Client-controlled runtime
The product retains its own local configuration, audit trail, licence state and operational workflow.
Where Trust Begins
Private access
Private access and ZTNA gateway for identity-aware, resource-scoped access without exposing the whole network. The product is positioned as a client-controlled security engine with professional deployment, audit and integration boundaries.

Core responsibility
identity-aware private routes, micro-access and gateway sessions
Roles: Super Admin, Access Admin, Gateway Operator, Security Admin, Auditor, Service Connector
Authentication: Local RBAC with MFA for users and admins; optional Eidon SSO; signed connector authentication.
Linked with: Optional Unified Cyber Security Command Center adapter, Eidon identity, Nomion licence, Topora resource map, Kleidion secrets, Tekmerion evidence, and Chronyx session timeline.
Boundary: Private access continues within local policy when Unified Cyber Security Command Center is offline; cached identity fallback depends on client policy.
Cybstyx model
The product should be strong alone first. Integration improves visibility and coordination, but it must not become an uncontrolled dependency.
The product retains its own local configuration, audit trail, licence state and operational workflow.
SecOwl can receive approved events and show posture or evidence if the client enables the adapter.
Products may connect to identity, evidence, licence, secrets or timeline services when policy allows.
Administrative changes, service events and proof exports should remain auditable.