Nexus Platform · Architecture

Platform
Architecture

Built from the Ground Up for Autonomous Enterprise Defence

The Nexus platform is not a collection of integrated products. It is a single, unified autonomous defence system in which five deeply integrated layers — data intelligence, investigation, response, trust, and AI governance — share a common data model, a common identity graph, and a common operational loop. Every layer makes every other layer smarter.

5
Deeply integrated product layers
1
Unified Security Graph
<60s
End-to-end detection-to-containment

Nexus Platform — Unified Architecture

Data & Intelligence Layer
Identity Providers Cloud Platforms SaaS / Email Endpoints AI Agents Network
Security Graph — Atlas™
Entity Modeling Attack Path Analysis Trust Mapping Blast Radius
Investigation — Overwatch AI™
Autonomous Investigation Cross-Domain Correlation Threat Hunting
Response — Vanguard™
Decision Engine Multi-Surface Containment Governance
Trust & AI — TrustAnchor™ + AgentShield™
Trust Scoring Recovery Agent Governance Prompt Defence
Design Philosophy

Seven Architectural Principles

Every design decision in Nexus traces back to one of seven core architectural principles. These principles are not aspirational statements — they are measurable constraints that every engineering decision is evaluated against.

Graph-Native by Default
The Security Graph is not a feature — it is the foundational data structure. Every entity, relationship, permission, and trust binding is a node or edge. Every detection query is a graph traversal. This is what enables attack path analysis, blast radius computation, and identity-aware threat correlation at enterprise scale.
Autonomy Within Governance
Every autonomous action Nexus takes is pre-authorised by a human-defined policy. The platform never acts outside its defined governance boundary. Autonomy and accountability are not in tension — the governance model is what makes autonomy safe to deploy at scale.
Closed-Loop Validation
No action is complete until it is validated. Vanguard does not just execute containment — it continuously verifies containment success, checks for residual risk, and escalates if validation fails. Every operational loop closes with evidence of outcome.
Trust as a Continuous Variable
Trust is not a binary granted at authentication. Every entity — human identity, machine identity, session, device, application, AI agent — carries a continuously computed trust score that reflects its current behaviour, history, and context. This score informs every detection and response decision.
Identity as the Foundational Context
Every signal, detection, and response decision is evaluated in the context of the identity behind it. Not just the user account — the complete identity context: role, trust score, session history, privilege level, group memberships, and known attack path exposure.
Unified Data Model Across All Surfaces
Telemetry from identity providers, cloud platforms, SaaS applications, endpoints, network infrastructure, and AI agents is normalised into a single unified data model before analysis. There are no integration seams — every signal speaks the same language when it reaches Overwatch AI.
Formal Recovery Assurance
Recovery is not complete until it is formally verified. TrustAnchor does not declare an incident resolved because containment executed — it validates that every affected identity is clean, every configuration is restored, every trust relationship is re-established, and produces cryptographic evidence that this is true.
Platform Architecture

Five Layers. One Operational Loop.

Nexus is designed as five deeply integrated layers — each with a distinct function, each continuously sharing intelligence with the others. No layer operates in isolation.

Identity Providers

Telemetry

Entra ID, Active Directory, Okta, Ping, ADFS — authentication events, sign-in logs, token issuances, group changes.

Cloud Platforms

Telemetry

AWS CloudTrail, Azure Activity Logs, GCP Audit Logs — IAM events, resource changes, API calls, configuration mutations.

SaaS & Email

Telemetry

M365, Google Workspace, Salesforce, Slack — access events, sharing changes, OAuth grants, email activity, data access logs.

Endpoints

Telemetry

EDR telemetry — process creation, network connections, file system events, registry changes, memory activity, lateral movement indicators.

AI Agents & MCP

Telemetry

Agent interaction logs, tool invocations, MCP server calls, prompt inputs, API calls, workflow execution events from all agent frameworks.

Network & DNS

Telemetry

Network flow data, DNS resolution logs, proxy logs, firewall events — C2 beaconing, DNS tunnelling, data exfiltration volume anomalies.

Atlas™ — Security Graph

Data Intelligence Layer

Continuously ingests and normalises telemetry from all six sources into a unified entity-relationship graph. Models every identity, asset, permission, trust relationship, and AI agent. Computes attack paths, blast radius, and exposure prioritisation in real time.

Entity Modeling Graph Analytics Attack Path Computation Trust Mapping Exposure Prioritisation

AgentShield™

AI Intelligence Layer

Continuously discovers AI agents and MCP infrastructure, models agent permissions into the Security Graph, detects prompt injection in real time, scores agent trust, and provides agent behavioural context to Atlas and Overwatch AI.

Agent Discovery Prompt Defence Trust Scoring MCP Security

Overwatch AI™ — Autonomous Investigation Engine

Investigation & Detection Layer

Continuously investigates every signal using graph-based reasoning over Atlas's Security Graph. Correlates activity across all six telemetry surfaces into coherent attack narratives. Performs autonomous threat hunting. Generates complete attack timelines, identifies root cause, and produces specific recommended actions for Vanguard — all without human initiation.

Graph-Based Reasoning Cross-Domain Correlation Autonomous Threat Hunting Attack Narrative Generation Timeline Reconstruction Root Cause Analysis Behavioural Baselining 500+ Detection Rules

Vanguard™ — Autonomous Defence & Response

Response & Containment Layer

Receives fully investigated threat context from Overwatch AI and executes coordinated containment across all affected surfaces simultaneously. Decision engine selects the least-disruptive effective action. Checks every action against governance policies before executing. Validates containment success through a closed loop and escalates if residual risk remains.

Autonomous Decision Engine Multi-Surface Containment Governance Policy Enforcement Session Termination Credential Revocation Endpoint Isolation AI Agent Suspension Closed-Loop Validation

TrustAnchor™ — Trust Governance & Recovery

Trust & Recovery Layer — Continuous Across All Layers

TrustAnchor does not sit at a single layer — it is a continuous operating system for trust that runs beneath all other layers. It maintains trust scores for every entity, validates trust relationships, detects trust degradation before compromise is confirmed, orchestrates recovery to formally validated trusted states, and produces cryptographic evidence of recovery for regulatory and legal purposes.

Continuous Trust Scoring Trust Degradation Detection Session Trust Monitoring Privileged Access Governance Recovery Orchestration Formal Recovery Assurance Regulatory Evidence Package
Layer Architecture

Each Layer in Detail

Every layer has a distinct architectural role. Understanding each one explains why Nexus performs differently from assembled point solutions.

LAYER 01

Atlas™

Security Graph & Intelligence

A continuously updating graph database that models every entity and relationship in the enterprise — identities, assets, permissions, trust paths, cloud resources, and AI agents — as nodes and edges with temporal metadata.

  • Graph updates within minutes of environment changes
  • Attack path computed via continuous graph traversal
  • Blast radius estimation per entity in real time
  • Exposure scoring weighted by business impact
  • Historical graph state queryable for forensics
LAYER 02

Overwatch AI™

Investigation Engine

An autonomous investigation system that continuously processes telemetry, runs detection logic against the Security Graph, generates attack narratives, and determines what Vanguard should do — without analyst initiation.

  • Graph-based reasoning using Atlas context
  • 500+ behavioural detection rules, updated weekly
  • Cross-surface correlation across all 6 telemetry types
  • Sub-5-minute investigation completion for most incidents
  • Continuous autonomous threat hunting, 24/7
LAYER 03

Vanguard™

Response & Containment

An autonomous response engine that evaluates threat context, selects the optimal containment action, checks governance policies, executes across all surfaces simultaneously, and validates success through a closed feedback loop.

  • Decision engine evaluates 8 contextual factors per action
  • Sub-60-second multi-surface coordinated containment
  • Governance tiers: autonomous / analyst-approved / executive
  • Closed-loop validation confirms containment success
  • 100% of actions logged with full audit trail
LAYER 04

TrustAnchor™

Trust Governance & Recovery

A continuous trust operating system that maintains dynamic trust scores, detects trust degradation before compromise, orchestrates formal recovery, and produces cryptographic assurance of operational health.

  • Trust scores recomputed continuously, not at sign-in
  • Trust degradation detection precedes confirmed compromise
  • Recovery to known-good states in days, not weeks
  • Cryptographic evidence chain for regulatory assurance
  • Trust signals shared with all other platform layers
LAYER 05

AgentShield™

AI Agent Security

A purpose-built AI security layer that discovers agents, governs their identities and permissions, detects prompt injection in real time, monitors runtime behaviour, and contains compromised agents before malicious actions complete.

  • Discovers shadow AI within minutes of deployment
  • Formal identity & lifecycle for every agent
  • Sub-1-second prompt injection detection
  • Behavioural baselining detects drift from normal
  • Agent trust scores flow into TrustAnchor and Atlas
SHARED

Unified Data Model

Cross-Layer Foundation

All five layers share a single, normalised data model for entities, relationships, events, and trust scores. There are no integration translation layers — every component speaks the same data language natively.

  • Single entity schema for all identity types
  • Shared event taxonomy across all telemetry sources
  • Trust score as a first-class platform primitive
  • Attack path as a shared operational data structure
  • No integration seams between product layers
Operational Data Flow

How Data Moves Through the Platform

The Nexus operational loop runs continuously and autonomously. From signal ingestion through investigation, decision, execution, and validation — every cycle tightens the platform's operational intelligence.

01

Multi-Source Telemetry Ingestion & Normalisation

Telemetry from identity providers, cloud platforms, SaaS applications, endpoints, AI agents, and network infrastructure is ingested continuously and normalised into the Nexus unified data model. Every event is enriched with contextual metadata — source, entity identifiers, trust context, timestamp, and confidence score — before it reaches the Security Graph. Ingestion latency is sub-minute for all connected sources.

02

Security Graph Update & Attack Path Recomputation

Normalised events are applied to Atlas's Security Graph as graph mutations — adding nodes, updating relationships, changing permission states, and modifying trust bindings. After each significant mutation, Atlas recomputes affected attack paths and updates exposure prioritisation scores. When a new service account is created, a permission is escalated, or an OAuth grant is issued, Atlas knows within minutes and updates the graph accordingly.

03

Autonomous Investigation Initiation

Overwatch AI continuously evaluates the event stream against its detection rule library and the Security Graph. When an event or sequence warrants investigation, Overwatch AI starts immediately — querying the Security Graph for entity context, enriching with threat intelligence, correlating related events across surfaces, and building a complete evidence chain. The investigation loop typically completes within 5 minutes for standard incidents and faster for high-confidence matches.

04

Trust Context Integration

As investigation proceeds, Overwatch AI queries TrustAnchor for current trust scores for every entity involved in the incident — identity trust, device trust, session trust, and for AI-related incidents, agent trust scores from AgentShield. Trust context materially affects investigation priority ranking and containment action selection, ensuring that a low-trust identity performing suspicious actions is treated differently from the same actions by a high-trust identity.

05

Response Decision & Governance Check

With investigation complete, Overwatch AI generates specific recommended containment actions for Vanguard, ranked by effectiveness and business disruption impact. Vanguard's decision engine evaluates each recommendation against current trust scores, business criticality of affected assets, active governance policies, and blast radius modelling from Atlas. Actions are classified as autonomous, analyst-approved, or executive-approved before execution proceeds.

06

Coordinated Multi-Surface Execution

Authorised containment actions execute simultaneously across all affected surfaces — identity systems, endpoints, cloud environments, SaaS platforms, and AI agent infrastructure — in a single coordinated action. Coordination is essential: piecemeal containment that executes sequentially alerts attackers and allows pivoting to alternative access. Nexus contains all vectors simultaneously, eliminating the attacker's ability to adapt before full containment is achieved.

07

Closed-Loop Validation & Trust Re-establishment

Following containment, Vanguard runs continuous validation checks — confirming that attacker access is removed, that no residual risk remains, and that affected systems are behaving normally. TrustAnchor concurrently validates the trust state of all affected entities and initiates recovery orchestration where required. The incident is not closed until both containment validation and trust re-establishment are confirmed and documented.

08

Platform Intelligence Update

Every completed incident cycle feeds back into the platform's operational intelligence. Atlas updates the Security Graph with any new attack paths or relationships discovered during the investigation. Overwatch AI updates its behavioural baselines. Detection rules are refined based on investigation outcomes. Trust scores are updated with incident context. Each cycle makes the platform measurably smarter than the last.

Deployment Architecture

Three Deployment Models

Nexus is engineered for deployment flexibility. The same platform architecture supports cloud-native, hybrid, and air-gapped environments without capability compromise.

Cloud-Native

Nexus Cloud

Fully managed cloud deployment operated by LogicBounce. Fastest time to value — operational in 48 hours with zero infrastructure investment from the customer.
  • 48-hour deployment to full coverage
  • Zero infrastructure requirements
  • Continuous platform updates automatically applied
  • Multi-tenant with strict data isolation
  • SOC 2 Type II and ISO 27001 certified
  • Suitable for most enterprise environments
Air-Gapped

Nexus Sovereign

Fully on-premises or air-gapped deployment for environments requiring complete data sovereignty — critical national infrastructure, defence, and classified environments.
  • Fully air-gapped deployment available
  • All data remains within customer-controlled perimeter
  • Platform updates via secure offline update packages
  • No external connectivity required for operation
  • Suitable for CNI, defence, and classified environments
  • 14-day typical deployment
Platform Security

How We Secure the Platform Itself

A security platform with weak security is a liability, not an asset. The Nexus platform is designed, built, and operated to the highest available security standards.

Platform Security Architecture

  • Zero-trust architecture throughout — no implicit trust between platform components
  • Mutual TLS for all inter-component communication
  • Encryption at rest (AES-256) and in transit (TLS 1.3) for all customer data
  • Customer data cryptographically isolated with per-tenant encryption keys
  • Secrets management via HSM-backed key management
  • All platform API access authenticated via short-lived tokens with least-privilege scopes
  • Continuous penetration testing by TDU red team against production infrastructure

Compliance & Certifications

  • SOC 2 Type II — security, availability, confidentiality, and processing integrity
  • ISO 27001:2022 — information security management system
  • ISO 27701 — privacy information management
  • GDPR-compliant data processing with DPA available for EU customers
  • FedRAMP Moderate authorisation (Nexus Cloud, in progress)
  • HIPAA Business Associate Agreement available for healthcare customers
  • Annual third-party security audit by independent assessors
  • Vulnerability disclosure programme with responsible disclosure policy

See the Architecture in Action.

Request a technical architecture briefing with our solutions engineering team — and see how Nexus would deploy in your specific environment.