Platform capability

Operational

Platform assurance: monitoring the monitoring

Continuous self-verification that answers the question most security platforms never ask - is this system still capable of detecting an attack right now?

Overview

A monitoring platform can fail in a way that produces no error at all. The service is running, the dashboard loads, the disk has space - and a log source stopped reporting eleven days ago, so nothing has been detected since. The system looks healthy precisely because it has gone quiet.

Vanguard runs a heartbeat across every component every few minutes and asks a harder question than whether a service is running: is it running and has it recently ingested data. Both conditions must hold.

The states are defined carefully. A channel that is alive, being read and has nothing to report is healthy - file integrity monitoring is quiet in a well-run environment, and treating that as a fault would generate constant noise. Degraded, not-detecting, starting and patching are distinguished from each other, so an alert means something specific.

The platform also alerts on unusual silence. If the system has produced no alerts at all across a window where it normally would, that is itself a symptom worth investigating.

What this identifies

  • Log sources that have silently stopped reporting
  • Endpoint agents that are disconnected or have been stopped
  • Components that are running but no longer processing
  • Certificates approaching expiry
  • Backup jobs that failed or produced an unusable result
  • Notification delivery failures, which would otherwise hide every other alert

Delivery status: Operational - deployed and in production service.

Capabilities

What platform assurance does

  • Component heartbeat

    Every component checked on a short cycle for both liveness and recent ingestion.

  • Log source health

    A source that stops reporting raises an alert within one cycle rather than being discovered during an investigation.

  • Silence detection

    An unusually quiet period is treated as a signal, not as good news.

  • Maintenance awareness

    Patch windows suppress pages precisely, scoped to the specific units involved rather than to any similarly named process.

  • Infrastructure monitoring

    Certificate expiry, disk, memory pressure, backup validation and notification delivery success.

Under the hood

The engineering underneath

How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.

  • A heartbeat runs on a short cycle and emits a single summary event with per-component counts.
  • Component states distinguish healthy quiet from degraded and from not-detecting; quiet is never counted as a fault.
  • Maintenance suppression matches on specific service units and the package lock holder, never on a bare process name.
  • Alerting monitors its own delivery success, and memory pressure is alerted on rather than allocation.

The full platform architecture is documented on the architecture page.

Services

Services delivered on this capability

The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.

  • Operational

    Managed SOC

    A staffed security operations centre in Windhoek monitoring your endpoints, servers and network around the clock, so you do not have to build one.

    Explore
  • Operational

    SIEM-as-a-Service

    A fully operated SIEM for Namibian organisations, covering collection, retention, correlation and detection, without the infrastructure cost of running one yourself.

    Explore

Related

  • Operational

    Security Reporting

    Monthly reporting generated from case records, written for both the technical team and the people who approve the budget.

    Explore
  • Operational

    SIEM & XDR

    Collects security telemetry from servers, endpoints, network devices and cloud workloads into one correlated detection engine.

    Explore
  • Operational

    Incident Response

    A defined path from alert to containment to closure, with analysts who investigate before they escalate.

    Explore

Get started

Find out what is actually happening on your network

A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.