Skip to content

Hecate

Protects dozens of client companies from a single console, without mixing their data.

Vertical: Cybersecurity Solid base

What it is for

Let a security services company manage the cyber defence of many clients at once, with real isolation between them.

What it does

Three planes: a management console for the operator (client onboarding, service levels, emergency stop), a forge where defence components are built and signed, and an isolated runtime for every protected company.

Sector

Managed cybersecurity: MSSP and SOC-as-a-service.

What it improves

A traditional SOC needs headcount proportional to its client count. This model makes the marginal cost of an additional client far lower, with protection levels differentiated by sector.

Target client

Security service providers, integrators and large groups with multiple subsidiaries.

Status and maturity

Very large codebase, documented architecture decisions and an explicit separation between what is built and what is planned.

Differentiator

Real tenant isolation — the operator sees the security posture, never the data — and fail-closed governance: if something breaks, the system closes rather than letting traffic through.

Commercial fit

Sold to operators per protected company and service level. The natural route to offering Moeris and Prometeo as a service rather than a licence.

Architecture

Layered architecture

Three planes with separated responsibilities and audited connections. The rule that explains the design: the factory that trains the models is never installed next to the agent that protects the client.

  1. 01

    Management plane (operator)

    The bridge that governs the client fleet: security-posture federation and remote governance. The operator sees the defence state, never client data, and irreversible actions are not executed remotely.

  2. 02

    Forge plane (factory)

    Where defence components — models, rules, policies — are trained and validated against a test bench and a simulated red team. What leaves here is a signed artefact, never unsealed code.

  3. 03

    Runtime plane (client)

    The living agent that protects, isolated per client and able to operate without connectivity. It includes the autonomous loop, per-vertical detection, governance and its own cryptographic vault with a chained ledger.

  4. 04

    Response ladder

    Five contractable protection levels and a graduated action ladder: shadow first, then reversible, and only with a human in the loop for the irreversible.

  5. 05

    Systemic survival plane

    Orchestration layer for the zero-day scenario hitting several clients at once. In advanced design, declared as such.

Inventory

Status per component

A real inventory of the asset’s components with their declared status. We publish capability, never code or internal figures.

Built and testedFunctional with declared debtDesigned, not implementedWired; depends on a third party
  • Plane separation and sovereign containment

    Built and tested

    Formalised, current architecture decision: sovereignty by containment, not by cutting dependencies. Runs air-gapped.

  • Governance: emergency stop, ladder and signed ledger

    Built and tested

    A non-negotiable backbone: autonomy cannot erode this layer.

  • Cryptographic vault with post-quantum and ledger

    Built and tested

    Proprietary component, inherited from the Moeris lineage and contained inside the runtime plane.

  • Training and validation forge

    Built and tested

    Trains and seals artefacts behind quality gates before deployment is allowed.

  • Sector detection verticals

    Functional with declared debt

    Banking, blockchain, national scope and energy at different degrees of completion; coverage is declared per contract, never promised generically.

  • Simulation and red team

    Built and tested

    Lives exclusively in the forge: not installed next to the client, precisely so defence does not become attack surface.

  • Multi-client systemic orchestration

    Designed, not implemented

    Design closed, implementation under way.

This profile describes capabilities and status, not implementation. Code, architecture documentation and internal figures are shared under a confidentiality agreement during due diligence.