WITHSTAND

One platform for your
complete data.

A sovereign raw-data lake beneath a mature, accredited body of detection and compliance content, with machine learning and constrained generative AI that never leave your boundary. Software on certified hardware or in your accredited private cloud.

An accredited layer, a new platform beneath.

Build order is deliberate: data plane first, capability overlay second, machine learning third, generative AI last. Each layer depends on the one beneath it, and nothing is routed outside your boundary to be analysed.

Sources: IT, OT, IoT, AI systems, data storesSovereign data planeCapability overlay: detection, correlation, complianceMachine learningGenerative AIInside your boundary

What the platform is built to do.

Every capability reads the same complete data on infrastructure you control.

  • Sovereign data plane

    Building now

    All telemetry lands once, raw, in open formats.

    Logs, endpoint, network, identity, file activity, OT protocol events, IoT device events and AI traces land in one store on hardware you control, queryable in seconds from hot storage. A streaming backbone, a columnar analytical store and an open-table lake for retention. You set retention; the vendor does not meter it.

  • Detection and correlation

    In production

    A mature body of content, running on complete data.

    Real-time rule evaluation on the stream, with detection content expressed in the open Sigma standard alongside native rules. Correlation runs on entities, not on log lines, so the same actor touching an identity, a model and a data store is seen as one story.

  • Compliance engine

    In production

    Whether a control fired, not whether it is documented.

    Control-level measurement of regulatory obligations from the same telemetry: government control baselines, operational-resilience rules and critical-infrastructure regimes. Continuous, evidenced, and mapped to the obligations a board is accountable for.

  • Investigation and response

    Building now

    Ask any question of any data, then act inside your boundary.

    Sub-second investigation over billions of events from one query surface. Response workflows run as data through an embedded orchestration engine; a human approves execution, and every action is recorded against the evidence that justified it.

  • Machine learning

    Roadmap

    Behavioural detection at millions of events per second.

    Baselining, anomaly scoring and classification per entity and per protocol, against the analytical store. CPU-class work, trained in Withstand's build environment and shipped as signed artefacts through the same offline channel as software.

  • Generative AI, constrained

    Roadmap

    Explains, drafts and ranks, and is never the lead detection claim.

    An open-weight model served on your own GPU tier, restricted to natural-language query, obligation-mapped incident narrative for boards, and response-playbook drafting. Nothing model-related leaves your environment, and your data never trains anyone's models.

Five source classes, because an adversary moves between them.

Collection is where most platforms quietly narrow their claims. A sovereign environment contains all five, and the platforms you already run are sources too.

  • IT

    In production

    Endpoint process, file, registry and network events; server and application logs; identity, privileged access and MFA; network flow and DNS; firewall, proxy and email gateway; hypervisor and storage events. Collected by agent, event forwarding, syslog, agentless pulls and network sensor.

  • OT

    Building now

    Asset inventory and protocol-level events from PLCs, RTUs, SCADA servers, HMIs and historians; control commands, set-point changes, firmware and logic changes. Observed passively on SPAN or TAP, crossing into the enterprise side through a data diode. Active scanning of OT assets is never performed.

  • IoT

    Building now

    Device discovery and fingerprinting; camera, sensor, building-management, access-control and medical-device traffic; broker and gateway events. Most devices cannot host an agent, so the value is behavioural baselining against each device's own normal.

  • AI systems

    Building now

    Prompts, responses and tool calls through AI gateways; agent actions and privilege use; model registry and deployment events; vector store and retrieval access; guardrail outcomes. Captured as OpenTelemetry-compatible traces and joined to the identity that initiated them and the data they touched.

  • Data stores

    Building now

    File and share access audit; database audit logs; classification and sensitivity labels; DLP and rights-management events; removable-media and cross-boundary transfer events. Lineage from source to model to output.

  • The platforms you already run

    In production

    Cloud security platforms and specialist OT monitoring tools are consumed as sources, not replaced. Withstand is the sovereign layer beside what you already run, for the networks those platforms cannot serve.

Every vendor now claims sovereign. It is a threshold with four tests.

TestWhat it requiresWhy it matters
OperationalThe platform runs inside your boundary; nothing phones home; updates arrive by controlled media.Any external dependency is an unassessed path into the most sensitive system on the network.
JurisdictionalThe vendor is owned, controlled and answerable inside your jurisdiction.Foreign ownership, foreign capital and foreign legal obligations survive on-premises deployment. Running the software yourself does not change who the vendor answers to.
Supply chainDocumented provenance of every component; imaging and hardening performed in-country; no excluded-vendor parts.Accreditation attaches to specific bills of materials. Supply chain is now a primary attack surface.
AI data governanceYour data never leaves your environment and never trains anyone's models, the vendor's or a third party's.Digital sovereignty has moved past privacy to control over national-interest data and AI training material.

Operational sovereignty means you run the software. Jurisdictional sovereignty means the vendor answers to your law. Only the second is a matter of law rather than trust. Withstand is independently owned, carries no intelligence-community capital, is delivered and hardened in your jurisdiction, and is designed so that inference happens inside your accreditation boundary. It is built to clear all four tests.

Machine learning detects. Language models explain, draft and rank.

Classical machine learning: detection

  • Enterprise environments generate millions of events per second. Token cost and context limits make generative models the wrong tool for real-time detection.
  • Behavioural baselining, anomaly scoring and gradient-boosted classification run against complete raw data, per entity and per protocol.
  • Models are trained in Withstand's build environment and shipped as signed artefacts. Adaptation on your telemetry runs on your own hardware and never leaves it.
  • Machine learning augments a mature body of detection content. It is never the lead claim.

Generative AI: three constrained jobs

  • Natural-language query of the lake in place of complex interfaces.
  • Incident and posture narratives mapped to your regulatory obligations, in language a board can act on.
  • Response playbooks drafted dynamically rather than from rigid templates. A human approves execution; a learned policy never chooses containment actions on a control network.

Withstand will never lead with an 'AI-powered detection' claim. Its detection credibility comes from proven content augmented by classical machine learning; generative capability is applied only where it is the right tool. Models are open-weight with published provenance and a model bill of materials, signed alongside each release.

Software on hardware you control, in your jurisdiction.

A signed image on certified hardware or in your accredited private cloud. Single site, clustered, hub and spoke, or one instance per classification domain. Nothing leaves the boundary.

  • Certified hardware

    Building now

    Your own servers from Withstand's hardware compatibility list, imaged and enrolled with a signed operating-system image, measured boot and drive binding. For agencies bound to hardware panels and estates that already own the metal.

  • Virtual

    Building now

    The same signed image as a virtual machine in your already-accredited private cloud. The trust posture is reduced and stated as such: the hypervisor is in the trust base.

  • Hub and spoke

    Building now

    A core instance plus edge collectors and passive sensors at remote sites and OT zones, joined by diodes or constrained links. Collectors hold local evidence if the link is lost and reconcile on reconnection.

  • Classification-separated

    Building now

    One instance per classification domain, with one-way flows through cross-domain guards where policy permits. Updates, content and models arrive on signed media and are verified against the trust root before use.

A security platform that cannot withstand attack is a liability.

Withstand is engineered on the assumption that it will be targeted. An attacker who reaches the monitoring layer can blind the organisation, alter evidence and hide.

  • Trust root and measured boot

    Building now

    A signed, immutable operating-system image on certified hardware, with measured boot from firmware to container images. The system refuses to run altered software and can prove what it is running.

  • Immutable evidence

    Building now

    Retained telemetry and audit logs are written to write-once storage tiers with cryptographic chaining, so an intruder who reaches the platform cannot silently alter history.

  • Least privilege inside the box

    Building now

    Services run isolated with per-service identities. Administrative access is role-based, multi-factor and fully audited. No shared credentials, no vendor back door.

  • Keys and encryption

    Building now

    FIPS-validated encryption at rest with keys bound to the TPM or an external HSM where mandated. Crypto-erase supports classified decommissioning.

  • Self-monitoring

    Building now

    The platform monitors itself with the same detection engine and raises alerts on its own integrity, configuration and access events to a separate, minimal channel.

  • Recovery

    Building now

    Offline, signed backups of configuration, detection content and models, and documented bare-metal recovery to a known-good state without any external service.

Build the next generation with us.

The next-generation Withstand platform is being built with design partners whose constraints are the specification. If your networks cannot leave, you are who this is for.

Become a design partner