Status: 104 capabilities — 20 GA, 84 Beta. Enforcement is monitor-only by default. Honest status →
Platform

How it reaches your systems, and what it does when it gets there

Estate management

Declarative desired state for the security controls you already own, applied over the channel each system actually speaks.

Credentials

Vaulted and injection-only. No API returns a secret; external PAM is dereferenced at connect time.

Sessions

Brokered, recorded and command-mediated. Recording cannot be disabled.

Change

Diff preview, dry run, commit gate, prior state captured, one-click rollback.

Linux packs

nftables, SELinux/AppArmor, auditd, PAM, SSH hardening, fapolicyd, LUKS status, CIS.

Windows packs

Defender, Firewall with Advanced Security, BitLocker, AppLocker/WDAC, ASR, STIG.

Device Console

Import an OpenAPI document; get a working admin page for that device, with quotas and dual control.

Workload segmentation

Learn what talks to what, propose the allow-list, show what enforcing it would break — then enforce, if you say so.

The segmentation pipeline Observe traffic, discover applications and policy, review the impact, then enforce on hosts, cloud accounts and Kubernetes. Enforcement is off by default. 1 · Observe NetFlow / IPFIX, agent packages, processes, CMDB + k8s labels 2 · Discover applications and tiers, then an allow-list from what actually happens 3 · Review impact analysis: what enforcing this would break, before it does 4 · Enforce host firewall · cloud SGs NetworkPolicy · NGFW off unless switched on Nothing is enforced by discovery. Publishing is a separate act, and enforcement refuses to run without a declared management network, refuses to isolate a workload, and captures the host's prior firewall state before it changes anything. Rollback is never gated.
Discovery is deterministic: the same window and metadata always produce the same policy, so it can be diffed and reviewed like code.

Detection & response

Security data lake

OCSF-native, tiered storage, federated query across your own lake.

Detection hub

Detection-as-code with Sigma, plus an ATT&CK heatmap that shows the gaps.

SOAR

Playbooks whose actions reach real hosts. OpenC2 and CACAO interop.

Agentic SOC

Triage and response agents with confidence thresholds and a kill switch.

Exposure

EASM and CTEM with attack paths to crown-jewel assets, and safe-exploitation validation.

Intel & deception

STIX/TAXII, IoC lifecycle, honeytokens with high-fidelity alerting.

Governance & trust

Identity governance

Joiner-mover-leaver with ≤60s session revocation; certification campaigns that auto-revoke.

Segregation of duties

Toxic-combination enforcement across module boundaries, not just within one app.

Sovereignty

Region residency, customer lockbox, BYOK and hold-your-own-key.

Audit

Append-only hash-chained bus, signed SLA reports, time-boxed auditor role.

Supply chain

Signed releases with SBOM, CBOM, VEX, SLSA — and a reproducible build.

MSP

Org hierarchy, delegated admin, deterministic entitlement merge, co-managed SOC.

Every operation in the API → · The assurance position →