How it reaches your systems, and what it does when it gets there
Estate management
Declarative desired state for the security controls you already own, applied over the channel each system actually speaks.
Credentials
Vaulted and injection-only. No API returns a secret; external PAM is dereferenced at connect time.
Sessions
Brokered, recorded and command-mediated. Recording cannot be disabled.
Change
Diff preview, dry run, commit gate, prior state captured, one-click rollback.
Linux packs
nftables, SELinux/AppArmor, auditd, PAM, SSH hardening, fapolicyd, LUKS status, CIS.
Windows packs
Defender, Firewall with Advanced Security, BitLocker, AppLocker/WDAC, ASR, STIG.
Device Console
Import an OpenAPI document; get a working admin page for that device, with quotas and dual control.
Workload segmentation
Learn what talks to what, propose the allow-list, show what enforcing it would break — then enforce, if you say so.
Detection & response
Security data lake
OCSF-native, tiered storage, federated query across your own lake.
Detection hub
Detection-as-code with Sigma, plus an ATT&CK heatmap that shows the gaps.
SOAR
Playbooks whose actions reach real hosts. OpenC2 and CACAO interop.
Agentic SOC
Triage and response agents with confidence thresholds and a kill switch.
Exposure
EASM and CTEM with attack paths to crown-jewel assets, and safe-exploitation validation.
Intel & deception
STIX/TAXII, IoC lifecycle, honeytokens with high-fidelity alerting.
Governance & trust
Identity governance
Joiner-mover-leaver with ≤60s session revocation; certification campaigns that auto-revoke.
Segregation of duties
Toxic-combination enforcement across module boundaries, not just within one app.
Sovereignty
Region residency, customer lockbox, BYOK and hold-your-own-key.
Audit
Append-only hash-chained bus, signed SLA reports, time-boxed auditor role.
Supply chain
Signed releases with SBOM, CBOM, VEX, SLSA — and a reproducible build.
MSP
Org hierarchy, delegated admin, deterministic entitlement merge, co-managed SOC.