Platform capability
OperationalPlatform assurance: monitoring the monitoring
Continuous self-verification that answers the question most security platforms never ask - is this system still capable of detecting an attack right now?
Overview
A monitoring platform can fail in a way that produces no error at all. The service is running, the dashboard loads, the disk has space - and a log source stopped reporting eleven days ago, so nothing has been detected since. The system looks healthy precisely because it has gone quiet.
Vanguard runs a heartbeat across every component every few minutes and asks a harder question than whether a service is running: is it running and has it recently ingested data. Both conditions must hold.
The states are defined carefully. A channel that is alive, being read and has nothing to report is healthy - file integrity monitoring is quiet in a well-run environment, and treating that as a fault would generate constant noise. Degraded, not-detecting, starting and patching are distinguished from each other, so an alert means something specific.
The platform also alerts on unusual silence. If the system has produced no alerts at all across a window where it normally would, that is itself a symptom worth investigating.
What this identifies
- Log sources that have silently stopped reporting
- Endpoint agents that are disconnected or have been stopped
- Components that are running but no longer processing
- Certificates approaching expiry
- Backup jobs that failed or produced an unusable result
- Notification delivery failures, which would otherwise hide every other alert
Delivery status: Operational - deployed and in production service.
Capabilities
What platform assurance does
Component heartbeat
Every component checked on a short cycle for both liveness and recent ingestion.
Log source health
A source that stops reporting raises an alert within one cycle rather than being discovered during an investigation.
Silence detection
An unusually quiet period is treated as a signal, not as good news.
Maintenance awareness
Patch windows suppress pages precisely, scoped to the specific units involved rather than to any similarly named process.
Infrastructure monitoring
Certificate expiry, disk, memory pressure, backup validation and notification delivery success.
Under the hood
The engineering underneath
How this capability is actually engineered and operated. The specific detection tooling behind the security operations centre is shared with customers under agreement rather than published, for the same reason you would not publish yours.
- A heartbeat runs on a short cycle and emits a single summary event with per-component counts.
- Component states distinguish healthy quiet from degraded and from not-detecting; quiet is never counted as a fault.
- Maintenance suppression matches on specific service units and the package lock holder, never on a bare process name.
- Alerting monitors its own delivery success, and memory pressure is alerted on rather than allocation.
The full platform architecture is documented on the architecture page.
Services
Services delivered on this capability
The platform provides the capability. These are the engagements in which Tech49Originals operates it on your behalf.
- Operational
Managed SOC
A staffed security operations centre in Windhoek monitoring your endpoints, servers and network around the clock, so you do not have to build one.
Explore - Operational
SIEM-as-a-Service
A fully operated SIEM for Namibian organisations, covering collection, retention, correlation and detection, without the infrastructure cost of running one yourself.
Explore
Related
Capabilities that work with this one
- Operational
Security Reporting
Monthly reporting generated from case records, written for both the technical team and the people who approve the budget.
Explore - Operational
SIEM & XDR
Collects security telemetry from servers, endpoints, network devices and cloud workloads into one correlated detection engine.
Explore - Operational
Incident Response
A defined path from alert to containment to closure, with analysts who investigate before they escalate.
Explore
Get started
Find out what is actually happening on your network
A short conversation is usually enough to establish whether monitoring would tell you something you do not already know. There is no obligation and no sales script.