Security

A defence tool must not become the weak point

A platform trusted with the logs of an entire network has to be the best-protected machine on it. Here is how it is built.

Design

Eight decisions made in advance

Perimeter

Your data stays with you

Analysis, evidence and decisions never leave your server. The platform runs offline. Internet is needed only to refresh the vulnerability database, and that file can be carried over from another machine.

Ledger

A signature on every entry

Each entry is chained to the previous one with SHA-256 and signed with an Ed25519 key that never leaves the server. The export carries the public key and the exact construction: the ledger can be verified outside the platform, without trusting it.

Access

Short-lived tokens

Access tokens live 15 minutes and are bound to the device. Least-privilege roles. Re-authentication before any action that could disrupt work. Refusals are recorded too.

Agents

An agent's credential is worth almost nothing

It sits unattended on hundreds of machines, so an agent can only deliver events: it cannot read cases, approve actions or open the console. One agent can send at most 60,000 events a minute.

Syslog

Only from named networks

Syslog carries no proof of who sent it, so “from anywhere” is never the default. Both the claimed hostname and the address a line actually came from are recorded.

Notifications

No evidence attached

Email, a webhook or syslog into a SIEM say what was found and how sure the platform is, but carry no evidence: they travel through systems outside your perimeter.

Container

Unprivileged

In Docker the platform runs as an unprivileged user, with a read-only filesystem and bounded memory.

Bill of materials

SBOM included

A list of every component and its licence ships with the product.

Zero trust

Three meanings, all implemented

01

Continuous evaluation

Every user, device and session carries a trust score recomputed on every request, with the factors that produced it listed.

02

Policy verification

Observed access is compared with the written access, segmentation and privilege policies. The gaps are separate findings, not incidents.

03

The platform itself

Short-lived tokens bound to the device, least-privilege roles, fresh confirmation before disruptive actions, and every decision and refusal in the ledger.

Standards

International frameworks, not one country's rules

The platform builds on international standards, so it makes sense in any jurisdiction. Every recommended action is mapped to NIST CSF 2.0 and ISO/IEC 27001:2022.

  • NIST CSF 2.0functions and categories
  • ISO/IEC 27001:2022Annex A controls
  • MITRE ATT&CKtechniques and tactics
  • NIST SP 800-207zero trust

Country profiles

A profile reminds you whom to notify about an incident and by when, with the source named. Profiles for the EU (NIS2) and the UK ship with the product; your own is added as a file.

Mapping to a framework is not a certification, and a country profile is a reminder, not legal advice.

Languages

The six official UN languages

Interface and explanations in English, Russian, Arabic (right to left), Chinese, Spanish and French. Explanations are built from the same facts and are deterministic: the same record produces the same words years later.

  • Русский
  • English
  • العربية
  • 中文
  • Español
  • Français
Pilot

Test it on your own data

A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.

Request a pilot →