Skip to content
EternaEdge

Markets · Large Enterprise

Run the global security operations center on one governed platform.

Protect the ideas, people, and operations your edge is built on. EternaEdge is GSOC software for corporate security — the global security operations center (GSOC) and the program around it: protective intelligence, insider risk, travel risk management, and investigations with complete auditability on one platform foundation, five product pillars, one assistant layer.

GSOC · Executive protection · Insider risk · Investigations · Travel risk · Cyber threat context

Scroll
01 · Problem

The GSOC runs on a point-solution stack that was never designed to connect.

A large enterprise security program carries the global security operations center, executive protection, threat management, investigations, travel, and insider risk — and most often runs each on a separate tool.

Operators swivel between consoles. Most alarms are noise, and the alarms that matter arrive without the context that would make them urgent: the itinerary, the access record, and the open-source mention that together describe one situation. Real-time feeds tend to measure themselves in sources and seconds, and leave relevance to the analyst.

The record of what was seen and decided is scattered across vendors. Boards ask whether executives are protected. Counsel asks whether the program is defensible. Neither question can be answered from a reconstruction assembled after the fact.

Point tools each watch one domain, and the stack a program assembles today was built to be bought one function at a time. Retrofitted IT security tooling was never designed to detect intent. Detection built around events starts after the loss; detection built around intent starts where the adversary does.

For chief security officers (CSOs) & VPs of corporate security · GSOC directors · chief information security officers (CISOs) · general counsel · heads of executive protection, travel security, insider risk & investigations

The point-solution stack

  1. Real-time event alerting

    Separate vendor · separate data model

  2. Open-source monitoring

    Separate console · keyword alerts

  3. Travel risk & duty of care

    Separate contract · separate traveler record

  4. Investigations & case management

    Spreadsheets, shared drives & email

  5. Insider risk tooling

    Built for IT telemetry · separate login

  6. Cyber threat intelligence feed

    Generic indicators · unlinked to people or sites

  7. Executive protection intelligence

    Manual research · separate inbox

Each line item carries its own contract, console, and record. The seams between them are where the pattern hides. One governed platform — one data fabric, one risk engine, one record.

Seven line items. One governed platform.

Coverage

What a corporate security program has to cover

A corporate security program is the set of functions that protect an enterprise's people, sites, information, and operations from human and physical threats. Eight recur across large programs. Each is a job the platform is designed to carry, with the person who owns it named beside the automation.

The architecture is always the same. One platform foundation: APEX — Platform Foundation. Five product pillars: OBSIDIAN — Counterintelligence, LUCID — OSINT Awareness, FORGE — Investigations, STRATUM — Cyber Threat, and PATHWAY — Travel Security. One assistant layer: AI FORCE — Autonomous Intelligence Assistants, in development.

01

GSOC & intelligence

Round-the-clock awareness of the events that touch people, sites, and travel — relevance-scored, correlated, and summarized so the desk reads risk intelligence rather than feeds.

LUCIDAPEX

02

Executive protection & protective intelligence

Who is interested in your principals, what they have said or done, and whether concern is escalating — designed to surface it for the executive protection team before an approach, not reconstructed after one.

OBSIDIANLUCID

03

Threat assessment & workplace violence prevention

Concerning-behavior reports taken in through guided intake, routed to the threat assessment team, and logged the way the plan requires. The team makes every determination.

FORGEOBSIDIAN

04

Investigations

Ethics, HR, fraud, and intellectual-property matters run in one case system with evidence hashed as it enters custody and an audit trail from initiation to export. Investigators run the matter; counsel reviews inside the same record.

FORGE

05

Travel risk & duty of care

Briefings, risk tiers, and in-travel monitoring for every traveler, with analysts engaged where the risk tier requires them and the assessment and incident record a defensible program calls for.

PATHWAY

06

Insider risk & trade secrets

Cross-domain anomalies scored against role and asset sensitivity; a case opens at threshold; security, HR, and counsel review inside the same record.

OBSIDIANFORGE

07

Supply chain & third-party vetting

Beneficial ownership, sanctions, and adverse media on suppliers, acquisition targets, and key hires — delivered as audit-ready reports so vetting staff, security officers, and counsel make the trust decision before it is extended.

OBSIDIAN

08

Crisis management & business continuity context

Regional risk and event alerts correlated to the facilities and crews they touch, so the crisis team starts with the picture instead of assembling it.

LUCIDPATHWAY

Consolidation

The point-solution stack, and what replaces it

The stack a program assembles today is bought one function at a time: one console per function, one contract per console, one data model per contract. What replaces it is not another console. It is a foundation the functions share.

Vendor sprawl

Status quo

One console per function, one contract per console, one data model per contract.

With EternaEdge

One platform foundation under every function: one canonical schema, one entity picture, one audit trail.

Swivel-chair correlation

Status quo

The connection between an itinerary, an open-source mention, and an access anomaly is found if the same analyst happens to see all three.

With EternaEdge

The shared risk engine scores every signal against everything else known about the same person, site, or program.

Alert fatigue

Status quo

Real-time feeds tend to measure themselves in sources and seconds, and leave relevance to the analyst.

With EternaEdge

Relevance-scored alerts correlated to your people, sites, and itineraries — summaries, not feeds.

Duplicate entity records

Status quo

The same executive tends to exist as a separate record in each tool, each with its own alerts.

With EternaEdge

Entity resolution collapses duplicate records and duplicate alerts into one picture.

Audit gaps

Status quo

What was seen, what was decided, and who approved it lives in inboxes, spreadsheets, and vendor logs.

With EternaEdge

Every consequential step is on the record — what was detected, what automation did, who approved — with authenticated export.

Per-tool logins

Status quo

A login per tool and a mental model per vendor for every analyst.

With EternaEdge

One governed platform with access controls set inside it; every user works inside the same authority and oversight model.

What stays

The platform is designed to complement, not replace, the systems the GSOC keeps — access control, video management, mass notification, the security information and event management (SIEM) platform, the human resources information system (HRIS), and travel booking. EternaEdge is not a mass-notification tool and not a physical security information management (PSIM) system. It sits above those layers and is designed to ingest what they see — the badge event, the itinerary, the alarm — into one entity picture.

  • Access control
  • Video management
  • Mass notification
  • SIEM
  • HRIS
  • Travel booking

Operations

How a global security operations center runs it

Four seats, one common operating picture, one record. Each role sees the picture its job requires, acts inside its own authority, and leaves a record the next role can rely on.

GSOC analyst

Sees
One queue of relevance-scored alerts, each already correlated to the people, sites, and itineraries it touches.
Does
Assesses, escalates, or closes — and opens a case when the picture warrants it.
The record it leaves
Every alert, assessment, and escalation logged with source and time.

Executive protection lead

Sees
Targeting indicators for each principal, the itinerary risk of the day, and the open-source signal around venues.
Does
Adjusts posture, requests a briefing, tasks the advance team.
The record it leaves
The protective-intelligence file the program can show the board.

Investigations lead

Sees
Cases that arrive with the entity timeline already assembled and evidence hashed as it enters custody.
Does
Assigns, investigates, resolves; counsel reviews inside the same record.
The record it leaves
Complete auditability, with authenticated export for counsel.

General counsel & the board

Sees
Program posture in outcomes: what was detected, what was decided, and who approved it.
Does
Asks whether the program is defensible — and gets the record, not a reconstruction.
The record it leaves
An audit-ready account of the program, built as events happened.

A day on the watch floor

Four signals arrive in four domains — open-source intelligence (OSINT), travel, cyber, and insider — over one day. Point tools each see one of them. The platform resolves all four to the same site, the same trip, and the same people — and opens one case.

Illustrative · designed behavior, not a customer result

  1. 02:14

    OSINT

    Unrest reported near a regional office

    LUCID
  2. 06:40

    Travel

    Executive itinerary lands in-region

    PATHWAY
  3. 09:05

    Cyber

    Supplier credential exposure surfaces

    STRATUM
  4. 13:30

    Insider

    Contractor access anomaly outside baseline

    OBSIDIAN
  5. Then

    One case · one timeline · entity-resolved

    Case opened at threshold. An analyst decides; the platform made sure the decision arrived in time.

    FORGE

Protective intelligence

Protective intelligence for executives and the workforce

Board attention has moved executive protection from a line item to a program with a mandate. The mandate is protective intelligence — and it has to cover the workforce as well as the principals.

What protective intelligence is

Protective intelligence is the proactive identification, assessment, and management of targeting before harm occurs. It asks who is interested in your people, what they have said or done, and whether concern is escalating — and it answers with a record, not a hunch. It is the discipline that lets an executive protection program act early and explain why it acted.

Executive protection and digital executive protection

OBSIDIAN Shield maps what the enterprise protects — principals, sites, programs — to who wants it, and raises targeting early warning across open-source, cyber, and travel signals. LUCID Pulse correlates open-source events to named people, venues, and itineraries, relevance-scored so the team reads summaries rather than feeds: the intelligence layer of digital executive protection, not a personal-data removal service. STRATUM Watch adds reconnaissance early warning — whether known actors are probing the enterprise around the same people and sites. The executive protection lead sets posture and tasks the advance team; the platform is designed to put the picture in front of them.

Behavioral threat assessment and the workplace violence prevention plan

FORGE Intake takes concerning-behavior reports through guided questionnaires, categorizes and routes them to the threat assessment team, and keeps the incident log the plan requires. OBSIDIAN Guard supplies behavioral baselines and cross-domain context, so the team assesses a person rather than a single report. The multidisciplinary team — security, HR, legal, behavioral health — makes every determination. The platform is designed to support workplace violence prevention plan (WVPP) programs, including state mandates such as California Labor Code section 6401.9. It is not legal advice and does not replace the plan.

Travel risk

Travel risk management and duty of care at corporate-program scale

Travel risk management is the discipline of preparing travelers before they go, staying aware while they are gone, and keeping the record that shows both were done. At program scale the work has to be automated first and staffed by exception.

PATHWAY — Travel Security supports ISO 31030 compliance programs. The assessment, the briefing, and the incident record are produced by the workflow itself rather than reconstructed for an audit — the record a defensible program depends on: reasonable steps, recorded. It is designed to help document a defensible duty-of-care program for every traveler, not only the principals who used to get a hand-built briefing.

Analysts conduct the pre-briefs and debriefs the scoring schedules, and security teams respond to every alert and SOS with the traveler's context already in front of them. PATHWAY is software, not an assistance service.

PATHWAY Brief

Briefings generated from live intelligence, including foreign-intelligence targeting context, delivered automatically for routine trips.

Human role

Analysts review and tailor high-risk briefings.

PATHWAY Risk

Multi-factor scoring across security, political, environmental, and health dimensions decides the workflow: brief only, pre-brief, or pre-brief plus mandatory debrief.

Human role

Analysts conduct the pre-briefs and debriefs; leadership tunes the thresholds.

PATHWAY Beacon

In-travel monitoring around the clock with location-based reassessment and emergency SOS — a FORGE case opens automatically on activation.

Human role

Security teams respond to every alert and SOS event.

Insider risk

An insider risk program the CSO, HR, and counsel can all stand behind

Insider risk is the exposure an enterprise carries because trusted people have access. A program the general counsel will sign is one that correlates signals the organization already governs, shows why an alert fired, and puts every determination in human hands.

OBSIDIAN — Counterintelligence builds behavioral baselines and correlates anomalies across access, travel, cyber, and open-source signals, scored by role and asset sensitivity through the shared risk engine. At threshold, a FORGE case opens with the entity timeline already assembled. Insider-risk analysts review, direct inquiries, and make every determination; HR and counsel review inside the same record.

It is not an endpoint agent and does not record screens or keystrokes. It is designed to reduce indiscriminate monitoring, not add to it — risk-prioritized output, human determination, and an audit trail that shows what was correlated and why.

OBSIDIAN Guard

Looks inward. Behavioral baselines and cross-domain anomaly correlation; a FORGE case opens automatically at threshold.

Human role

Insider-risk analysts review and make all determinations.

OBSIDIAN Shield

Looks outward. Maps what you protect to who wants it — targeting early warning, supply-chain exposure, and foreign-dependency identification.

Human role

Program protection leads validate warnings and choose countermeasures.

OBSIDIAN Check

Looks at who you are about to trust. Beneficial ownership, sanctions, politically exposed persons, and adverse media on acquisition targets, suppliers, and key hires — as audit-ready reports.

Human role

Vetting staff, security officers, and counsel make the trust decision.

Investigations

Investigation case management with complete auditability

Ethics, HR, fraud, and intellectual-property matters end up in front of counsel, a regulator, or a court. The record they find there should have been built as the work happened.

FORGE — Investigations opens cases automatically when the risk engine crosses threshold, from an Intake report, or by hand. Each case arrives entity-centric: the people, sites, and programs involved on one timeline, with every known signal attached, so security, HR, legal, and ethics investigate in one case rather than four silos.

Investigators run the investigation; counsel reviews inside the same record; the export carries an authentication certificate. Complete auditability is the promise — every access and transfer logged, every evidence item hashed — and the human judgment that closes a case stays human.

FORGE CaseOps

Automated case creation at risk thresholds, task assignment with deadlines and escalation, and entity-centric timelines with the intelligence picture attached.

Human role

Investigators run the investigation; supervisors see workload and deadlines.

FORGE Intake

Guided reporting for incidents, ethics matters, and foreign contacts, categorized and routed automatically to the right queue.

Human role

Reviewers receive triaged, complete reports; reporters get a low-friction path.

FORGE Chain

SHA-256 evidence hashing, tamper detection, a complete audit trail of every access and transfer, access controls inside the case system, and authenticated export.

Human role

Investigators and counsel rely on the record; integrity is automatic rather than procedural.

Cyber threat context

Cyber threat intelligence in counterintelligence context — not a SIEM replacement

Security convergence, in practice: not a SIEM replacement, and not a vulnerability scanner. The CISO keeps the security operations center; the GSOC gains the cyber context its picture has been missing.

STRATUM— Cyber Threat sits above the SIEM, endpoint, and vulnerability tooling the CISO already runs and answers a question those tools were not built to answer: what does this digital activity mean for our people, our sites, and our program? Exposure is prioritized by mission impact rather than raw volume, so the ranking is designed to put what matters to the program at the top of the analyst’s list.

The seam between the SOC and the GSOC is where serious compromises can hide: a digital anomaly the SOC judged low and a behavioral anomaly the insider-risk program judged low that together describe one person. STRATUM Signal corroborates OBSIDIAN assessments in both directions — alignment raises confidence, its absence reduces it — and cyber analysts and counterintelligence teams make every call.

STRATUM Watch

Threat-actor profiling with attribution confidence, campaign correlation, dark-web monitoring, and reconnaissance early warning.

Human role

Cyber analysts tune priorities and decide response postures.

STRATUM Vector

Attack surface mapping and shadow-IT discovery, with exposure prioritized by mission impact rather than raw counts of known vulnerabilities (CVEs).

Human role

Security teams work a short, mission-ranked exposure list.

STRATUM Signal

Cyber-insider nexus detection that corroborates OBSIDIAN findings — raising or reducing confidence with every new signal.

Human role

Counterintelligence teams and cyber analysts make every determination.

02 · Promise

One platform foundation for every corporate security function.

A corporate security platform is one governed foundation under every function the program carries — one platform foundation, five product pillars, one assistant layer. Start with the pillar that maps to the most exposed function, then expand across the foundation; each product makes the next more valuable, because they share one entity picture and one audit trail.

APEX — Platform Foundation is the foundation under all five: one data fabric, one shared risk engine, entity resolution, and orchestration with human-in-the-loop controls on every consequential step.

Explore Platform
AI FORCE

AI for physical security, governed.

The assistant layer is in development. It is designed as the capability multiplier that enables enterprise-wide protection without added staff — and it is designed to be governed before it is designed to be fast.

AI FORCE — Autonomous Intelligence Assistants is designed so that Sentinel monitors every source around the clock, Oracle correlates signals and delivers briefings on demand, Scribe documents cases continuously with the chain of custody in view, and Guide keeps people moving through the workflow. Your analysts and leadership stay in command: every consequential step routes to a person for decision, every automated action is logged, and an analyst can see why an alert fired — the source chain and the verification steps.

AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight.

Figures from the pillars

150+
LUCID collection agents
50+
LUCID languages
<30s
LUCID critical alerts
2–4
PATHWAY analyst-hours per traveler

Designed capability of the product pillars — not measured customer results.

03 · Outcome

Early warning, defensible action, an audit-ready record.

The program the CSO can defend to the board and the general counsel can defend anywhere — designed so fewer analyst-hours go to each alert, not more.

01

Early warning

Designed to surface targeting during the reconnaissance phase — the approach to a principal, the probe of a supplier, the anomaly in trusted access — while there is still time to act.

02

Defensible action

Human-in-the-loop controls on every consequential step. What was detected, what automation did, and who approved it are on the record as it happens, not reconstructed for counsel.

03

Audit-ready record

Complete audit trails with authenticated export, ready for the general counsel, the board, and regulators. Supports ISO 31030 compliance programs for travel and workplace violence prevention plan programs for threat management.

Enterprise security risk management (ESRM) asks the program to tie every control to a business risk and an owner. The platform is designed to make that case in outcomes — and to scale the program without standing up a round-the-clock watch floor.

Definition

What is GSOC software? Global security operations center (GSOC) security, defined.

GSOC software is the system a global security operations center runs on: the system that takes in the signals that touch an enterprise's people, sites, and travel, correlates them to the entities they concern, routes what matters to the right desk, and keeps the record of what was seen and decided. It is corporate security software, distinct from the physical security software and systems that produce many of those signals — access control, video, mass notification — and from the SIEM the CISO's security operations center runs on networks and data. EternaEdge is designed as that platform: one platform foundation, five product pillars, one assistant layer, with people keeping every decision.

A SOC defends networks and data. A GSOC protects people, sites, executives, and travel — and increasingly needs the cyber context the SOC sees, which is what STRATUM is designed to carry across the seam.

Buying it

What procurement asks

The questions that decide an enterprise purchase are about fit, governance, and control. These are our answers.

Complements the systems you keep

Designed to complement, not replace, the access-control, video-management, mass-notification, SIEM, HRIS, and travel-booking systems the program already runs. EternaEdge is not a mass-notification tool and not a physical security information management (PSIM) system. It sits above those layers and is designed to ingest what they see.

Governed data

Every signal lands in one canonical schema with shared historical context, resolved to the entity it concerns. Access is controlled inside the platform, and what automation did and who approved it are part of the audit trail rather than a separate export.

Human-in-the-loop

Orchestration is threshold-based, and consequential steps route to a person for decision. What was detected, what automation did, and who approved it are on the record — the answer to the question the general counsel will ask.

How we secure the platform

The controls we run on the platform itself, and how we handle the data inside it, are described plainly on our security page.

Security at EternaEdge 

Adoption

How enterprise programs adopt the platform

Start with the most exposed function on the platform foundation, then expand pillar by pillar. Integration is at the data and identity level rather than the console level, so the second pillar makes the first more valuable. A platform architect maps the sequence to the way the program is organized.

FAQ

Questions enterprise programs ask

Plain answers on the terms, the standards, and the boundaries of what the platform is designed to do.

What is a global security operations center (GSOC)?

A global security operations center (GSOC) is the enterprise function that monitors threats to people, sites, travel, and executives worldwide and coordinates the response. Operators watch events, analysts assess what matters, managers escalate and document. GSOC software brings those signals and workflows into one governed picture. EternaEdge is designed to be that foundation: one platform foundation, five product pillars, one assistant layer. People keep every decision; the platform gives them the picture and the record.

What is the difference between a GSOC and a SOC?

A security operations center (SOC) defends networks and data; the CISO runs it on SIEM, endpoint, and identity tooling. A global security operations center (GSOC) covers the human and physical remit: executives, employees, facilities, travel, events, and the open-source signals around them. Many enterprises run both under different leaders. STRATUM — Cyber Threat adds cyber threat intelligence with counterintelligence context to the GSOC's picture. It is not a SIEM replacement; it complements the stack the CISO already runs.

What is protective intelligence, and how does it support executive protection?

Protective intelligence is the proactive identification and assessment of targeting before harm occurs: who is interested in your people, what they have said or done, and whether concern is escalating. OBSIDIAN — Counterintelligence maps what the enterprise protects to who wants it and raises targeting early warning. LUCID — OSINT Awareness correlates open-source signals to named people, sites, and itineraries and is designed to alert in near real time. STRATUM adds the cyber context: whether reconnaissance against the enterprise's digital footprint aligns with the targeting of the same people and sites. Analysts and the executive protection team decide what to do with it.

Does the platform support a workplace violence prevention plan (WVPP), including California SB 553?

Yes, as support for the employer's own program. FORGE — Investigations provides guided intake for concerning-behavior reports, categorizes and routes them to the threat assessment team, keeps the incident log, and preserves the record with a complete audit trail. OBSIDIAN supplies behavioral baselines and cross-domain context. The multidisciplinary team — security, HR, legal, and behavioral health — makes every determination. EternaEdge is designed to support workplace violence prevention plan programs, including state mandates such as California Labor Code section 6401.9. It is not legal advice and does not replace the plan itself.

Does it support travel risk management, duty of care, and ISO 31030?

PATHWAY — Travel Security supports ISO 31030 compliance programs. ISO 31030 is a guidance standard for managing travel risk; a program follows it, and the record shows how. PATHWAY generates pre-travel briefings from live intelligence, applies multi-factor risk scoring that decides the workflow — brief only, pre-brief, or pre-brief plus mandatory debrief — and monitors travelers in transit, opening a FORGE case automatically on an emergency SOS. Analysts conduct the pre-briefs and debriefs the scoring schedules and respond to every alert. It is designed to help document a defensible duty-of-care program: assessment, briefing, and incident record produced by the workflow itself. It is software, not an assistance service.

What is the difference between insider risk and insider threat, and how does the platform respect employee privacy?

Insider risk is the exposure any organization carries because trusted people have access; an insider threat is a specific person whose behavior indicates harm, whether malicious, negligent, or manipulated. OBSIDIAN — Counterintelligence supports the program layer: it correlates access, travel, cyber, and open-source anomalies against behavioral baselines, scores them by role and asset sensitivity, and opens a FORGE case at threshold. It is not an endpoint agent and does not record screens or keystrokes. Security, HR, and counsel review every inquiry, and the audit trail shows why an alert fired.

Can it replace the point-solution stack we already run?

It is designed to unify the functions those tools split apart — monitoring, protective intelligence, travel risk, insider risk, investigations, and cyber-threat context — on one platform foundation with one entity picture and one audit trail. It is not designed to replace the access-control, video, mass-notification, or SIEM systems you keep; it sits beside them and is designed to ingest what they see. Start with the pillar that maps to the most exposed function and expand across the foundation; a platform architect maps the sequence.

How is AI used for physical security in the GSOC, and who stays in control?

AI assistants operate within APEX, using governed, auditable data. They do not bypass authority, workflows, or oversight. AI FORCE — Autonomous Intelligence Assistants, in development, is designed so that Sentinel monitors sources, Oracle correlates and briefs, Scribe documents cases, and Guide keeps people moving through the workflow. Every consequential step routes to a person for decision, every automated action is logged, and an analyst can see why an alert fired: the source chain and the verification steps. The goal is context for human judgment, not control over it.

Bring the whole program onto one record.

Tell us how the GSOC, executive protection, investigations, travel, and insider risk are organized today. A platform architect will map one platform foundation, five product pillars, one assistant layer to the way your program actually runs — and to the record it has to keep.

 All markets