05 · Resources
essays · architecture · policy packs

Short essays, written for an architect or an auditor — not a marketing slide.

The pieces below describe how Threxen is actually organised — the agent families and what each one does, the per-tenant key envelope that makes the isolation guarantee work, and the sector policy packs that bind verdicts to the regulator who expects them. No forward-deployed engineer required.

  • essay

    The four agents, explained

    A field guide to the Watchdog, Decoy, Containment, and Playbook agents — what each one does, what your analysts see, and what they never do.

    Read essay
  • essay

    Per-tenant key envelopes

    Why every Threxen tenant runs inside its own cryptographic envelope — and what that guarantee actually buys your auditor.

    Read essay
  • essay

    Sector policy packs

    How Threxen ships each regulated framework as a first-class control plane — detections, containment rules, evidence formats, and reporting cadences tuned to the regulator that matters.

    Read essay
  • essay

    FedRAMP active defense

    A cornerstone for federal contractors: how Threxen’s FedRAMP-aligned tenants sit inside the authorization boundary, run continuous monitoring as a first-class workload, and turn active-defense containment into a control the agency can sign off on.

    Read essay
  • essay

    HIPAA active defense

    A cornerstone for covered entities: how Threxen’s HIPAA-aligned tenants run risk analysis as a workload, lock ePHI behind per-tenant key envelopes, and turn the agent loop into an artifact an HHS / OCR reviewer can sign off on.

    Read essay
  • essay

    PCI-DSS active defense

    A cornerstone for the cardholder data environment: how Threxen’s PCI-DSS 4.0-aligned tenants segment the CDE, bind every containment action to a numbered requirement, and produce the audit-ready evidence an acquirer or QSA can review.

    Read essay
  • essay

    DORA active defense

    A cornerstone for EU financial entities: how Threxen’s DORA-aligned tenants run ICT-risk management as a workload, keep the cross-border delegation surface replayable, and bind every incident packet to the regulator’s notification cadence.

    Read essay
  • essay

    NIS2 active defense

    A cornerstone for EU essential and important entities: how Threxen’s NIS2-aligned tenants run operational resilience as a workload, satisfy the 24-hour / 72-hour / one-month reporting cadence, and keep the supply-chain surface auditable.

    Read essay