Open Public catalog
Public catalog

Public reference catalog

Vendor library

Vendors don't pay to appear here and can't influence ordering. These 21 production catalogue records support evidence-bound matching inside governed workspaces. A customer route still requires qualified transcript evidence, current review authority, overlap authority and organisation-level commercial entitlement.

Production catalogue · governed activation

Comprehensive solution-services catalog

The CEO-requested 21-vendor scope is normalized, activated and mapped to concrete solution families, customer outcomes, buying signals, deployment dependencies, exclusions and discovery questions. The complete research matrix covers every vendor pair. Customer recommendations remain gated by transcript evidence and the signed-in organisation's current commercial authority.

21 production vendors
CEO-scope vendors
21 normalized
Solution families
122 mapped
Official evidence links
87 current
Pairwise route coverage
210 of 210
  • Amazon Web Services (AWS)

    Cloud infrastructure, data platforms, AI and native security services

    Production
    • compute and containers
    • storage and resilience
    • database, analytics and integration
    • AI and machine learning
    • networking and edge
    • security, identity and operations
    Open full solution and discovery map

    Solution services

    • compute and containers

      Amazon EC2 · AWS Lambda · Amazon ECS · Amazon EKS

      Run virtual machines, serverless functions and container platforms with elastic consumption.

    • storage and resilience

      Amazon S3 · Amazon EBS · Amazon FSx · AWS Backup

      Provide durable object, block and file storage with policy-led backup and recovery.

    • database, analytics and integration

      Amazon RDS · Amazon Aurora · Amazon Redshift · AWS Glue · Amazon MSK

      Modernise operational data, analytics and event-driven integration.

    • AI and machine learning

      Amazon Bedrock · Amazon SageMaker

      Build, govern and operate generative-AI and machine-learning workloads.

    • networking and edge

      Amazon VPC · AWS Transit Gateway · AWS Direct Connect · Amazon CloudFront

      Connect and deliver workloads across accounts, regions, sites and edge locations.

    • security, identity and operations

      AWS IAM · AWS Organizations · Amazon GuardDuty · AWS Security Hub · AWS Config

      Apply shared-responsibility controls, multi-account governance, threat detection and configuration assurance.

    Buying signals

    • data-centre exit or cloud migration
    • new AI or data platform
    • resilience, sovereignty or multi-account governance gap

    Routing boundaries

    • Do not map a generic cloud mention without a named workload, owner and change event.
    • AWS supplies platform capabilities; specialist third-party controls may remain required where evidence identifies a distinct control gap.

    Architecture and dependencies

    • Region and service availability vary.
    • Customer architecture, identity, network connectivity, data classification and shared-responsibility controls must be established.
    • Contracting entity and marketplace/channel entitlement are geography-specific.

    Discovery questions

    1. Which workloads and outcomes are in scope, and why now?
    2. Which regions, residency rules, accounts and landing-zone controls apply?
    3. Which managed-service constraints, availability targets and recovery objectives must be met?
    4. Who owns cloud economics, security architecture and commercial commitment?
  • Fortinet

    Integrated networking and security platform

    Production
    • secure networking
    • SASE and zero trust access
    • campus, branch and OT
    • security operations
    • cloud and application security
    • endpoint, email and data
    Open full solution and discovery map

    Solution services

    • secure networking

      FortiGate · FortiOS · Secure SD-WAN

      Converge firewall, routing and branch security policy.

    • SASE and zero trust access

      FortiSASE · FortiClient · FortiNAC

      Secure users, devices, branches and private-app access.

    • campus, branch and OT

      FortiSwitch · FortiAP · FortiNAC · FortiGate Rugged

      Apply integrated access, segmentation and operations across distributed and industrial sites.

    • security operations

      FortiAnalyzer · FortiSIEM · FortiSOAR · FortiNDR

      Centralise telemetry, analytics, investigation and response.

    • cloud and application security

      FortiCNAPP · FortiWeb · FortiADC · FortiDDoS

      Protect cloud posture, workloads, web applications, APIs and delivery.

    • endpoint, email and data

      FortiEDR · FortiMail · FortiDLP

      Reduce endpoint, messaging and data-loss risk within a broader Security Fabric.

    Buying signals

    • firewall or branch refresh
    • security-tool consolidation
    • campus, OT, application or SOC modernisation

    Routing boundaries

    • Do not route a pure DDI, autonomous EDR, data-centric SSE or specialist high-scale ADC requirement to Fortinet by default.
    • Acquired-product lineage is not proof of current integration, SKU availability or entitlement.

    Architecture and dependencies

    • Physical, virtual, cloud and SaaS deployment models differ by family.
    • Feature availability varies by appliance, FortiOS release, subscription and geography.
    • Fabric integration depth must be validated for the exact products and versions.

    Discovery questions

    1. Which program is primary: edge, branch, campus, OT, SASE, SecOps, application or cloud security?
    2. What Fortinet and competitor estate exists and when does it renew?
    3. Which shared policies, telemetry and operational outcomes justify consolidation?
    4. Which models, subscriptions, throughput and inspection requirements apply?
  • Gigamon

    Deep observability and traffic-intelligence pipeline

    Production
    • hybrid-cloud visibility
    • traffic aggregation and brokering
    • network intelligence
    • security visibility
    • orchestration and operations
    Open full solution and discovery map

    Solution services

    • hybrid-cloud visibility

      GigaVUE Cloud Suite · GigaVUE V Series

      Acquire and normalise network-derived telemetry across data centre, virtual and public-cloud estates.

    • traffic aggregation and brokering

      GigaVUE HC Series · GigaVUE TA Series · GigaVUE-FM

      Deliver the right traffic to security and observability tools at scale.

    • network intelligence

      GigaSMART · Application Intelligence

      De-duplicate, slice, mask, decrypt and enrich network traffic before tool ingestion.

    • security visibility

      Precryption · TLS decryption · ThreatINSIGHT

      Reduce encrypted and east-west visibility gaps without confusing visibility with enforcement.

    • orchestration and operations

      GigaVUE-FM · Fabric Health Analytics

      Operate physical and cloud visibility fabrics through a common control plane.

    Buying signals

    • security tools cannot see east-west or encrypted traffic
    • tool cost and packet duplication are rising
    • hybrid-cloud migration is breaking visibility

    Routing boundaries

    • Gigamon supplies visibility and traffic processing; it is not the primary enforcement control.
    • Investment, partner and portfolio material cannot prove exact SKU support.

    Architecture and dependencies

    • Physical taps, virtual taps, cloud mirroring or agent-based acquisition must be designed per environment.
    • Tool destinations, throughput, packet fidelity and encrypted-traffic authority must be established.
    • Licensing differs across GigaVUE-FM, GigaVUE-OS, modules, GigaSMART and cloud volume.

    Discovery questions

    1. Where is traffic currently unavailable or too expensive to observe?
    2. Which tools require packets, flows, metadata or decrypted sessions?
    3. What throughput, topology and cloud-account scope applies?
    4. Which acquisition method and privacy controls are acceptable?
  • Arista Networks

    Data-centre, AI, campus and multi-domain cloud networking

    Production
    • data-centre and AI networking
    • campus wired and wireless
    • network operations and automation
    • routing, WAN and SD-WAN
    • observability and visibility fabric
    • segmentation and security integration
    Open full solution and discovery map

    Solution services

    • data-centre and AI networking

      Arista switching platforms · Etherlink · EOS

      Build high-throughput leaf-spine and AI fabrics with a common network operating system.

    • campus wired and wireless

      Universal Cloud Network · CloudVision CUE · AGNI

      Unify campus access, Wi-Fi operations and network identity.

    • network operations and automation

      CloudVision · EOS

      Provide state streaming, automation, compliance and change control across domains.

    • routing, WAN and SD-WAN

      CloudEOS · Arista routing · VeloCloud SD-WAN

      Connect data centres, clouds and branches with consistent operations.

    • observability and visibility fabric

      DANZ Monitoring Fabric · DMF

      Broker network telemetry and improve tool visibility.

    • segmentation and security integration

      Macro-Segmentation Service · CloudVision · AGNI

      Apply network segmentation and integrate policy with security ecosystems.

    Buying signals

    • AI or data-centre fabric build
    • campus refresh with operational simplification
    • network automation, telemetry or change-control gap

    Routing boundaries

    • Do not equate network observability or segmentation with endpoint, SSE or full security enforcement.
    • Acquired and separately branded products require exact lifecycle, integration and SKU validation.

    Architecture and dependencies

    • Hardware platform support and EOS features vary.
    • CloudVision is offered as SaaS and on-premises; lifecycle policies differ.
    • VeloCloud, Wi-Fi, DMF and AGNI packaging require explicit entitlement checks.

    Discovery questions

    1. Is the funded domain AI/data centre, campus, WAN, cloud networking or operations?
    2. Which topology, speeds, optics, routing scale and availability targets apply?
    3. What automation, telemetry and compliance workflow is required?
    4. Which EOS, CloudVision and adjacent-product licences are needed?
  • Barracuda

    Email, data, application and network protection for lean security teams

    Production
    • email protection
    • data protection
    • XDR and managed security
    • network security
    • application and API security
    • identity resilience
    Open full solution and discovery map

    Solution services

    • email protection

      Barracuda Email Protection · Impersonation Protection · Security Awareness Training

      Reduce phishing, account takeover, business-email compromise and user risk.

    • data protection

      Barracuda Backup · Cloud-to-Cloud Backup

      Protect and recover infrastructure, Microsoft 365 and cloud data.

    • XDR and managed security

      Barracuda XDR · Managed XDR

      Provide cross-control detection and 24x7 monitoring for resource-constrained teams.

    • network security

      CloudGen Firewall · SecureEdge

      Secure branches, WAN connectivity and cloud access.

    • application and API security

      Web Application Firewall · WAF-as-a-Service · Application Protection

      Protect web applications, APIs and bots across deployment models.

    • identity resilience

      Evo Security acquired capabilities

      Treat announced identity direction as lineage until specific generally available packaging is proven.

    Buying signals

    • email compromise or Microsoft 365 protection gap
    • backup and ransomware recovery concern
    • lean team needs managed XDR, branch or application protection

    Routing boundaries

    • An acquisition announcement or future embedding statement cannot become a GA capability.
    • Confirm whether requirements belong to email, backup, XDR, network or application control rather than treating Barracuda as one undifferentiated suite.

    Architecture and dependencies

    • SaaS, appliance, virtual and public-cloud delivery varies by product.
    • CloudGen subscriptions and services have separate licence validity.
    • Identity capabilities require an exact current-product and entitlement check.

    Discovery questions

    1. Which risk domain and operating team owns the funded problem?
    2. What Microsoft 365, server, cloud, branch and web-app estate is in scope?
    3. Is the desired operating model product-led, co-managed or fully managed?
    4. Which licence package, retention, throughput and recovery objectives apply?
  • Cloudera

    Hybrid data, analytics and enterprise AI platform

    Production
    • hybrid data platform
    • enterprise AI
    • open data lakehouse
    • governance and observability
    • data in motion
    • object and operational data
    Open full solution and discovery map

    Solution services

    • hybrid data platform

      Cloudera on cloud · Cloudera Base on premises · Hybrid Cloud

      Operate consistent data services across cloud and on-premises estates.

    • enterprise AI

      Cloudera AI · AI Inference · AI Studios · AI Workbench

      Build and operate governed private AI applications, agents and models.

    • open data lakehouse

      Data Warehouse · Data Engineering · Apache Iceberg

      Unify analytics and engineering on open table formats.

    • governance and observability

      SDX · Data Catalog · Data Lineage · Observability

      Apply metadata, lineage, access and operational governance across data.

    • data in motion

      DataFlow · Streaming · Edge Management

      Collect, route and process batch, streaming and edge data.

    • object and operational data

      Cloudera Object Store · Apache Ozone · Operational Database

      Support scalable object and low-latency operational data services.

    Buying signals

    • hybrid data fragmentation
    • private enterprise AI program
    • Hadoop modernisation, lakehouse or governance initiative

    Routing boundaries

    • The supplied discovery playbook is a design fixture, not product authority.
    • Legacy CDH, HDP and CDP naming must not create duplicate active products; technical-preview and entitlement qualifiers must be preserved.

    Architecture and dependencies

    • Cloud, on-premises and hybrid services have different support matrices.
    • Cloud providers, runtime versions, storage, identity and network prerequisites must align.
    • Some data-sharing and hybrid capabilities are technical preview or entitlement-gated.

    Discovery questions

    1. Which data and AI workloads must run where, and why?
    2. Which legacy platforms, runtimes and migration constraints exist?
    3. What governance, lineage, sovereignty and workload-portability outcomes are required?
    4. Which cloud, on-premises and entitlement dependencies apply?
  • CrowdStrike

    Endpoint, cloud, identity and AI-native security operations

    Production
    • endpoint and XDR
    • cloud security
    • identity security
    • SIEM and security operations
    • exposure and data protection
    • threat intelligence and managed response
    Open full solution and discovery map

    Solution services

    • endpoint and XDR

      Falcon Prevent · Falcon Insight XDR · Falcon Fusion

      Prevent, detect, investigate and respond across endpoint telemetry.

    • cloud security

      Falcon Cloud Security · CSPM · CWPP · CIEM

      Protect cloud posture, identities, workloads and applications.

    • identity security

      Falcon Identity Protection · Next-Gen Identity Security

      Detect and contain identity attacks and risky access.

    • SIEM and security operations

      Falcon Next-Gen SIEM · Charlotte AI

      Unify security data, detection, automation and AI-assisted investigation.

    • exposure and data protection

      Falcon Exposure Management · Falcon Data Protection

      Prioritise attack surface and protect sensitive endpoint data.

    • threat intelligence and managed response

      Falcon Adversary Intelligence · Falcon Complete MDR · Incident Response

      Add adversary context and managed 24x7 detection and response.

    Buying signals

    • endpoint or ransomware program
    • cloud or identity attack-path gap
    • SIEM modernisation or managed detection requirement

    Routing boundaries

    • Do not route pure network infrastructure, DDI or SSE requirements to CrowdStrike.
    • Acquired capabilities and integrations must retain GA, preview, packaging and data-ingestion qualifiers.

    Architecture and dependencies

    • Falcon sensor and cloud modules vary by endpoint/workload and package.
    • Data ingestion, retention and module dependencies affect SIEM and XDR outcomes.
    • Identity and cloud coverage require directory, account and workload integration.

    Discovery questions

    1. Which funded entry point is primary: endpoint, cloud, identity, SIEM, exposure or MDR?
    2. What endpoint, workload, directory and security-data scale applies?
    3. Which incumbent modules, retention, integrations and renewal dates matter?
    4. Does the team want self-operated, co-managed or managed response?
  • Infoblox

    DDI, DNS security, asset intelligence and digital risk

    Production
    • enterprise DDI
    • network automation
    • asset intelligence
    • protective DNS
    • threat intelligence and digital risk
    Open full solution and discovery map

    Solution services

    • enterprise DDI

      NIOS · Universal DDI Management · NIOS-X

      Provide authoritative DNS, DHCP and IP address management across hybrid estates.

    • network automation

      Universal DDI · Terraform and API integrations

      Automate network services and reduce spreadsheet-led address conflicts.

    • asset intelligence

      Asset Insights · Infoblox Portal

      Create cross-environment asset context from network and cloud sources.

    • protective DNS

      BloxOne Threat Defense · DNS Detection and Response

      Detect and block DNS-layer threats, tunnelling and exfiltration.

    • threat intelligence and digital risk

      Threat Intelligence · SOC Insights · Brand Protection

      Prioritise DNS threats and identify external impersonation risk.

    Buying signals

    • manual or fragmented DDI
    • DNS-borne threat or exfiltration
    • unknown assets, hybrid-cloud network automation or brand abuse

    Routing boundaries

    • Infoblox is not EDR, a full SSE platform, NGFW or SIEM.
    • Announced transactions and retired BloxOne DDI SKUs must not become current native capability or sellability claims.

    Architecture and dependencies

    • NIOS appliances, virtual instances and NIOS-X service points differ.
    • Existing DNS authority, IP plan, cloud accounts and automation platforms must be mapped.
    • NIOS release, hardware generation and licence type affect support.

    Discovery questions

    1. Is the root problem DDI authority, DNS security, asset truth or external digital risk?
    2. Which DNS, DHCP, IPAM and cloud-native systems exist?
    3. How are addresses, assets and changes reconciled with CMDB and automation?
    4. Which NIOS release, platform and subscription constraints apply?
  • Netskope

    Data-centric SSE, SASE and AI governance

    Production
    • security service edge
    • SASE and branch
    • data security
    • cloud threat and posture
    • AI security
    • enterprise browser and experience
    Open full solution and discovery map

    Solution services

    • security service edge

      Next Gen Secure Web Gateway · CASB · Cloud Firewall · Netskope Private Access

      Control web, SaaS, private-app and non-web traffic through cloud-delivered policy.

    • SASE and branch

      Netskope One · NewEdge · SD-WAN

      Converge access, security and branch connectivity.

    • data security

      DLP · DSPM · Data Lineage

      Discover sensitive data and control its movement across cloud, web and devices.

    • cloud threat and posture

      Threat Protection · SSPM · Public Cloud Security

      Reduce cloud application, configuration and malware risk.

    • AI security

      AI Guardrails · AI Gateway · AI Red Teaming

      Govern employee, application and agent use of AI while preserving data policy.

    • enterprise browser and experience

      Netskope One Enterprise Browser · Digital Experience Management

      Secure unmanaged or high-risk access and measure user experience.

    Buying signals

    • proxy or VPN replacement
    • SaaS, DLP or unmanaged-device gap
    • branch SASE or enterprise AI governance

    Routing boundaries

    • Netskope is not EDR, authoritative DDI or an application-delivery controller.
    • Edition, region, steering path, product lifecycle and entitlement constrain broad SASE and AI claims.

    Architecture and dependencies

    • Traffic steering, client, tunnel, browser and API modes vary by use case.
    • Identity provider, endpoint posture, application inventory and data classifications are prerequisites.
    • Licences expose exact product codes, quantities and AI usage entitlements.

    Discovery questions

    1. Which entry point is funded: web/SaaS, ZTNA, data, branch, browser, cloud posture or AI?
    2. Which users, devices, sites and applications generate the traffic?
    3. What data activities must be allowed, coached, blocked or audited?
    4. Which steering, identity, licence and regional requirements apply?
  • Okta

    Workforce and customer identity, governance, privileged access and identity threat protection

    Production
    • workforce access
    • identity lifecycle and automation
    • identity governance
    • privileged access
    • identity threat and posture
    • customer identity
    Open full solution and discovery map

    Solution services

    • workforce access

      Okta Single Sign-On · Adaptive MFA · Okta FastPass · Universal Directory · Device Access

      Centralise workforce authentication and apply phishing-resistant, contextual access across applications and devices.

    • identity lifecycle and automation

      Lifecycle Management · Okta Workflows

      Automate joiner, mover and leaver access changes and orchestrate identity-led IT and security processes.

    • identity governance

      Okta Identity Governance · Access Requests · Access Certifications · Entitlement Management

      Govern least-privilege access with requests, reviews, entitlement context and auditable decisions.

    • privileged access

      Okta Privileged Access · Advanced Server Access

      Reduce standing privilege and govern access to servers, service accounts and critical resources.

    • identity threat and posture

      Identity Threat Protection with Okta AI · Identity Security Posture Management · ThreatInsight

      Continuously evaluate identity risk, expose posture gaps and automate session or account remediation.

    • customer identity

      Okta Customer Identity Cloud · Auth0

      Add authentication and authorization to customer-facing applications while preserving developer control over sign-up and login experiences.

    Buying signals

    • workforce SSO, MFA or passwordless transformation
    • joiner-mover-leaver, access-review or privileged-access control gap
    • customer authentication or identity-threat program

    Routing boundaries

    • Okta is not EDR, SIEM, SSE, DDI or network enforcement; route by the identity population and control point.
    • Auth0 is an owned but distinct customer-identity platform and must not be treated as an interchangeable alias for every Okta workforce product.

    Architecture and dependencies

    • Directory, HR source, application, device and identity-provider integrations must be mapped before policy or lifecycle design.
    • SAML, OIDC, SCIM, agent and connector support varies by application and deployment pattern.
    • Workforce Identity and Customer Identity use distinct tenants, packaging, identity populations, regional options and commercial entitlements.

    Discovery questions

    1. Is the funded identity population workforce, privileged users, non-human identities, partners or application customers?
    2. Which directories, HR sources, applications, devices and authentication protocols are in scope?
    3. Is the primary outcome access, lifecycle, governance, privileged control, threat response, posture or customer experience?
    4. Which tenancy, region, integration, assurance, availability and entitlement constraints apply?
  • OpenText

    Information management, cybersecurity, service operations and DevSecOps

    Production
    • content and information management
    • cybersecurity
    • data privacy and protection
    • DevSecOps and application delivery
    • observability and service management
    • AI and automation
    Open full solution and discovery map

    Solution services

    • content and information management

      OpenText Content Cloud · Documentum · Extended ECM

      Govern, collaborate on and retain enterprise content across business processes.

    • cybersecurity

      OpenText Cybersecurity Cloud · Core Threat Detection and Response · NetIQ · Fortify

      Protect identities, applications, data and security operations across a broad portfolio.

    • data privacy and protection

      Voltage SecureData · Data Discovery and Risk Insights · Data Protector

      Discover, protect and recover sensitive enterprise information.

    • DevSecOps and application delivery

      Fortify · Core Software Delivery Platform · ALM/Quality Center

      Embed application security, testing and delivery governance.

    • observability and service management

      Operations Bridge · Network Observability · Service Management

      Operate applications, infrastructure, networks and enterprise services.

    • AI and automation

      OpenText Aviator

      Apply generative AI and automation within governed information-management workflows.

    Buying signals

    • content or records modernisation
    • application-security or DevSecOps program
    • IT operations, identity, data-protection or service-management consolidation

    Routing boundaries

    • OpenText corporate breadth never proves a specific product match.
    • Historical brands, Micro Focus lineage and divested businesses require current product ownership and lifecycle proof.

    Architecture and dependencies

    • SaaS, private cloud and software delivery varies widely by product.
    • Legacy product names and licence schedules must be resolved at product level.
    • Integration with content repositories, identity, developer toolchains and operations data must be scoped.

    Discovery questions

    1. Which OpenText domain and exact product owns the outcome?
    2. What legacy brand, version, repository or operational platform exists?
    3. Which data, compliance, workflow and integration requirements apply?
    4. What current licence schedule, deployment model and support lifecycle governs the product?
  • Palo Alto Networks

    Network, cloud, SASE, security operations and AI security platforms

    Production
    • network security
    • SASE
    • cloud security
    • security operations
    • AI security
    • services and threat intelligence
    Open full solution and discovery map

    Solution services

    • network security

      Strata · PA-Series · VM-Series · Cloud NGFW · PAN-OS

      Protect data-centre, branch, cloud and internet traffic with policy-led prevention.

    • SASE

      Prisma Access · Prisma SD-WAN · Prisma SASE · Autonomous DEM

      Secure users and branches while improving digital experience.

    • cloud security

      Prisma Cloud · Cortex Cloud

      Unify cloud posture, application, workload, code and runtime security.

    • security operations

      Cortex XDR · Cortex XSIAM · Cortex XSOAR · Cortex Xpanse

      Modernise detection, investigation, automation and attack-surface operations.

    • AI security

      Prisma AIRS · Cortex AgentiX

      Protect AI applications, models, data and agentic workflows with exact availability qualifiers.

    • services and threat intelligence

      Unit 42 · Advanced WildFire · Threat Prevention

      Add incident response, advisory services and shared threat intelligence.

    Buying signals

    • firewall or SASE transformation
    • CNAPP or cloud-SOC convergence
    • XDR/SIEM modernisation or AI application protection

    Routing boundaries

    • Acquired products remain distinct until exact integration, GA and packaging evidence proves otherwise.
    • Do not infer a funded displacement from an incumbent Palo Alto mention without pain, timing and ownership.

    Architecture and dependencies

    • Hardware, VM, cloud-native and SaaS models have separate licences and release trains.
    • Panorama or Strata Cloud Manager, identity, endpoint and cloud integrations affect operations.
    • Product and cloud-region availability must be checked at feature level.

    Discovery questions

    1. Which platform outcome is primary: network, SASE, cloud, SOC, AI or services?
    2. What PAN-OS, Prisma, Cortex and competitor estate exists?
    3. Which traffic, users, cloud accounts, data and response workflows are in scope?
    4. Which licences, subscriptions, integrations and renewal dates create the decision window?
  • Proofpoint

    Human-centric email, data, identity-threat and compliance security

    Production
    • email and collaboration security
    • human and identity risk
    • data security
    • compliance and archive
    • AI security and governance
    Open full solution and discovery map

    Solution services

    • email and collaboration security

      Email Protection · Targeted Attack Protection · Cloud App Security Broker

      Prevent phishing, malware, impersonation and collaboration-channel threats.

    • human and identity risk

      Identity Threat Defense · Threat Protection · Security Awareness

      Prioritise attacked people, compromised identities and risky behaviours.

    • data security

      Information Protection · DLP · DSPM · Insider Threat Management

      Discover and protect sensitive data across endpoints, cloud and user activity.

    • compliance and archive

      Enterprise Archive · Intelligent Compliance · Supervision

      Retain, discover and supervise regulated communications.

    • AI security and governance

      Acuvity-derived AI security capabilities

      Discover AI use and protect prompts, data and applications only where current packaging is verified.

    Buying signals

    • phishing, BEC or account-takeover exposure
    • insider risk, DLP or DSPM program
    • regulated archive, supervision or enterprise AI governance

    Routing boundaries

    • Proofpoint is not an endpoint, NGFW, DDI or network-infrastructure platform.
    • Acquisition context does not prove every announced AI-security function is integrated, GA or entitled.

    Architecture and dependencies

    • Mail-flow, Microsoft 365 or Google Workspace integration is foundational for email controls.
    • Endpoint agents, cloud connectors, identity and data classification vary by module.
    • Archive, compliance and AI capabilities have distinct regulatory and packaging constraints.

    Discovery questions

    1. Is the funded problem email, identity/human risk, data, compliance or AI?
    2. Which mail, collaboration, identity, endpoint and data repositories are in scope?
    3. What threat, regulatory or change event creates urgency?
    4. Which modules, retention, regions and managed-service requirements apply?
  • Rubrik

    Cyber resilience, data security and identity recovery

    Production
    • backup and recovery
    • ransomware and cyber recovery
    • cloud and SaaS resilience
    • data security posture
    • identity resilience
    • cyber recovery services
    Open full solution and discovery map

    Solution services

    • backup and recovery

      Rubrik Security Cloud · Rubrik CDM

      Protect and recover enterprise applications, databases, files and virtual infrastructure.

    • ransomware and cyber recovery

      Threat Monitoring · Anomaly Detection · Clean Room Recovery

      Detect destructive activity and restore clean, tested data after cyber incidents.

    • cloud and SaaS resilience

      Cloud Data Protection · Microsoft 365 Protection · Salesforce Protection

      Protect cloud-native and SaaS data through policy-led recovery.

    • data security posture

      Data Threat Analytics · Sensitive Data Discovery

      Find sensitive data, exposure and suspicious change across protected estates.

    • identity resilience

      Identity Recovery · Identity Roll Forward

      Recover identity systems and changes with GA versus preview qualifiers preserved.

    • cyber recovery services

      Rubrik Cyber Recovery · Incident Response support

      Operationalise recovery planning, testing and incident execution.

    Buying signals

    • ransomware recovery concern
    • legacy backup modernisation
    • cloud/SaaS or identity recovery gap

    Routing boundaries

    • Do not equate backup completion with tested cyber recovery.
    • Private-preview, roadmap and GA identity-resilience capabilities must remain separate.

    Architecture and dependencies

    • Workload support depends on Rubrik CDM/RSC release and compatibility matrix.
    • Archive targets, immutability, network, identity and retention design affect recovery.
    • Each major CDM release follows a support lifecycle and upgrade path.

    Discovery questions

    1. Which workloads, identities and SaaS systems have explicit recovery objectives?
    2. What immutable copies, isolation, clean-room and test practices exist?
    3. Which CDM/RSC versions and compatibility constraints apply?
    4. What RPO, RTO, retention and cyber-insurance evidence is required?
  • SentinelOne

    Endpoint, cloud, identity, AI SIEM and managed response

    Production
    • endpoint and XDR
    • cloud security
    • identity security
    • AI SIEM and security data
    • AI-assisted operations
    • managed security
    Open full solution and discovery map

    Solution services

    • endpoint and XDR

      Singularity Endpoint · Singularity XDR

      Prevent, detect, contain and remediate endpoint attacks with autonomous response.

    • cloud security

      Singularity Cloud Security · CNAPP

      Protect cloud workloads, containers, posture and runtime.

    • identity security

      Singularity Identity

      Detect identity exposure, credential misuse and lateral movement.

    • AI SIEM and security data

      Singularity AI SIEM · Security Data Lake

      Ingest, retain and investigate multi-source security telemetry.

    • AI-assisted operations

      Purple AI

      Accelerate hunting and investigation with natural-language assistance.

    • managed security

      Vigilance MDR · WatchTower · DFIR

      Add 24x7 monitoring, hunting and incident expertise.

    Buying signals

    • ransomware or EDR replacement
    • cloud or identity lateral-movement risk
    • SIEM cost, analyst workload or 24x7 coverage gap

    Routing boundaries

    • SentinelOne is not a network access, DDI, SSE or infrastructure platform.
    • Preview and announced AI offerings require exact GA and package evidence.

    Architecture and dependencies

    • Agents, cloud connectors, identity integration and telemetry ingestion vary by family.
    • Retention, endpoint count, MDR scope and package tier change outcomes.
    • AI features must be checked for region, release and entitlement.

    Discovery questions

    1. Which entry point is funded: endpoint, cloud, identity, SIEM/data, AI or MDR?
    2. What endpoint, workload, directory and data-ingestion scale applies?
    3. What response, rollback, retention and operating-model outcome is required?
    4. Which package, renewal and integration constraints apply?
  • Zero Networks

    Agentless microsegmentation, identity segmentation and ZTNA

    Production
    • network microsegmentation
    • identity segmentation
    • zero trust network access
    • OT and IoT segmentation
    • AI-agent and non-human access controls
    Open full solution and discovery map

    Solution services

    • network microsegmentation

      Zero Networks Microsegmentation

      Reduce lateral movement with automated network policies and existing host firewalls.

    • identity segmentation

      Identity Segmentation

      Constrain privileged, service and administrative identity paths.

    • zero trust network access

      ZTNA

      Provide brokered employee and third-party access without broad network exposure.

    • OT and IoT segmentation

      Agentless segmentation

      Segment devices where endpoint agents are impractical.

    • AI-agent and non-human access controls

      Platform policy controls

      Apply exact verified identity and network controls to service or agent access.

    Buying signals

    • ransomware lateral-movement concern
    • segmentation program stalled by complexity
    • third-party, OT or service-account access exposure

    Routing boundaries

    • The ambiguous alias Zero is forbidden.
    • Agentless simplicity claims do not remove the need to validate operating-system firewall, directory, network and application dependencies.

    Architecture and dependencies

    • Directory, network telemetry and host-firewall compatibility must be validated.
    • ZTNA and segmentation enforce at different control points.
    • Legal entity, geography, package and API support require exact contract evidence.

    Discovery questions

    1. Which lateral-movement path or access population is in scope?
    2. Which hosts, devices, directories and operating systems can enforce policy?
    3. What exceptions, learning period and application dependencies exist?
    4. Is the funded outcome microsegmentation, identity segmentation, ZTNA or a phased combination?
  • Darktrace

    Behavioural-AI detection, response and exposure management

    Production
    • network detection and response
    • email and collaboration security
    • cloud security
    • OT security
    • identity and endpoint context
    • exposure, incident and managed services
    Open full solution and discovery map

    Solution services

    • network detection and response

      Darktrace / NETWORK · Autonomous Response

      Model network behaviour, investigate anomalies and respond to threats.

    • email and collaboration security

      Darktrace / EMAIL

      Detect account, content and behavioural threats across messaging.

    • cloud security

      Darktrace / CLOUD

      Detect and investigate behavioural risk across cloud workloads and control planes.

    • OT security

      Darktrace / OT

      Monitor industrial assets, protocols and operational context.

    • identity and endpoint context

      Darktrace / IDENTITY · Endpoint integrations

      Add identity behaviour and endpoint context to cross-domain investigations.

    • exposure, incident and managed services

      PREVENT · HEAL · MDR · Incident Readiness and Recovery

      Prioritise exposure, support response and supplement security operations.

    Buying signals

    • unknown or novel-threat detection gap
    • network, email, cloud or OT behavioural visibility
    • lean SOC needs autonomous response or managed monitoring

    Routing boundaries

    • Ownership context cannot substitute for product, architecture, lifecycle or entitlement evidence.
    • Behavioural detection should not be presented as a replacement for every preventative control.

    Architecture and dependencies

    • Sensors, integrations, data sources and response authority differ by domain.
    • Appliance, virtual and cloud-service specifications must be validated.
    • MDR, response and data-processing terms are separately scoped.

    Discovery questions

    1. Which domain lacks visibility or response: network, email, cloud, OT, identity or exposure?
    2. Which telemetry and enforcement integrations are available?
    3. What autonomous action is permitted and how will it be governed?
    4. Which product modules, services, deployment and data-residency terms apply?
  • ExtraHop

    Network detection, packet forensics and performance visibility

    Production
    • network detection and response
    • network performance and observability
    • packet and record forensics
    • intrusion detection
    • encrypted and hybrid-cloud visibility
    • security integrations
    Open full solution and discovery map

    Solution services

    • network detection and response

      RevealX 360 · RevealX Enterprise

      Detect, investigate and respond using network-derived evidence.

    • network performance and observability

      ExtraHop sensors · Dashboards · Records

      Troubleshoot application, service and protocol performance.

    • packet and record forensics

      Packetstore · Recordstore · Forensic Investigations

      Retain packets and records for high-fidelity investigation.

    • intrusion detection

      RevealX detections · IDS capabilities

      Detect suspicious activity with protocol and behavioural context.

    • encrypted and hybrid-cloud visibility

      TLS decryption · Cloud sensors

      Extend network evidence into encrypted and public-cloud environments.

    • security integrations

      REST APIs · CrowdStrike integration · SIEM/SOAR integrations

      Enrich and orchestrate broader security workflows.

    Buying signals

    • east-west visibility or investigation gap
    • packet evidence needed for incidents
    • network and application performance issues share the same telemetry need

    Routing boundaries

    • NDR, IDS, forensics and performance are distinct capabilities with separate retention and package needs.
    • ExtraHop visibility and detection do not replace network policy enforcement.

    Architecture and dependencies

    • Sensors require traffic access through taps, mirrors or cloud-native sources.
    • Console, sensor, recordstore and packetstore sizing affect retention and performance.
    • Subscription and protocol-module licences affect available data and features.

    Discovery questions

    1. Which networks, clouds and traffic paths must be observed?
    2. Is the priority detection, packets, records, performance or a combination?
    3. What throughput, retention and encryption requirements apply?
    4. Which response, SIEM, endpoint and cloud integrations are required?
  • Illumio

    Breach containment, segmentation and lateral-movement visibility

    Production
    • hybrid visibility and insights
    • data-centre workload segmentation
    • cloud segmentation
    • endpoint segmentation
    • breach containment
    • vulnerability-informed policy
    Open full solution and discovery map

    Solution services

    • hybrid visibility and insights

      Illumio Insights

      Map communications, risk and lateral-movement exposure across hybrid estates.

    • data-centre workload segmentation

      Illumio Segmentation for Data Centers

      Apply label-based policy to workload communications.

    • cloud segmentation

      Illumio Segmentation for Cloud

      Extend segmentation to public-cloud and cloud-native workloads.

    • endpoint segmentation

      Illumio Endpoint

      Contain peer-to-peer and ransomware movement across endpoints.

    • breach containment

      Illumio Platform

      Combine visibility, policy and enforcement to reduce blast radius.

    • vulnerability-informed policy

      Vulnerability Maps

      Prioritise segmentation using vulnerability context where licensed.

    Buying signals

    • microsegmentation mandate
    • ransomware blast-radius concern
    • hybrid application dependency and lateral-movement visibility gap

    Routing boundaries

    • Renamed products and legacy CloudSecure documentation must resolve to one current identity.
    • Visibility, policy authoring and enforcement must be distinguished for each workload type.

    Architecture and dependencies

    • PCE, VEN and lightweight/agentless approaches vary by use case and release.
    • Label design, application owners, host compatibility and existing firewalls affect enforcement.
    • Vulnerability features and deployment modes have separate licences.

    Discovery questions

    1. Which workloads, endpoints and clouds define the containment scope?
    2. What application dependency and label data is trustworthy?
    3. Which enforcement points and operating systems are supported?
    4. What rollout, exception, policy-test and licence model is required?
  • Oracle

    Cloud infrastructure, databases, enterprise applications and industry platforms

    Production
    • cloud infrastructure
    • database and data AI
    • enterprise applications
    • developer and integration
    • security and identity
    • industry platforms
    Open full solution and discovery map

    Solution services

    • cloud infrastructure

      Oracle Cloud Infrastructure · Compute · Storage · Networking

      Run enterprise workloads on public, dedicated-region and hybrid cloud infrastructure.

    • database and data AI

      Oracle Database · Autonomous Database · Exadata · HeatWave

      Operate transactional, analytical and AI-enabled data platforms.

    • enterprise applications

      Oracle Fusion Cloud ERP · HCM · SCM · CX

      Modernise finance, people, supply-chain and customer operations.

    • developer and integration

      Oracle Integration · API Management · Container Engine for Kubernetes

      Integrate applications and build cloud-native services.

    • security and identity

      OCI IAM · Cloud Guard · Data Safe · Oracle Access Governance

      Control identities, posture, data and cloud threats.

    • industry platforms

      Oracle Health · Communications · Financial Services · Retail

      Support sector-specific applications and operating models.

    Buying signals

    • Oracle database or application modernisation
    • OCI migration, sovereign/dedicated region or multicloud program
    • ERP/HCM/SCM transformation

    Routing boundaries

    • Oracle corporate breadth never proves a specific product fit.
    • OCI, database, applications and industry products require separate owners, architectures, licences and evidence.

    Architecture and dependencies

    • Commercial, government, dedicated-region, Cloud@Customer and SaaS models differ.
    • Database editions, options, metrics and application modules have detailed licensing.
    • Identity, network, data migration and coexistence architecture must be explicit.

    Discovery questions

    1. Which Oracle product, workload and business outcome is actually funded?
    2. Is the program infrastructure, database, application, integration, security or industry specific?
    3. What version, edition, option, region and deployment model applies?
    4. Who owns licensing, migration, architecture and operating change?
  • Saviynt

    Converged identity governance, privileged access and identity posture

    Production
    • identity governance and administration
    • privileged access management
    • identity security posture
    • application access governance
    • external identity management
    • non-human and AI identity
    Open full solution and discovery map

    Solution services

    • identity governance and administration

      Saviynt IGA

      Automate identity lifecycle, access requests, certifications and least-privilege governance.

    • privileged access management

      Saviynt PAM · Just-in-Time Access

      Reduce standing privilege and govern privileged sessions and credentials.

    • identity security posture

      Saviynt ISPM

      Find excessive access, misconfiguration and identity risk.

    • application access governance

      Application Access Governance

      Apply fine-grained and cross-application controls to enterprise applications.

    • external identity management

      External Identity Management

      Govern vendors, contractors, partners and other third parties through their lifecycle.

    • non-human and AI identity

      Non-Human Identity · Identity Security for AI · Saviynt MCP Server

      Discover and govern machine, service and AI-agent identities with exact release qualifiers.

    Buying signals

    • legacy IGA replacement
    • PAM and governance convergence
    • third-party, non-human or AI identity risk

    Routing boundaries

    • Savient is a forbidden misspelling and unsafe alias.
    • Financing is not acquisition; IGA, PAM, ISPM, application and AI modules need separate package proof.

    Architecture and dependencies

    • Native SaaS and private-cloud options have different architecture constraints.
    • Authoritative HR, directories, applications, roles and entitlement data must be integrated.
    • Connector coverage, data quality and operating governance determine time to value.

    Discovery questions

    1. Which identity populations and applications are in scope?
    2. Is the funded outcome lifecycle, certification, PAM, posture, external or non-human identity?
    3. Which source systems, connectors, roles and toxic combinations must be governed?
    4. What deployment, residency, package and implementation-service requirements apply?