Skip to content
● Enterprise operating model · dedicated deployment, customer-cloud and private-network optionsOpen Trust Center
Enterprise architecture & operations

Control the platform. Control the boundary.

Choose the tenant, network, region, keys, model-processing path and operator-access policy that match your risk model—without losing one normalized view across a global estate.

Identity-nativeOIDC SSO (SAML on roadmap), SCIM 2.0, MFA, role mapping, JIT and break-glass governance.
Isolated by designShared SaaS, dedicated managed tenant or customer-cloud deployment.
Response is separateDiscovery remains observation-focused; actions use an approved control path.
Procurement-readyArchitecture, DPA, data map, SBOM, pentest evidence and operational policies.
Deployment tiers

One product, three isolation models.

Every deployment uses tenant-scoped identity, encryption and audit controls. Regulated environments can increase infrastructure, network and key isolation without changing the operating workflow.

ControlEnterprise SaaSDedicated managed tenantCustomer cloud / air-gapped
ComputeRegional, horizontally isolated service with tenant-scoped workloadsDedicated application and ingestion resourcesRuns in the customer-controlled account/VPC or approved offline environment
DatabaseLogical tenant isolation enforced in application and row-level policyDedicated database and backup boundaryCustomer-owned database and storage boundary
Encryption keysService-managed keys with scheduled rotationDedicated tenant key; customer-managed key optionCustomer KMS/HSM and key policy
NetworkAuthenticated TLS over approved FQDNsPrivate ingress and egress controls availablePrivateLink/private endpoints, proxy-only or no-internet operation
Reasoning modelManaged regional model or deterministic-onlyDedicated approved model pathCustomer Bedrock, Azure OpenAI, Vertex or local inference
OperationsAraghatta operated under audited access policyNamed change windows and customer-approved support accessCustomer-operated or jointly managed under documented runbook
Data residencySelected supported service regionContracted tenant region and backup regionCustomer chooses region, sovereign boundary and replication policy
Control-plane design

Regional data, global governance.

The management plane coordinates tenant policy and configuration. Regional data planes ingest and store telemetry inside the selected boundary. Export and response paths are explicit and independently controlled.

ESTATEEndpoints, servers & cloudSigned sensors, workload collectors and read-only cloud connectors produce normalized, redacted evidence.
INGESTRegional data planeAuthenticated ingestion, schema validation, deduplication, bounded queues and encrypted durable storage.
INTELLIGENCERisk & threat engineDeterministic policy, CVE/threat correlation and optional tenant-approved reasoning.
GOVERNTenant control planeInventory, policy, evidence, approvals, exceptions, RBAC and immutable administrative audit.
OPERATESOC & responseSIEM, SOAR, ITSM, API and a separately authorised response channel with rollback.
Availability

Failure-domain isolation

Multi-zone services, durable queues, health-based failover and independently recoverable tenant storage reduce the blast radius of component failure.

Continuity

Backups that are restored, not assumed

Encrypted backups, documented RTO/RPO by deployment tier, scheduled restore exercises and customer-visible recovery evidence.

Degraded mode

Endpoints keep working safely

Bounded local spooling, exponential backoff, deduplication and reconciliation prevent a temporary control-plane issue becoming silent data loss.

Identity & privileged access

Enterprise access from first login to offboarding.

Customer identity remains authoritative. Human and non-human access is least-privilege, time-bound where required and represented in the same immutable audit trail.

OIDC GA

OIDC single sign-on

Okta, Entra ID, Google Workspace, Auth0 and standards-compatible OIDC providers with domain enforcement. SAML is on the roadmap.

GA

SCIM lifecycle

Provision, update, group-map and deactivate users automatically. Offboarding can trigger AI-access review and revocation workflows.

Authorization

RBAC and custom roles

Viewer, Analyst, Admin, Owner and scoped custom roles with separation of duties for policy, evidence and response.

Vendor access

Customer-approved support

Disabled by default, reason-bound, time-limited, least-privilege and recorded. Emergency access is separately governed and reviewed.

Safe response design

Observation and action are separate trust paths.

The discovery sensor cannot execute arbitrary commands. Response uses a narrow, authenticated policy channel with explicit target, action, approval, expiry and rollback semantics.

StageRequired controlEvidenceFailure behavior
DetectRead-only or metadata-focused collection under tenant policyAsset, signal, identity, source and timestampSpool locally and retry without weakening device security
SimulateDry-run evaluates policy against affected assets before activationProjected actions, exceptions and blast-radius summaryNo endpoint action
ApproveRole, ticket/reason, target scope, duration and separation-of-duties ruleApprover, change reference and before-stateExpired or incomplete approvals fail closed
ActPause or server-side revoke today; warn, redact, block and quarantine via the customer-authorised policy path (roadmap)Target acknowledgement, result and after-stateBounded retry; no arbitrary shell or remote desktop channel
RollbackVersioned policy and emergency disable at tenant and fleet levelRollback actor, reason, affected assets and completion stateRevert to the last known approved policy
Production operations

Predictable change, support and evidence.

Exact contractual objectives are stated in the enterprise order form and architecture pack, including regional availability, recovery, retention and support commitments.

Release engineering

Attested, staged and reversible

  • Reproducible builds with SHA-256 checksums and an SBOM per release
  • Collector attests every sensor against the published release; Authenticode / Apple Developer-ID signing on certificate procurement
  • Canary, pilot and broad deployment rings
  • Version pinning, rollback and compatibility window
Support

Global enterprise response

  • 24×7 handling for Severity 1 incidents
  • Named escalation and technical account ownership
  • Severity, response and restoration commitments
  • Customer status communications and post-incident review
Assurance

Evidence your reviewers can verify

  • Secure SDLC, threat model and architecture
  • Penetration-test summary and remediation evidence
  • Backup/restore, incident response and BCP/DR tests
  • Access reviews, vulnerability SLAs and dependency inventory
Procurement package

Shorten security and legal review.

Enterprise evaluations receive a controlled package aligned to the selected deployment model and data boundary.

Security

Architecture pack

Threat model, data flow, network paths, IAM, encryption, key lifecycle, support access and response design.

Privacy

Data and legal pack

DPA, SCCs, subprocessors, field dictionary, retention/deletion policy, DPIA and works-council support.

Operations

Service pack

SLA, support policy, BCP/DR, RTO/RPO, maintenance, lifecycle, deprecation and incident communications.

Product

Technical evaluation pack

Deployment guides, exact permissions, API/event schemas, test plan, rollback plan, SBOM and sample evidence.

Review the architecture before the pilot.

We will map your identity, MDM/UEM, SIEM, cloud hierarchy, network boundary, data residency and change-control requirements into one evaluation plan.

Request architecture review