Neocortex

Neocortex SecOps

Enterprise security, from every angle.

Neocortex SecOps is the security operations layer around the AI operating system: identity, data, secrets, agents, MCP, applications, infrastructure, testing, evidence and incident response — governed as one system.

Defence in depth

Security is not one scanner. It is a system of controls.

SecOps connects preventative controls, active testing, operational guardrails and evidence. A weakness discovered in one layer becomes a signal for the others.

01

Identity & access

Provider-backed authentication, MFA/SSO options, role-aware access checks and organisation boundaries protect who can reach each capability.

02

Data isolation

Organisation-scoped data, least-privilege access and controlled storage keep customer knowledge and records separated.

03

Secrets & keys

Doppler, Azure Key Vault, Vercel runtime injection and PB-LEGION DPAPI provide a layered secret-management model.

04

AI & agents

Tool scopes, context boundaries, budgets, approvals and policy checks constrain what agents can see and do.

05

MCP & integrations

Connected tools are treated as attack surfaces: authentication, scopes, parameters and resource access are tested.

06

Application security

SAST, dependency, API, backend, database, web, configuration and data-leakage checks cover the application layer.

07

Runtime assurance

Trusted runners, health checks, monitoring, safe preflight and controlled operational workflows provide continuous assurance.

08

Evidence & response

Findings, remediations, verification, key lifecycle events and security decisions become auditable evidence.

Secure Key Management

Secrets are a security operation — not a settings field.

Credential posture, rotation, revocation, provider health and dependencies belong inside SecOps. The platform manages references and metadata while dedicated providers protect the underlying secret material.

Layered provider hierarchy

1

Doppler

Operational source of truth

2

Azure Key Vault

Crown-jewel enterprise vault

3

Vercel

Runtime copy of only what the application requires

4

DPAPI

Protected PB-LEGION local protection

5

.env / set-env.cmd

Pointers and configuration — never committed credentials

Hash, don’t hoard

Neocortex-issued agent API keys are hashed after creation; safe fragments identify them without retaining the credential.

Rotate before compromise

Age, expiry and usage signals identify credentials that should be rotated before they become an incident.

Revoke decisively

Compromised or obsolete credentials can be revoked and the action recorded as security evidence.

Verify without revealing

Health probes report configured/healthy state and metadata — never the secret value.

Understand blast radius

Rotation and revocation can identify dependent services and scopes before an operator changes access.

Keep evidence clean

Audit records contain actor, action, target and result — never bearer tokens or private secret material.

What is protected

Every modern enterprise attack surface.

Code & dependencies

SAST, dependency audit, secret detection, licence and IaC checks.

Web & API

OWASP web and API testing, headers, sessions, authentication and input validation.

AI & MCP

Prompt injection, jailbreak, tool injection, resource access and context-isolation testing.

Data & privacy

Sensitive-data, PII, PCI-oriented and leakage checks.

Infrastructure

DNS, domain, configuration, connection and operational security checks.

Quality & resilience

Browser, accessibility, E2E, load, chaos and performance assurance.

Demonstrable control loop

A security signal becomes an accountable action.

Detect → assess → contain → remediate → verify → record. The point is not to produce more alerts; it is to make security posture observable and actionable.

  1. 01

    Detect

    Scanner, policy or monitoring signal

  2. 02

    Assess

    Severity, affected asset and blast radius

  3. 03

    Contain

    Scope, approval, isolation or revoke

  4. 04

    Remediate

    Fix the control, code or dependency

  5. 05

    Verify

    Run a safe verification probe

  6. 06

    Evidence

    Record the result without secret material

Security lifecycle

Security follows the software from design to production.

Threat modelling, AI-assisted development controls, code review, integration testing, staging security tests, production validation and continuous monitoring form one lifecycle.

01

Design

Threat model the system and map requirements before implementation.

02

Build

Scan code, dependencies, infrastructure and AI-generated changes continuously.

03

Release

Test APIs, web applications, MCP, performance and real user journeys before release.

04

Operate

Monitor posture, manage keys, respond to findings and retain evidence over time.

Explore the platform

Security is built into the Neocortex operating model.

SecOps works alongside the AI Conductor, Marketplace, Second Brain, integrations and agentic workflows — protecting the platform and the data flowing through it rather than sitting beside it.

SecOps describes the capabilities and architecture currently being developed for Neocortex. Compliance and assurance outcomes remain deployment-, customer- and scope-specific; Neocortex does not claim certifications it has not independently obtained.