The Orphean Platform
A unified intelligence layer that sits above your existing security stack, correlating signals across physical, cyber, and operational domains — and turning that same intelligence into continuous, audit-ready governance, risk, and compliance.
Architecture
Four Layers. One Intelligence.
Orphean ingests, analyzes, correlates, and acts on security events from every domain. It doesn't replace your investments — it makes them collectively smarter.
Ingestion Layer
Normalizes and deduplicates events from source systems across physical, cyber, and operational domains.
Intelligence Layer
Convergence detection, behavioral baselines, anomaly detection, and event correlation powered by machine learning.
Application Layer
Entity-centric risk scoring, case management, investigation tools, and customizable executive dashboards.
Automation Layer
Event rules, OSINT rules, recommendation workflows, and visual workflow builder for orchestrated response.
Core Capability
Cross-Domain Convergence Engine
The heart of Orphean. When two or more independent security systems flag the same entity within a time window, Orphean recognizes the pattern and scores the convergence.
Convergence Scoring
Every convergence is scored 0–100 from source and domain diversity, entity criticality, behavioral deviation, source reliability, and event severity, with a bonus when a named pattern fires. Scores at or above the case threshold — 70 by default, configurable — automatically generate investigation cases.
Threat Pattern Recognition
Ten built-in cross-domain patterns, including Impossible Travel, Credential Compromise, After-Hours Data Access, Reconnaissance, Physical-to-Cyber Attack Chain, Data Exfiltration with Physical Presence, Privilege Escalation Chain, and Tailgating Followed by System Access.
Continuous Entity Risk
Entity risk is recomputed continuously from every event’s severity and status, with exponential time decay so recent activity dominates and stale events fade. Only entities touched since the last pass are rescored, keeping the picture current without rescanning the estate.
Explainable Intelligence
Every score includes plain-English drivers. No black boxes. Analysts understand exactly why an entity is flagged and can act with confidence.
Tunable Detection Windows
Each pattern carries its own time window — from 30 minutes to eight hours — and its own minimum event count, so bursts of automated activity are evaluated over the span that actually reveals them.
Severity Flooring
A matched pattern floors the convergence severity. An Impossible Travel match scores Critical even when the underlying events arrived as informational, so a cross-domain signal still clears the case threshold.
Core Capability
AI Agent Security
AI agents almost always act through an identity you already govern — a user’s credentials, an API token, a service account. Orphean detects them the way it detects any actor behaving unlike itself: by deviation from an established baseline, corroborated across physical and digital domains.
Baseline Deviation Detection
Five behavioral dimensions on a rolling 30-day window establish what an identity normally does. Automation acting on its behalf rarely stays inside that shape.
Machine-Tempo Anomalies
Event-rate and hourly-pattern baselines, with z-score thresholds and multivariate outlier detection, make the volume and timing signature of automated activity visible.
Scope & Reach Anomalies
Source-mix and event-type baselines surface an identity suddenly touching systems or performing actions outside anything in its history.
Physical Corroboration
Cross-domain patterns test digital activity against badge, door, and camera evidence — catching an identity that is busy while its owner is demonstrably elsewhere.
Explainable Drivers
Every risk score carries plain-English drivers, so an analyst can tell a misconfigured automation from a hijacked credential rather than guessing.
Immutable Activity Trail
Detections, risk-score changes, and case actions are written to an immutable log — the operating evidence behind your access and account-management controls.
Intelligence
Behavioral Analytics
Orphean learns what "normal" looks like for every entity across five behavioral dimensions over 30-day rolling windows. When behavior deviates, you know immediately.
- Event rate and frequency patterns
- Severity distribution analysis
- Source system mix monitoring
- Hourly activity patterns
- Event type distribution tracking
- Z-score anomaly detection with configurable thresholds
- Isolation Forest & DBSCAN clustering for multivariate outliers
- Multi-window analysis across 24h, 7d, 30d, 90d, and 1-year horizons
- Baselines applied uniformly to user, device, application, and service-account entities
- Machine-tempo detection for automated and AI-driven activity
Threat Intelligence
Integrated OSINT Collection
Orphean aggregates intelligence from 21 open sources across six risk categories, automatically correlating external threats with your monitored entities.
Cyber
- NVD CVEs
- CISA KEV
- GitHub Advisories
- Abuse.ch Malware
- AlienVault OTX
Threat
- ThreatFox IOCs
- AbuseIPDB Blacklist
Environmental
- NWS Weather Alerts
- USGS Earthquakes
- NASA FIRMS Wildfires
- NOAA Severe Storms
Geopolitical
- GDELT Events
- State Dept Travel
- OFAC Sanctions
- GDACS Disasters
- ReliefWeb
Infrastructure
- Cloudflare Radar
- SANS ISC Diary
- Shodan Trends
Physical
- FBI Wanted Persons
- Physical Security Feed
Governance, Risk & Compliance
Built-In GRC, Powered by Live Security Data
Orphean turns the same converged intelligence into continuous compliance evidence — no separate spreadsheets, no point-in-time guesswork. Risk, controls, and frameworks stay current automatically.
Risk Register
Manage enterprise risk across seven categories on a 5×5 likelihood–impact matrix, with automated scoring (1–25), heatmap visualization, and treatment tracking — accept, mitigate, transfer, or avoid.
Compliance Frameworks
Seventeen frameworks built in — SOC 2, ISO/IEC 27001:2022, NIST CSF 2.0, NIST SP 800-53 Rev. 5, CIS Controls v8, PCI DSS v4.0.1, SOX, GLBA, HIPAA Security Rule, GDPR, DORA, NIS2, the FCA Handbook, Cyber Essentials v3.3, FDA 21 CFR Part 11, ISO 9001:2015, and ISO 14001:2015 — with requirement mapping, coverage scoring, and gap analysis across the US, UK, and EU.
Unified Controls
A single control library with effectiveness ratings that auto-maps to compliance requirements and pulls live evidence from cases, events, analytics, and OSINT.
Control Testing
Schedule and record control tests with pass/fail tracking, overdue alerts, and evidence capture — so your control posture is always provable.
Policies & KRIs
Govern policies through draft, published, and review cycles, and track Key Risk Indicators against thresholds to surface emerging exposure early.
Vendor Risk
Tier third-party vendors by criticality, monitor contract expirations, and fold supplier risk into the same converged risk picture.
Audit Packages
Assemble auditor-ready evidence packages on demand, backed by an immutable audit log of every compliance status change.
Regulatory Notifications
Stay ahead of regulatory deadlines with built-in notifications and alerts tied to your active frameworks and obligations.
Live Compliance Evidence
Controls draw evidence from ten source types — cases, events, entities, source systems, analytics, OSINT, correlations, policies, control tests, and vendor assessments — plus manual attachments, keeping fulfillment status continuously up to date.
Automation
From Detection to Response in Seconds
Build automated response workflows that trigger on events, OSINT intelligence, or convergence patterns. No manual correlation required.
Event Rules
Automated actions based on event type, severity, entity, or status. Set severity, auto-resolve, or create cases instantly.
Visual Workflows
Drag-and-drop workflow builder with decision logic, API integrations, notifications, and multi-step orchestration.
OSINT Rules
Trigger automated actions when external threat intelligence matches your monitored entities or defined patterns.
Case Management
Auto-create investigation cases for high-confidence convergences. Link events, add notes, and track resolution.
Recommendations
Multi-step guided recommendations with completion tracking. Ensure consistent response across your team.
API Integration
REST API with token-based auth for programmatic access. Integrate Orphean intelligence into your existing toolchain.
See the Platform in Action
Book a live demo with our team and explore how Orphean fits your security architecture.
Request a Demo