Detection System of Record Architecture

SecuMap is a Detection System of Record (DSoR) — a vendor-neutral governance layer that continuously maps threat intelligence to detection coverage, measures detection effectiveness, and governs detection health across the full threat-to-detection operating loop.

The architecture places that governance layer above execution systems, validation platforms, and infrastructure domains so teams can measure, trace, and improve detection health without replacing SIEM, EDR, BAS, or CTI systems.

On this page: where SecuMap sits in the stack, how it is deployed in your environment, and what the governance layer connects.

The Modern Security Stack

Modern security operations rely on specialised domains:

  • Threat Intelligence — Context and adversary insight.
  • Detection Engineering — Authoring detection logic.
  • SIEM / EDR / NDR — Signal collection and alerting.
  • Validation — BAS and purple team verification.
  • Incident Management — Operational response and remediation.
  • Infrastructure & Telemetry — Data pipelines, agents, ingestion layers, and execution engines that enable detection signal generation.

Each domain optimises within its own scope. Infrastructure health underpins them all. None govern detection health across the system as a whole.

The Missing Governance Layer

Detection health is often inferred from isolated metrics — alert volumes, validation results, or rule coverage — within individual tools.

Infrastructure reliability, execution stability, and validation outcomes are typically monitored separately, by different teams, using different measurements.

Without a governance layer operating across these domains, detection health cannot be persistently measured as a system capability.

Where the Detection System of Record Sits

The Detection System of Record operates at the architectural layer above security tooling domains.

It unifies threat intelligence, detection logic, incident outcomes, and validation results within a single operational model — governing detection health across tools rather than executing detections within them.

Security systems continue to execute their specialised functions. The DSoR provides persistent, system-level visibility and lifecycle traceability across them.

Detection System of Record architecture: Governance Layer above Architectural Governance Layer, Execution Domains (Threat Intelligence, Detection Engineering, SIEM/EDR/NDR, Validation, Incident Management), and Infrastructure and Telemetry Health foundation.

Execution systems generate signals. Infrastructure enables reliable signal integrity. The Detection System of Record governs detection health across both layers — instrumenting performance without replacing execution systems or underlying technology.

How SecuMap is deployed

For licensing tiers and the capability matrix, see Editions. This section covers technical deployment characteristics for architects and assessors.

SecuMap is not multi-tenant SaaS. You run a single-tenant, customer-hosted instance in your environment — the same deployment model for Community, Professional, and Enterprise.

Packaging uses sealed Docker container images (delivered as an offline-capable archive) orchestrated with Docker Compose on a Linux or Windows virtual machine. All application data remains inside your organisation. After initial delivery, SecuMap can operate fully offline where required; optional outbound HTTPS supports updates, licensing, and threat-intel sync.

The hosted interactive demo at See it in action uses sample data on SecuMap infrastructure — it is separate from a production deployment in your environment.

SecuMap deployment characteristics
Characteristic Description
Deployment model Single-tenant, customer-hosted — your stack, your controls.
Packaging Sealed Docker container images in an offline-capable delivery archive.
Orchestration Docker Compose on a Linux or Windows VM (single-node).
Data residency Application and detection governance data stay in your environment.
Connectivity Air-gap capable after delivery; optional HTTPS for updates and licensing.
Editions Same installation process; license file governs tier entitlements.

Compare licensing tiers on Editions. Assessor-facing detail: Deployment architecture (public docs). Start with Community signup in the portal; installation steps follow account registration.

Evaluate SecuMap in your context

Understand stack placement and deployment first — then explore the product with sample data or start a free Community deployment in your environment.

Get started free See it in action

Open demo