Skip to content
Product · OCO

A CVE lands. Two days later you still cannot say whether it touches you.

The public reference layer under OCO is open to AI agents as Lattice, in private beta. See Lattice

OCO is the vulnerability and detection graph, cross-linked to its sources. Ask what a CVE touches in the estate you actually run, against records that carry the public source they came from. No external AI API, no telemetry leaving the site.

Most people meet OCO without touching it. It is what we watch your estate on when we run the IT and security for a small firm — the reason that service can be priced for a twenty-person company rather than a two-hundred-person one. This page is for the reader who wants to know what is underneath.

CVE + KEV
Vulnerability records, linked to the software and configurations they affect rather than listed beside them
Sigma
Detection rules mapped to the techniques they cover — and to the ones nothing covers
D3FEND
Countermeasures on that same technique space, so a finding leads to something you can do
No external AI API
Local models only. Your estate data never leaves your site

Every record in the graph carries the public source it was drawn from. Capability position as at 2 August 2026; this page describes what is running on that date, not a roadmap.

What it looks like

Ask in words. Get back the records the answer came from.

A question about your own estate, answered against your own data, with the source records listed underneath so you can check the answer rather than trust it.

The SOC Copilot screen: the question 'which hosts expose public facing service?' answered with five services and their host, port and protocol, and beneath it the five source records the answer was drawn from.
A demo tenant, and the addresses are RFC5737 documentation ranges rather than anyone's real estate — no customer data goes into a delivered artifact, and that is enforced by one of the six checks rather than by a policy. Note what is under the answer: the specific records it came from. Being able to check an answer is the whole point; an assistant that cannot show its working is a confident stranger.
What is in the graph

Cross-linked, not just collected.

Vulnerabilities

CVE records and known-exploited-vulnerability entries, linked to the software and configurations they actually affect.

Detections

Sigma rules and response playbooks, connected to the techniques they cover — and, importantly, the ones they do not.

Countermeasures

D3FEND countermeasures mapped against the same technique space, so a finding leads to something you can do.
Properties

Each of these has a probe behind it.

Runs fully local

Local models only. Your data never leaves your site — verified by a probe against the running system, not asserted in a brochure.

Honest coverage

The system reports what it cannot detect as well as what it can. A coverage score you can query is more useful than a dashboard that only shows green.

Multi-tenant from day one

Tenant scoping is in the data model, not bolted on. One core, many estates, no cross-tenant read path.

Each of these corresponds to a capability probe that must pass before the statement may appear on this page.

What the probes do not cover is worth saying before you find it yourself. OCO tells you what a finding connects to; it does not hand you a ranked remediation plan, and it does not take any action on your systems. Deciding what to fix first, and doing the fixing, both stay with your team. If what you need is something that closes tickets on its own, that is not what this is today.

Want to see it against your own estate?

For most firms the answer is to have us run it — that is the IT and security service, and it starts with an asset review. If you run your own security team and want the graph itself, sandbox access is granted case by case; a person reviews every request, and we will tell you when it is not a fit.

Request access