Architecture
An on-prem architecture with explicit trust boundaries.
Agents collect evidence, a local control plane analyses it and holds the records, and every inbound release is verified before it is staged.
SysCyber · Reference architectureSheet 01
Trust boundary summary
- Deployment
- Inside the customer environment
- Control plane
- Local — analysis, workflows and records
- Evidence
- Endpoint Agents on each host
- Security data
- Designed to stay local
- Inbound
- Signed product, Agent and intelligence releases — verified before staging
- Outbound
- No outbound path for security data
Status · Reference viewFig. 1 below
Control stays inside your environment.
One boundary, one verification point, no outbound path for security data.
SysCyber release channel
- Signed product releaseSigned
- Signed Agent releaseSigned
- Signed vulnerability intelligenceSigned · Versioned
- 2.1Asset & evidence inventory
- 2.2Exposure analysis
- 2.3Attack paths
- 2.4Remediation workflows
- 2.5Audit trail
- 2.6Reports
Endpoint Agents
- Application serverAGENT-01
- Database serverAGENT-02
- Service hostAGENT-03
No outbound path for security data
Callouts
- Endpoint Agents
- One boundary per host.
- Local control plane
- Inside the customer environment.
- SysCyber release channel
- Outside. Signed releases only.
- Local security data
- Held locally.
- Local vulnerability intelligence
- Active once verified.
- Verify
- Every inbound release, before staging.
Legend
- Customer environment boundary
- Agent boundary, per host
- Signed inbound release
- Verification gate
- Drawing
- SysCyber reference architecture
- Sheet
- Trust boundary
- Status
- Illustrative
What runs where.
Six components, each in a defined place.
| Component | Where it runs | Responsibility |
|---|---|---|
| Endpoint Agent | On each host | Collects asset and security evidence on each host. |
| Local control plane | Inside your environment | Analysis, workflows, records and reporting. |
| Local security data | Local | Evidence, paths, operations and audit records. |
| Local vulnerability intelligence | Local · verified | Operates locally once verified and activated. |
| Exposure and attack paths | Control plane | Routes toward critical assets and the controls that break them. |
| Remediation, audit and Reports | Control plane | Approval, verification and the audit record. |
Endpoint Agent
On each host
Collects asset and security evidence on each host.
Local control plane
Inside your environment
Analysis, workflows, records and reporting.
Local security data
Local
Evidence, paths, operations and audit records.
Local vulnerability intelligence
Local · verified
Operates locally once verified and activated.
Exposure and attack paths
Control plane
Routes toward critical assets and the controls that break them.
Remediation, audit and Reports
Control plane
Approval, verification and the audit record.
Fig. 2 · Release states inside the customer environment
| Release | Received | Verified | Staged | Active |
|---|---|---|---|---|
| Product releaseVersioned release | reached | reached | reached | current state |
| Agent releaseVersioned release | reached | reached | current state | pending |
| Vulnerability intelligenceVersioned release | reached | current state | pending | pending |
Signed distribution
Verified at the boundary, then staged.
Releases arrive signed and versioned. Your environment verifies each one, stages it, then activates it.
Review the deployment model.
Walk through trust boundaries, release verification and how SysCyber fits your operational constraints with our engineers.