One control plane for exposure, detection, response, intelligence, PQC, and compliance. Explore platform

SecurityPlatform overviewExpansion modulesCompliancePricingContact
← All resources

Learn / frequently asked questions

FAQs

Answers grounded in the Axix Oryx customer presentation — platform, MSSP, production, air-gap, and pricing.

Security professional reviewing platform documentation

Answers grounded in how teams actually deploy Oryx.

Platform scope, MSSP portfolio mode, scan safety, dual approval, air-gap paths, and packaging — without implementation jargon.

These FAQs mirror the customer brief: what Oryx is, coexistence with Splunk and CrowdStrike, MSSP portfolio mode, scan safety Gate, dual approval, air-gap, and packaging.

Five lenses on faqs.

Platform scope

What is Axix Oryx?

A unified cybersecurity control plane for exposure validation, detection, response, compliance evidence, and quantum readiness.

  • Seven modules on one OCSF event language
  • Tenant-safe operations by default
  • Governed automation — not reckless playbooks

Coexistence

Do we have to replace our SIEM or EDR?

No. Connectors extend Splunk, Axix CyberDragon, and roadmap SIEM/SOAR partners while you adopt native modules at your pace.

  • Hybrid SOC paths available today
  • Honest roadmap for QRadar and Sentinel
  • OCSF-native correlation in Sentinel

MSSP

Can one operator serve many clients?

Portfolio mode delivers multi-workspace isolation, grant-audited client entry, and per-tenant branding.

  • Consolidated portfolio dashboard
  • Row-level security per workspace
  • White-label console surfaces

Safety

Is active scanning safe for production?

Safety Gate blocks unauthorized active scans by default. Destructive Reflex actions require dual approval.

  • Passive classification until approved
  • Policy Engine fail-closed
  • Stage-then-execute honesty

Deployment

Where can Oryx run?

SaaS, private cloud, on-premises, and air-gap tiers — scoped to your residency and sovereignty requirements.

  • Jurisdiction packs for regulated sectors
  • Offline LLM path for air-gap
  • Metering for scans, EPS, and seats
FAQ

Frequently asked questions.

What is Axix Oryx?
Axix Oryx is a multi-tenant cybersecurity operating system for enterprises and MSSPs — one control plane powering Vantage, Sentinel, Reflex, Horizon, Aegis, Comply, and Copilot over shared OCSF events.
Do we have to replace Splunk or CrowdStrike?
No. Oryx integrates via connectors. Many customers start with Vantage + Comply while keeping existing SIEM/EDR, then adopt native Sentinel/Reflex at their pace.
Can MSSPs use one platform for all clients?
Yes. Workspace isolation, grant-audited client switch, portfolio dashboard, and per-client branding are built in.
Is active scanning safe for our production network?
Safety Gate blocks unauthorized active scans by default. Passive classification only until dual approval.
Who can approve isolate host or block IP?
Two distinct owner/admin approvers. Analysts can propose but not approve destructive actions.
Can Oryx be deployed air-gapped?
Yes. Deployment tiers include SaaS, private cloud, on-premises, and air-gap (offline, local LLM, no outbound).
How does pricing work?
Packages span Core, Validate, Compliance, Quantum, MSSP, and Enterprise. Contact sales for MSSP and air-gap pricing — metering covers scan usage, alert volume, and seats.

Discuss faqs with the Oryx team.

A guided walkthrough scoped to your SOC, compliance, and production footprint — not a slide deck.