Everything is an event.
A process starting, a session revoked, a file changing, a login from a country nobody uses. Each one becomes the same kind of record, sealed on the machine where it happened, before anything reads it. Detection, investigation, response and identity are not four products here. They are four readers of that one record.
The first figure is read from this page by a build-time guard and compared with the running platform's own coverage count; a page that drifts from the code does not ship. Ask us what we cannot see — every gap names the feed it waits on.
Twenty-odd named fields with one meaning each, written once at the source. Nothing downstream has to guess what a column meant on a Tuesday.
Who did what, to what, and how it ended. An identity is attached at the moment of the act, not reconstructed from three systems afterwards.
Every event names the event that caused it. Sequence is a property of the record, so what led to a moment survives without anyone rebuilding it by hand.
A shell opened where a shell had never opened.
The agent on web-07 sees nginx spawn /bin/sh. It becomes one event, signed and timestamped on the host, naming the event that caused it. Tampering after this point is detectable, not arguable.
This web server has never spawned a shell in ninety days of baseline. Two events later the same process reaches for the billing database on a port it has never used. The chain is already in the record, so the finding is a sequence you can walk, not a score you have to accept.
The session is revoked and both hosts isolated four minutes after the first signal. Every world-changing action passed a single approval gate that can allow it, hold it for a person, or refuse it — and each decision is itself an event, so the question “who did this to my server” has one answer in one place.
What the analytics plane learned is compiled into a rule the agent enforces by itself. That return path is the reason this is one platform and not four that share a login.
One record. Four readers. No copies.
Pick a plane. The fields it reads stay lit; the rest dim. Nothing is re-parsed, re-normalised or re-indexed on the way — which is why two planes can never disagree about what happened.
Takes the record as written and keeps it that way: identity, time, origin, seal and the link to what caused it. Retention and proof of integrity live here, so every other plane can stop worrying about whether the data is intact.Reads what kind of act this was, who performed it and on what, then compares it against ninety days of that host behaving normally. The causal link is already in the record, so a finding arrives as a sequence rather than a score.Needs to know what to reach for and how far it got: the process, the host, the destination it tried, and how serious it is. Whatever it decides passes one approval gate and is written back as another event.Every event already carries the identity that acted and the machine that observed it, so standing can be judged at the moment of the act. Revoking a session is one decision, not a tour of six consoles hoping each honours it.
Read the plane →Four things that follow from the event floor, and only from it.
The same binary on the host does detection, application firewalling, identity enforcement and posture. One thing to install, one thing to upgrade, one place a decision is actually applied.
What the analytics plane learns is compiled into enforcement the agent carries out by itself. The second machine to try the same thing meets a rule, not a queue.
Containment, revocation and each approval decision are written into the same sealed stream as the activity that prompted them. The audit trail and the evidence are one record, not two systems to reconcile.
Each event is signed on the machine that produced it, classical and post-quantum together, before anything reads or routes it. Integrity is a property of the record rather than a promise about the pipeline.
All four are checkable inside a trial licence on your own hardware. None of them require you to take our word for it.
Eleven categories of tool, one event model.
These were separate products because they were built by separate companies, each with its own idea of what an event is. Categories only — we do not compare against named products.
Browse the capability catalogue →