New: Telecom-native cyber defense for ISPs and operators  Explore OneMesh →
XSecurity One/Platform
The XSecurity One platform

The security decision layer for connected infrastructure.

XSecurity One brings security signals, evidence, graph context, detection, investigation and guarded response into one architecture.

Architecture

Eight logical planes. One decision path.

Signals enter at the edge and leave as approved, signed, reversible actions — with evidence preserved at every plane in between.

Endpoint & Edge

Agents, sensors and collectors gather authorized telemetry from endpoints, workloads, network elements and telecom infrastructure.

Collect
Ingestion

Parsing, normalization and enrichment into one canonical event model with tenant, asset and identity resolution.

Normalize
Detection

Behavioral analytics, rules-as-code and scheduled detections evaluated against enriched events and baselines.

Detect
Security Graph

Assets, identities, processes, domains, network elements, data and telecom context connected as one queryable graph.

Correlate
Response

Playbooks, approvals, blast-radius checks and guarded automation executing signed, scoped, reversible actions.

Act
Control

Tenancy, policy, RBAC, quotas and release controls governing everything the platform is allowed to do.

Govern
Experience

SOC console, investigation views, hunting, dashboards and APIs — the surfaces where humans meet the platform.

Operate
Evidence

An append-only evidence layer preserving events, decisions, approvals and actions for investigation and regulators.

Preserve
OneCore

One core. Nine responsibilities.

OneCore is the unified data, graph, policy, evidence and decision layer every module reads and writes. Nothing in XSecurity One keeps a private copy of the truth.

See how modules build on OneCore
Tenant

Hard isolation and per-tenant policy

Asset

Endpoints, workloads, network elements

Identity

Users, service accounts, privileges

Graph

Relationships across every domain

Policy

What may be detected, stored, done

Evidence

Append-only, exportable, auditable

Incident

The unit of understanding & action

Response

Approvals, execution, rollback

Integration

Connectors in, enforcement out

onecore · canonical event
{
  "event_id":      "evt_9f42e1a8",
  "tenant_id":     "tn_xeonfiber",     // hard isolation boundary
  "timestamp":     "2026-08-22T09:52:18.412Z",
  "source":        "onemesh.netflow",
  "asset_ref":     "ast_cpe_88h2",     // resolved, not raw
  "identity_ref":  "idn_pseu_4471",    // pseudonymous
  "network":       { "proto": "udp", "dst": "185.x.x.24:53" },
  "process":       null,               // no agent on CPE
  "evidence_ref":  "evd_c2214",        // append-only store
  "correlation_id":"inc_0248"          // one incident
}
Unified event model

Every signal speaks the same language.

An EDR process event, a NetFlow record and a RADIUS accounting packet all normalize into one schema — with tenant, asset, identity, evidence and correlation references resolved at ingestion.

That is what makes cross-domain correlation a query, not a data-science project.

Security graph

See how risk can move.

Assets, identities, processes, domains, network paths, data stores and telecom elements — one graph your detections, investigations and blast-radius checks all query.

onecore · graph explorer Evidence linked
Identity r.mehta Asset WKS-114 Session vpn-2291 Process svcx.exe Telecom CPE-88H2 Correlated INC 0248 signed in opened spawned routed via links to raises blast radius
Guarded response

Automate response without automating regret.

Every action moves through the same guarded path — no shortcuts, including for the platform's own AI.

01Detection
02Proposed action
03Blast-radius check
04Human approval
05Signed command
06Evidence written
07Rollback available
Approval required Tenant scoped Time limited Signed action Rollback available
Deployment models

Security architecture that meets the environment where it runs.

India SaaS

Xonware-managed, India-hosted. Control plane, event store and evidence remain in-region.

Dedicated hosted

A single-tenant environment operated for you — your data, your update window, your DR plan.

Private cloud

Deploy into your own subscription with your identity provider and your encryption keys.

On-premises

Full on-premises for regulated, sovereign and critical-infrastructure environments.

Walk the architecture with the people who built it.

A working session on your estate, your telemetry sources and your constraints — not a slide deck.