Useful outside the dashboard

Carry evidence and outcomes into the systems you already operate.

HNPT integrations are typed, tenant-scoped, retryable, and explicit about delivery. A notification is acknowledged only after an idempotent effect or a durable deduplication record.

Early accessStatus labels distinguish working contracts from active build and roadmap items.

What the platform is designed to deliver

Each capability carries an explicit delivery state. We do not present a roadmap item as a deployed control.

  • NATS event bridge

    Prefix-constrained subjects carry typed HNPT events with durable-delivery and deduplication contracts.

    Foundation available
  • OpenTelemetry

    ORES telemetry conventions keep operational dimensions bounded and redact credentials, payloads, and attacker-controlled identifiers.

    Foundation available
  • Webhooks

    Signed, retryable, idempotent notifications will deliver case and outcome events to customer-owned endpoints.

    In development
  • SIEM and incident systems

    Normalized exports for common security analytics, alerting, and case-management destinations.

    Roadmap
  • SQLite and Supabase sync

    HNPT Sync wraps opto-sync contracts for offline browser and app views while deriving actor and tenant identity from verified principals.

    In development

Telemetry describes the system, not the attacker.

High-cardinality evidence belongs in protected evidence records. Metrics and logs use bounded dimensions, typed outcomes, and stable reason codes.

At-least-once is explicit

Consumers deduplicate by stable event identity before committing an effect.

Secrets never become flags

Executables use flags-2-env contracts; credentials stay in approved secret references.

Build with us

Start with a bounded, observable pilot.

Define what may be observed, what a quarantine can affect, how it expires, and who reviews the evidence before connecting a production system.