WysperHub A SIEM built for federally regulated environments.
Deterministic security monitoring aligned to NIST controls, from CMMC Level 2 to FedRAMP-aligned deployments and disconnected networks. Deployed in your own cloud, operated by your team.
The console
Purpose-built for assessment-ready operations.
One console, seven operational surfaces, each aligned to the requirements of CMMC assessment, incident response, and continuous monitoring.
- Overview and ExplorePosture at a glance, and full search across everything collected.
- Incidents and RulesCorrelated cases to work, and the detection logic behind every alert.
- Coverage and ComplianceWhat is reporting, what is silent, and how it maps to your controls.
- Access CenterWho can see and do what, with an audit trail on the system itself.
Why it exists
Compliance-grade visibility should not require an enterprise SOC.
Contractors handling CUI are asked to prove continuous monitoring, audit trails, and incident readiness, often on top of everything else their IT team already owns. WysperHub is built for exactly that reality.
Detection content included
Detection packs across 30 source families ship with the product, versioned and reviewed, so monitoring produces signal without months of rule writing.
Every rule maps to a control
Detections carry their NIST SP 800-171 control mappings, so the monitoring you run is the monitoring your assessment needs.
Deterministic by design
Detection logic is explainable and repeatable. No AI verdicts sit between you and your assessor, on purpose.
Evidence you can defend
Raw events are stored immutably with hashes and lineage, and legal hold is supported. Drill-downs retrieve the exact bytes and verify them.
Incidents, not alert noise
Related findings across sources correlate into cases, so a risky sign-in and a firewall deny spike become one incident to work, not two alerts to triage.
Transparent query language
WysperQL drives search, dashboards, and detections with a single readable syntax. Detection behavior is fully inspectable at all times.
Open formats underneath
Normalized history targets open Parquet segments and standard stores. Your evidence is not locked inside a proprietary database.
Signed, versioned releases
Every release ships as coordinated signed artifacts with declared compatibility, built for environments that verify before they install.
Coverage aligned to the assessed environment.
Detection packs ship for the systems that process, store, and transmit CUI in contractor environments. Coverage continues to expand through development.
Control plane monitoring for cloud accounts.
Detection packs for AWS cover CloudTrail management activity, GuardDuty threat findings, and VPC Flow Logs, surfacing account compromise paths, high-risk configuration change, and anomalous network movement as findings.
Authentication, privilege, and directory monitoring.
Coverage spans cloud identity providers, Active Directory and LDAP, and federation services. The packs monitor sign-in risk, privilege escalation, and directory abuse: the account-level activity present in the majority of confirmed incidents.
Endpoint coverage where CUI resides.
Windows packs cover Security, System, PowerShell, Defender, RDP, DHCP, WMI, and the host firewall. Linux packs cover auditd and syslog, from privilege escalation to persistence and tampering. All shipped by the Sensor, a thin static binary.
Boundary and workload visibility.
Firewall families including Fortinet, Cisco ASA, CEF, and generic syslog on the edge. Kubernetes audit and container runtime, Docker, web servers (Apache, NGINX, IIS), and PostgreSQL behind it.
Monitoring integrity, continuously verified.
File integrity monitoring and endpoint posture checks cover the hosts, and dedicated health coverage monitors the collection fleet itself. A non-reporting Sensor is raised as a finding, not left as a blind spot.
Fleet health
A silent source is a finding.
Sensors transmit the full log output of each endpoint, and Core maintains the expected reporting state for every source. When a host or source stops reporting, the gap is flagged in the console. Missing logs are a security gap and an assessment finding.
- Expected versus observedCoverage continuously compares expected reporting against observed reporting, per source and per host.
- Gaps become findingsA stalled Sensor or interrupted log pipeline is surfaced for remediation before it is discovered in an assessment.
- Evidence in both statesThe record documents when coverage was healthy and when it was not, keeping continuous-monitoring evidence defensible.
Deployment
Deployed in your environment. Operated under your authority.
WysperHub installs as a single topology with three roles: Core for processing and the console, Gateway for boundary aggregation and connectors, and Sensor, a thin static binary for Windows and Linux hosts. It runs in your own account, including GovCloud, with no vendor data plane. Your security data never leaves your environment.
- Customer-operatedYou own the infrastructure, patching, and rollout. We ship the software, requirements, and validation.
- Built for hardened environmentsCryptography runs in FIPS 140 mode using validated modules, with support for STIG-hardened and network-restricted hosts.
- Designed for disconnected operationThe architecture supports network-restricted and air-gapped deployments where data cannot leave the boundary.
- Fleet visibility includedEnrollment, health, and version state for every Sensor and Gateway, from the Core console.
WysperQL
A query language built for clarity and repeatability.
One query language drives search, dashboards, and detections. A fleet-wide failed-authentication query is a single statement, and results are deterministic across every execution.
Every detection built on it carries a severity and its control mapping, with reviewed provenance for where the logic came from.
event.outcome:failure
| stats count, dc(source.ip) as ips by user.name
| where count >= 10
How WysperHub compares.
Three ways contractors approach security monitoring, measured against what an assessment requires.
| Approach | WysperHub This one Compliance-first, deployed in your environment | Enterprise SIEM Capable, built for enterprise scale and staffing | Assembled open-source stack Maximum flexibility, maximum engineering burden |
|---|---|---|---|
| Where security data lives | Your cloud account, with no vendor data plane | Vendor cloud or hybrid, commonly | Your infrastructure |
| Detection content included | Yes | Included, tuned by dedicated staff | Built and maintained in-house |
| Control mapping to NIST SP 800-171 | Yes | Add-on or manual, typically | Manual |
| Deterministic, explainable detections | Yes | Varies; ML verdicts are common | Depends on the build |
| Operable without dedicated SIEM engineers | Yes | No | No |
| Assessment-ready evidence export | Immutable and hash-verified | Varies | Assembled by hand |
| Designed for disconnected environments | Yes | Limited, typically | Possible with significant effort |
| Get launch updates |
At a glance
What WysperHub covers.
- Built for
Government contractors handling CUI, federal delivery environments, and organizations in regulated industries that require compliance-grade monitoring without enterprise overhead.
- Alignment
Detections and evidence map to NIST SP 800-171 controls, with CMMC Level 1 and 2 as the primary target. The architecture is designed for FedRAMP-aligned cloud deployments and disconnected networks, and the evidence model supports commercial attestations such as SOC 2.
- Evidence
Control coverage mapping and exportable audit evidence, structured around CMMC assessment requirements, backed by immutable raw storage with verifiable lineage.
- Boundaries
WysperHub does not certify your environment, and no product can. It gives you the monitoring, the mapping, and the evidence so the assessment conversation starts from proof.
- Status
In active development with the practice's own environments as the first deployment ground.
Follow WysperHub to launch.
WysperHub is in active development. Register your details and we will notify you as availability approaches. No obligation.