Status: 104 capabilities — 20 GA, 84 Beta. Enforcement is monitor-only by default. Honest status →
Security estate management

One plane for every security control you already own.

Native OS controls, open-source tooling and third-party products — managed from one console, under one identity, with one audit trail.

Managed, self-hosted, or fully air-gapped — every capability works with zero egress.

USCP above a heterogeneous security estate One control plane reaches Linux hosts, Windows machines, network devices, out-of-band hardware, cloud accounts, Kubernetes clusters and third-party security products over seven channels plus an optional agent. Unified Security Control Plane one identity · one policy · one audit trail SSH · WinRM/PowerShell · RDP · NETCONF/gNMI · SNMPv3 · Redfish/IPMI · API · optional agent Linux nftables, SELinux, auditd, fapolicyd Windows Defender, WFAS, BitLocker, WDAC Network & BMC switches, firewalls, out-of-band hardware Cloud & K8s security groups, NSGs, NetworkPolicy Products NGFW, EDR, IdP, SIEM Credentials vaulted and injection-only · every privileged session brokered, recorded and command-mediated staged rollout · per-target reporting · global kill switch
Seven channels plus an optional agent. Agentless first; an agent only where an agentless channel genuinely cannot do the job.
104
capabilities, separately licensable
8
ways to reach a system
508
API operations, all entitlement-gated
100%
work air-gapped

Four planes

Estate

Reach and configure every system. Vaulted credentials, recorded sessions, desired-state packs.

Segmentation

Flow telemetry, application discovery, allow-list policy, enforcement on hosts, cloud and Kubernetes.

Detect & respond

OCSF lake, detection-as-code, ATT&CK coverage, SOAR whose actions reach real hosts.

Govern

IGA, access certification, segregation of duties, DLP, residency, hold-your-own-key.

How each one works →

Three things most platforms here don't do

Drives the estate

Most consoles read from your tools. This one writes to them — and every write is staged, recorded and reversible.

Air-gap is not a variant

All 104 capabilities work with zero egress, including licensing. Same release stream, not a stripped build.

Won't overstate itself

Availability is declared per capability and enforced by CI. Empty telemetry shows an empty state. A score with no evidence says unknown.

Deployment

Managed

We run it. Tenant-isolated, region-pinned, customer lockbox on vendor access.

Self-hosted

One signed binary and Postgres. SBOM, CBOM, VEX, SLSA provenance, reproducible build.

Air-gapped

Zero egress. Offline entitlements and advisory feeds, in-perimeter collection.

Implementation guide →

Ask us to prove it

A walkthrough covers the architecture, the channels against your own systems, and the assurance position stated plainly — including what is Beta and what has not been certified.

Email hello@uscp.example with the shape of your estate: how many hosts, which operating systems, which security tools, and whether any of it is air-gapped.

Placeholder address — replace before publishing.