CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Pillar 03 · Evidence-Grade

Evidence an auditor can verify, not a screenshot you exported.

Detections, response actions, approvals, and policy denials are hash-chained and Ed25519-signed. Distinct evidence theme — not the same layout as Core or Edge.

Chain of custody

Capture → hash → sign → verify → export.

01

Capture

Detection, response action, and approval decisions are written as immutable records.

02

Hash

Each record is hashed and chained to its predecessor — any edit breaks the chain.

03

Sign

Ed25519 signatures seal the chain using Vault-backed key material.

04

Verify

Chain verification runs on demand; lab run verified 66 entries OK.

05

Export

Auditor-ready ZIP packets with policy reason codes, including OT denials.

Vault

Hash-chained Evidence Vault

  • Verify chain. Export an auditor packet.
  • Ed25519-signed, tamper-evident.
  • Tenant-admin and auditors get export; operators do not mix client evidence.
CyberDragon Evidence Vault
OT denials are evidence too

Policy reason codes are sealed with the incident.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now

Frameworks

Compliance and audit

  • IEC 62443-3-3, NERC CIP, NIST CSF 2.0, ISO 27001:2022.
  • Controls mapped from live events — not a spreadsheet after the fact.
  • Same vault the PoV evidence export uses.
Compliance dashboard
Record anatomy

What lives inside a single vault entry.

FieldWhy it is there
Sequence and previous hashPosition in the chain. Any reordering or deletion breaks verification.
Tenant and actorWhich tenant, which analyst or service identity, under which RBAC tier.
Event referencesThe correlated detections and raw event IDs that justified the decision.
Policy decisionThe OPA verdict with reason code — including denials issued after human approval.
TimestampsDetection, approval, and execution times, so dwell and response are reconstructable.
Ed25519 signatureSeals the record using Vault-backed key material that application code never handles.

Access

IAM that owns who can export

  • Role-gated: auditors view, operators change, admins own users.
  • MFA enrollment is first-class.
  • Sovereign AuthZ — no third-party IdP required for core sessions.
CyberDragon Access Control and IAM dashboard
Verified in the lab

Chain integrity is measured, not asserted.

22.4h
Baseline duration
41,959
Baseline events processed
15,093
Live IOCs in corpus
0
False incidents (baseline)
6/6
Attack detection rate
8.0–20.5s
MTTD range
66
Evidence vault entries (chain OK)
1
OT guardrail post-approval denial
Lab-validated metrics reflect controlled test environments. Proof of Value results vary by site.
FAQ

Frequently asked questions.

What exactly is signed?
Each vault entry is hashed, chained to the previous entry, and signed with Ed25519 using Vault-backed key material.
What does an auditor receive?
A ZIP evidence packet with the chained records, signatures, control mappings, and reason codes — including actions that OPA denied after human approval.
Has verification been tested?
Yes. The lab run produced 66 vault entries with chain verification OK. Lab-validated metrics reflect controlled test environments.

Export a signed evidence packet from your trial tenant.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.