The security decision layer for connected infrastructure.
XSecurity One brings security signals, evidence, graph context, detection, investigation and guarded response into one architecture.
Eight logical planes. One decision path.
Signals enter at the edge and leave as approved, signed, reversible actions — with evidence preserved at every plane in between.
Agents, sensors and collectors gather authorized telemetry from endpoints, workloads, network elements and telecom infrastructure.
CollectParsing, normalization and enrichment into one canonical event model with tenant, asset and identity resolution.
NormalizeBehavioral analytics, rules-as-code and scheduled detections evaluated against enriched events and baselines.
DetectAssets, identities, processes, domains, network elements, data and telecom context connected as one queryable graph.
CorrelatePlaybooks, approvals, blast-radius checks and guarded automation executing signed, scoped, reversible actions.
ActTenancy, policy, RBAC, quotas and release controls governing everything the platform is allowed to do.
GovernSOC console, investigation views, hunting, dashboards and APIs — the surfaces where humans meet the platform.
OperateAn append-only evidence layer preserving events, decisions, approvals and actions for investigation and regulators.
PreserveOne core. Nine responsibilities.
OneCore is the unified data, graph, policy, evidence and decision layer every module reads and writes. Nothing in XSecurity One keeps a private copy of the truth.
See how modules build on OneCoreHard isolation and per-tenant policy
Endpoints, workloads, network elements
Users, service accounts, privileges
Relationships across every domain
What may be detected, stored, done
Append-only, exportable, auditable
The unit of understanding & action
Approvals, execution, rollback
Connectors in, enforcement out
{
"event_id": "evt_9f42e1a8",
"tenant_id": "tn_xeonfiber", // hard isolation boundary
"timestamp": "2026-08-22T09:52:18.412Z",
"source": "onemesh.netflow",
"asset_ref": "ast_cpe_88h2", // resolved, not raw
"identity_ref": "idn_pseu_4471", // pseudonymous
"network": { "proto": "udp", "dst": "185.x.x.24:53" },
"process": null, // no agent on CPE
"evidence_ref": "evd_c2214", // append-only store
"correlation_id":"inc_0248" // one incident
}
Every signal speaks the same language.
An EDR process event, a NetFlow record and a RADIUS accounting packet all normalize into one schema — with tenant, asset, identity, evidence and correlation references resolved at ingestion.
That is what makes cross-domain correlation a query, not a data-science project.
See how risk can move.
Assets, identities, processes, domains, network paths, data stores and telecom elements — one graph your detections, investigations and blast-radius checks all query.
Automate response without automating regret.
Every action moves through the same guarded path — no shortcuts, including for the platform's own AI.
Security architecture that meets the environment where it runs.
India SaaS
Xonware-managed, India-hosted. Control plane, event store and evidence remain in-region.
Dedicated hosted
A single-tenant environment operated for you — your data, your update window, your DR plan.
Private cloud
Deploy into your own subscription with your identity provider and your encryption keys.
On-premises
Full on-premises for regulated, sovereign and critical-infrastructure environments.
Walk the architecture with the people who built it.
A working session on your estate, your telemetry sources and your constraints — not a slide deck.