundaries, least privilege, human oversight, and traceability.

Mission and direction

Security, continuous compliance, and cost clarity should increase confidence.

Our mission is to empower organizations with practical cybersecurity and governance that make risk visible, responsibilities clear, evidence maintainable, and technology decisions more predictable.

Our direction

We want organizations to use technology and AI confidently because the operating conditions are understood: authority is named, controls are implemented, evidence is reviewable, exceptions are visible, and change is governed.

What confidence means here

Confidence is not a promise of zero incidents, automatic compliance, perfect AI, or guaranteed outcomes. It is the result of disciplined decisions, capable people, explicit boundaries, tested processes, and current evidence.

Operating principles

How we intend to earn trust.

Mission before tools

Start with the business outcome, obligation, risk, authority, and operating constraint before selecting a platform or control.

Evidence before assertion

Separate what is sourced, implemented, tested, approved, current, and publishable from what is planned, assumed, or still under review.

Human authority remains

Technology and AI may support decisions and actions; accountable people retain business, legal, policy, data, and risk authority.

Scope is explicit

Define systems, users, locations, data, services, hours, dependencies, exclusions, assumptions, and change triggers.

Stewardship over dependency

Design for ownership, portability, continuity, understandable records, and informed client decisions—not avoidable lock-in.

Improve the system

Use incidents, findings, exceptions, tests, service reviews, and operational data to improve the next decision and control cycle.

Accountability model

Responsibility is assigned, not implied.

eTrepid leadership

  • Owns company ethics, delivery expectations, capacity, quality, escalation, and contracted commitments.
  • Approves public claims and makes sure material limitations are visible.
  • Names accountable service, governance, technical, and relationship owners.

eTrepid delivery teams

  • Perform authorized work within scope and record material decisions, actions, changes, evidence, and exceptions.
  • Escalate conflicts, ambiguity, risk, and work outside authority.
  • Validate completion against the agreed method and acceptance criteria.

Client leadership

  • Retains business purpose, accurate facts, data ownership, policy approval, funding, risk acceptance, and human accountability.
  • Provides timely decisions, access, dependencies, and approvals.
  • Uses counsel, assessors, regulators, acquisition officials, insurers, and specialists for decisions they retain.

Founder and leadership

Lead with the mission and remain accountable for the work.

Thomas R. Blandford III founded eTrepid on March 2, 2010 and serves as President & CEO. The durable leadership theme in the company’s records is direct: begin with the end in mind, understand the mission, and take responsibility for the work.

Current leadership

Thomas R. Blandford III

Founder • President & CEO

Executive responsibility includes company direction, client accountability, service expectations, escalation, and approval of material public claims.

Leadership standard

eTrepid describes current roles and relevant experience without relying on stale team rosters, unsupported credential lists, personal contact details, or claims that exceed the available record.

One accountable relationship

The brand architecture clarifies who owns what.

eTrepid

The customer-relationship and accountability brand: advisory, implementation, managed operations, government contracting, and stewardship of the contracted outcome.

ThreatKrusher

eTrepid’s seven-pillar Cyber Defense Ecosystem: Comply, ITSM, Trust, Access, Cloud, Continuity, and Command.

AI Governance

The discipline for policy, authority, risk classification, data and vendor controls, testing, oversight, evidence, exceptions, and lifecycle review.

AI-as-a-System

eTrepid’s implementation methodology for combining governed AI agents, operating roles, secure orchestration, data, integrations, controls, and human oversight.

Auctoric AIBOS

An independently owned enabling platform that may implement AI-as-a-System where contracted. Auctoric retains its platform, intellectual property, licensing controls, and roadmap.

Government acquisition

A route for eligible government buyers. Contract vehicle, scope, SIN, pricing, ordering, entity, and socioeconomic facts require current official verification.

Who we serve

Organizations where technology decisions carry business consequences.

Defense Industrial Base

Contractors and subcontractors protecting FCI, CUI, contract eligibility, customer confidence, and evidence under CMMC and related obligations.

Regulated businesses

Organizations managing sensitive information, professional obligations, fragmented systems, lean internal teams, and pressure to adopt AI responsibly.

Government buyers

Federal, state, and local programs seeking bounded cybersecurity, information technology, governance, AI, and professional services through an appropriate acquisition route.

What to expect

Accountability should be visible in the engagement.

  • A named owner for the business outcome, relationship, delivery, and material decisions.
  • Explicit scope, assumptions, dependencies, exclusions, authority, and acceptance criteria.
  • Clear separation among eTrepid, client, assessor, acquisition, legal, platform, and provider responsibilities.
  • Records of material decisions, actions, changes, evidence, exceptions, and approvals.
  • Escalation when facts, authority, risk, scope, or responsibilities are unclear.
  • Current claims and credentials with limitations visible rather than buried.
  • Secure handling paths for CUI, credentials, vulnerabilities, procurement-sensitive information, and confidential architecture.
  • Review and improvement when incidents, findings, tests, exceptions, or operating conditions change.

About eTrepid

Questions an evaluator should be able to answer.

Is eTrepid a general-purpose IT company?

Managed technology remains part of the operating foundation, but eTrepid’s current positioning centers on GRC, CMMC and DIB readiness, integrated cyber defense, government acquisition, and safe, governed AI adoption.

Why does this page describe eTrepid as veteran-owned?

The current official GSA eLibrary record identifies eTrepid as a Veteran Owned Small Business. Government buyers should still verify the authoritative record and solicitation-specific requirements when socioeconomic status matters to an acquisition.

Is ThreatKrusher a separate company?

No. ThreatKrusher is eTrepid’s integrated seven-pillar Cyber Defense Ecosystem and service-delivery model.

Is Auctoric part of eTrepid?

No. Auctoric is an independent platform company. Where applicable agreements permit, eTrepid may provide partner-enabled onboarding, integration, governance, managed-operation, or security services around Auctoric AIBOS. The exact responsibilities remain contract-specific.

Who remains accountable when eTrepid supports AI?

eTrepid is accountable for its contracted advisory, implementation, integration, security, and managed-service work. The client retains business purpose, data ownership, policy approval, risk acceptance, and human-only accountability. Platform and other providers retain their respective product and service responsibilities.

Meet eTrepid

Bring us the mission, the constraint, and the evidence you have.

We will help define the operating problem, identify accountable decision-makers, separate known facts from assumptions, and determine whether advisory, project, managed, acquisition, or partner-enabled work is the right next step.