Infrastructure and security engineering · Metro Detroit

Infrastructure and security, delivered with proof.

Compliance readiness, network and security engineering, and verified AI systems for credit unions, defense suppliers, and regulated businesses. Where a claim on this page can be checked against a source outside this website, it carries a mark. Follow the marks.

The trust layer

We wrote the trust layer ourselves. Third Level IT authored VIRP, an open infrastructure trust protocol published through the IETF draft process E1 and independently reviewed by outside engineers. E2 The same discipline runs through everything we deliver: claims backed by evidence, systems that prove what they did.

What we do

Three services, one standard

Delivered by the engineer who answers the phone, verified against device output, and filed as evidence your examiner can open.

  1. 01

    Compliance readiness

    GLBA · NCUA · NIST 800-171 · CMMC

    Gap assessments and remediation for GLBA, NCUA, NIST 800-171, and CMMC. We map your controls to real evidence, fix what is missing, and leave you ready for the examiner.

    How readiness work runs →
  2. 02

    Network and security engineering

    Firewalls · Routing · Segmentation · SIEM

    Firewalls, routing, segmentation, SIEM. Fortinet partner. E3 We run our own gear in our own colocation facility, so we operate what we recommend. E4

    How engineering work runs →
  3. 03

    Custom AI systems, built and verified

    On your hardware · Ships with tests · Your data stays put

    AI-powered software that runs on hardware you own. Every system ships with tests that prove it works, and nothing leaves your building unless you decide it does.

    How AI work runs →

Industries

Who we work with

Financial institutions

NCUA · GLBA · FFIEC

Exam findings closed with evidence for credit unions and community banks.

For financial institutions →

Defense contractors

CMMC 2.0 L2 · NIST 800-171 · DFARS

Scoped CUI enclaves designed, built, and documented for the assessor.

For defense contractors →

Municipal and utility

OT/SCADA · AWIA

Segmented OT networks, hardened remote access, and evidence for the state.

For municipal and utility →

The founder

The founder is the engineer

Nate Howard spent fifteen years at enterprise integrators, Presidio and Sentinel Technologies, designing and securing networks for Fortune 500 environments. He wrote VIRP because infrastructure ran on assertion, and he runs Third Level IT the way the protocol works: publish the claim, attach the evidence, invite the check. When you call, you get the person who designed your network.

“Your regulator doesn't grade effort. It grades evidence. I build infrastructure that produces it.”

Nate Howard, Founder and Principal Engineer
More about how we work →

Evidence

Check the claims

Each mark on this page resolves to a source outside this website. Unmarked statements are ours to defend in conversation.

  1. E1 Authored VIRP, an open infrastructure trust protocol published through the IETF draft process IETF Datatracker ↗
  2. E2 Independently reviewed by outside engineers Acknowledgments, draft-howard-virp-06 ↗
  3. E3 Fortinet partner Fortinet partner locator ↗
  4. E4 We run our own gear in our own colocation facility thirdlevel.ai ↗

One conversation

Facing an exam, an assessment, or a system nobody can prove?

Email or call. We'll tell you within one conversation whether we're the right fit, and if we're not, we'll point you to someone who is.