Now in public beta v0.1 ships Core API scaffold. Read the changelog
Governed Security Services Platform

An army of effective tools.
One auditable operating system.

Orcas unifies AppSec triage, cloud posture review, threat intelligence, incident timelines, and compliance evidence onto a shared engine with confidence-scored AI and expert oversight gates. Deploy in our cloud or self-host in your VPC so your entire security organization operates with complete provenance, auditability, and zero vendor lock-in.

AppSec, cloud, threat intel, IR, detection, and compliance — one governed platform.

One platform
  • Application security
  • Cloud & DevSecOps
  • Threat intelligence
  • Incident response
  • Detection engineering
  • Compliance & GRC
  • Attack paths
Faster triage & response

Real-time IOC enrichment, automated email dissection, and instant log normalization mean security alerts move from detection to containment in minutes without tab-switching.

Deep attack-path visibility

Map how attackers move from external edge assets to your crown jewels with validated threat links, replacing theoretical vulnerability counts with proof of reachability.

Auditor-ready provenance

Every finding, execution log, and AI decision is recorded with complete provenance, giving CISOs and auditors continuous evidence instead of manual screenshotting.

03 The platform

Six domains. One security platform.

Most security teams stitch together half a dozen scanners and a pile of ad-hoc scripts that never talk to each other. Orcas is built the other way around: security services on one engine, one workflow layer, and one presentation layer.

Every finding, IOC, timeline, and evidence artifact lives in the same system, so context follows the asset instead of getting trapped in a tab.

  1. M1

    Application security

    SAST/DAST triage, secure code review, and web vulnerability validation that cuts scanner noise to true positives.

    Live
  2. M2

    Cloud & DevSecOps

    Cloud posture review, CI/CD security gates, and supply chain risk across AWS, Azure, and GCP.

    Live
  3. M3

    SOC & incident response

    Alert enrichment, incident timeline reconstruction, and phishing analysis that shrink meantime-to-remediate.

    Live
  4. M4

    Threat intelligence & OSINT

    One-shot IOC enrichment and verdict scoring that plugs into every other service on the platform.

    Live
  5. M5

    GRC & compliance

    Continuous, auditor-ready evidence for SOC 2, ISO 27001, and CIS — assembled, not screenshotted.

    Live
  6. M6

    Offensive & red team

    Attack-path mapping, attack-surface monitoring, and breach simulation — offense-informed defense.

    Live
04 Web vulnerability triage

Scanner output in.
Validated findings out.

TriageLens ingests output from the tools you already run — Burp, Nuclei, Semgrep, CodeQL — deduplicates across them, and AI-scores each finding for real exploitability. What reaches your queue is a short, prioritized list with severity rationale and a fix hint attached.

  • Cross-tool deduplication. One finding instead of five copies across scanners, normalized to a common schema.
  • Exploitability scoring, not just severity. Each finding is scored on whether it is actually reachable and exploitable, so true positives surface first.
  • Fix suggestions attached. Every validated finding ships with a remediation hint, ready to hand to engineering.
  • Tool-agnostic ingest. Bring SARIF, Nuclei JSON, or Burp exports. No rip-and-replace of your current stack.
Findings queue After triage
SI
SQL Injection — /api/orders User input concatenated into query; auth bypass confirmed.
Critical
XS
Stored XSS — profile bio Payload executes in admin view; reachability confirmed.
High
ID
IDOR — invoice lookup Object reference not scoped to session user.
Medium
400 scanner findings triaged to 3 validated, prioritized results.
05 Incident response timelines

Reconstruct the incident
from the logs.

Upload logs and alerts from any source — EVTX, syslog, cloud trails — and TimeLoom normalizes, correlates, and assembles a sourced incident timeline with the gaps made explicit. An AI narrative ties it together with MITRE tagging, so the story writes itself.

Multi-source parsing

EVTX, JSON, syslog, and cloud audit trails normalized to one event schema.

Entity correlation

Pivot across users, hosts, and IPs to reconstruct who did what, when.

Gap detection

Missing or clock-skewed evidence is rendered as a gap, never hallucinated.

MITRE-tagged narrative

An AI-generated summary maps the incident to tactics and techniques.

IP
203.0.113.42 Enriched indicator
Verdict
Malicious · 94% confidence
Reputation
Listed on 5 feeds
First seen
2026-07-14 03:11 UTC
Related malware
Cobalt Strike beacon
Sources
VirusTotal — 12/90 detections
AbuseIPDB — 1,204 reports
URLScan — phishing kit match
06 Threat intelligence enrichment

Any IOC in.
Full context out.

Drop in an IP, domain, hash, or URL and ContextIQ fans out across VirusTotal, AbuseIPDB, passive DNS, WHOIS, and URLScan in parallel, then synthesizes a verdict with a confidence score. It is the enrichment step every other service reuses — and it is free to start.

  • Parallel multi-source enrichment. Half a dozen reputation feeds queried at once, not one tab at a time.
  • Verdict with confidence. An LLM synthesis returns a clean verdict — malicious, suspicious, or benign — scored and sourced.
  • Embedded everywhere. The same engine feeds phishing analysis, incident timelines, and file triage.
  • Free tier to start. Rate-limited enrichment that is cheap to serve and easy to adopt.
07 Phishing email analysis

Forward the email.
Get the verdict.

HookCheck takes a suspicious email and dissects the whole thing — SPF/DKIM/DMARC authentication, hop anomalies, URLs, and attachments — then layers in a social-engineering read. SOC analysts forward from the mailbox; practitioners get a full-stack verdict without standing up a pipeline.

  • Header and auth analysis. Spoofing and forwarding anomalies flagged against SPF, DKIM, and DMARC.
  • URL and attachment triage. Links enriched against threat intel; attachments run static malware triage.
  • Social-engineering read. An LLM assesses the lure itself — urgency, impersonation, and pretext.
  • Forward-and-analyze. Mailbox integration means analysts triage at inbox speed.
F Inbox → HookCheck
Analyzed
"Urgent: your Microsoft 365 password expires today. Verify now to avoid lockout."
Verdict: Phishing · 96% confidence. DMARC fail, sender domain lookalike, credential-harvest link.
Attachment on this one too — is it safe?
Attachment triaged: macro-enabled doc, matches known loader family. Recommend block + reset.
Forward a suspicious email to analyze
08 The service catalog

Fifteen services.
One platform.

Every Orcas service is a packaged workflow built on the same engine — scanner wrappers, AI triage, enrichment, and report templates composed end to end. Start with one; chain them as you grow. This is the full catalog.

Application security

TriageLens — Web vulnerability triage

Scanner output in, validated and prioritized findings out.

Cloud security

CloudVerdict — Cloud posture review

The cloud misconfigs that actually matter, with fix diffs.

Threat intelligence

ContextIQ — IOC enrichment

Any IOC in, fully enriched and verdict-scored in seconds.

Application security

Secure Code Review Assistant

PR-level security review with exploitability ranking and patches.

Incident response

TimeLoom — IR timeline generator

Logs in, a reconstructed, sourced incident timeline out.

Malware analysis

VerdictDrop — Malicious file detector

Drop a file, get a static triage verdict with explained indicators.

DevSecOps

Gatekeeper AI — CI/CD security gate

A pipeline gate that blocks on real risk, not scanner noise.

Compliance & GRC

AuditLoom — Compliance evidence

Continuous, auditor-ready evidence for SOC 2, ISO 27001, and CIS.

Offensive & red team

Pathfinder — Attack path mapping

From external surface to crown jewels: mapped, validated attack paths.

IR & detection

HookCheck — Phishing analyzer

Forward a suspicious email — full header, URL, and attachment verdict.

Offensive & red team

Attack Surface Monitor

Continuous discovery of exposed assets and what changed this week.

Supply chain

Container & Supply Chain Review

Image and SBOM risk, prioritized by reachability and exploitability.

AI security

PromptSiege — LLM app assessment

Probe your LLM app for injection, leakage, and guardrail bypass.

Application & cloud

Secrets Exposure Sweep

One sweep for leaked credentials across repos, buckets, and logs.

Detection engineering

Blindspot — Detection coverage

Map detections against MITRE and find the blind spots.

Attack path External surface → Crown jewels
Recon Exposed assets and leaked secrets discovered
Initial access Phishing or vulnerable service reached
Privilege escalation Over-permissive IAM and lateral paths
Crown jewels Sensitive data store reachable
Unvalidated edges shown distinctly from confirmed ones. Map your paths
09 Attack path mapping

From the edge
to the crown jewels.

Pathfinder maps the routes an attacker would actually take — from exposed assets through lateral movement to your crown jewels — and validates the weak links along the way. It is the offense-informed input that makes every defensive decision sharper, from detection coverage to remediation priority.

  • External surface to crown jewels. Hypothesized attack paths with each edge labeled validated or unvalidated.
  • Validation, not just theory. Safe probes confirm the weak links so remediation targets real exposure.
  • Feeds detection coverage. Paths become the test cases for the question every SOC asks: would we catch this?
Explore Pathfinder
10 CI/CD security gate

Block on real risk.
Not on scanner noise.

Gatekeeper AI sits in your pipeline and enforces policy on what actually matters — severity weighted by exploitability and reachability — so builds pass when they are safe and fail when they are not. Sane defaults out of the box; tune the thresholds as you mature.

Exploitability-weighted policy

Severity × exploitability × reachability, not raw finding counts.

Simulation mode

Run the gate in observe-only mode before enforcing, so devs are not surprised.

PR annotations

Findings land as reviewable comments with fix suggestions, never auto-committed.

Tunable thresholds

CIS-aligned defaults you can tighten or relax per repo and per environment.

Pipeline gate — PR #4821
Result: BLOCK · 1 critical finding above threshold (SQL Injection, reachable).
Gate blocked — fix required
11 Reporting & analytics

See how your security
program performs.

Orcas reports on the data its own services generate — findings by severity, triage precision, meantime-to-remediate, and posture coverage — so leaders read security performance from the same system that runs the work.

Findings by severity

Critical, high, medium, and low, after triage.

Triage precision

AI verdicts confirmed by expert review, over time.

Remediation status

Open In review Remediated

Where validated findings sit in the fix lifecycle.

Posture coverage

Share of the estate under active findings review.

Charts shown are schematic. Orcas reports on your own live data; no sample figures and no vanity metrics.
12 Platform & architecture

A real platform,
not a toolbox.

Under every service is the same four-layer architecture — foundation utilities, the engine of scripts, a workflow orchestration layer, and presentation. That is what turns a pile of scripts into governed, composable, auditable security services.

FOUNDATION

Foundation layer

Shared utilities — LLM gateway, HTTP/retry clients, parsers, sandboxing — so logic is never duplicated.

ENGINE

Engine

The scanners, analyzers, enrichers, and AI triage themselves, each behind a standard runner interface.

WORKFLOW

Workflow layer

DAG orchestration that chains scripts into services, with retries, schema validation, and metering.

PRESENTATION

Presentation layer

Report templates, SARIF/STIX emitters, and dashboard payloads — rebrand without touching engine code.

COMPOSE

Custom workflows

Compose your own services from the script registry — the app store of security scripts.

DEPLOY

Self-host or cloud

Run in our cloud, or deploy in your VPC with containers and Helm.

13 Trust & governance

Built to be trusted
with your security.

Security services sit on top of sensitive data and live systems, so governance is part of the operating model, not an afterthought. Every AI decision is logged, confidence-scored, and overridable by your experts.

Deploy in our cloud or yours, behind SSO and RBAC, with full audit trails and artifact retention you control.

Confidence-scored AI

Every AI verdict carries a confidence flag; low-confidence routes to expert review.

Expert gates

Critical claims and generated detection rules pass a human gate before they ship.

Tiered sandboxing

Execution isolation scales with risk — in-process, container, or isolated VM.

Full audit trails

Every execution is logged with inputs, outputs, and provenance.

SSO, RBAC & self-host

SAML SSO, role-based access, and VPC deployment for regulated environments.

14 The roadmap

Live today. Sharper
from here.

The foundation services are in production now. This is how the platform expands — honestly framed as foundation, workflow packaging, and platform phases rather than finished proof.

Expanding

More workflow services

Chaining recon → attack paths → validation → detection checks into one-click services.

Expanding

Detection rule drafts

Generated Sigma-first rules from coverage gaps, ready for engineer review.

Expanding

EPSS scoring

Exploit-likelihood feeds wired into triage across services.

Coming soon

Detonation sandbox

Dynamic analysis for packed samples and email attachments.

Coming soon

More SIEM importers

KQL and SPL alongside Sigma for detection coverage.

Coming soon

Enterprise hardening

SOC 2 Type II, deeper RBAC, and artifact retention controls.

15 Final call to action

Run security on
one orchestrated platform.

Start with the services live in production today — AI vulnerability triage, threat intel enrichment, incident response timelines, phishing dissection, and attack path mapping. Bring your own targets and keep your workflow on a single governed source of truth.

Security services platform for practitioners and engineering teams. Self-host ready.