Fixed scope first, written capability statement attached to every proposal. Three things we never do: log on to your production systems, hold your vendors' licences, or claim beyond the printed coverage.
Read-only over your artifacts and fixtures; each ends in an evidence document.
| Engagement | Deliverable | Notes |
|---|---|---|
| Seam assessment | the full analyzer report — layout drift vs deployed configs, lineage matrix, batch-window DAG, risk register — plus a findings walkthrough | artifact capture by your staff; report is offline-readable and audit-archivable |
| ISO 20022 conformance assessment | citation-backed conformance report per institution and rail; remediation list with evidence | the BSP Circular 1223 recurring-report obligation, answered |
| Pre-cutover rehearsal | your mapping exercised against full synthetic cycles on the bench; seeded edge cases; re-run per rulebook update | subscription-shaped: annual re-certification runs |
| Migration verification | independent golden-run equivalence proof of any vendor's migration output | target-agnostic; your migration vendor stays your migration vendor |
| Exit-plan assessment | a credible, costed migration plan held as renewal leverage — whether or not you ever execute it | Adabas/Natural first; refreshed each renewal cycle |
| Scheduler-migration rehearsal | both scheduler definitions imported, cycles replayed side by side, outcomes diffed | CA-7 and Control-M-style definitions supported |
| SCM-migration verification | generate processors replayed; Git-built binaries proven equivalent to the SCM-built originals | on demand |
Standing capability we set up for your team — priced to recur, built to your standards.
| Engagement | Deliverable | Notes |
|---|---|---|
| Modernization rehearsal environment | a standing mirror of your estate's shape + the fixture-capture loop for your team's rehearsals | priced per instance/month |
| Shop-standard environment build | a golden environment image to your enterprise standards — naming, PROCs, security model, calendars, coding-standard lab graders — snapshot-cloned for cohorts or project teams | intake is one working session + your artifact pack; days to stand up, versioned thereafter |
| Agent access (MCP) Clients only · by request | your AI agents get CobolStack environments and verification as governed MCP tools — provision, submit, snapshot, and prove, with evidence-bearing responses | enabled per client under your security review; never self-serve |
| Fixture-capture enablement | the capture protocol, scripts and manifest tooling for your staff | the method behind everything above: we never touch your licensed systems |
The situation: your mainframe, midrange and relational estates exchange files every night through interfaces whose authors have left. Nobody can say with confidence what breaks if you change a copybook, a loader config, or a schedule time — so nothing changes, and every modernization plan stalls at the same boundary.
What you receive: a board-readable report that inventories every handoff, verifies the deployed loader configurations against the record layouts of record, traces each interface field to the columns it lands in, draws the cross-platform batch window as one dependency graph, and ranks the risks — with evidence attached to every finding, and anything we could not resolve listed honestly rather than guessed.
What it changes: the boundary stops being tribal knowledge. Change requests, audits and migration RFPs can cite one document instead of three retirees.
Inputs: copybooks/DDS, loader configs, scheduler definitions, JCL/CL, stored procedures — captured by your staff per our written protocol. Typical duration: 2–4 weeks per estate slice. We never log on to your systems.
The situation: the regulator has found industry implementations inconsistent and now requires proof, on a recurring basis, that your mappings conform — with full compliance defined as retiring translators altogether. "Our messages validate" is no longer an answer; the question is whether the numbers inside them are right.
What you receive: a conformance report that ties every finding to the circular's own sections: schema validation, field-level equivalence from your core's actual extract bytes to the message, completeness proof against your own control totals, and a prioritized remediation list. Version-pinned and offline-readable — built to be filed, audited, and re-run.
What it changes: your recurring conformance-report obligation becomes a repeatable exercise with an evidence trail, not an annual scramble.
Inputs: extract samples + record layouts + your mapping specification or output messages. Per institution, per rail. Findings imply no regulator endorsement.
The situation: your new native-ISO mapping must eventually face production traffic. The first full-volume test should not be the live rail.
What you receive: your mapping exercised against complete synthetic settlement cycles — including the ugly cases: non-preferred sign nibbles, truncations, charset violations, control-total drift — with a scored verdict per run. Rulebook updates become a scheduled re-certification run rather than a project.
Subscription-shaped. Runs on our environments; your data never required — the synthetic core generates authentic traffic.
The situation: your migration vendor reports percent-complete; your auditors ask a different question — does the new system compute what the old one computed? Row-count reconciliation answers the copy. It does not answer the computation.
What you receive: baseline outputs produced by actually executing your batch — your programs, your job streams, masked data — then a byte-level comparison of the migrated target's posted state, control tables and reports against that baseline. Divergences come explained with evidence or flagged unexplained; a cause is never invented to close a ticket.
What it changes: "did we get it right?" becomes a document, independent of the vendor being measured. Most vendors welcome it — it converts their claim into proof.
Target-agnostic. Expected fixtures captured by your staff on your systems under SOW. Priced per engagement + per re-run during parallel running.
The situation: a legacy vendor prices your renewal against the cost of leaving — which is unanswerable, so you pay. The strongest counter is a credible, costed exit plan you may never execute.
What you receive: a feasibility assessment of migrating the estate — inventory, complexity ranking, target options, effort band, risk register — engineered to be credible in a negotiation. Refreshed each renewal cycle; useful every time whether or not anyone migrates.
Adabas/Natural estates first (fixed-term keys and platform end-of-support make the conversation concrete). Also applicable to Sybase ASE estates, where end of mainstream maintenance has already passed.
The situation: moving between scheduler products (or consolidating after a merger) means re-expressing thousands of job definitions, calendars and trigger chains — and the first missed dependency shows up as a missed settlement window.
What you receive: both sets of definitions imported, complete cycles replayed side by side on our environments, and the outcome differences listed — before anything touches your production scheduler.
CA-7-style captures and Control-M-style exports both supported. Assembly of existing capability — fast to scope.
The situation: moving mainframe source from a legacy SCM into Git migrates metadata; it does not prove the Git-built binaries match what the legacy processors built.
What you receive: generate processors replayed, both build paths executed, outputs compared — the compile-and-compare proof that the history move lost nothing that matters.
On demand. Pairs naturally with the DevOps enablement bootcamp (CS450).
The situation: generic training environments teach generic habits. Your shop has a standards manual — naming, job cards, PROCs, security conventions, scheduler calendars — and every new hire spends their first weeks unlearning the course and learning the house.
What you receive: a golden environment image built to your standards from your own artifact pack, with lab graders that enforce your conventions. Snapshot-cloned per seat for cohorts, or per team for project and test work. Maintained as a versioned template: your standards updates roll through as releases, and cohort two costs almost nothing.
What it changes: day-one-on-the-job stops being week three. Training output arrives already fluent in your shop, and your standards document becomes something the environment enforces rather than a PDF nobody reads.
Intake: one working session with your technical lead + the artifact pack (standards manual, sample JCL/PROCs, security export, scheduler export) under NDA — all your own IP. Typical stand-up: days for naming/JCL/security/scheduler; a domain-shaped synthetic estate on top is scoped separately. We mirror conventions and platform semantics, not third-party licensed tools.
The situation: your teams are wiring AI agents into delivery — and the agents have the same problem your developers always had: nothing safe to run against. Nobody clears an agent to exercise write-tools on licensed iron, and the emerging mainframe MCP ecosystem (Zowe's server, z/OS Connect's MCP support, IBM's IBM i server) points agents at live systems for inspection. Useful — but an agent that can only look cannot rehearse.
What you receive: a client-private MCP endpoint over your CobolStack environments: tools to provision an instance, submit jobs, read spool, compile, run cycles, snapshot and reset — plus the tools nobody else has: golden-run comparison, seam assessment, replay, and conformance checks that return evidence, not just verdicts. Your agent proposes; the tools prove; your people review an evidence trail. The division of labor stays clean: your Zowe/z/OSMF-side tooling inspects the real estate read-only, the CobolStack surface is where anything actually executes, and your licensed system remains the sole conformance authority.
What it changes: AI-assisted modernization gets a rehearsal loop with machine verification on every iteration — "verified, not autonomous" as an architecture, not a slogan.
The two servers, their tool surfaces and the evaluation workflow are laid out on the MCP page. Enabled per client under your security review. Governance built in: OAuth 2.1 with PKCE and audience-bound tokens, scoped per-client credentials, single-tenant instances only, a read-only assessment tier separate from the execute tier, audit on every tool call, and human-approval-friendly tool descriptions that carry the specification-conformant disclaimer. Not self-serve; not offered outside an existing client relationship.
The situation: your migration team needs somewhere consequence-free to rehearse — and your non-production LPAR is shared, change-controlled and licence-metered.
What you receive: a standing environment shaped like your estate (layouts, jobs, schedules ingested from your artifacts), with snapshot/rollback per rehearsal and the fixture loop to keep it honest against your real system.
Priced per instance/month. The fixture-capture protocol and scripts are included — your staff run them; we never touch your licensed systems.
Translation generation, additional language grammars and other gated work appear on the capability & roadmap page — engagement-gated by policy, and we'll tell you so to your face rather than sell it as available.