Reachability in the answer
A detection is read against the relationships that decide what it can touch.
- Events
- Time series
Events, identities and relationships on one clock.
Security data is telemetry plus relationships: something happened, and the question is what it can reach.
A detection that carries its own reachability context.
Authentication, network, endpoint and application events. It is the first of 4 workloads running in Cybersecurity.
A detection is read against the relationships that decide what it can touch.
Cybersecurity data moves through 4 stages — Collect → Inventory → Correlate → Investigate. The shapes in play are Time series, Graph, SQL, Events, JSON / documents, and answering one question means reading across all of them.
Security questions are traversals with a time filter. These are the parts that keep them fast and local.
Events arrive continuously from endpoints and networks, identities and assets are records, and the relationships between them decide exposure. PLOMID holds the events, the entities and the relationships in one layer, so a detection carries its own reachability context.
Planning, execution and transactions first — then the workloads that use them and the shapes they name.
What runs against this data.
The shapes those workloads read and write.
One path from a request to the data it names.
How the work reaches the layer.
4 workload families over one set of shapes. Choose one to see what it moves and where it lands.
Authentication, network, endpoint and application events.
Users, service accounts, hosts, services and their owners.
Access, membership, trust and reachability structure.
Investigations, notes, evidence and remediation records.
Walk the path the data takes, from the environment that produces it to the questions it answers. Select a station, or a shape, to read each step.
A detection that carries its own reachability context.
The estate
Endpoints, networks and identities generating events continuously.
Events · Time series
5 shapes carry this domain. Choose a stage to read the operation, or a shape to see every stage that handles it.
Collect
Endpoint, network and identity events
Events · Time series
Each one reads telemetry with the records that explain it, from the same layer rather than a sidecar store.
A detection is read against the relationships that decide what it can touch.
Telemetry stays in the same layer as the inventory it concerns, so history is not a separate archive.
Notes, findings and the events they reference stay queryable together.
Where security telemetry may live is a governance decision, not an afterthought.
Sensitive telemetry often has to stay inside a boundary, which makes placement part of the security design.
Deployment, residency and control