Vault SOC

Environment

Everything Vault SOC connects to inside Halcyon Precision's tenants.

Cortex XDR Pro

Healthy
Last sync
07:30:12 PT
Volume (24h)
612k events
Scope
Read + Act
  • Agents418 · 411 connected · 5 disconnected >7d · 2 out of date
  • Prevention policy coverage99.5% (416/418)
  • XQL dataset accessxdr_data, endpoints, alerts
  • API key roleVault SOC – Investigator + Responder
  • ConnectionAdvanced API key, IP-allowlisted to GovCloud NAT

Strata Cloud Manager

Healthy
Last sync
07:29:48 PT
Volume (24h)
9.1M logs
Scope
Read + EDL
  • Managed devicesHQ-FW-01/02 (PA-3410 HA) · 3× PA-445 · Prisma Access (180 MU)
  • SubscriptionsATP · Adv. URL · Adv. DNS · Adv. WildFire
  • BPA score84%
  • Posture insights3 rules with "any" app · 1 decryption gap
  • ATP coverageEnabled on 92% of rules
  • Config push accessEDLs + folder "Vault-SOC" only

Microsoft 365 GCC High

Healthy
Last sync
07:30:02 PT
Volume (24h)
48k signals
Scope
Read + Act
  • Entra ID P2Risky users: 2
  • Defender for Office 365Plan 2 · Safe Links / Attachments on
  • Purview DLPCUI sensitivity labels (CUI, CUI//SP-EXPT)
  • Intune231 managed devices
  • App registrationAzure Government · portal.azure.us
  • Graph permissionsSecurityEvents.Read.All, SecurityIncident.ReadWrite.All, User.RevokeSessions.All, ThreatHunting.Read.All, AuditLog.Read.All
  • Endpointsgraph.microsoft.us · security.microsoft.us

AWS GovCloud · AI SOC

Healthy
Last sync
07:30:15 PT
Volume (24h)
1,284 runs
Scope
Customer-owned
  • ModelCustomer-approved model · AWS GovCloud (us-gov-west-1)
  • Regionus-gov-west-1
  • CloudTrailLogging on
  • KMSCustomer-managed key
  • Vault accessIAM role VaultSOC-Operator (revocable)
  • Monthly usage$412

Model provenance

DEMO DATA

Customer-approved models only · MP-01 · customer model approval policy v1.0

ModelProviderHostingStatusApproved by / policy ownerDate
Approved model A (non-Anthropic)ACTIVE DEMO SELECTIONCustomer-approved provider AAWS GovCloud BedrockApprovedHalcyon CISOSep 1, 2026
Approved model B (non-Anthropic)Customer-approved provider BAzure OpenAI in Azure GovernmentApprovedHalcyon CISOSep 1, 2026
All Anthropic modelsAnthropicAll hosting locationsBlockedCustomer account policyMar 3, 2026

All Anthropic models — denied by account policy (IAM/SCP deny on bedrock:InvokeModel for anthropic.*)

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "DenyAnthropicModels",
      "Effect": "Deny",
      "Action": [
        "bedrock:InvokeModel",
        "bedrock:InvokeModelWithResponseStream"
      ],
      "Resource": [
        "arn:aws-us-gov:bedrock:*::foundation-model/anthropic.*",
        "arn:aws-us-gov:bedrock:*:*:inference-profile/*anthropic.*"
      ]
    }
  ]
}

Illustrative policy, registry and evidence — not deployed account controls or a claim of model catalog availability. Production controls must cover inference profiles and every model hosting location.

Last 30 days: 41,920 model invocations · 0 Anthropic invocations · source: CloudTrail

September 8–October 8, 2026 (last 30 days) · Synthetic evidence, not a certification of the live demo chat.

Demo only · Swapping needs customer approval and is logged in the Audit Log. The demo chat connection is unchanged.

Data boundary

Customer boundary · Halcyon Precision
Cortex XDR
Strata Cloud Manager
M365 GCC High
AWS GovCloud AI SOC · your approved AI model

Telemetry, CUI and ITAR technical data never leave this boundary. The AI runs here.

Summaries & metadata onlyno CUI
Vault Agentics

Receives incident summaries for engineer review. Acts only through the revocable cross-account role.