Back to Infrastructure Module
Infrastructure Tech Stack · Stack Positioning

//AIRGAPT composes with your
security stack, it doesn't replace it.

Detection and authorization already live in your SIEM, EDR, PAM, and IAM. //AIRGAPT adds the enforcement-and-evidence layer beneath them: when your tools detect or authorize, //AIRGAPT enforces the boundary and returns a hardware-signed, tamper-evident record of what happened.

DetectSIEM · EDR
AuthorizePAM · IAM
Enforce//AIRGAPT
Stack Comparison

Where each layer begins and ends

Every "No" in an //AIRGAPT column is intentional architecture, not a gap. Every "No" in a vendor column is their design choice, not a flaw. The stack works because each layer keeps to its purpose.

SIEM

//AIRGAPT + SIEM, Detection & Logging

Capability
Splunk
Sentinel
QRadar
//AIRGAPT
Detect threats across telemetry
Yes
Yes
Yes
Not our role
Generate alerts for SOC
Yes
Yes
Yes
Not our role
Correlate across data sources
Yes
Yes
Yes
Not our role
Composes with detection, signed enforcement evidence
No
No
No
Yes
Tamper-evident signed receipt per enforcement
No
No
No
Yes
Generate eIDAS Qualified Electronic Signature audit trail
No
No
No
Yes
Together →

Your SIEM detects; //AIRGAPT enforces the boundary at the device and returns a signed, tamper-evident evidence record.

EDR / XDR

//AIRGAPT + EDR / XDR, Endpoint Detection

Capability
CrowdStrike Falcon
SentinelOne
Microsoft Defender
//AIRGAPT
Behavioural analysis & ML detection
Yes
Yes
Yes
Not our role
Endpoint forensics & threat hunting
Yes
Yes
Yes
Not our role
Quarantine & process termination
SW
SW
SW
Not our role
Tamper-evident signed receipt per response
No
No
No
Yes
Evidence path independent of EDR agent health
No
No
No
Yes
Hardware-anchored enforcement (FIDO2 cryptographic intent)
No
No
No
Yes

* The July 2024 incident illustrates that a single agent layer is itself a dependency; //AIRGAPT provides a separate, hardware-anchored evidence path.

Together →

Your EDR detects; //AIRGAPT enforces the boundary at the device and returns a signed, tamper-evident evidence record.

PAM

//AIRGAPT + PAM, Privileged Access Management

Capability
CyberArk
BeyondTrust
Delinea
//AIRGAPT
Vault privileged credentials
Yes
Yes
Yes
Not our role
Session recording & monitoring
Yes
Yes
Yes
Not our role
Just-in-time privilege elevation
Yes
Yes
Yes
Not our role
Hardware-anchored proof of human consent per session
No
No
No
Yes
Cryptographic proof of human consent per privileged action
SW
SW
SW
HW
Tamper-evident signed evidence per privileged session event
No
No
No
Yes
Together →

Your PAM authorizes; //AIRGAPT enforces the boundary at the device and returns a signed, tamper-evident consent record.

IAM

//AIRGAPT + Identity & Access Management

Capability
Microsoft Entra ID
Okta
Ping Identity
//AIRGAPT
Federated identity & SSO
Yes
Yes
Yes
Not our role
Conditional Access policies
Yes
Yes
Yes
Not our role
Multi-factor authentication orchestration
Yes
Yes
Yes
Not our role
Runtime hardware-anchored proof of consent per protected action
No
No
No
Yes
Tamper-evident signed consent record per protected action
No
No
No
Yes
Bridges existing FIDO2 keys into attributable consent evidence
Auth only
Auth only
Auth only
Yes
Together →

Your IdP authorizes; //AIRGAPT enforces the boundary at the device and returns a signed, tamper-evident consent record.

Scope Clarity

Where //AIRGAPT does not replace existing tools

Not a SIEM. We do not aggregate or analyze log data.
Not an EDR. We do not perform behavioural threat detection.
Not a PAM vault. We do not store or rotate privileged credentials.
Not an IdP. We do not federate identity or manage user lifecycle.
Not a firewall. We do not inspect network packets at the perimeter.

//AIRGAPT adds a tamper-evident enforcement-and-evidence layer beneath the tools you already run.

Reference Architecture

Where //AIRGAPT sits in your stack

Detect → Authorize → Enforce. Most enterprise stacks have the first two. //AIRGAPT is the third.

Your Security Stack
SIEM · EDR · PAM · IAM
Splunk / Sentinel / QRadarCrowdStrike / SentinelOne / DefenderCyberArk / BeyondTrust / DelineaEntra ID / Okta / Ping
Detect & Authorize
//AIRGAPT Composition Layer
Signed, tamper-evident enforcement receipts
//AIRGAPT
Enforcement & Evidence
Hardware-anchored enforcement at the device
Enforce
CISO FAQ

Questions we get in every technical evaluation

Get Started

Ready to Harden Your Stack?

Integrate //AIRGAPT on top of your existing SIEM and PAM investment. No new hardware. No rip-and-replace.

Request Integration Brief
Vanguard Pilot · Now Accepting Applications
Pilot Company Waitlist Open, Setup Fees Waived for Founding Cohort