Product · In development

WysperHub A SIEM built for federally regulated environments.

Deterministic security monitoring aligned to NIST controls, from CMMC Level 2 to FedRAMP-aligned deployments and disconnected networks. Deployed in your own cloud, operated by your team.

The console

Purpose-built for assessment-ready operations.

One console, seven operational surfaces, each aligned to the requirements of CMMC assessment, incident response, and continuous monitoring.

  • Overview and ExplorePosture at a glance, and full search across everything collected.
  • Incidents and RulesCorrelated cases to work, and the detection logic behind every alert.
  • Coverage and ComplianceWhat is reporting, what is silent, and how it maps to your controls.
  • Access CenterWho can see and do what, with an audit trail on the system itself.
Illustration of the WysperHub console

Why it exists

Compliance-grade visibility should not require an enterprise SOC.

Contractors handling CUI are asked to prove continuous monitoring, audit trails, and incident readiness, often on top of everything else their IT team already owns. WysperHub is built for exactly that reality.

Detection content included

Detection packs across 30 source families ship with the product, versioned and reviewed, so monitoring produces signal without months of rule writing.

Every rule maps to a control

Detections carry their NIST SP 800-171 control mappings, so the monitoring you run is the monitoring your assessment needs.

Deterministic by design

Detection logic is explainable and repeatable. No AI verdicts sit between you and your assessor, on purpose.

Evidence you can defend

Raw events are stored immutably with hashes and lineage, and legal hold is supported. Drill-downs retrieve the exact bytes and verify them.

Incidents, not alert noise

Related findings across sources correlate into cases, so a risky sign-in and a firewall deny spike become one incident to work, not two alerts to triage.

Transparent query language

WysperQL drives search, dashboards, and detections with a single readable syntax. Detection behavior is fully inspectable at all times.

Open formats underneath

Normalized history targets open Parquet segments and standard stores. Your evidence is not locked inside a proprietary database.

Signed, versioned releases

Every release ships as coordinated signed artifacts with declared compatibility, built for environments that verify before they install.

Coverage aligned to the assessed environment.

Detection packs ship for the systems that process, store, and transmit CUI in contractor environments. Coverage continues to expand through development.

Cloud control plane

Control plane monitoring for cloud accounts.

Detection packs for AWS cover CloudTrail management activity, GuardDuty threat findings, and VPC Flow Logs, surfacing account compromise paths, high-risk configuration change, and anomalous network movement as findings.

Fleet health

A silent source is a finding.

Sensors transmit the full log output of each endpoint, and Core maintains the expected reporting state for every source. When a host or source stops reporting, the gap is flagged in the console. Missing logs are a security gap and an assessment finding.

  • Expected versus observedCoverage continuously compares expected reporting against observed reporting, per source and per host.
  • Gaps become findingsA stalled Sensor or interrupted log pipeline is surfaced for remediation before it is discovered in an assessment.
  • Evidence in both statesThe record documents when coverage was healthy and when it was not, keeping continuous-monitoring evidence defensible.
Console coverage view flagging a source that stopped sending logs

Deployment

Deployed in your environment. Operated under your authority.

WysperHub installs as a single topology with three roles: Core for processing and the console, Gateway for boundary aggregation and connectors, and Sensor, a thin static binary for Windows and Linux hosts. It runs in your own account, including GovCloud, with no vendor data plane. Your security data never leaves your environment.

  • Customer-operatedYou own the infrastructure, patching, and rollout. We ship the software, requirements, and validation.
  • Built for hardened environmentsCryptography runs in FIPS 140 mode using validated modules, with support for STIG-hardened and network-restricted hosts.
  • Designed for disconnected operationThe architecture supports network-restricted and air-gapped deployments where data cannot leave the boundary.
  • Fleet visibility includedEnrollment, health, and version state for every Sensor and Gateway, from the Core console.
Core, Gateway, and Sensor topology

WysperQL

A query language built for clarity and repeatability.

One query language drives search, dashboards, and detections. A fleet-wide failed-authentication query is a single statement, and results are deterministic across every execution.

Every detection built on it carries a severity and its control mapping, with reviewed provenance for where the logic came from.

event.outcome:failure
  | stats count, dc(source.ip) as ips by user.name
  | where count >= 10
Accounts with ten or more failures across distinct source addresses.

How WysperHub compares.

Three ways contractors approach security monitoring, measured against what an assessment requires.

Approach WysperHub This one Compliance-first, deployed in your environment Enterprise SIEM Capable, built for enterprise scale and staffing Assembled open-source stack Maximum flexibility, maximum engineering burden
Where security data lives Your cloud account, with no vendor data plane Vendor cloud or hybrid, commonly Your infrastructure
Detection content included Yes Included, tuned by dedicated staff Built and maintained in-house
Control mapping to NIST SP 800-171 Yes Add-on or manual, typically Manual
Deterministic, explainable detections Yes Varies; ML verdicts are common Depends on the build
Operable without dedicated SIEM engineers Yes No No
Assessment-ready evidence export Immutable and hash-verified Varies Assembled by hand
Designed for disconnected environments Yes Limited, typically Possible with significant effort
Get launch updates

At a glance

What WysperHub covers.

Built for

Government contractors handling CUI, federal delivery environments, and organizations in regulated industries that require compliance-grade monitoring without enterprise overhead.

Alignment

Detections and evidence map to NIST SP 800-171 controls, with CMMC Level 1 and 2 as the primary target. The architecture is designed for FedRAMP-aligned cloud deployments and disconnected networks, and the evidence model supports commercial attestations such as SOC 2.

Evidence

Control coverage mapping and exportable audit evidence, structured around CMMC assessment requirements, backed by immutable raw storage with verifiable lineage.

Boundaries

WysperHub does not certify your environment, and no product can. It gives you the monitoring, the mapping, and the evidence so the assessment conversation starts from proof.

Status

In active development with the practice's own environments as the first deployment ground.

Follow WysperHub to launch.

WysperHub is in active development. Register your details and we will notify you as availability approaches. No obligation.