Markets · Large Enterprise
Run the global security operations center on one governed platform.
Protect the ideas, people, and operations your edge is built on. EternaEdge is GSOC software for corporate security — the global security operations center (GSOC) and the program around it: protective intelligence, insider risk, travel risk management, and investigations with complete auditability on one platform foundation, five product pillars, one assistant layer.
GSOC · Executive protection · Insider risk · Investigations · Travel risk · Cyber threat context
The GSOC runs on a point-solution stack that was never designed to connect.
A large enterprise security program carries the global security operations center, executive protection, threat management, investigations, travel, and insider risk — and most often runs each on a separate tool.
Operators swivel between consoles. Most alarms are noise, and the alarms that matter arrive without the context that would make them urgent: the itinerary, the access record, and the open-source mention that together describe one situation. Real-time feeds tend to measure themselves in sources and seconds, and leave relevance to the analyst.
The record of what was seen and decided is scattered across vendors. Boards ask whether executives are protected. Counsel asks whether the program is defensible. Neither question can be answered from a reconstruction assembled after the fact.
Point tools each watch one domain, and the stack a program assembles today was built to be bought one function at a time. Retrofitted IT security tooling was never designed to detect intent. Detection built around events starts after the loss; detection built around intent starts where the adversary does.
For chief security officers (CSOs) & VPs of corporate security · GSOC directors · chief information security officers (CISOs) · general counsel · heads of executive protection, travel security, insider risk & investigations
The point-solution stack
Real-time event alerting
Separate vendor · separate data model
Open-source monitoring
Separate console · keyword alerts
Travel risk & duty of care
Separate contract · separate traveler record
Investigations & case management
Spreadsheets, shared drives & email
Insider risk tooling
Built for IT telemetry · separate login
Cyber threat intelligence feed
Generic indicators · unlinked to people or sites
Executive protection intelligence
Manual research · separate inbox
Each line item carries its own contract, console, and record. The seams between them are where the pattern hides. One governed platform — one data fabric, one risk engine, one record.
Seven line items. One governed platform.
Coverage
What a corporate security program has to cover
A corporate security program is the set of functions that protect an enterprise's people, sites, information, and operations from human and physical threats. Eight recur across large programs. Each is a job the platform is designed to carry, with the person who owns it named beside the automation.
The architecture is always the same. One platform foundation: APEX — Platform Foundation. Five product pillars: OBSIDIAN — Counterintelligence, LUCID — OSINT Awareness, FORGE — Investigations, STRATUM — Cyber Threat, and PATHWAY — Travel Security. One assistant layer: AI FORCE — Autonomous Intelligence Assistants, in development.
01
GSOC & intelligence
Round-the-clock awareness of the events that touch people, sites, and travel — relevance-scored, correlated, and summarized so the desk reads risk intelligence rather than feeds.
02
Executive protection & protective intelligence
Who is interested in your principals, what they have said or done, and whether concern is escalating — designed to surface it for the executive protection team before an approach, not reconstructed after one.
03
Threat assessment & workplace violence prevention
Concerning-behavior reports taken in through guided intake, routed to the threat assessment team, and logged the way the plan requires. The team makes every determination.
04
Investigations
Ethics, HR, fraud, and intellectual-property matters run in one case system with evidence hashed as it enters custody and an audit trail from initiation to export. Investigators run the matter; counsel reviews inside the same record.
05
Travel risk & duty of care
Briefings, risk tiers, and in-travel monitoring for every traveler, with analysts engaged where the risk tier requires them and the assessment and incident record a defensible program calls for.
06
Insider risk & trade secrets
Cross-domain anomalies scored against role and asset sensitivity; a case opens at threshold; security, HR, and counsel review inside the same record.
07
Supply chain & third-party vetting
Beneficial ownership, sanctions, and adverse media on suppliers, acquisition targets, and key hires — delivered as audit-ready reports so vetting staff, security officers, and counsel make the trust decision before it is extended.
08
Crisis management & business continuity context
Regional risk and event alerts correlated to the facilities and crews they touch, so the crisis team starts with the picture instead of assembling it.
Consolidation
The point-solution stack, and what replaces it
The stack a program assembles today is bought one function at a time: one console per function, one contract per console, one data model per contract. What replaces it is not another console. It is a foundation the functions share.
Seam
Status quo
With EternaEdge
Vendor sprawl
Status quo
One console per function, one contract per console, one data model per contract.
With EternaEdge
One platform foundation under every function: one canonical schema, one entity picture, one audit trail.
Swivel-chair correlation
Status quo
The connection between an itinerary, an open-source mention, and an access anomaly is found if the same analyst happens to see all three.
With EternaEdge
The shared risk engine scores every signal against everything else known about the same person, site, or program.
Alert fatigue
Status quo
Real-time feeds tend to measure themselves in sources and seconds, and leave relevance to the analyst.
With EternaEdge
Relevance-scored alerts correlated to your people, sites, and itineraries — summaries, not feeds.
Duplicate entity records
Status quo
The same executive tends to exist as a separate record in each tool, each with its own alerts.
With EternaEdge
Entity resolution collapses duplicate records and duplicate alerts into one picture.
Audit gaps
Status quo
What was seen, what was decided, and who approved it lives in inboxes, spreadsheets, and vendor logs.
With EternaEdge
Every consequential step is on the record — what was detected, what automation did, who approved — with authenticated export.
Per-tool logins
Status quo
A login per tool and a mental model per vendor for every analyst.
With EternaEdge
One governed platform with access controls set inside it; every user works inside the same authority and oversight model.
What stays
The platform is designed to complement, not replace, the systems the GSOC keeps — access control, video management, mass notification, the security information and event management (SIEM) platform, the human resources information system (HRIS), and travel booking. EternaEdge is not a mass-notification tool and not a physical security information management (PSIM) system. It sits above those layers and is designed to ingest what they see — the badge event, the itinerary, the alarm — into one entity picture.
- Access control
- Video management
- Mass notification
- SIEM
- HRIS
- Travel booking
Operations
How a global security operations center runs it
Four seats, one common operating picture, one record. Each role sees the picture its job requires, acts inside its own authority, and leaves a record the next role can rely on.
GSOC analyst
- Sees
- One queue of relevance-scored alerts, each already correlated to the people, sites, and itineraries it touches.
- Does
- Assesses, escalates, or closes — and opens a case when the picture warrants it.
- The record it leaves
- Every alert, assessment, and escalation logged with source and time.
Executive protection lead
- Sees
- Targeting indicators for each principal, the itinerary risk of the day, and the open-source signal around venues.
- Does
- Adjusts posture, requests a briefing, tasks the advance team.
- The record it leaves
- The protective-intelligence file the program can show the board.
Investigations lead
- Sees
- Cases that arrive with the entity timeline already assembled and evidence hashed as it enters custody.
- Does
- Assigns, investigates, resolves; counsel reviews inside the same record.
- The record it leaves
- Complete auditability, with authenticated export for counsel.
General counsel & the board
- Sees
- Program posture in outcomes: what was detected, what was decided, and who approved it.
- Does
- Asks whether the program is defensible — and gets the record, not a reconstruction.
- The record it leaves
- An audit-ready account of the program, built as events happened.
A day on the watch floor
Four signals arrive in four domains — open-source intelligence (OSINT), travel, cyber, and insider — over one day. Point tools each see one of them. The platform resolves all four to the same site, the same trip, and the same people — and opens one case.
Illustrative · designed behavior, not a customer result
- 02:14LUCID
OSINT
Unrest reported near a regional office
- 06:40PATHWAY
Travel
Executive itinerary lands in-region
- 09:05STRATUM
Cyber
Supplier credential exposure surfaces
- 13:30OBSIDIAN
Insider
Contractor access anomaly outside baseline
- ThenFORGE
One case · one timeline · entity-resolved
Case opened at threshold. An analyst decides; the platform made sure the decision arrived in time.
Protective intelligence
Protective intelligence for executives and the workforce
Board attention has moved executive protection from a line item to a program with a mandate. The mandate is protective intelligence — and it has to cover the workforce as well as the principals.
What protective intelligence is
Protective intelligence is the proactive identification, assessment, and management of targeting before harm occurs. It asks who is interested in your people, what they have said or done, and whether concern is escalating — and it answers with a record, not a hunch. It is the discipline that lets an executive protection program act early and explain why it acted.
Executive protection and digital executive protection
OBSIDIAN Shield maps what the enterprise protects — principals, sites, programs — to who wants it, and raises targeting early warning across open-source, cyber, and travel signals. LUCID Pulse correlates open-source events to named people, venues, and itineraries, relevance-scored so the team reads summaries rather than feeds: the intelligence layer of digital executive protection, not a personal-data removal service. STRATUM Watch adds reconnaissance early warning — whether known actors are probing the enterprise around the same people and sites. The executive protection lead sets posture and tasks the advance team; the platform is designed to put the picture in front of them.
Behavioral threat assessment and the workplace violence prevention plan
FORGE Intake takes concerning-behavior reports through guided questionnaires, categorizes and routes them to the threat assessment team, and keeps the incident log the plan requires. OBSIDIAN Guard supplies behavioral baselines and cross-domain context, so the team assesses a person rather than a single report. The multidisciplinary team — security, HR, legal, behavioral health — makes every determination. The platform is designed to support workplace violence prevention plan (WVPP) programs, including state mandates such as California Labor Code section 6401.9. It is not legal advice and does not replace the plan.
Travel risk
Travel risk management and duty of care at corporate-program scale
Travel risk management is the discipline of preparing travelers before they go, staying aware while they are gone, and keeping the record that shows both were done. At program scale the work has to be automated first and staffed by exception.
PATHWAY — Travel Security supports ISO 31030 compliance programs. The assessment, the briefing, and the incident record are produced by the workflow itself rather than reconstructed for an audit — the record a defensible program depends on: reasonable steps, recorded. It is designed to help document a defensible duty-of-care program for every traveler, not only the principals who used to get a hand-built briefing.
Analysts conduct the pre-briefs and debriefs the scoring schedules, and security teams respond to every alert and SOS with the traveler's context already in front of them. PATHWAY is software, not an assistance service.
PATHWAY Brief
Briefings generated from live intelligence, including foreign-intelligence targeting context, delivered automatically for routine trips.
Human role
Analysts review and tailor high-risk briefings.
PATHWAY Risk
Multi-factor scoring across security, political, environmental, and health dimensions decides the workflow: brief only, pre-brief, or pre-brief plus mandatory debrief.
Human role
Analysts conduct the pre-briefs and debriefs; leadership tunes the thresholds.
PATHWAY Beacon
In-travel monitoring around the clock with location-based reassessment and emergency SOS — a FORGE case opens automatically on activation.
Human role
Security teams respond to every alert and SOS event.
Insider risk
An insider risk program the CSO, HR, and counsel can all stand behind
Insider risk is the exposure an enterprise carries because trusted people have access. A program the general counsel will sign is one that correlates signals the organization already governs, shows why an alert fired, and puts every determination in human hands.
OBSIDIAN — Counterintelligence builds behavioral baselines and correlates anomalies across access, travel, cyber, and open-source signals, scored by role and asset sensitivity through the shared risk engine. At threshold, a FORGE case opens with the entity timeline already assembled. Insider-risk analysts review, direct inquiries, and make every determination; HR and counsel review inside the same record.
It is not an endpoint agent and does not record screens or keystrokes. It is designed to reduce indiscriminate monitoring, not add to it — risk-prioritized output, human determination, and an audit trail that shows what was correlated and why.
OBSIDIAN Guard
Looks inward. Behavioral baselines and cross-domain anomaly correlation; a FORGE case opens automatically at threshold.
Human role
Insider-risk analysts review and make all determinations.
OBSIDIAN Shield
Looks outward. Maps what you protect to who wants it — targeting early warning, supply-chain exposure, and foreign-dependency identification.
Human role
Program protection leads validate warnings and choose countermeasures.
OBSIDIAN Check
Looks at who you are about to trust. Beneficial ownership, sanctions, politically exposed persons, and adverse media on acquisition targets, suppliers, and key hires — as audit-ready reports.
Human role
Vetting staff, security officers, and counsel make the trust decision.
Investigations
Investigation case management with complete auditability
Ethics, HR, fraud, and intellectual-property matters end up in front of counsel, a regulator, or a court. The record they find there should have been built as the work happened.
FORGE — Investigations opens cases automatically when the risk engine crosses threshold, from an Intake report, or by hand. Each case arrives entity-centric: the people, sites, and programs involved on one timeline, with every known signal attached, so security, HR, legal, and ethics investigate in one case rather than four silos.
Investigators run the investigation; counsel reviews inside the same record; the export carries an authentication certificate. Complete auditability is the promise — every access and transfer logged, every evidence item hashed — and the human judgment that closes a case stays human.
FORGE CaseOps
Automated case creation at risk thresholds, task assignment with deadlines and escalation, and entity-centric timelines with the intelligence picture attached.
Human role
Investigators run the investigation; supervisors see workload and deadlines.
FORGE Intake
Guided reporting for incidents, ethics matters, and foreign contacts, categorized and routed automatically to the right queue.
Human role
Reviewers receive triaged, complete reports; reporters get a low-friction path.
FORGE Chain
SHA-256 evidence hashing, tamper detection, a complete audit trail of every access and transfer, access controls inside the case system, and authenticated export.
Human role
Investigators and counsel rely on the record; integrity is automatic rather than procedural.
Cyber threat context
Cyber threat intelligence in counterintelligence context — not a SIEM replacement
Security convergence, in practice: not a SIEM replacement, and not a vulnerability scanner. The CISO keeps the security operations center; the GSOC gains the cyber context its picture has been missing.
STRATUM— Cyber Threat sits above the SIEM, endpoint, and vulnerability tooling the CISO already runs and answers a question those tools were not built to answer: what does this digital activity mean for our people, our sites, and our program? Exposure is prioritized by mission impact rather than raw volume, so the ranking is designed to put what matters to the program at the top of the analyst’s list.
The seam between the SOC and the GSOC is where serious compromises can hide: a digital anomaly the SOC judged low and a behavioral anomaly the insider-risk program judged low that together describe one person. STRATUM Signal corroborates OBSIDIAN assessments in both directions — alignment raises confidence, its absence reduces it — and cyber analysts and counterintelligence teams make every call.
STRATUM Watch
Threat-actor profiling with attribution confidence, campaign correlation, dark-web monitoring, and reconnaissance early warning.
Human role
Cyber analysts tune priorities and decide response postures.
STRATUM Vector
Attack surface mapping and shadow-IT discovery, with exposure prioritized by mission impact rather than raw counts of known vulnerabilities (CVEs).
Human role
Security teams work a short, mission-ranked exposure list.
STRATUM Signal
Cyber-insider nexus detection that corroborates OBSIDIAN findings — raising or reducing confidence with every new signal.
Human role
Counterintelligence teams and cyber analysts make every determination.
One platform foundation for every corporate security function.
A corporate security platform is one governed foundation under every function the program carries — one platform foundation, five product pillars, one assistant layer. Start with the pillar that maps to the most exposed function, then expand across the foundation; each product makes the next more valuable, because they share one entity picture and one audit trail.
APEX — Platform Foundation is the foundation under all five: one data fabric, one shared risk engine, entity resolution, and orchestration with human-in-the-loop controls on every consequential step.
Explore PlatformAI for physical security, governed.
The assistant layer is in development. It is designed as the capability multiplier that enables enterprise-wide protection without added staff — and it is designed to be governed before it is designed to be fast.
AI FORCE — Autonomous Intelligence Assistants is designed so that Sentinel monitors every source around the clock, Oracle correlates signals and delivers briefings on demand, Scribe documents cases continuously with the chain of custody in view, and Guide keeps people moving through the workflow. Your analysts and leadership stay in command: every consequential step routes to a person for decision, every automated action is logged, and an analyst can see why an alert fired — the source chain and the verification steps.
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.
Figures from the pillars
Designed capability of the product pillars — not measured customer results.
Early warning, defensible action, an audit-ready record.
The program the CSO can defend to the board and the general counsel can defend anywhere — designed so fewer analyst-hours go to each alert, not more.
01
Early warning
Designed to surface targeting during the reconnaissance phase — the approach to a principal, the probe of a supplier, the anomaly in trusted access — while there is still time to act.
02
Defensible action
Human-in-the-loop controls on every consequential step. What was detected, what automation did, and who approved it are on the record as it happens, not reconstructed for counsel.
03
Audit-ready record
Complete audit trails with authenticated export, ready for the general counsel, the board, and regulators. Supports ISO 31030 compliance programs for travel and workplace violence prevention plan programs for threat management.
Enterprise security risk management (ESRM) asks the program to tie every control to a business risk and an owner. The platform is designed to make that case in outcomes — and to scale the program without standing up a round-the-clock watch floor.
Where to begin
Your program needs to…
Start where the exposure is. Each link goes to the pillar — or the platform — that carries the job.
- protect executives and travelersPATHWAY
- run a converged global security operations centerAPEX
- investigate with complete auditabilityFORGE
- stand up an insider-risk program HR and counsel can stand behindOBSIDIAN
- monitor open sources without alert fatigueLUCID
- add cyber context to physical securitySTRATUM
- support an ISO 31030 travel programPATHWAY
- report to the board on program performanceAPEX
Definition
What is GSOC software? Global security operations center (GSOC) security, defined.
GSOC software is the system a global security operations center runs on: the system that takes in the signals that touch an enterprise's people, sites, and travel, correlates them to the entities they concern, routes what matters to the right desk, and keeps the record of what was seen and decided. It is corporate security software, distinct from the physical security software and systems that produce many of those signals — access control, video, mass notification — and from the SIEM the CISO's security operations center runs on networks and data. EternaEdge is designed as that platform: one platform foundation, five product pillars, one assistant layer, with people keeping every decision.
A SOC defends networks and data. A GSOC protects people, sites, executives, and travel — and increasingly needs the cyber context the SOC sees, which is what STRATUM is designed to carry across the seam.
Buying it
What procurement asks
The questions that decide an enterprise purchase are about fit, governance, and control. These are our answers.
Complements the systems you keep
Designed to complement, not replace, the access-control, video-management, mass-notification, SIEM, HRIS, and travel-booking systems the program already runs. EternaEdge is not a mass-notification tool and not a physical security information management (PSIM) system. It sits above those layers and is designed to ingest what they see.
Governed data
Every signal lands in one canonical schema with shared historical context, resolved to the entity it concerns. Access is controlled inside the platform, and what automation did and who approved it are part of the audit trail rather than a separate export.
Human-in-the-loop
Orchestration is threshold-based, and consequential steps route to a person for decision. What was detected, what automation did, and who approved it are on the record — the answer to the question the general counsel will ask.
How we secure the platform
The controls we run on the platform itself, and how we handle the data inside it, are described plainly on our security page.
Adoption
How enterprise programs adopt the platform
Start with the most exposed function on the platform foundation, then expand pillar by pillar. Integration is at the data and identity level rather than the console level, so the second pillar makes the first more valuable. A platform architect maps the sequence to the way the program is organized.
FAQ
Questions enterprise programs ask
Plain answers on the terms, the standards, and the boundaries of what the platform is designed to do.
What is a global security operations center (GSOC)?
What is a global security operations center (GSOC)?
A global security operations center (GSOC) is the enterprise function that monitors threats to people, sites, travel, and executives worldwide and coordinates the response. Operators watch events, analysts assess what matters, managers escalate and document. GSOC software brings those signals and workflows into one governed picture. EternaEdge is designed to be that foundation: one platform foundation, five product pillars, one assistant layer. People keep every decision; the platform gives them the picture and the record.
What is the difference between a GSOC and a SOC?
What is the difference between a GSOC and a SOC?
A security operations center (SOC) defends networks and data; the CISO runs it on SIEM, endpoint, and identity tooling. A global security operations center (GSOC) covers the human and physical remit: executives, employees, facilities, travel, events, and the open-source signals around them. Many enterprises run both under different leaders. STRATUM — Cyber Threat adds cyber threat intelligence with counterintelligence context to the GSOC's picture. It is not a SIEM replacement; it complements the stack the CISO already runs.
What is protective intelligence, and how does it support executive protection?
What is protective intelligence, and how does it support executive protection?
Protective intelligence is the proactive identification and assessment of targeting before harm occurs: who is interested in your people, what they have said or done, and whether concern is escalating. OBSIDIAN — Counterintelligence maps what the enterprise protects to who wants it and raises targeting early warning. LUCID — OSINT Awareness correlates open-source signals to named people, sites, and itineraries and is designed to alert in near real time. STRATUM adds the cyber context: whether reconnaissance against the enterprise's digital footprint aligns with the targeting of the same people and sites. Analysts and the executive protection team decide what to do with it.
Does the platform support a workplace violence prevention plan (WVPP), including California SB 553?
Does the platform support a workplace violence prevention plan (WVPP), including California SB 553?
Yes, as support for the employer's own program. FORGE — Investigations provides guided intake for concerning-behavior reports, categorizes and routes them to the threat assessment team, keeps the incident log, and preserves the record with a complete audit trail. OBSIDIAN supplies behavioral baselines and cross-domain context. The multidisciplinary team — security, HR, legal, and behavioral health — makes every determination. EternaEdge is designed to support workplace violence prevention plan programs, including state mandates such as California Labor Code section 6401.9. It is not legal advice and does not replace the plan itself.
Does it support travel risk management, duty of care, and ISO 31030?
Does it support travel risk management, duty of care, and ISO 31030?
PATHWAY — Travel Security supports ISO 31030 compliance programs. ISO 31030 is a guidance standard for managing travel risk; a program follows it, and the record shows how. PATHWAY generates pre-travel briefings from live intelligence, applies multi-factor risk scoring that decides the workflow — brief only, pre-brief, or pre-brief plus mandatory debrief — and monitors travelers in transit, opening a FORGE case automatically on an emergency SOS. Analysts conduct the pre-briefs and debriefs the scoring schedules and respond to every alert. It is designed to help document a defensible duty-of-care program: assessment, briefing, and incident record produced by the workflow itself. It is software, not an assistance service.
What is the difference between insider risk and insider threat, and how does the platform respect employee privacy?
What is the difference between insider risk and insider threat, and how does the platform respect employee privacy?
Insider risk is the exposure any organization carries because trusted people have access; an insider threat is a specific person whose behavior indicates harm, whether malicious, negligent, or manipulated. OBSIDIAN — Counterintelligence supports the program layer: it correlates access, travel, cyber, and open-source anomalies against behavioral baselines, scores them by role and asset sensitivity, and opens a FORGE case at threshold. It is not an endpoint agent and does not record screens or keystrokes. Security, HR, and counsel review every inquiry, and the audit trail shows why an alert fired.
Can it replace the point-solution stack we already run?
Can it replace the point-solution stack we already run?
It is designed to unify the functions those tools split apart — monitoring, protective intelligence, travel risk, insider risk, investigations, and cyber-threat context — on one platform foundation with one entity picture and one audit trail. It is not designed to replace the access-control, video, mass-notification, or SIEM systems you keep; it sits beside them and is designed to ingest what they see. Start with the pillar that maps to the most exposed function and expand across the foundation; a platform architect maps the sequence.
How is AI used for physical security in the GSOC, and who stays in control?
How is AI used for physical security in the GSOC, and who stays in control?
AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight. AI FORCE — Autonomous Intelligence Assistants, in development, is designed so that Sentinel monitors sources, Oracle correlates and briefs, Scribe documents cases, and Guide keeps people moving through the workflow. Every consequential step routes to a person for decision, every automated action is logged, and an analyst can see why an alert fired: the source chain and the verification steps. The goal is context for human judgment, not control over it.
Bring the whole program onto one record.
Tell us how the GSOC, executive protection, investigations, travel, and insider risk are organized today. A platform architect will map one platform foundation, five product pillars, one assistant layer to the way your program actually runs — and to the record it has to keep.