New: Telecom-native cyber defense for ISPs and operators  Explore OneMesh →
XSecurity One/Products
The module family

One platform. Modules that light up as you grow.

Every XSecurity One module reads and writes the same OneCore data model, security graph and evidence layer. Product names are typographic labels — the platform is the product.

Production Pilot Preview Roadmap
Protect

Stop threats at every domain.

EPP · EDR · Workload

XSecurity One / OnePulse Pilot

Stop endpoint threats where they start.

Endpoint telemetry, behavioral detection, local protection and guarded response — with a process-and-ancestry story for every detection, not a bare alert.

behavioral telemetryprocess treeransomware protectioncredential-abuse detectionoffline protectionhost isolationtriage collectionsigned updates
NDR · Telecom

XSecurity One / OneMesh Pilot

Network detection built with telecom context.

Flow, DNS, RADIUS, BNG, CGNAT, OLT/ONU, CPE and routing signals — detected against operator-scale baselines and connected to the incident that matters.

netflow · ipfixdns tunnellingbeaconingcpe compromiseradius anomalybgp · rpkiguarded network action
Explore OneMesh
ITDR · Identity posture

XSecurity One / OneIdentity Preview

Stop identity attacks before trust becomes movement.

Identity threat detection, posture and privileged-access risk — because most modern intrusions sign in before they break in.

anomalous sign-inprivilege escalationidentity-to-asset linkssession revocation
CNAPP · CSPM · CWPP

XSecurity One / OneCloud Preview

Connect cloud posture to runtime reality.

Cloud posture, workload protection, entitlements and container security — correlated with everything else in the graph, from code to cloud to runtime.

cspmcwppciemkubernetescloud detection & response
DSPM · DLP

XSecurity One / OneData Preview

Know where sensitive data is. Know when it moves.

Data discovery, classification and loss prevention — feeding the same incident pipeline when sensitive data starts moving somewhere it shouldn't.

discoveryclassificationmovement detectiondpdp-aware categories
AI security

XSecurity One / OneAI Guard Preview

Secure the agents that can act.

AI application, agent, model and tool-call security — the same evidence discipline applied to the fastest-growing part of your attack surface.

agent tool-call pathsprompt securitymodel accessmcp security
Detect & investigate

Understand the attack, not the alert.

XDR

XSecurity One / OneSight Pilot

Turn separate detections into one attack story.

Cross-domain incidents with entity correlation, attack timeline, blast radius and evidence references. Less alert stitching. More attack understanding.

unified incidentsattack timelineroot-cause hypothesisgraph blast radiusrecommended investigation
Next-gen SIEM

XSecurity One / OneSignal Pilot

Security data that is ready to answer questions.

Collectors, normalization, bounded high-speed hunt, rule-as-code detection engineering, retention tiers and honest cost visibility — with evidence export built in.

live tailsaved searchesrules as codeparser lifecycletenant quotasingestion visibility
Threat intelligence

XSecurity One / OneIntel Preview

Intelligence that enters the investigation, not another portal.

IOC/IOA intelligence, hunting content and sector context surfaced inside the incident — where a decision is actually being made.

ioc · ioahunting contentsector intelligence
Exposure management

XSecurity One / OneExposure Preview

Prioritize what can actually become an incident.

Exposure, vulnerability and attack-path management scored against your graph — not a generic CVSS list.

attack pathsreachabilitygraph-scored priority
DFIR

XSecurity One / OneForensics Preview

Preserve the story before the evidence disappears.

Incident response, forensic collection and chain-of-custody — on the same evidence layer regulators will eventually ask about.

triage collectionchain of custodyevidence export
Respond & govern

Act safely. Prove it afterwards.

SOAR

XSecurity One / OneFlow Pilot

Automate response without automating regret.

Visual playbooks guarded by scope, confidence, approvals, blast radius, time limits, rollback and audit — regret-minimizing response by design.

visual playbookshuman approvalcompensation · rollbackkill switchexecution evidence
India governance

XSecurity One / OneGovern Pilot

From incident evidence to regulatory readiness.

CERT-In six-hour workflows, DPDP breach assessment and DoT evidence — built from the incident's own evidence chain, with human sign-off.

regulatory clock fabricevidence chronologybreach assessmentsubmission tracking
Explore OneGovern
XIMS integration

XSecurity One / OneBridge for XIMS Pilot

Connect subscriber context to security response — without duplicating OSS/BSS.

A narrow, signed, audited bridge: pseudonymous subscriber references and security events in; quarantine recommendations, CoA and block requests back. Purpose-bound. Minimal. Audited.

pseudonymous refsactive ip mappingcpe · onu idsquarantine requestradius coa
MDR service

XSecurity One / OneCommand MDR Preview

A managed SOC built on the same evidence your team sees.

Multi-tenant MDR with strict tenant boundaries and delegated access — a managed service without a black box.

multi-tenant socdelegated accessshared evidence view
Resilience

XSecurity One / OneResilience Roadmap

Security is not complete until recovery is proven.

Cyber-resilience, recovery evidence, deception and clean-room workflows — planned as the closing loop of the platform.

recovery evidenceclean-room workflowdeception

Start with the module that hurts most.

Every module stands alone and gets stronger together — because they all read the same graph.