SOC
Where every Core module lands
- Live, partial, and roadmap labeled honestly on the platform page.
- Detection, risk, compliance, and identity share the same incident.
- Click a module, then come back to the operator board.

Every CyberDragon session JWT is hybrid-signed with ML-DSA-65 + Ed25519. MFA, API keys, and Vault-backed material keep sovereign control without a third-party IdP dependency for core sessions.
ML-DSA-65 (NIST FIPS 204) + Ed25519 hybrid JWTs
TOTP MFA for privileged roles
cdag_* API keys with instant revocation
HashiCorp Vault custody for signing keys
SOC

ML-DSA-65 (NIST FIPS 204) + Ed25519 hybrid JWTs
TOTP MFA for privileged roles
cdag_* API keys with instant revocation
HashiCorp Vault custody for signing keys
Playbooks

ML-DSA-65 + Ed25519 hybrid JWTs; MFA; API keys; Vault-backed signing keys.
Ingest, normalize, enrich, detect, and respond on shared topics.
Passive OT capture plus syslog, HEC, and cloud telemetry.
Detections and decisions hash-chained for auditors.
UEBA

One platform, two planes — Core control plane and Edge collector for converged IT/OT.
Kafka-backed indigenous SIEM/SOAR — ingest, detection, risk, compliance, and response.
Passive SPAN capture at the industrial DMZ — telemetry up only, no PLC agents.
Modbus, DNP3, OPC-UA, and MQTT parsed natively at Purdue L3.
Indigenous global SIEM and Temporal-orchestrated SOAR with human approval gates.
W15 / W60 / W24 cascading windows across MITRE ATT&CK and ICS tactics.
A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.