CLOUD SERVICE · VEDANUX · PRIVATE THREAT INTELLIGENCE NETWORK

VEDANUX — Know what's hostile. Before it costs you.

Dedicated reputation cloud service for the NOGTUS ecosystem — one place to ask whether an object, URL, domain, or address is known to be hostile, and receive a clear, defensible answer. Complements the NOGTUS Analytics Cluster (live telemetry, alarms, ticketing) with authoritative on-demand reputation verdicts over aged, governed indicators — for triage, hunting, post-incident forensics, and compliance review.

Cloud-native private threat intelligence network for object & URL reputation — NOGTUS-produced, curated, and confidence-scored indicator knowledge fused into a single verdict surface with four-tier taxonomy and numeric 0–100 scores.

1 Console
Universal Inquiry Bar
4 Verdict Classes
Clean · Suspicious · Malicious · Unknown
24/7
SaaS Availability · Tiered SLA
7 Modules
Cooperating behind one console
Product Identification
PRODUCT
NOGTUS VEDANUX — Cloud-Native Private Threat Intelligence Network
TYPE
Object & URL reputation · SaaS subscription (datasheet v1.0 prototype · April 2026)
COVERAGE
Web console app.vedanux.nogtus.cloud · API api.vedanux.nogtus.cloud · TLS 1.3 · multi-tenant SaaS — quotas & SLA per Service Description / order
DELIVERY MODEL
Annual subscription · no hardware shipment · NOGTUS-operated SaaS
OPERATOR
PT Neurogs Inovasi Teknologi
TENANCY
Multi-tenant, per-tenant isolation
What VEDANUX Is

The architectural role and operating thesis.

VEDANUX is standalone and separately licensed: it complements — but does not duplicate — the NOGTUS Analytics Cluster. Where the Analytics Cluster reasons over live telemetry to detect, alarm, and ticket events in real time, VEDANUX reasons over aged, governed indicators to deliver authoritative reputation verdicts on demand during triage, hunting, post-incident forensics, or compliance review. It can be used alone for reputation-centric teams or wired into the Analytics Cluster and Forensic Integrated Platform as the single authoritative reputation source — eliminating parallel TI feeds and giving every analyst one shared verdict surface across the NOGTUS estate.

Delivery matches the datasheet: exclusively cloud-native SaaS — no on-prem edition, no customer appliance, no installable package. Subscribers use the public console (app.vedanux.nogtus.cloud) and managed API (api.vedanux.nogtus.cloud). Every lookup follows the same three-stage path the datasheet describes — Vedanux Engine → Knowledge Sources (Threat Intelligence Core + Reputation Corroboration Grid, both NOGTUS-operated, parallel, fused) → Verdict Workspace — whether the inquiry is a console search, an API call from the cluster, or batch work from a forensic case file. One inquiry, one verdict, one audit trail.

Analyst experience follows the datasheet modules V03–V07: universal inquiry bar with auto type detection; verdict workspace with Detection · Details · Relations · History · Export tabs; object vs web inspection panels; relations graph with semantic edges and permalinks; history, bookmarks, tags, watchlists, and exports including STIX 2.1. Commercially, VEDANUX is an annual subscription service — Starter, Professional, and Enterprise tiers differ by quota, users/workspaces, coverage depth, API rate, retention, and support; SLA figures (e.g. indicative ≥99.9% monthly availability for Enterprise, sub-second p95 cached latency) are tier-dependent and binding only where reproduced in the customer's Service Description and Order Form.

Architecture Overview · Three-Stage Resolution

One inquiry. One governed verdict. One audit trail.

Every VEDANUX lookup follows a deterministic three-stage path. The Vedanux Engine orchestrates resolution; Knowledge Sources — the Threat Intelligence Core and the Reputation Corroboration Grid, both operated end-to-end by NOGTUS — return verdicts; and the Verdict Workspace presents a structured, exportable result. The same path serves a manual analyst search, an API call from the Analytics Cluster, and a batch lookup from a forensic case file.

Stage 1 · V01

Vedanux Engine

The reputation reasoning core. Identifies indicator type, routes parallel queries, fuses multi-source signals, and produces a single normalised verdict — category, numeric score (0–100), contributing-layer breakdown, and timestamps.

  • Auto type detection — MD5 / SHA-1 / SHA-256 / SHA-512 / URL / Domain / IPv4 / IPv6
  • Parallel resolution with timeout governance
  • Verdict fusion via documented scoring model
  • Hot-cache for repeat lookups < 1 second
  • Full audit trail — every query and verdict change logged
Stage 2 · V02

Knowledge Sources

Threat Intelligence Core and Reputation Corroboration Grid — both produced and managed in-house by NOGTUS. Unified schema, graceful degradation if any internal layer is degraded.

  • NOGTUS-produced indicator knowledge with per-indicator confidence (0–100)
  • Tagging by malware family, campaign, MITRE ATT&CK, target sector
  • Long retention with archival tier; every verdict change audit-logged
  • Service health, freshness, and capacity governed by NOGTUS
  • Graceful degradation with clear partial-confidence indicator
Stage 3 · V04

Verdict Workspace

Structured result page — verdict badge, multi-layer matrix, relations graph, history, and export. Every workspace is shareable, bookmarkable, and exportable as JSON, CSV, or PDF.

  • Above-the-fold verdict badge (Clean · Suspicious · Malicious · Unknown) + score
  • Multi-layer detection matrix per NOGTUS-operated source
  • Technical metadata tab — hashes, GeoIP, ASN, TLS fingerprint
  • Relations graph — pivot from any indicator to its neighborhood
  • Export: JSON · CSV · PDF · STIX 2.1
Capability Architecture · Platform Specification

Regrouped by engineering capability.

Capability Domain — Reputation Engine

Object & URL reputation · Vedanux Engine · Parallel fusion · numeric 0–100 scores · datasheet-aligned pipeline

Object and URL reputation are resolved through the Vedanux Engine — the join point between the inquiry surface and NOGTUS-operated knowledge sources.

The engine routes parallel queries to the Threat Intelligence Core and Reputation Corroboration Grid, then fuses multi-source signals into one final verdict category plus a numeric reputation score (0–100).

Every indicator follows the deterministic three-stage datasheet path: Vedanux Engine (routing, caching, fusion) → Knowledge Sources (parallel NOGTUS layers) → Verdict Workspace (structured, exportable UI) — one consistent audit trail.

Auto type detection covers hashes (MD5 / SHA-1 / SHA-256 / SHA-512), URL, domain, IPv4, IPv6, and file upload — from input shape alone, without analyst-provided type hints.

Capability Domain — Universal Inquiry Console

Single universal search bar · auto-detection · Minimal home shell · bulk CSV · workspaces

Web console with one universal search bar that automatically detects input type — MD5/SHA-1/SHA-256/SHA-512 hashes, URL, domain, IPv4, IPv6 — matching the datasheet inquiry model.

Live inline type hints while typing (e.g. SHA-256, Domain, IPv6) for confidence before submit; drag-and-drop file upload from the home page with configurable limits and sandboxed handling.

Bulk inquiry via CSV for large batches — results delivered as tracked async jobs with downloadable exports.

Deliberately austere landing experience: anything that is not the search bar is recent history, bookmarks, workspaces, or bulk upload — analysts decide what to ask, not where to type.

Capability Domain — Verdict Workspace & History

Structured result surface · permalink-ready · Detection · Details · Relations · History · Export

Structured reputation result pages with full verdict history — aligned with the Verdict Workspace module in the NOGTUS VEDANUX datasheet.

Above-the-fold verdict badge plus numeric score (0–100); tabs for Detection (multi-layer matrix), Details (type-appropriate metadata), Relations (graph), History (verdict timeline), and Export.

History captures when an indicator first appeared, how its category evolved, and who reviewed it — every verdict change logged with user, timestamp, and contributing sources.

Workspaces are shareable and bookmarkable with stable permalinks for collaboration, peer review, and incident reporting.

Capability Domain — Verdict taxonomy

Clean · Suspicious · Malicious · Unknown · Operational meanings tied to evidence depth

Concise four-class assessment on every result — the same taxonomy described in the product datasheet.

Clean: no hostile signal in the governance window — proceed with standard handling. Suspicious: mixed or low-confidence signal — pivot, deepen inspection, or escalate per playbook. Malicious: high-confidence hostile attribution from corroborated NOGTUS layers — block, contain, document. Unknown: insufficient usable signal — policy follows organisational workflow context.

Numeric reputation scores (0–100) add granularity for dashboards and automation while badges stay glanceable for triage.

Taxonomy is deterministic and documented — each verdict traces to agreed/disagreeing knowledge layers and last-seen freshness.

Capability Domain — Analyst workflow & export

History · bookmarks · tags · watchlists · JSON · CSV · PDF · STIX 2.1 handover

Per-user searchable inquiry history with verdict and timestamp — every lookup is a reusable artefact, not a throwaway query.

Bookmarks pin recurring indicators to the sidebar with notifications on verdict change; free-form and structured tags (campaign, case, incident, sector) filter across investigations.

Exports: JSON (machine-readable full result), CSV (spreadsheet-friendly summary), PDF (signed evidence document), and STIX 2.1 for structured TI handover — per datasheet.

Watchlists subscribe curated indicator lists to verdict-change alerts via email and webhook.

Capability Domain — Relations graph explorer

Visual pivoting · semantic edges · PNG · SVG · JSON · stable graph permalinks

Relations tab renders cross-indicator connections as an interactive graph — zoom, pan, expand neighbourhoods on click, filter by relation type, and open a fresh VEDANUX inquiry from any node.

Node types include File, URL, Domain, IPv4, IPv6, Email, Campaign, Actor, and TTP — colour-coded for fast reading. Semantic edge labels: communicates-with, drops, downloads-from, resolves-to, signed-by, observed-with.

Export graphs as PNG, SVG, or JSON for case files, decks, and downstream tooling; share graph views via stable session URLs.

Capability Domain — Object & web inspection

Type-aware deep panels · single workspace shell · Static file cues · WHOIS · TLS · safe URL preview

Details adapts automatically: hashes and uploaded files open the Object Inspection Panel — headers, embedded strings, signer status, hash families (incl. ssdeep/imphash), packer hints, optional deeper dynamic-analysis handoff.

URLs, domains, and IPs open the Web Inspection Panel — WHOIS and passive DNS, TLS inspection (CN, SAN, issuer, JA3/JA3S/JARM), GeoIP and ASN context, captured HTTP headers, and static screenshot preview where safe.

Same Verdict Workspace chrome for every indicator — only the Details inner view swaps; no cross-product navigation.

Capability Domain — Cloud delivery & SLA

Managed SaaS · multi-tenant · active-active · Public endpoints · tiered targets · order-bound specifics

Fully managed multi-tenant cloud — no subscriber appliance, no customer-maintained infrastructure for core service delivery; NOGTUS operates capacity, upgrades, security patching, and availability.

Public web console at app.vedanux.nogtus.cloud and managed REST API at api.vedanux.nogtus.cloud — TLS 1.3 and modern cipher suites.

Active-active tier with automatic failover; indicative ≥99.9% monthly availability target for Enterprise — Professional and Starter targets set per order.

Activated as a subscription — no shipment or installer; basic onboarding requires no professional services. Cached lookups target sub-second p95 latency; cold orchestration and file-analysis latency remain capacity-governed per datasheet.

Modules at a Glance · Seven Cooperating Modules

Seven cooperating modules behind one console.

From the moment an analyst pastes an indicator to the moment a finalized report is exported, VEDANUX moves the work through seven cooperating modules — each focused, none in the way.

V01

Vedanux Engine

The reputation reasoning core. Resolves verdicts, fuses evidence, scores indicators, applies governance windows. Every inquiry lands here first.

V02

Knowledge Sources

NOGTUS-operated reputation knowledge base — Threat Intelligence Core and Reputation Corroboration Grid — the authoritative substrate every verdict draws from.

V03

Universal Inquiry Console

One search bar. Hashes, URLs, domains, IPs — auto-detected, routed, and displayed without category-picking friction. Drag-and-drop, bulk CSV, workspace navigation.

V04

Verdict Workspace

The unified verdict surface. Badge, score, evidence trail, and source agreement matrix in one defensible view. Shareable, bookmarkable, exportable.

V05

Object & Web Inspection Panels

Object-type aware deep panels for files, URLs, domains, and addresses — purpose-built layouts. Object Inspection Panel for binaries, Web Inspection Panel for URLs/domains/IPs.

V06

Relations Graph Explorer

Pivot from any indicator to its neighborhood — related infrastructure, co-resolved indicators, shared attribution. Interactive, exportable, permalink-shareable.

V07

Analyst Workflow & Export

Save, tag, comment, share, and export inquiry records as audit-ready artifacts. Per-user history, bookmarks, watchlists with verdict-change alerts, JSON/CSV/PDF/STIX 2.1 export.

Where VEDANUX Is Used · From Triage to Final Report

From first triage to final report.

VEDANUX fits naturally into the workflows analysts already run — without adding ceremony, without locking teams to a specific SIEM or playbook.

Alert Triage

Verify hashes, URLs, and addresses surfacing in SIEM, EDR, or email security alerts before escalation. Paste any indicator and receive a governed verdict in seconds.

Threat Hunting

Pivot through related infrastructure and co-resolved indicators via the Relations Graph to widen scope from a single suspicious lead to a full campaign picture.

Forensic Review

Reconstruct the reputation context an indicator carried at investigation time, with audit-ready provenance through the History tab and verdict timeline.

Incident Reporting

Export defensible verdict records as JSON, CSV, PDF, or STIX 2.1 bundles into incident reports, regulatory filings, and post-mortem documentation.

Compliance & Audit

Demonstrate due-diligence reputation checks with traceable, time-stamped evidence on demand — signed PDF export serves as audit-defensible record.

Workflow Enrichment

Companion lookup surface for NOGTUS Analytics Cluster and Forensic Integrated Platform — single authoritative reputation source, eliminating parallel TI feeds.

Delivery & Subscription · Service Tiers

Delivered as a SaaS subscription.

VEDANUX is sold as an annual subscription. Tiers differ in inquiry volume, number of users and workspaces, reputation coverage depth, API rate, retention window, and support response. Final tier composition for a given customer is set in the order document.

Tier · STARTER

Starter

Small teams, evaluation, occasional triage

INQUIRY QUOTAEntry-level monthly quota
USERS & WORKSPACESLimited users
SUPPORTBusiness-hours email
AVAILABILITY TARGETPer order
RETENTIONPer order
EXPORT FORMATSJSON · CSV · PDF · STIX 2.1
Tier · PROFESSIONAL

Professional

Operational SOC and IR teams

INQUIRY QUOTAOperational monthly quota
USERS & WORKSPACESMulti-user, multiple workspaces
SUPPORTBusiness-hours email + chat
AVAILABILITY TARGETPer order
RETENTIONPer order
EXPORT FORMATSJSON · CSV · PDF · STIX 2.1
Tier · ENTERPRISE

Enterprise

Large organisations, multi-tenant holdings, integrated automation

INQUIRY QUOTAHigh monthly quota with burst allowance
USERS & WORKSPACESExtensive, with workspace federation
SUPPORT24×7 email, chat, named contact
AVAILABILITY TARGET≥ 99.9% monthly
RETENTIONPer order
EXPORT FORMATSJSON · CSV · PDF · STIX 2.1

Quotas, coverage depth, retention windows, and SLA values are confirmed per order. The values above are indicative; the binding values live in the customer's order document and Service Description.

Datasheet · Canonical specification

Numbered specification aligned with product specs.

The following blocks mirror NOGTUS VEDANUX — Cloud-Native Private Threat Intelligence Network in — single source of truth for navigation, search, JSON-LD detail lines, and this page.

Positioning & NOGTUS Ecosystem

  1. VP-01

    VEDANUX is the dedicated reputation cloud service of the NOGTUS ecosystem — cloud-native private threat intelligence network for object & URL reputation.

  2. VP-02

    Security teams use one place to ask: “Is this object, URL, domain, or address known to be hostile?” — and receive a clear, defensible answer from a multi-layer NOGTUS-operated reputation knowledge base consolidated into a single verdict surface.

  3. VP-03

    Standalone, separately-licensed cloud service that complements — but does not duplicate — the NOGTUS Analytics Cluster: where the Analytics Cluster reasons over live telemetry to detect, alarm, and ticket events in real time, VEDANUX reasons over aged, governed indicators to deliver authoritative reputation verdicts on demand — during triage, hunting, post-incident forensics, or compliance review.

  4. VP-04

    Can be used standalone for organisations that primarily need reputation lookup, or wired into the NOGTUS Analytics Cluster and Forensic Integrated Platform as the single authoritative reputation source — eliminating parallel TI feeds and giving every analyst one shared verdict surface across the entire NOGTUS estate.

Architecture Overview — Three Stages

  1. AR-01

    Every VEDANUX lookup follows a deterministic three-stage path: Stage 1 — Vedanux Engine (routing, caching, parallel orchestration, multi-layer verdict fusion, reputation scoring 0–100 per indicator); Stage 2 — Knowledge Sources (Threat Intelligence Core and Reputation Corroboration Grid, both NOGTUS-operated, queried in parallel and fused into one verdict); Stage 3 — Verdict Workspace (structured result — verdict badge, multi-layer matrix, relations graph, history — exportable to JSON · CSV · PDF).

  2. AR-02

    The same three-stage path serves a manual analyst search, an API call from the Analytics Cluster, and a batch lookup from a forensic case file.

  3. AR-03

    Indicators are produced and governed end-to-end by the NOGTUS intelligence team; validation removes unverified or transient noise before publication.

  4. AR-04

    Per-indicator confidence score (0–100) with documented methodology and version history; tagging by malware family, campaign, MITRE ATT&CK technique, and target sector.

  5. AR-05

    Long retention with archival tier; every verdict change is audit-logged.

  6. AR-06

    NOGTUS-produced · curated · confidence-scored · versioned — subscribers see one verdict, one schema, one auditable trail — never a fragmented multi-tab view.

V01 · Vedanux Engine — Reputation Orchestrator

  1. VE-01

    V01 — Vedanux Engine (reputation orchestrator): every inquiry that enters the console or the API lands here first; the engine identifies indicator type, routes parallel queries to the Threat Intelligence Core and the NOGTUS Reputation Corroboration Grid, fuses signals, and produces a single normalised result — verdict category, numeric score, contributing-layer breakdown, and timestamps.

  2. VE-02

    Auto type detection: Hash (MD5 / SHA-1 / SHA-256 / SHA-512), URL, Domain, IPv4, IPv6, file upload — detected from input shape; no analyst hint required.

  3. VE-03

    Parallel resolution: all NOGTUS-operated reputation layers queried concurrently with internal timeout and resilience governance.

  4. VE-04

    Verdict fusion: multi-source verdicts merged through a documented scoring model into one final category and numeric reputation score (0–100).

  5. VE-05

    Result caching: hot-cache layer for repeat lookups within configurable TTL, keeping common-indicator latency under a second.

  6. VE-06

    Asynchronous jobs: file-upload analysis, bulk lookups, and deep enrichment run as tracked async jobs with status polling.

  7. VE-07

    Audit trail: every query, verdict, and verdict change is logged with user, timestamp, and contributing sources for later review.

V02 · Knowledge Sources

  1. VK-01

    V02 — Knowledge Sources: Threat Intelligence Core & Reputation Corroboration Grid — two complementary reputation layers, both produced and managed in-house by NOGTUS.

  2. VK-02

    Threat Intelligence Core — authoritative core: indicators produced, validated, deduplicated, and confidence-scored by NOGTUS before they ever surface in a verdict; NOGTUS-produced indicator knowledge with documented validation, per-indicator confidence (0–100), tagging, and version history.

  3. VK-03

    Reputation Corroboration Grid — second NOGTUS-produced reputation surface that broadens and corroborates verdicts; produced and operated end-to-end by NOGTUS as the principal — no customer-facing orchestration to integrate or maintain.

  4. VK-04

    Unified schema: all signals merged into one VEDANUX verdict schema — a single result format for analysts and integrations.

  5. VK-05

    Service governance: health, freshness, and capacity of every layer monitored and managed by NOGTUS as part of the service.

  6. VK-06

    Graceful degradation: when any internal layer is degraded, the verdict still returns from the remaining healthy layer with a clear partial-confidence indicator.

  7. VK-07

    Single source of truth: Threat Intelligence Core is authoritative; corroboration enriches but never overrides governance.

V03 · Universal Inquiry Console

VEDANUX Universal Inquiry Console — app.vedanux.nogtus.cloud/inquiry with SHA-256 auto-detected
Reference UI: universal inquiry bar, inline type detection, RECENT · BOOKMARKS · WORKSPACES · BULK UPLOAD.
  1. VI-01

    V03 — Universal Inquiry Console — one bar, every indicator: deliberately empty search bar; analyst pastes hash, URL, domain, IP, or drags a file — no input-type dropdowns, no separate search pages, no wizards.

  2. VI-02

    Single search bar on the home page auto-detects hash, URL, domain, IPv4, IPv6, or file upload from input shape alone.

  3. VI-03

    Drag-and-drop upload: drop a file anywhere on the page; configurable size limit, sandboxed handling.

  4. VI-04

    Inline type hint: live label as the analyst types — e.g. SHA-256, Domain, IPv6 — for confidence before submission.

  5. VI-05

    Bulk inquiry: CSV upload accepts large indicator batches; results delivered as an async job with downloadable export.

  6. VI-06

    Workspaces: per-tenant workspace selector — searches stay isolated by workspace; Recent history, Bookmarks, Workspaces, Bulk Upload one click away.

  7. VI-07

    Theming & i18n: dark and light themes; English UI on launch; roadmap room for additional locales.

  8. VI-08

    Design intent: austere home page — every pixel that is not the search bar is history, bookmarks, or workspace navigation.

V04 · Verdict Workspace & Taxonomy

VEDANUX Verdict Workspace — verdict taxonomy and Detection · Details · Relations · History · Export tabs
Reference UI: verdict classes (Malicious · Suspicious · Clean · Unknown) and tabbed workspace.
  1. VW-01

    V04 — Verdict Workspace — structured, tabbed, exportable: answers first — what is this thing's reputation? Bold verdict badge (Clean, Suspicious, Malicious, or Unknown) and numeric reputation score (0–100) above the fold.

  2. VW-02

    Tabs: Detection (multi-source matrix), Details (technical metadata), Relations (graph), History (verdict timeline), Export (download bundle); workspace shareable and bookmarkable.

  3. VW-03

    Verdict badge: above-the-fold category with colour, icon, and numeric reputation score (0–100).

  4. VW-04

    Detection tab: multi-layer verdict matrix — each NOGTUS-operated reputation layer that contributed, with per-layer category and last-seen timestamp.

  5. VW-05

    Details tab: metadata for indicator type — hashes, file size, signer, ownership context, ASN, GeoIP, TLS fingerprint, and similar.

  6. VW-06

    Relations tab: graph showing connections — communicating IPs, sibling URLs, observed campaigns.

  7. VW-07

    History tab: chronological verdict timeline — first appearance, category evolution, who reviewed.

  8. VW-08

    Export tab: JSON, CSV, PDF, or STIX 2.1 bundle for evidence handover and ticket attachment.

  9. VW-09

    Verdict taxonomy: Clean — no negative signal; Suspicious — partial signal, low confidence; Malicious — confirmed by authoritative sources; Unknown — insufficient data to decide; numeric score gives finer granularity for dashboards and automation.

V05 · Object & Web Inspection Panels

  1. VO-01

    V05 — Object & Web Inspection Panels — Details tab adapts: files (uploaded or by hash) → Object Inspection Panel; URLs, domains, IPs → Web Inspection Panel — same workspace shell, two specialised inner views.

  2. VO-02

    Object Inspection Panel: static analysis — header parsing, embedded strings, signer status, hash family, family-level similarity hints; hash family MD5/SHA-1/SHA-256/SHA-512/ssdeep/imphash; packer or obfuscation hints; optional handoff to deeper analysis services for dynamic inspection.

  3. VO-03

    Web Inspection Panel: WHOIS and passive DNS history, TLS certificate inspection, GeoIP and ASN context, captured response headers, and a static rendering screenshot of the URL where applicable (CN, SAN, issuer, JA3 / JA3S / JARM fingerprints per datasheet).

V06 · Relations Graph

  1. VG-01

    V06 — Relations Graph — visual pivoting: interactive graph — zoom, pan, expand neighbourhood on click, filter by relation type, pivot into a new VEDANUX inquiry from any node.

  2. VG-02

    Node types: File · URL · Domain · IPv4 · IPv6 · Email · Campaign · Actor · TTP — colour-coded.

  3. VG-03

    Edge labels: communicates-with · drops · downloads-from · resolves-to · signed-by · observed-with — semantic, not just lines.

  4. VG-04

    Interaction: zoom, pan, expand-on-click, hover preview, filter chips, one-click pivot to fresh inquiry.

  5. VG-05

    Density control: adjustable expansion depth for readable graphs on dense indicators.

  6. VG-06

    Export: PNG / SVG / JSON for case files, slide decks, downstream tooling.

  7. VG-07

    Permalinks: every graph view shareable as a URL — stable across sessions.

V07 · Analyst Workflow

  1. V7-01

    V07 — Analyst Workflow — history, bookmarks, tags, export: every lookup preserved as a reusable artefact — JSON, CSV, PDF (and STIX 2.1); audit-ready record analysts and reviewers can stand behind.

  2. V7-02

    Search history: per-user chronological log with verdict and timestamp; searchable and filterable.

  3. V7-03

    Bookmarks: pin indicators to sidebar; notify on verdict change.

  4. V7-04

    Tagging: free-form and structured tags — campaign, case, incident, sector — cross-cutting filters.

  5. V7-05

    Watchlists: curated indicator lists with subscription to verdict changes; alerts via email and webhook.

  6. V7-06

    Export formats: JSON (full machine-readable result), CSV (summary), PDF (signed evidence), STIX 2.1 (structured TI handover).

  7. V7-07

    Sharing: permalink verdict workspace or graph view; share within workspace or across tenants where permitted.

Cloud Service Architecture (CSA)

  1. CS-01

    CSA — Cloud service architecture: fully-managed multi-tenant cloud; web console app.vedanux.nogtus.cloud and managed API api.vedanux.nogtus.cloud — no installable package, no customer-managed infrastructure, no subscriber patching window.

  2. CS-02

    Delivery model: SaaS subscription — activated as subscription; no shipment, no installer; basic use needs no professional services.

  3. CS-03

    Tenancy: multi-tenant with strict per-tenant isolation; per-tenant workspace partitioning, encryption keys, and audit log.

  4. CS-04

    Endpoints: web console + managed REST API; TLS 1.3 and modern cipher suites over public internet.

  5. CS-05

    Hosting: NOGTUS service team in NOGTUS-managed cloud regions; capacity, patching, upgrades fully managed.

  6. CS-06

    Availability: active-active tier with automatic failover — continuous service through individual component failures.

  7. CS-07

    Commercial framing: subscription on price list — recurring contract; no hardware asset inventory, no warranty period, no end-of-life hardware replacement.

Subscription Tiers (SUB — indicative)

  1. ST-01

    SUB — Subscription tiers (indicative; binding values in order document & Service Description): sold as annual subscription; tiers differ in inquiry volume, users & workspaces, reputation coverage depth, API rate, retention window, and support response.

  2. ST-02

    Starter — small teams, evaluation, occasional triage: entry-level monthly quota; limited users/workspaces; business-hours email.

  3. ST-03

    Professional — operational SOC and IR: operational monthly quota; multi-user, multiple workspaces; business-hours email + chat.

  4. ST-04

    Enterprise — large orgs, multi-tenant holdings, integrated automation: high monthly quota with burst; extensive workspaces with federation; 24×7 email, chat, named contact.

Service Levels (SLA — indicative)

  1. SL-01

    SLA — Service levels (tier-dependent; indicative Enterprise targets; confirmed in Service Description): service availability targeted ≥ 99.9% monthly (Enterprise); Professional and Starter lower targets per order.

  2. SL-02

    Cached lookup latency: sub-second p95 for indicators present in the verdict cache.

  3. SL-03

    Cold lookup latency: best-effort orchestration for first-time lookups; governed by NOGTUS internal capacity.

  4. SL-04

    File analysis latency: asynchronous job model — completion depends on size, complexity, analysis depth.

  5. SL-05

    Support response: tier-dependent; Enterprise includes 24×7 channels with named contact for priority cases.

  6. SL-06

    Service status: public status page with incident history and planned-maintenance announcements.

Datasheet Disclaimers

  1. DC-01

    Closing & disclaimers (datasheet): capabilities, quotas, retention, coverage depth, export formats, and SLA values depend on tier and binding order; figures are descriptive intent unless reproduced in signed Service Description / Order Form; roadmap items (extra layers, formats, locales) are transparency only — not commitments.

Related Platform Modules
Engagement · Subscription & Technical Evaluation

Put a defensible verdict behind every inquiry.

Request a tier proposal, evaluation access, or a technical workshop. The NOGTUS commercial team will walk through capacity sizing, onboarding, and integration scoping for your environment.

✉ info@neurogs.tech✆ +44 7467 141305⬡ PT Neurogs Inovasi Teknologi, Lt.19 Menara 165, Jakarta