the architecture is right.
Frequently Asked Questions
What makes AUXO™ different from other SIEM/SOAR platforms?
Every other SIEM, SOAR, and MDR platform handles Zero Trust as an event pipeline first, with ZT reporting bolted on afterwards. AUXO™ uses the protect surface as its native data schema, which is what lets EventFlow's agentic AI reduce 69 events to 3 analyst investigations.
Why does non-human identity matter for Zero Trust?
In agentic AI environments, non-human identities outnumber human ones 10:1, and the standard CISA five-pillar model does not cover this. Zero Trust for AI agents maps each pillar to what it means when the actor is software.
How current does protect surface metadata need to be?
In cloud environments, protect surface metadata drifts by default. There is a five-stage maturity ladder for keeping it current, and AUXO™'s Azure API reaches Stage 5: real-time source capture.
What is the Zero Trust Dictionary?
The Zero Trust Dictionary is the authoritative Zero Trust lexicon, with definitions by John Kindervag, updated for 2026 with nine new terms covering Non-Human Identity, Ephemeral Privilege, Intent Validation, and more.
Can Zero Trust stop attacks that don't use malware or a known vulnerability?
Yes. In the SalesLoft Drift breach, 700+ organisations were hit by valid credentials used from a slightly wrong IP range, with no CVE and no IOC involved. The Kipling Method's WHERE question would have stopped it.