Markets · Critical Infrastructure
Detect intent before it reaches the perimeter.
A unified risk picture, traveler safety, and threat intelligence for operators of essential services — without standing up a 24/7 watch floor. Physical, cyber, and human threats are converging on the same critical infrastructure sites. The security stack is not.
For CISOs & CSOs · security operations · critical infrastructure protection & compliance leads · field operations & travel risk managers
The threat crosses domains. The tools do not.
Operators of essential services defend dispersed assets no one can staff around the clock — substations, pump stations, compressor stations, terminals, corridors.
The people who threaten them cross organizational lines. A copper thief, an ideologically motivated attacker, a hobby drone over a switchyard, a state reconnaissance operation, and a targeted employee each register as a different alarm in a different tool, watched by a different team. Each of those tools is built to watch one domain; connecting an adversary's intent to the operator's sites, crews, and people is left to people to do by hand.
The stack a program assembles today — an alert feed, a notification tool, a travel tracker, a case tool, a threat-intelligence subscription — carries separate contracts and separate data models, and none of them is built to hold the shared picture of the facility they all describe. Real-time alert feeds are built to report the world, not to resolve it to a specific substation. Mass-notification and critical-event tools are built to own the response, not to connect intent to a site.
And every regulator asks the same questions: what is the threat, what is the vulnerability, what did you do, and can you show the record. Answering by hand, from separate systems, at review time, is where programs lose ground.
For utility CSOs · CIP senior managers · security intelligence leads · field operations
Three domains, one facility
Facility · regional operations
- STRATUM — Cyber Threat
Cyber reconnaissance against exposed assets
Adversary reconnaissance against the site's remote-access footprint, mapped and prioritized by what the exposure means for the mission — not by CVE count.
- LUCID — OSINT Awareness
Civil unrest reported 40 km from the site
An open-source alert, relevance-scored and correlated to the facility and the crews assigned to it — not a feed item somebody has to notice.
- PATHWAY — Travel Security
Crew rotation in transit
A field crew moving toward the site, with a risk score that already reflects what the other two domains know.
Risk rescored · site + crews + exposure
Case opened at threshold · analyst notified
APEX — Platform Foundation rescores the facility as one entity — site, crews, and exposure together — and FORGE — Investigations opens a case at threshold with an analyst notified. People decide what happens next.
One picture for operations.
Where the platform sits
Not a SIEM. Not OT monitoring.
EternaEdge is not an operational technology (OT) security platform, and STRATUM — Cyber Threat is not a security information and event management (SIEM) replacement. The platform is designed to sit above the OT platform, the SIEM, access-control, video, mass-notification, and critical-event tools you already run.
What it adds is counterintelligence context. APEX — Platform Foundation correlates what those tools detect with adversary intent from open sources, insider indicators, cyber threat context, and field-crew movements — so the operator sees one risk picture across sites and people, with the record of what was done about it. The OT team keeps its tools and its authority.
Built for the critical infrastructure sectors where physical and cyber risk converge.
The platform is designed for operators across the critical infrastructure sectors the Cybersecurity and Infrastructure Security Agency (CISA) designates. We start where dispersed sites, field crews, and external reconnaissance meet.
Where we start
- Energy
- Water and wastewater systems
- Transportation systems
- Communications
- Chemical
- Critical manufacturing
- Defense industrial base
Also designated
- Commercial facilities
- Dams
- Emergency services
- Financial services
- Food and agriculture
- Government services and facilities
- Healthcare and public health
- Information technology
- Nuclear reactors, materials, and waste
Seven sectors lead · the platform is designed for operators across all sixteen
Insider risk at the operator.
An insider threat mitigation program is a human-led discipline: it identifies anomalous behavior and responds in a way that preserves trust.
Adversaries collect workforce data to find the person with the badge, the credential, or the route into the plant. At an operator, access is physical as much as digital: a contractor's after-hours entry to a substation, a crew member's unexplained travel, a login from a location the roster does not support. Each looks ordinary in the one system that saw it.
OBSIDIAN— Counterintelligence watches for the pattern across every signal the platform holds. It is designed to support the program elements described in CISA's Insider Threat Mitigation Guide and in the National Counterintelligence and Security Center's (NCSC) guidance for critical infrastructure entities — and to reduce indiscriminate monitoring, not add to it, by correlating signals the organization already governs and elevating only what is risk-prioritized.
Guard surfaces and organizes. Security, HR, legal, and privacy officers make every determination. Endpoint tools are built to detect, not to run the program those functions share.
Identify
Guard builds behavioral baselines for the workforce and correlates anomalies across access, travel, cyber, and open-source signals — an after-hours badge at a substation weighs differently for a contractor with switching authority.
Correlate
The APEX risk engine scores each pattern against role sensitivity, asset criticality, and signal diversity, so a minor-looking signal escalates only when it completes a pattern — not because it tripped a rule.
Respond
At threshold a FORGE case opens with the entity timeline already assembled. Security, HR, legal, and privacy officers decide what happens next — in a way that preserves trust.
Physical threat intelligence for the sites you cannot staff.
Physical threat intelligence is early warning about the people and groups who intend harm to specific sites — drawn from publicly available information and correlated to the assets they threaten.
LUCID— OSINT Awareness is the platform's always-on open-source sensing layer. Grid collects continuously across 150+ agents and 50+ languages. Horizon scores country and regional risk for every region where the operator holds assets. Pulse delivers critical alerts in under 30 seconds, relevance-scored and correlated to your facilities, crews, and travel. Analysts read summaries, never feed dumps, and confirm relevance before anything escalates.
Asset-anchored, not a firehose. A published threat against a class of facility, an ideologically motivated call to action, a pattern of reconnaissance sightings, chatter about a drone flight over a switchyard — LUCID is designed to surface these as open-source indicators tied to the site they concern. It reads what is published; it does not detect aircraft. Detection hardware, response, and any flight-restriction request remain with the operator and the relevant agencies.
Analysts steer collection priorities and confirm relevance. Security operations acts on what is confirmed.
Status quo
With LUCID
Status quo
Real-time alert feeds are built to report the world, not to resolve it to a specific substation.
With LUCID
Pulse alerts are relevance-scored and correlated to your facilities, crews, and travel — the alert arrives already attached to the site it concerns.
Status quo
Regional watch desks staffed in shifts, with nights and weekends as the gap.
With LUCID
Grid is designed to collect continuously — without shift gaps or analyst tasking — and to deliver summaries, never feed dumps.
Status quo
Keyword alerts: high noise, no synthesis, and the one signal that matters buried.
With LUCID
Relevance scoring designed to reduce alert fatigue; analysts confirm relevance before anything escalates.
Status quo
Leadership briefed on a region only when an analyst has the hours.
With LUCID
Horizon scores country and regional risk continuously and generates executive briefings on demand.
Investigations and records regulators can follow.
Every review comes down to the record: what was the threat, what was the vulnerability, what did you do, and can you show it.
FORGE— Investigations is where the platform's findings become documented, auditable action. Cases open automatically when the APEX risk engine crosses threshold, from a report submitted through Intake, or by hand. Every case is organized around the entities it concerns — the site, the crew, the contractor, the adversary — with the full intelligence picture attached.
Chain provides complete auditability: SHA-256 hashing and tamper detection on every evidence item, a full audit trail of every access and transfer, multi-level access controls inside the case system, and authenticated export for counsel, oversight, and regulators.
That record is designed to support the documentation programs already keep: the threat and vulnerability evaluation and physical security plan a transmission owner documents under North American Electric Reliability Corporation (NERC) CIP-014, the incident timelines a pipeline program aligned to Transportation Security Administration (TSA) security directives maintains, and the malevolent-act inputs an America's Water Infrastructure Act (AWIA) risk and resilience assessment draws on. Compliance is the operator's determination. FORGE holds the evidence.
Investigators run the investigation. Counsel draws on the Chain audit trail behind every item. Evidence-integrity checks are designed to run automatically rather than by procedure.
- What was detected
- The signals, from every domain, resolved to the site, crew, or person they concern.
- What automation did
- Every threshold crossed, case opened, alert routed, and re-briefing triggered — logged as it happened.
- Who approved it
- The human decision at each consequential step, with the record of who made it and when.
- Evidence integrity
- SHA-256 hashing and tamper detection on every item, a full audit trail of every access and transfer, and authenticated export.
Above OT security. Not instead of it.
Not a SIEM replacement. Not a vulnerability scanner. Not an OT or industrial control system (ICS) security tool. Cyber threat intelligence with counterintelligence context, above the stack the operator already runs.
STRATUM — Cyber Threat is not a SIEM replacement or a vulnerability scanner. It adds counterintelligence context above the security operations center (SOC) and the OT stack: which actors matter to this operator, which exposures matter to this mission, and whether cyber activity aligns with human-behavioral risk.
This is what converged security means in practice — cyber-physical context, not OT monitoring. When reconnaissance against an exposed asset coincides with unrest near the site and a crew in transit, the risk engine sees one facility, not three alerts. The SIEM stays the system of record for logs and detections. The OT platform stays in charge of the process. STRATUMtells both what the activity means for the operator's sites, crews, and mission.
Cyber analysts tune priorities and decide response postures. STRATUM is designed to elevate only what is risk-prioritized.
STRATUM Watch
Outward
Looks out at the adversary: threat-actor profiling with attribution confidence, campaign correlation, dark-web and adversary-forum monitoring, and early warning of reconnaissance against the operator.
STRATUM Vector
Inward
Looks at the operator as the adversary sees it: continuous mapping of the external attack surface and shadow IT, with exposure prioritized by mission impact — a short, ranked list instead of a scan report.
STRATUM Signal
The seam
Looks at the seam between cyber and human: cyber-insider nexus detection that corroborates OBSIDIAN — raising confidence when digital and behavioral signals align, reducing it when they do not.
Duty of care for field crews and remote sites.
Storm response, rotations, remote sites, international projects, contractors — the workforce that keeps essential services running is in motion, and duty of care travels with it.
PATHWAY — Travel Security scores each movement across security, political, environmental, and health factors, and the score decides the workflow. Brief generates the intelligence briefing from live LUCID collection — designed to save 2–4 analyst-hours per traveler. Beacon monitors in the field with location-based reassessment, and an emergency SOS opens a FORGE case automatically, with a configurable handoff to your call center or security operations center.
PATHWAY is software. It complements a lone-worker device program rather than replacing it, and it is not a medical or evacuation service. It supports ISO 31030 compliance programs with audit-ready records the workflow produces itself — designed to help document a defensible duty-of-care program, with reasonable steps recorded as they are taken.
Security staff conduct the pre-briefs and debriefs. Leadership tunes the thresholds. Security operations responds to alerts and SOS events.
- Low risk
- Briefing generated and delivered automatically. No analyst tasking required; security staff set the threshold.
- Medium risk
- Pre-travel briefing scheduled automatically.
- High risk
- Pre-brief and post-travel debrief required. Calendar integration handles the scheduling.
One governed picture across sites, people, and adversaries.
One platform foundation, five product pillars, one assistant layer — governed from day one. One situational awareness platform across sites, crews, and exposure. It is the common operating picture a dispersed program otherwise assembles by hand. Start with the pillar that maps to your most exposed function, then expand across the platform.
APEX — Platform Foundation holds one entity picture across sites, crews, contractors, and adversaries: a unified data fabric that normalizes every signal, a shared risk engine that scores intent across domains, entity resolution that collapses duplicate records into one, and orchestration with human-in-the-loop controls on every consequential step.
Around-the-clock awareness without a watch floor.
Four assistants designed to do the labor that otherwise caps a security program at the size of its team — under governance, with people at every decision point.
AI FORCE — Autonomous Intelligence Assistants is in development. Sentinel is designed to run all-source monitoring around the clock and route contextual alerts to the people who need them. Oracle is designed to correlate signals across domains and deliver briefings on demand. Scribe is designed to document cases continuously, aware of chain of custody from the first entry. Guide is designed to keep people moving through the workflow. Security operations stays in command: every consequential step routes to a human for decision, and every automated action is logged.
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
Early warning, documented decisions, a defensible program.
Early warning scored against the operator's own sites and people. One risk picture without standing up a watch floor. Crews briefed and monitored by exception. A record the program can draw on at review time.
Early warning
Designed to detect targeting and reconnaissance against your sites while there is still time to act — a pattern across substations seen as one pattern, an approach to a crew seen before the crew arrives.
Defensible action
Human-in-the-loop controls on every consequential step. What was detected, what automation did, and who approved it — all on the record, in the operator's own terms.
Audit-ready record
Complete audit trails with authenticated export, ready for counsel, oversight, and the regulators who ask the same questions every review cycle.
Alignment map
The frameworks an operator's program answers to — or is preparing for — what each asks the program to show, and the modules designed to support that showing.
Framework
What the program must show
Supporting modules
Framework
NERC CIP-014 · physical security of critical transmission stations
What the program must show
A documented threat and vulnerability evaluation and a physical security plan, with the intelligence behind both on the record.
Supporting modules
LUCIDFORGEFramework
TSA pipeline security directives
What the program must show
Incident records and timelines a cybersecurity coordinator can report from, with evidence integrity preserved.
Supporting modules
FORGESTRATUMFramework
AWIA §2013 · risk and resilience assessment
What the program must show
Malevolent-act inputs to the assessment, and the emergency response plan they inform.
Supporting modules
LUCIDFORGEFramework
Insider threat mitigation program · CISA and NCSC guidance
What the program must show
A human-led program that identifies anomalous behavior, responds in a way that preserves trust, and documents what it did.
Supporting modules
OBSIDIANFORGEFramework
ISO 31030 · travel risk management
What the program must show
A traveler risk assessment, briefing, and monitoring record produced by the workflow itself.
Supporting modules
PATHWAYFORGEFramework
CIRCIA · cyber incident reporting rulemaking
What the program must show
An incident timeline with evidence integrity, ready for whatever reporting obligations apply when rules take effect.
Supporting modules
STRATUMFORGEAlignment and support language only. Compliance determinations belong to the operator and its regulators. For how the platform itself is secured and governed, see our security posture.
From the newsroom.
Dispatches on the operating environment this page describes — with the sourced context that stays in the newsroom.
FAQ
Frequently asked questions.
Answer-first, and plain about what the platform is not.
Is EternaEdge an OT or ICS security platform?
No. EternaEdge does not monitor industrial control systems, SCADA networks, or field devices, and it is not a substitute for the OT security platform or the internal network monitoring a utility's CIP program requires. It sits above those tools. APEX correlates what they detect with adversary intent from open sources, insider indicators, cyber threat context, and field-crew movements, so security operations sees one risk picture across sites and people. The OT team keeps its tools and its authority; EternaEdge is designed to give it earlier warning and a documented record.
Does STRATUM replace our SIEM?
No. STRATUM is not a SIEM replacement and not a vulnerability scanner. It complements the stack the security operations center already runs with threat-actor profiling with attribution confidence, campaign correlation, dark-web monitoring for reconnaissance against the operator, and attack-surface exposure prioritized by mission impact rather than CVE count. STRATUM Signal also corroborates OBSIDIAN indicators, raising or reducing confidence in a possible cyber-insider nexus. Analysts decide what to act on. The SIEM stays the system of record for logs and detections.
Does EternaEdge make us NERC CIP, TSA, or AWIA compliant?
No product can do that. Compliance is the registered entity's or operator's determination, made with its regulators. EternaEdge is designed to support the intelligence, documentation, and investigation elements those programs already maintain: the threat and vulnerability evaluation and physical security plan a transmission owner documents under CIP-014, the incident records a pipeline program aligned to TSA security directives keeps, and the malevolent-act inputs an AWIA-aligned risk and resilience assessment draws on. FORGE holds the evidence and the audit trail. Your compliance staff, counsel, and regulators make the determinations. We claim no certification against any of these standards.
Can it help with drones and physical reconnaissance at sites?
It helps with early warning and the record, not with detection hardware. EternaEdge is not a drone-detection or counter-UAS system. LUCID surfaces open-source signals of interest in your facilities, including ideologically motivated targeting and published reconnaissance. APEX correlates sightings, incidents, and reports across sites and over time, so a pattern at several substations is seen as one pattern. FORGE opens a case at threshold with a documented timeline your security lead and law-enforcement contacts can act on. Detection, response, and any flight-restriction request remain with the operator and the relevant agencies.
How does it protect field crews and remote workers?
PATHWAY scores each movement on security, political, environmental, and health factors, and the score decides the workflow: low risk gets a briefing, medium risk a pre-brief, high risk a pre-brief plus a mandatory debrief. Crews deploying to storm-response areas, remote sites, or international projects receive briefings generated from live intelligence. Beacon monitors in the field, and an emergency SOS opens a FORGE case automatically for security operations to respond to. PATHWAY supports ISO 31030 compliance programs. It is software, not a medical or evacuation service, and it complements a lone-worker device program rather than replacing it.
Does it support an insider threat mitigation program?
Yes, as the analysis and case layer beneath a human-led program. OBSIDIAN is designed to support the program elements described in CISA's Insider Threat Mitigation Guide and in NCSC guidance for critical infrastructure entities: identifying anomalous behavior across access, travel, cyber, and open-source signals, correlating it against behavioral baselines, and opening a FORGE case at threshold with the record a multidisciplinary team needs. Security, HR, legal, and privacy officers keep the decision. It correlates signals the organization already governs; it is not a tool for watching employees, and it does not replace endpoint tools or the program itself.
Does EternaEdge handle classified information or CUI?
No. The platform is designed for unclassified use with open-source collection and the organization's own governed data. Classification inside FORGE and APEX refers to access-control tiers on the platform, not to government classification. This site does not state accreditations, impact levels, or clearance-related handling; deployment questions are worked through with a platform architect. Operators with defense-critical infrastructure obligations should treat EternaEdge as the unclassified intelligence and case layer beside their existing programs.
How is physical threat intelligence different from a real-time alert feed?
An alert feed is built to report the world. Physical threat intelligence is early warning about the people and groups who intend harm to specific sites, drawn from publicly available information and correlated to the assets they threaten. LUCID is asset-anchored: every alert is relevance-scored against your facilities, crews, and travel, and what reaches an analyst is a summary, never a raw feed. Horizon adds country and regional risk for the places you operate. Analysts confirm relevance and steer collection; security operations acts on what is confirmed. The difference is that the alert knows which substation is yours.
Bring every site, crew, and exposure into one picture.
Tell us how your security, operations, and compliance functions are organized — and which sites and crews you cannot staff around the clock. A platform architect will map one platform foundation, five product pillars, one assistant layer to the way your operation actually runs.