One control plane for exposure, detection, response, intelligence, PQC, and compliance. Explore platform

SecurityPlatform overviewExpansion modulesCompliancePricingContact
← All resources

Learn / platform flow

How it works

Vulnerability → case → remediation across Vantage, Sentinel, Reflex, approval, and Comply.

Analysts walking through the platform workflow on a wall display

From finding to evidence — one governed chain.

Vantage surfaces exposure, Sentinel correlates alerts, Reflex stages response, and Comply maps live evidence — with approval gates throughout.

Presentation flow: Vantage finds a critical issue as an OCSF Security Finding → Sentinel correlates related alerts → Reflex auto-creates a case → analyst approval with staged response if destructive → Comply maps scan and case as live control evidence.

Five lenses on how it works.

Step 1

Vantage finds authorized exposure.

Continuous validation produces OCSF Security Findings scoped to the workspace and approved scan policy.

  • Safety Gate before active scans
  • Signed reports per tenant
  • Feeds Sentinel correlation

Step 2

Sentinel correlates related alerts.

Tenant-scoped indices normalize events in OCSF and build entity timelines analysts can trust.

  • Hybrid Splunk connector path
  • AI-drafted rules — human approved
  • Jurisdiction overlays

Step 3

Reflex opens a governed case.

Playbooks are proposed — not auto-fired — with Kanban stages from new through resolved.

  • Dual approval for isolate and block
  • Dead-letter queue with audit
  • OCSF triggers from Sentinel

Step 4

Analyst approves staged response.

Destructive actions wait for two distinct owner/admin approvers before execution.

  • Policy Engine fail-closed
  • No fake completed states
  • Connector paths stay governed

Step 5

Comply records live control evidence.

Scans, cases, and approvals map to frameworks as continuous proof — not point-in-time exports.

  • SOC 2, ISO 27001, PCI mappings
  • Regional packs: DORA, RBI, MAS
  • Exportable evidence packs
Flow

Finding to evidence.

Step 1

Vantage

Scan finds a critical issue → OCSF Security Finding

Step 2

Sentinel

Correlates the finding against related alerts

Step 3

Reflex

Auto-creates a case from the OCSF trigger

Step 4

Approval

Analyst approves playbook → staged response if destructive

Step 5

Comply

Maps the scan and case as live control evidence

Discuss how it works with the Oryx team.

A guided walkthrough scoped to your SOC, compliance, and production footprint — not a slide deck.