NOXA product scope is presented from implemented runtime behavior.
This page follows repository-backed capabilities and responsibility boundaries across runtime, factory, and packager.
Runtime capabilities confirmed in repository documentation
Each capability below is anchored to runtime docs and code paths.
Incidents are the primary operational object, with ticket flows maintained as compatibility paths where needed.
Heterogeneous events are normalized into stable operational fields while raw payload access stays controlled and auditable.
NOXA links incidents to assets, findings, remediation plans, and timeline events to support coordinated response workflows.
NOXA integrates with SIEM/EDR/XDR/scanners/webhooks while focusing on correlation, deduplication, and incident operations.
MITRE mapping, analyst decisions, enrichment actions, and workflow transitions are expected to remain traceable.
AI support is optional, local-first/controlled, and constrained by RBAC, data visibility rules, and trust-chain policies.
Runtime, Factory, and Packager keep explicit roles
Signing and key generation remain outside runtime; runtime stays verify-only.