Back to home
Platform

Architecture your security team can adopt with confidence.

SentriScope organizes each tenant workspace as a Cyber Risk Intelligence Platform: governed data ingestion, canonical normalization, intelligence correlation, investigation workflows, and decision governance, with strict tenant isolation, tamper-evident auditability, and analyst-led decisions. No autonomous remediation.

Tenant architecture

How capabilities relate inside your workspace

A stable conceptual model helps teams evaluate where ingestion, analysis, investigation, and decision support fit, and where human analysts remain accountable. These layers describe SentriScope at a public-safe level of abstraction. They are not deployment diagrams.

  1. 1 Governed data ingestion External security sources connect through governed connector sessions. Data arrives with operational state tracking and credential handling designed to avoid plaintext secret storage.
  2. 2 Canonical normalization Ingested data is normalized into shared entity concepts (assets, identities, vulnerabilities, exposures, controls, incidents, and threat intelligence) so analysts work across sources in one tenant-scoped model.
  3. 3 Intelligence correlation Threat intelligence enrichment, dashboard summaries, and correlation capabilities provide context for prioritization and investigation.
  4. 4 Investigation & analyst workspace Investigation workflows emphasize evidence and analyst-led analysis, including attack path analysis support. Conclusions require human validation.
  5. 5 Decision support & governance Deterministic risk prioritization, explainability, override governance, and tamper-evident audit logging support accountable decisions. AI assistance does not replace deterministic scoring.

Cross-cutting foundations (multi-tenant isolation, role-based access control, audit logging, and read-only AI assistance) apply across every layer.

Data operations

Governed ingestion into the canonical model

Connectors are not passive pipes. Every ingestion path is governed, tenant-scoped, auditable, and designed for safe synchronization.

Analyst foundations

Workspace services that support analysts and governance

Beyond ingestion and normalization, the tenant workspace provides structured investigation and institutional memory: analyst enablement without autonomous remediation.

Trust architecture

Built for isolation, accountability, and bounded AI

Enterprise adoption depends on verifiable architecture, not certification theater. These are the trust foundations SentriScope ships today.

Multi-tenant isolation

Tenant data is isolated by design. Shared or dedicated database modes to match your compliance needs.

Governance & RBAC

Role-based access with least privilege by default. Clear boundaries on who can view, change, and govern risk decisions inside your tenant.

Tamper-evident audit trails

Cryptographic hash-chained audit logging for sensitive actions. Every entry links to the previous, making tampering detectable.

Decision governance

Risk scoring overrides require explicit governance records with reason, approver, and expiry. All override decisions are appended to the tamper-evident audit chain.

Guardrailed, read-only AI

LLM assistance is schema-grounded, SQL-validated, and read-only when enabled: decision support only, with no autonomous remediation.

No autonomous remediation

The workspace supports analyst investigation and prioritization. It does not autonomously remediate findings or execute unsupervised changes.

Security & trust depth

Tenant foundations

Governance, data architecture, and operations

Additional foundations grouped by domain: the controls, data spine, and operational layer beneath product capabilities inside your tenant.

  • Governance and controls
    Feature flags & enterprise controls Per-tenant feature flags for CTI enrichment, LLM access, and advanced risk modules: enterprise-grade control scoped to your workspace.
    Decision governance Override governance with reason, approver, expiry, and full audit trail for risk scoring decisions.
    RBAC boundaries Role-based access with least-privilege defaults inside your tenant workspace.
  • Data architecture and canonical model
    Canonical normalization Assets, vulnerabilities, identities, and findings unified into one model with provenance and tenant scope.
    Connector governance Governed connector sessions with trust tiers, encrypted credential references, rate limits, and health monitoring.
  • Operations and observability
    Tamper-evident audit chain Hash-chained audit logging for compliance readiness and independent chain integrity verification.
    Connector health monitoring Operational state tracking and health visibility for governed ingestion sessions.
  • Analyst enablement
    Investigation workspace Structured investigation sessions and scenario workbench for security analysts.
    Organizational knowledge Playbooks, evidence libraries, and operational intelligence for repeatable analyst decisions.
Explore further

Related areas

Security

Isolation depth, audit chain, RBAC, and LLM guardrail specifications.

Integrations

Live connector catalog: ingestion sources and CTI enrichment providers.

Product

Capability catalog: exposure, prioritization, and investigation modules.

Contact

Architecture questions, deployment models, and enterprise evaluation.

Evaluate the tenant architecture

Review security and trust depth, browse the connector catalog, or talk to our team about multi-tenant deployment and governance requirements.