Workspace › Overview
All systems operational
Security Overview
Loading…
Live
Enrolled Devices
protecting endpoints
24h
Events (24h)
total signal volume
DLP
Secrets Caught (24h)
leak attempts blocked
OPEN
Open Incidents
awaiting review
⚡ Live Event Stream
auto-refresh · 2s
Loading events…
Signal Breakdown · 24h
by collector
DLP Catches
No DLP hits in last 24h
🖥 Device Fleet
HostnameOSAgentStatusLast seen
🚨 Recent Incidents
TitleSeverityStatusWhen
No incidents — all clear 🛡
ShieldMind · v1.0 ·
Polling /api/shieldmind/_live/ every 2s · Last fetch
Risk Engine
Fleet-wide composite risk · time-decayed · peer-relative · auto-mitigated
Live
Fleet Size
enrolled assets
μ
Mean ARS
95p —
OPEN
Vuln Instances
across the fleet
Pending Approval
auto-executed 24h: —
🔥 Top Risk Assets
click to drill down
#AssetUserARSPctTop Vuln
Loading…
⚠ Top Vulnerabilities (VRS)
CVSS × env × temporal × prev
IDTitleVRSAssetsTrend
Loading…
👥 Top Risk Users (URS)
composite across all devices
UserURSDevicesPrimary ARSTop Vuln
Loading…
Asset Fleet
All enrolled devices · click any row to drill into vulnerabilities + mitigations
All Assets
ARSHostnameOSUserVulnsLast Seen
Loading…
Vulnerability Catalog
All known patterns the brain detects · CVSS-shape base score · MITRE ATT&CK mapped
Catalog
IDTitleCatBaseVRSAssetsMITREPlaybook
Loading…
Mitigation Approval Inbox
Pending actions with risk/benefit math · approve or reject · audit-tracked
⏳ Pending Approval
Loading…
📜 Recent Actions
last 50
WhenTierActionTargetStatusDecided By
Loading…
Playbooks
YAML-defined CAPA response templates · containment / corrective / preventive / verification
Loaded Playbooks
hot-reloadable from /playbooks/*.yaml
IDTitleTriggerAutoEfficacyRunsVerified
Loading…
AI Agent Firewall
OWASP LLM Top 10 protection for your AI agents · intent-based ML detection · in-flight tokenization · auto red-team
LIVE
Registered Agents
24h
Scans
WARN
Warnings
BLOCK
Blocks
— block rate
🤖 Registered AI Agents
click to manage
NameKindModeScansBlocksLast
No agents registered yet. POST to /api/shieldmind/_aifw/agents/ to onboard one.
OWASP LLM Top 10 Hits
last 30 events
No OWASP findings yet
⚡ Recent Scans
last 30
WhenAgentDirectionVerdictRiskOWASP
No scans yet
Audit Log
Immutable record of every admin action · SOC 2 CC7.2 + ISO 27001 A.12.4 evidence · last 200 entries
Audit Trail
WhenActionActorTargetSeveritySummary
No audit entries yet
Compliance Evidence Pack
Auditor-ready ZIP for SOC 2 Type II · ISO 27001 · PCI DSS 4.0.1 · HIPAA · GDPR · NIST 800-171 · FedRAMP Moderate
📦 Generate Evidence Pack
cuts SOC 2 prep from 6 weeks to 30 seconds

Your auditor's request list, satisfied automatically. Click to download a ZIP containing:

  • manifest.json — coverage summary + metadata
  • controls.csv — every control across all frameworks with status + evidence pointer
  • evidence/<framework>_<control>.txt — actual evidence per control (RBAC dumps, audit log, incident records, mitigations, crypto config)
  • audit_log.csv — complete audit log for the chosen window
  • report.html — executive summary for the auditor

Window:    ⬇ Download Evidence Pack

Frameworks Covered
FrameworkControlsStatus
SOC 2 Type II9 (Trust Service Criteria)automated
ISO 270015 (mapped to SOC 2)automated
PCI DSS 4.0.14 (Req-7, 8, 10, 12.10)automated
HIPAA4 (164.308 / 164.312)automated
GDPR3 (Art.5.1.f / 32 / 33)automated
NIST 800-1713 (3.1.1 / 3.3.1 / 3.14.6)automated
Settings
Org-level controls · risk thresholds · autonomy mode
Risk Engine

Auto-Approve Threshold: 10.0 (net benefit must exceed this for auto-execution)

Friction Weight: 3.0 (cost per friction-point per affected user)

Admin Cost: 0.4 benefit-points per admin-minute required

Confidence Floor: 0.3 (minimum confidence multiplier)

Tuning these knobs lives in services/risk_benefit.py and will move to per-tenant ShieldMindConfigModel in v2.

Recompute Jobs

python -m core.manage shieldmind_recompute_risk --seed # nightly

python -m core.manage shieldmind_verify --weekly # every 15min + weekly post-mortem