The Orphean Platform

A unified intelligence layer that sits above your existing security stack, correlating signals across physical, cyber, and operational domains — and turning that same intelligence into continuous, audit-ready governance, risk, and compliance.

Four Layers. One Intelligence.

Orphean ingests, analyzes, correlates, and acts on security events from every domain. It doesn't replace your investments — it makes them collectively smarter.

01

Ingestion Layer

Normalizes and deduplicates events from source systems across physical, cyber, and operational domains.

02

Intelligence Layer

Convergence detection, behavioral baselines, anomaly detection, and event correlation powered by machine learning.

03

Application Layer

Entity-centric risk scoring, case management, investigation tools, and customizable executive dashboards.

04

Automation Layer

Event rules, OSINT rules, recommendation workflows, and visual workflow builder for orchestrated response.

Cross-Domain Convergence Engine

The heart of Orphean. When two or more independent security systems flag the same entity within a time window, Orphean recognizes the pattern and scores the convergence.

Convergence Scoring

Every convergence is scored 0–100 from source and domain diversity, entity criticality, behavioral deviation, source reliability, and event severity, with a bonus when a named pattern fires. Scores at or above the case threshold — 70 by default, configurable — automatically generate investigation cases.

Threat Pattern Recognition

Ten built-in cross-domain patterns, including Impossible Travel, Credential Compromise, After-Hours Data Access, Reconnaissance, Physical-to-Cyber Attack Chain, Data Exfiltration with Physical Presence, Privilege Escalation Chain, and Tailgating Followed by System Access.

Continuous Entity Risk

Entity risk is recomputed continuously from every event’s severity and status, with exponential time decay so recent activity dominates and stale events fade. Only entities touched since the last pass are rescored, keeping the picture current without rescanning the estate.

Explainable Intelligence

Every score includes plain-English drivers. No black boxes. Analysts understand exactly why an entity is flagged and can act with confidence.

Tunable Detection Windows

Each pattern carries its own time window — from 30 minutes to eight hours — and its own minimum event count, so bursts of automated activity are evaluated over the span that actually reveals them.

Severity Flooring

A matched pattern floors the convergence severity. An Impossible Travel match scores Critical even when the underlying events arrived as informational, so a cross-domain signal still clears the case threshold.

AI Agent Security

AI agents almost always act through an identity you already govern — a user’s credentials, an API token, a service account. Orphean detects them the way it detects any actor behaving unlike itself: by deviation from an established baseline, corroborated across physical and digital domains.

Baseline Deviation Detection

Five behavioral dimensions on a rolling 30-day window establish what an identity normally does. Automation acting on its behalf rarely stays inside that shape.

Machine-Tempo Anomalies

Event-rate and hourly-pattern baselines, with z-score thresholds and multivariate outlier detection, make the volume and timing signature of automated activity visible.

Scope & Reach Anomalies

Source-mix and event-type baselines surface an identity suddenly touching systems or performing actions outside anything in its history.

Physical Corroboration

Cross-domain patterns test digital activity against badge, door, and camera evidence — catching an identity that is busy while its owner is demonstrably elsewhere.

Explainable Drivers

Every risk score carries plain-English drivers, so an analyst can tell a misconfigured automation from a hijacked credential rather than guessing.

Immutable Activity Trail

Detections, risk-score changes, and case actions are written to an immutable log — the operating evidence behind your access and account-management controls.

Behavioral Analytics

Orphean learns what "normal" looks like for every entity across five behavioral dimensions over 30-day rolling windows. When behavior deviates, you know immediately.

  • Event rate and frequency patterns
  • Severity distribution analysis
  • Source system mix monitoring
  • Hourly activity patterns
  • Event type distribution tracking
  • Z-score anomaly detection with configurable thresholds
  • Isolation Forest & DBSCAN clustering for multivariate outliers
  • Multi-window analysis across 24h, 7d, 30d, 90d, and 1-year horizons
  • Baselines applied uniformly to user, device, application, and service-account entities
  • Machine-tempo detection for automated and AI-driven activity
Behavioral deviation 30-day baseline
3.2σ
Observed Baseline mean Normal range Anomaly
Learned seasonality Daily activity rhythm
Observed Expected pattern Normal range

Integrated OSINT Collection

Orphean aggregates intelligence from 21 open sources across six risk categories, automatically correlating external threats with your monitored entities.

Cyber

  • NVD CVEs
  • CISA KEV
  • GitHub Advisories
  • Abuse.ch Malware
  • AlienVault OTX

Threat

  • ThreatFox IOCs
  • AbuseIPDB Blacklist

Environmental

  • NWS Weather Alerts
  • USGS Earthquakes
  • NASA FIRMS Wildfires
  • NOAA Severe Storms

Geopolitical

  • GDELT Events
  • State Dept Travel
  • OFAC Sanctions
  • GDACS Disasters
  • ReliefWeb

Infrastructure

  • Cloudflare Radar
  • SANS ISC Diary
  • Shodan Trends

Physical

  • FBI Wanted Persons
  • Physical Security Feed

Built-In GRC, Powered by Live Security Data

Orphean turns the same converged intelligence into continuous compliance evidence — no separate spreadsheets, no point-in-time guesswork. Risk, controls, and frameworks stay current automatically.

Risk Register

Manage enterprise risk across seven categories on a 5×5 likelihood–impact matrix, with automated scoring (1–25), heatmap visualization, and treatment tracking — accept, mitigate, transfer, or avoid.

Compliance Frameworks

Seventeen frameworks built in — SOC 2, ISO/IEC 27001:2022, NIST CSF 2.0, NIST SP 800-53 Rev. 5, CIS Controls v8, PCI DSS v4.0.1, SOX, GLBA, HIPAA Security Rule, GDPR, DORA, NIS2, the FCA Handbook, Cyber Essentials v3.3, FDA 21 CFR Part 11, ISO 9001:2015, and ISO 14001:2015 — with requirement mapping, coverage scoring, and gap analysis across the US, UK, and EU.

Unified Controls

A single control library with effectiveness ratings that auto-maps to compliance requirements and pulls live evidence from cases, events, analytics, and OSINT.

Control Testing

Schedule and record control tests with pass/fail tracking, overdue alerts, and evidence capture — so your control posture is always provable.

Policies & KRIs

Govern policies through draft, published, and review cycles, and track Key Risk Indicators against thresholds to surface emerging exposure early.

Vendor Risk

Tier third-party vendors by criticality, monitor contract expirations, and fold supplier risk into the same converged risk picture.

Audit Packages

Assemble auditor-ready evidence packages on demand, backed by an immutable audit log of every compliance status change.

Regulatory Notifications

Stay ahead of regulatory deadlines with built-in notifications and alerts tied to your active frameworks and obligations.

Live Compliance Evidence

Controls draw evidence from ten source types — cases, events, entities, source systems, analytics, OSINT, correlations, policies, control tests, and vendor assessments — plus manual attachments, keeping fulfillment status continuously up to date.

From Detection to Response in Seconds

Build automated response workflows that trigger on events, OSINT intelligence, or convergence patterns. No manual correlation required.

Event Rules

Automated actions based on event type, severity, entity, or status. Set severity, auto-resolve, or create cases instantly.

Visual Workflows

Drag-and-drop workflow builder with decision logic, API integrations, notifications, and multi-step orchestration.

OSINT Rules

Trigger automated actions when external threat intelligence matches your monitored entities or defined patterns.

Case Management

Auto-create investigation cases for high-confidence convergences. Link events, add notes, and track resolution.

Recommendations

Multi-step guided recommendations with completion tracking. Ensure consistent response across your team.

API Integration

REST API with token-based auth for programmatic access. Integrate Orphean intelligence into your existing toolchain.

See the Platform in Action

Book a live demo with our team and explore how Orphean fits your security architecture.

Request a Demo