A defence tool must not become the weak point
A platform trusted with the logs of an entire network has to be the best-protected machine on it. Here is how it is built.
Eight decisions made in advance
Your data stays with you
Analysis, evidence and decisions never leave your server. The platform runs offline. Internet is needed only to refresh the vulnerability database, and that file can be carried over from another machine.
A signature on every entry
Each entry is chained to the previous one with SHA-256 and signed with an Ed25519 key that never leaves the server. The export carries the public key and the exact construction: the ledger can be verified outside the platform, without trusting it.
Short-lived tokens
Access tokens live 15 minutes and are bound to the device. Least-privilege roles. Re-authentication before any action that could disrupt work. Refusals are recorded too.
An agent's credential is worth almost nothing
It sits unattended on hundreds of machines, so an agent can only deliver events: it cannot read cases, approve actions or open the console. One agent can send at most 60,000 events a minute.
Only from named networks
Syslog carries no proof of who sent it, so “from anywhere” is never the default. Both the claimed hostname and the address a line actually came from are recorded.
No evidence attached
Email, a webhook or syslog into a SIEM say what was found and how sure the platform is, but carry no evidence: they travel through systems outside your perimeter.
Unprivileged
In Docker the platform runs as an unprivileged user, with a read-only filesystem and bounded memory.
SBOM included
A list of every component and its licence ships with the product.
Three meanings, all implemented
Continuous evaluation
Every user, device and session carries a trust score recomputed on every request, with the factors that produced it listed.
Policy verification
Observed access is compared with the written access, segmentation and privilege policies. The gaps are separate findings, not incidents.
The platform itself
Short-lived tokens bound to the device, least-privilege roles, fresh confirmation before disruptive actions, and every decision and refusal in the ledger.
International frameworks, not one country's rules
The platform builds on international standards, so it makes sense in any jurisdiction. Every recommended action is mapped to NIST CSF 2.0 and ISO/IEC 27001:2022.
- NIST CSF 2.0functions and categories
- ISO/IEC 27001:2022Annex A controls
- MITRE ATT&CKtechniques and tactics
- NIST SP 800-207zero trust
Country profiles
A profile reminds you whom to notify about an incident and by when, with the source named. Profiles for the EU (NIS2) and the UK ship with the product; your own is added as a file.
Mapping to a framework is not a certification, and a country profile is a reminder, not legal advice.
The six official UN languages
Interface and explanations in English, Russian, Arabic (right to left), Chinese, Spanish and French. Explanations are built from the same facts and are deterministic: the same record produces the same words years later.
- Русский
- English
- العربية
- 中文
- Español
- Français
Test it on your own data
A pilot runs on one server inside your network. You see what the platform finds there, and how many alerts stop reaching your analysts.
Request a pilot →