Product mesh

SecOwl commands. Phylaxis engines operate.

The Cybstyx ecosystem is built as a security mesh: standalone applications protect, detect, map, connect, prove, respond and govern. SecOwl provides command-center visibility and governed action only through approved adapters.

SecOwl — Unified Cyber Security Command Center
Ecosystem architecture

SecOwl — Unified Cyber Security Command Center

Central command visibility for approved telemetry, risk posture, evidence status, adapter health and governed action across enabled Cybstyx products.

  • Role: Command center
  • Sends approved telemetry and evidence only when enabled
  • Receives governed commands through signed adapter
  • Keeps local operation available if command layer is offline
Runs standaloneSigned adapter onlyNo hard dependency
Open details

Cybstyx model

The golden architecture rule

No product should hard-fail because another product or command center is offline unless that exact workflow explicitly depends on it.

Command layer

SecOwl

Central posture, evidence, reports, adapter health and approved commands.

Backbone services

Identity, licence, secrets, evidence

Eidon, Nomion, Kleidion and Tekmerion support workflows that explicitly need them.

Protection engines

Operational security products

Endpoint, access, data, web, deception, response, AI, integrity and exposure engines operate locally.

Adapter standard

Signed and audited

Adapters share only approved scopes and must be disabled by default.

Interactive mesh

Every product has a place.

Command center

SecOwl

The central command layer for approved telemetry, risk posture, evidence visibility, adapter health and governed action across the Cybstyx ecosystem.

Endpoint security

Phylax Endpoint Guard

Endpoint protection, posture, device trust, and quarantine workflow for laptops, servers, and endpoint agents.

Private access

Pteron Private Access

Private access and ZTNA gateway for identity-aware, resource-scoped access without exposing the whole network.

Secrets governance

Kleidion Vault

Secrets, keys, certificates, OTP seeds, adapter secrets, and approval-bound vault operations.

Evidence governance

Tekmerion Evidence Vault

Evidence governance, chain-of-custody, legal hold, compliance packs, and audit-proof exports.

Threat investigation

Chronyx Threat Timeline

Event lake, threat timeline, correlation, case workflow, and investigation console.

Response orchestration

Keraunix Response Grid

SOAR-like response grid for playbooks, approvals, containment, action tracking, and response evidence.

Data protection

Phragma Data Guard

DLP, sensitive data classification, export approval, and data movement guardrails.

Deception security

Dolion Decoy Grid

Deception and honeypot grid with decoy assets, honeytokens, trap events, and attacker storyline evidence.

Integrity operations

Sideron Integrity Guard

Patch integrity, endpoint fleet update verification, rollback, compliance, and maintenance evidence.

AI governance

Noetron AI Guard

AI governance, prompt and policy guardrails, human approval, knowledge snapshot, and AI audit evidence.

Web and DNS security

Orama Web Shield

Web and DNS security filtering, policy enforcement, URL reputation, internet control, and web evidence.

Identity security

Eidon Identity Mesh

Identity mesh, local IAM, SSO-ready federation, SCIM/LDAP/OIDC/SAML connector governance, and role claims.

Resource mapping

Topora Resource Mapper

Resource discovery, topology mapping, asset relationships, sensitivity classification, and connector planning.

Licence authority

Nomion Licence Authority

Licence generation, entitlement, activation, offline import/export, renewal, and vendor-client licence governance.

Exposure intelligence

Nyxara DarkWatch

Dark web, brand, leak, and exposure monitoring with external intelligence watch and controlled internet features.