Markets · Defense & Intelligence Community
Detect targeting in the reconnaissance phase — and prove what you did about it.
Foreign intelligence entities work the reconnaissance phase long before an incident — expert outreach, consulting and résumé approaches, online recruiting of current and former personnel. Each signal lands in a different system; analysts correlate by hand. EternaEdge is counterintelligence software for that phase. One governed platform correlates those signals and is designed to raise early warning while there is still time to act — decision advantage during reconnaissance. Analysts decide; the platform keeps the record oversight expects — what was detected, what automation did, and who approved it.
For counterintelligence teams · insider threat hubs · program protection · security leadership · counsel and oversight
The adversary’s reconnaissance is visible — across the wrong systems.
Foreign intelligence entities target, solicit and cultivate people, and non-traditional collectors work from inside programs and supply chains. Each approach looks ordinary in the one system that saw it: a networking message, a conference invitation, a consulting inquiry, a trip.
The insider threat hub sees access. The counterintelligence office sees reporting. Program protection sees the critical program information list. The open-source cell sees a job posting that quotes your program’s vocabulary. Travel security sees an itinerary. Each is sub-threshold on its own; together they are the pattern — and the correlation is done by hand, if it is done at all.
Detection built around events starts at compromise, when there is finally something to log. Detection built around intent starts where the adversary does. Moving detection left widens the time to act — the difference between a defensive briefing and a damage assessment — and the record has to show which one you gave. Detect intent, not just events.
For counterintelligence (CI) analysts and special agents · counter-insider threat hub managers · program protection leads · operations security (OPSEC) and travel security · counsel, privacy officers and inspectors general
The adversary’s phases
Reconnaissance
Programs, people, suppliers and travel are researched from the outside — open sources, professional networks, conference rosters, published research.
Where EternaEdge is designed to detect
Targeting
Specific people are selected: the expert with access, the supplier with a weak control, the traveler with a published schedule.
Approach
Contact begins — a consulting offer, a résumé request, a conference invitation, a relationship cultivated over months.
Compromise
Access is obtained or an insider acts. This is the first moment an event-based tool has anything to log.
Where event-based tools detect
Exploitation
Information moves. Detection here is a damage assessment, not a warning.
Program protection, inside the platform.
OBSIDIAN — Counterintelligence carries the program: what you protect and who wants it, the people already inside, and the entities you are about to trust. Three modules on one pillar, every warning validated by a person before anything follows from it. Each module stands on APEX — Platform Foundation, which scores intent against role and mission sensitivity, and hands a case at threshold to FORGE — Investigations.
OBSIDIAN Shield
What you protect, and who wants it
Shield inverts the lens. It links critical program information, technologies and suppliers to the threat actors and collection priorities that want them, watches targeting indicators across open-source, cyber and travel signals, and surfaces foreign dependencies worth a closer look. It is designed to support the threat picture a Program Protection Plan relies on — not to write the plan.
Human role
Program protection leads and counterintelligence officers validate each warning and choose countermeasures.
OBSIDIAN Guard
Insider patterns across access, travel, cyber and open sources
Guard builds behavioral baselines and correlates anomalies across domains, scored by the APEX risk engine against role and mission sensitivity — a badge anomaly for a program manager weighs differently. Output is a risk-prioritized alert, not a single-stream spike, and at threshold a FORGE case opens with the entity timeline already assembled.
Human role
Insider threat analysts review alerts, direct inquiries and make every determination. Guard surfaces and organizes; people decide.
OBSIDIAN Check
Vetting with FOCI indicators
Check answers whether an entity can be trusted — a hire, a supplier, a teaming partner, an investor. It maps beneficial ownership and hidden corporate structures, screens sanctions, politically exposed persons and adverse media, and flags foreign ownership, control or influence (FOCI) indicators, delivered as audit-ready reports with counterintelligence red flags called out.
Human role
Vetting staff, security officers and counsel make the trust decision.
Insider threat programs built beyond the minimum standards.
The National Insider Threat Policy and its minimum standards set the floor: a multidisciplinary hub that prevents, deters, detects, mitigates and reports. A maturing counter-insider threat program adds integration, analytics and behavioral science on top.
OBSIDIAN Guard is designed to support that layer — not to run the program. Guard is not an endpoint agent and does not perform user activity monitoring. It correlates the signals the organization already governs — access, travel, cyber, open-source and self-reports — and scores them against role and mission sensitivity, so the hub works a short, prioritized queue instead of an alert flood. Because the scoring weighs signal diversity and corroboration, it is designed to reduce indiscriminate review as deliberately as it raises real risk.
What stays with the hub
- Program ownership and policy under the senior official
- Legal, privacy and civil-liberties review of every practice
- Inquiries, referrals and determinations
- Training, awareness and reporting culture
- Reporting to oversight and the inspector general
What the platform contributes
- Integration of the signals the organization already governs — access, travel, cyber, open-source, self-reports
- Cross-domain correlation scored against role and mission sensitivity
- Risk-prioritized alerts instead of single-stream spikes and alert floods
- A FORGE case at threshold, with the entity timeline assembled
- A record of every alert, review and disposition, exportable for review
Legal · security · counterintelligence · cyber · HR · behavioral science — one queue, one record
Open-source early warning, CI-aware.
The Intelligence Community’s own strategy calls open-source intelligence the INT of first resort. LUCID — OSINT Awareness is designed to make it the first signal a counterintelligence program sees: publicly and commercially available information, collected continuously, scored for relevance to your people, programs and sites, and summarized for action — never a raw feed.
Grid collects across regions, domains and languages without analyst tasking or shift gaps, and detects coordinated campaigns and influence operations, not just mentions. Pulse correlates critical events to personnel, programs and travel and can trigger a FORGE case or an OBSIDIAN escalation when an event implicates a protected entity. Horizon keeps country and regional risk current for the missions that depend on it.
Open-source only, by definition. Analysts steer collection priorities and decide what an alert means; the platform does the watching.
What reaches an analyst
- Relevance-scored summary
- Scored against your people, programs and sites — a synthesized product, not a keyword hit.
- Entity correlation
- Attached by APEX to the person, program or site it concerns, so it lands in the same risk picture as every other signal.
- Relevance rationale
- Designed to show what was collected, from where, and why it scored as it did, so an analyst can check the alert before acting on it.
- Campaign detection
- Coordinated campaigns and influence operations surfaced as a pattern, not as a flood of mentions.
Inquiries, referrals and cases that survive oversight.
FORGE — Investigations is where a warning becomes a documented inquiry. Cases open automatically when the APEX risk score crosses threshold — manual initiation is always available — and arrive with the entity timeline and the platform’s intelligence about the people, programs and suppliers involved already attached. Investigators run the inquiry; the platform removes the administrative drag. Every consequential step lands on one record, in three columns.
What was detected
Every signal that contributed to an alert, with its source, its time, and the entity it resolved to — an access anomaly, a travel record, an open-source mention, a self-report — so a reviewer can see why the alert fired.
What automation did
Each automated step on the record: the correlation that raised the score, the case that opened at threshold, the trip that was re-tiered, the alert that was routed — and what it read to do it.
Who approved it
Every consequential step carries the name of the authorized person who approved it and the time they did, so inquiry, referral and countermeasure decisions are attributable, not implied.
Foreign contact reporting, through the front door
Intake captures foreign contact reports, suspicious contact reports and security incidents through guided questionnaires, with automatic categorization and routing to the right queue. Reports are signals too — they flow into APEX and can corroborate an OBSIDIAN assessment. The security office remains the reporting official for obligations under SEAD 3 and 32 CFR Part 117; the platform keeps the record it reports from and never files to a government system.
Evidence that stays whole
Chain is the defensibility layer: SHA-256 hashing and tamper detection on every evidence item, a complete audit trail of every access and transfer, multi-level access controls inside the case system, and authenticated export for counsel, the inspector general and program review. Complete auditability of the process; the outcome of any proceeding stays with the adjudicating authority.
Cyber context with counterintelligence framing — not a SIEM replacement.
STRATUM — Cyber Threat is not a security information and event management (SIEM) replacement or a vulnerability scanner. It sits above the security operations stack — SIEM, endpoint detection and response (EDR), scanners — as an intelligence layer, and answers a question that stack is not built to answer: what does this digital activity mean for our people, programs and mission?
Watch profiles threat actors with attribution confidence — stated certainty, an auditable-claims discipline — correlates campaigns across infrastructure and tradecraft, and raises early warning for reconnaissance against the organization. Vector maps the external footprint, finds shadow IT and unknown assets, and ranks exposure by mission impact rather than by raw vulnerability volume.
Signal works the seam between cyber and human. It correlates digital anomalies with travel and access patterns and corroborates OBSIDIAN assessments in both directions. Cyber analysts tune priorities and decide response postures; counterintelligence teams get digital evidence for attribution and insider assessments.
Corroboration, both ways
- Cyber and behavioral signals align
- Confidence in the assessment is raised; the case carries the digital evidence.
- No alignment
- Confidence is reduced and review is de-prioritized — designed to protect people from a false accusation as deliberately as it flags real risk.
Complements the SIEM, EDR and scanner already in place
Movement risk for personnel and missions.
Travel is when personnel are most exposed to a foreign intelligence approach, and pre-briefs and debriefs are core counterintelligence practice. PATHWAY — Travel Security automates the scheduling and the documentation: itineraries are ingested, a briefing is generated from live intelligence including foreign-intelligence targeting context, and a multi-factor risk score decides the workflow.
Low risk
Briefing delivered automatically
A pre-travel briefing built from live intelligence, including foreign-intelligence targeting context for the destination. Analysts engage by exception; the briefing and its delivery land on the travel record the security office reviews.
Medium risk
Pre-travel briefing scheduled
The workflow schedules a pre-brief with the security office before departure. Counterintelligence staff conduct it and record it.
High risk
Pre-brief and mandatory debrief
Both sessions are scheduled automatically. The debrief is designed to capture foreign contacts and approaches through Intake, so the program record is current before the next check.
Every briefing, pre-brief and debrief lands in an audit-ready record — the foreign travel record the security office reports from, and the documentation that supports ISO 31030 compliance programs. Beacon keeps a traveler in view during the trip with location-based reassessment and an emergency SOS that opens a FORGE case on activation. Counterintelligence staff conduct the sessions the workflow schedules; security leadership tunes the thresholds.
Continuous vetting changed the cadence; the program record has to keep up.
Government continuous vetting runs in its own systems, and legacy periodic reinvestigations have been retired for the vetted workforce. That changes what a security office is asked for: not a snapshot every few years, but a current answer whenever a check surfaces something — what was reported, when, and what the program did.
The platform is continuous-evaluation-aligned. It keeps the organization’s own program record — self-reports, foreign contacts and travel from Intake and PATHWAY, inquiries and their disposition from FORGE, targeting warnings from Shield — current between government checks, so a security officer reports from a record rather than from memory.
It does not enroll anyone, file to a government system or replace the vetting program. The security office remains the reporting official; the platform keeps the record the report is drawn from — current, attributable and exportable with authentication.
The record between checks
- Self-reports and foreign contact reports, categorized and routed
- Foreign travel — briefed, pre-briefed, debriefed, recorded
- Inquiries and referrals with their disposition
- Targeting warnings validated by program protection
- Who reviewed what, and when — exportable with authentication
What we do not claim.
This buyer reads the fine print first. Here it is, in plain language.
How the platform isolates data, controls access and keeps its audit trail is described on our security page.
- The platform is not offered for classified information, and nothing on this site implies a clearance.
- We use alignment language only: NISPOM-aligned under 32 CFR Part 117, continuous-evaluation-aligned, supports ISO 31030 compliance programs. We do not state accreditations or hosting authorizations here.
- STRATUM is not a SIEM replacement. OBSIDIAN is not an endpoint agent and does not perform user activity monitoring.
- The platform does not file to any government system. The security office remains the reporting official; the platform keeps the program record it reports from.
- The assistant layer is in development. No assistant acts without a named human approving the consequential step.
How organizations engage
An engagement is scoped as a pilot around one hub, one program or one travel population, on the organization’s own governed data, with the record reviewed by counsel before anything expands. Deployment, hosting and data-isolation questions are worked through with a platform architect.
One intelligence picture for CI, insider threat and program protection.
One platform foundation, five product pillars, one assistant layer.
APEX resolves access, travel, cyber and open-source signals to one entity and scores intent against role and mission sensitivity; the pillars carry the program; the assistants — in development — will take the watching and the writing, and people keep the deciding. Start with the pillar that maps to your hub or CI office, then expand.
Governed automation, human authority.
AI FORCE — Autonomous Intelligence Assistants is in development: four assistants designed to work across every module so a program can scale to enterprise-wide protection without added staff. Sentinel will monitor every governed source around the clock. Oracle will correlate signals and draft briefings on demand. Scribe will document cases continuously, chain-of-custody aware. Guide will keep people moving through the workflow.
Analysts, program officials and counsel stay in command: every consequential step routes to a named person, and every automated action is logged. The Intelligence Community’s own AI ethics principles describe human judgment tempering technological guidance, and oversight increasingly asks how procured AI is tracked for transparency and accountability. The chain of authority below is the record that question is answered with.
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
Chain of authority
Four steps between a signal and an action. A person is named at every one.
Signal arrives
A governed signal lands in APEX — an access anomaly, a travel record, an open-source mention, a self-report. Entity resolution attaches it to the right person, program or supplier.
Human
Collection managers and the security office decide what the platform is allowed to see.
Assistant proposes
Sentinel is designed to flag the pattern and Oracle to draft the correlation — a proposal with its source chain attached, never an action.
Human
An analyst reads the proposal and decides whether it holds.
Authorized human approves
Every consequential step — an inquiry, a referral, a countermeasure — routes to a named, authorized person before it is taken.
Human
The program official approves, declines or redirects.
FORGE records
The case captures what was detected, what automation did and who approved it, with hashed evidence and timestamps, exportable with authentication for counsel and the inspector general.
Human
Counsel, privacy officers and oversight read the same record the hub does.
Early warning, defensible action, an audit-ready record.
Early warning
Designed to surface targeting during the adversary's reconnaissance phase — while a defensive briefing, a countermeasure or a conversation still changes the outcome. Decision advantage, in the government's own phrase.
Defensible action
Human authority on every consequential step. Inquiries, referrals and countermeasures are approved by named people, and the platform records what was detected, what automation did and who approved it.
Audit-ready record
Complete auditability from signal to disposition — hashed evidence, a full audit trail and authenticated export for counsel, the inspector general and program review. A record the hub, oversight and leadership read alike.
Related reading
From the newsroom, where the sourced numbers live.
Frequently asked questions
What counterintelligence, insider threat and program protection teams ask before a pilot — answered in the same language we use on the record.
What does EternaEdge do for a counterintelligence or insider threat program?
It is designed to support the program you already run. APEX correlates access, travel, cyber and open-source signals into one entity picture and scores intent against role and mission sensitivity. OBSIDIAN raises targeting early warnings when a foreign intelligence entity works the reconnaissance phase, LUCID adds open-source context, and FORGE opens a case at threshold with the evidence attached. Analysts review every alert and make every determination. The platform records what was detected, what automation did and who approved each step, so the hub, counsel and oversight read the same record.
Does the platform replace user activity monitoring, a SIEM or the insider threat hub?
No. EternaEdge is designed to ingest and correlate signals the organization already governs, not to replace the sensors or the people. OBSIDIAN is not an endpoint agent, STRATUM is not a SIEM replacement, and the hub remains the multidisciplinary team that prevents, deters, detects, mitigates and reports. The platform gives that team one operating picture, a governed workflow and an auditable case record. It sits beside the tools in place and complements them.
How does it relate to the National Insider Threat Policy minimum standards and the maturity framework?
The platform is designed to support program elements that DoD insider threat program requirements and the National Insider Threat Task Force maturity framework describe: integration of stakeholder data, analytics, behavioral-science-informed risk scoring, and case management that preserves the integrity of an inquiry. It is not a substitute for program assessment; software alone is not. Program ownership, policy, training, and legal and civil-liberties review remain with the senior official and counsel. What the platform contributes is a current, defensible record of signals, assessments and decisions that a program can show to reviewers.
Does the platform handle classified information?
No. Nothing on this site states an accreditation, a hosting authorization or clearance-related handling, and the platform is described here for environments that run on open-source and governed organizational data. Inside the product, the word classification refers to platform access controls, never to classified information. Deployment, hosting and data-isolation questions are worked through directly with a platform architect, who can walk through the architecture and the record the platform keeps for oversight.
How is the AI governed?
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight. AI FORCE is in development. Its assistants are designed to monitor, correlate and document; people approve every consequential step. Each assistant-generated summary is designed to carry its source chain, and the audit trail records who invoked it and what it read. That is the human-centered posture the Intelligence Community's own AI ethics principles describe, and it is the record an oversight body or a chief AI officer will ask for.
What does program protection mean in the platform?
OBSIDIAN Shield links critical program information, technologies and suppliers to the threat actors and collection priorities that want them, and raises targeting early warnings for program protection staff. It is designed to support the threat and vulnerability picture a Program Protection Plan relies on, and to flag foreign dependencies worth a closer look. It does not write the plan, perform supply-chain illumination or choose countermeasures. Program protection leads and counterintelligence officers validate each warning and decide what to do about it.
How does FORGE support inquiries, referrals and legal or inspector general proceedings?
FORGE opens cases automatically at risk thresholds, builds entity-centric timelines, and captures foreign contact, suspicious contact and incident reports through guided intake with categorization and routing. Evidence is hashed with SHA-256, tamper detection runs on every access, investigators run the inquiry and every action lands in the audit trail, and authenticated export delivers the record to counsel or an inspector general. The result is complete auditability of the process. The outcome of any proceeding remains with the adjudicating authority.
How does continuous vetting fit?
The platform is continuous-evaluation-aligned: it keeps the organization's own program record — self-reports, foreign contacts, travel, inquiries and their disposition — current between government checks, so security officers report from a record rather than from memory. Government continuous vetting runs in its own systems and replaced legacy periodic reinvestigations for the vetted workforce. The platform does not enroll people, file to government systems or replace the vetting program. The security office remains the reporting official.
Bring the reconnaissance phase into view.
Tell us how your counterintelligence, insider threat and program protection functions are organized, and what oversight asks you for. A platform architect will map one platform foundation, five product pillars, one assistant layer to the program you run — and to the record you have to keep.