SOC is live — launch the app to connect your first log source.
SOCAlerts · CVE Radar · Threat Intel · Traces · Coverage

Detect, investigate,
and respond — before a
small alert becomes a big problem.

Obiguard SOC — our Security Operations Center — streams your logs, metrics, traces, dependencies, and commits into one place, and turns them into alerts, dependency CVEs cross-matched against real-world exploit intel, and a service map that builds itself from what's actually running.

Launch SOC →Talk to sales ↗
Real-time detection. Exploit-aware prioritization.
Logs, metrics & traces
OpenTelemetry / OTLP
CVE scanning
On every push + daily
Threat intel
CISA KEV + FIRST EPSS
Code review
Every commit, by AI

Stream logs, metrics, and code from what you already run

GitHub
Kubernetes (EKS/GKE/AKS)
OpenTelemetry Collector
AWS CloudWatch · soon
Google Cloud Logging · soon
Azure Monitor · soon
Slack · soon
PagerDuty · soon
Webhooks · soon
01 / The Problem

Most tools tell you something broke.
Few tell you which one matters.

🔔

Alert fatigue buries the signal that matters

Logs pile up across a dozen tools with no correlation. By the time a human notices the pattern, the underlying problem has already been running for hours.

📦

CVEs pile up faster than you can patch

A dependency scanner tells you what's vulnerable. It doesn't tell you whether the fix is safe to ship, whether it's actually being exploited right now, or what else in your org depends on the same package.

🧩

Logs, metrics, and traces live in three different tools

Nobody keeps a service map up to date by hand, so tracing a slow request back to the host or dependency that caused it means hopping between dashboards that were never built to talk to each other.

🧑‍💻

Nobody reviews every commit for security issues

Security review happens in scheduled audits, not on every push. Issues that a reviewer would've caught ship straight to production instead.

02 / Platform

Three pillars.
One security operations center.

CVE Radar & Threat Intelligence

Know which vulnerabilities to fix first — and which ones are already being exploited

Every connected repo is scanned for vulnerable dependencies on every push and once a day. Each finding gets the exact file and line to fix, and — before you upgrade — a compatibility risk report with a 0–100 safety score and the blast radius across every other repo that depends on the same package. Threat Intelligence then cross-checks every finding against CISA's Known Exploited Vulnerabilities (KEV) catalog and FIRST.org's EPSS exploit-prediction scores, so a CVE that's actively being exploited in the wild is flagged immediately instead of sitting in a queue of hundreds ranked only by CVSS. Every commit to a connected repo also gets an automatic LLM code review, surfacing issues before they ever ship.

  • Scans on every push + daily baseline
  • Exact file/line location, not just a package name
  • Upgrade-impact analysis with a safety score
  • Cross-repo blast radius before you upgrade
  • Matched live against CISA KEV & FIRST.org EPSS
  • Automatic LLM code review on every push
soc / cve-radar
📦CVE-2024-XXXX · lodashKEV match
📦KEV: exploited in wild
📦Safety score: 82/100
📦Fixed in 4.17.22
Full-stack observability

One place to watch everything — as it happens

Stream logs, host metrics, and distributed traces all through OpenTelemetry — including a ready-made Kubernetes daemonset for EKS, GKE, and AKS. Live Logs shows every event in real time with level, source, and full-text filters; Metrics tracks CPU, memory, disk, and network per host; Traces surface per-service latency and error rate; and the Service Map builds itself automatically from ingested traces, so you see what calls what — and what's currently broken — without drawing it by hand.

  • Logs, metrics & traces over a single OTLP pipeline
  • One-command Kubernetes daemonset for EKS, GKE, and AKS
  • Distributed tracing with per-service latency & error-rate stats
  • Service map builds itself from traces — no manual topology
  • Silent-host and degraded-service detection
soc / service-map
🕸checkout-api → paymentsHealthy
🕸p99: 240ms
🕸0.8% err rate
🕸host-web-03 · CPU 88%
Code Coverage

Track test coverage across every repo, without standing up a separate service

Upload an lcov report from any test runner — Jest, pytest-cov, gcov2lcov for Go, and anything else that emits lcov — using a one-line GitHub Action or a plain curl/jq script. SOC tracks line coverage per repo over time, so a drop shows up the moment it happens instead of at the next scheduled audit.

  • Works with any lcov-emitting test tool
  • One-line GitHub Action, or a plain script for other CI
  • Per-repo coverage trend — rising or falling since last run
  • Same token & gateway model as log and metric ingestion
soc / coverage
obiguard/gateway-service+1.6%
Lines: 84.2%
+1.6% vs last run
Uploaded via CI
03 / Deployment

Live in minutes, not a quarter.

01

Connect your sources

Roll out the OTel Collector for logs, host metrics, and traces — a one-command Kubernetes daemonset covers EKS, GKE, and AKS. Connect GitHub to pull in deployments, pushes, and workflow runs.

02

Watch it stream live

Logs, metrics, and traces show up immediately in Live Logs, Metrics, and Traces — searchable, filterable, and exportable — while the Service Map draws itself from whatever traffic is actually flowing. No dashboards to build first.

03

Let detection run

Alerts fire from log-volume and rule matches. CVE Radar scans every push and once a day, then Threat Intelligence cross-checks findings against CISA KEV and FIRST.org EPSS. Every commit also gets an automatic LLM code review — all without you writing a single detection rule.

04

Track coverage from CI

Add the obiguard-coverage-upload-action (or a plain curl/jq step) to any workflow that already produces an lcov report, and SOC starts tracking that repo's line coverage trend on every run.

05

Work the queue in priority order

Every alert, CVE finding, threat match, and code finding lands severity-scored and ranked — exploited-in-the-wild CVEs first, with the exact file and line and the upgrade safety score attached — so your team knows what to pick up next.

04 / Audit trail

A record of what happened and who decided what.

Every alert, CVE finding, threat match, and code finding keeps a history — not just an alert that disappears once it's acknowledged. This is SOC's own audit trail, separate from the Audit Ledger that Governance AI and Obichat write to.

Alert timeline
Every alert keeps a full evidence timeline, linked back to the raw log events that triggered it.
Dismiss / restore trail
Dismissing a CVE or code finding requires a comment, and both actions are recorded to your organization's audit log.
Threat match lifecycle
Acknowledging or resolving a CISA KEV / EPSS threat match is tracked per-match, so there's a record of who triaged an actively-exploited finding and when.
05 / FAQ

Common questions.

Now Available

Ready to see what's actually happening?

Launch SOC and connect your first log source, repo, or metrics collector in minutes.