Decision Intelligence Operating System™

The Decision
Intelligence
Operating System

Transform data into decisions.
Transform decisions into outcomes.

21+
Live Modules
5
Agent Types
12
Industries
< 90s
Avg. Decision Time
Category Definition

SAM is not a SIEM.
Not a SOAR. Not a dashboard.

SAM is NOT
SIEM SOAR Data Lake Search Engine Dashboard Platform Analytics Tool
SAM IS
Decision Intelligence Operating System™ The AI layer where data, sensors, agents & humans converge Explainable, auditable, defensible decisions Purpose-built for government, defense & enterprise
The Platform Architecture

Five layers.
One decision.

SAM integrates every signal source, intelligence module, and AI agent into a single decision pipeline — from raw sensor data to executed action in under 90 seconds.

Explore the Platform →
Layer 01 · Ingest

Capture Everything

Cameras, sensors, threat feeds, OT systems, identity platforms, social channels — every signal ingested and normalized to the SAM schema.

Layer 02 · Intelligence

Correlate & Understand

SAM AI correlates signals across sources, scores risk in real time, and separates noise from threat using multi-modal reasoning.

Layer 03 · Decision

Recommend with Evidence

Ranked, explainable decisions with full evidence attribution, confidence scores, and recommended actions. Every call is auditable.

Layer 04 · Action

Execute & Orchestrate

Notifications, workflow triggers, access controls, EM protocols — actions executed through connected platforms or approved by operators.

Layer 05 · Network

Learn & Predict

The Security Predictability Index improves with every decision, building institutional memory that makes every future call sharper.

Agentic AI Ecosystem

Agents that reason,
plan, and decide.

SAM's AI agents don't just retrieve — they reason, plan, use tools, collaborate, and hand decisions back to humans with full transparency.

SAM
DIOS™
Cyber
Agent
OSINT
Agent
Risk
Agent
Mission
Agent
Exec
Agent
Predict
Agent
🛡
Cyber Agent

Network, identity & endpoint correlation

🔍
OSINT Agent

Open-source, dark web & social intelligence

🎯
Mission Agent

Operational & critical-infrastructure focus

📊
Risk Agent

Predictive scoring & exposure modeling

🏛
Executive Agent

Principal protection & travel intelligence

Predictive Agent

Pattern learning & forward threat modeling

Core Capabilities

From signal to decision
in every domain.

🏙
Decision Intelligence

Command Operations

Fuse every camera, sensor, and feed into one explainable decision queue. SAM replaces the alert wall with ranked, actionable intelligence.

Converged Defense

Cyber-Physical Fusion

Correlate OT anomalies with perimeter events and identity signals to expose coordinated intrusions no single-domain system can see.

🌐
Protective Intelligence

OSINT & Exposure

Monitor principals, brands, and assets across the open web, dark web, and social channels — decisions made before threats materialize.

🚨
Response Orchestration

Notification & Action

From shelter-in-place to facility lockdown: SAM calculates the right response and executes it across every connected platform simultaneously.

📡
Predictive Intelligence

SPI Risk Scoring

The Security Predictability Index learns from every incident and near-miss to score sites, assets, and sectors before events occur.

🤖
Agentic AI

Autonomous Reasoning

AI agents that plan, use tools, collaborate across domains, and hand decisions to operators with full reasoning chains — not just alerts.

Compliance & Trust

Built for the most demanding environments.

🏛FedRAMP Ready
🔐Zero Trust Architecture
📋NIST CSF
🛡CMMC Aligned
🏥HIPAA Controls
🚔CJIS Security
SOC 2 Type II
🌐ISO 27001
💳PCI DSS
Multi-Tenant Isolation
Integration Network

21 live modules.
One decision core.

Every certified module plugs into SAM's decision core — and every decision SAM makes draws evidence from all of them.

21 modules
Why SAM

Why security leaders choose SAM.

Original intelligence.

Purpose-built, defensible technology — not a wrapper on someone else's model. SAM's decision engine is the product of original research and engineering.

Explainable decisions.

Every recommendation shows its evidence. Built for audit, liability, and command review — so you can defend the call you made.

Converged by design.

Physical, cyber, OSINT, OT, and environmental signals treated as one problem — because sophisticated threats are never domain-specific.

Open to your stack.

SAM Extend lets your threat feeds, sensors, analytics, and response tools become first-class modules in the decision network.

Government-grade.

Designed for federal, state, local, and DoD deployment from day one — with the compliance posture, audit trails, and access controls those environments require.

Network effects.

Every deployment makes the platform smarter. The SPI learns from every incident across the SAM Network — and every new module sharpens every decision.

Get Started

The Decision Intelligence
Operating System™ is ready.

Request a guided demonstration or connect with the Security 2.0 team.

The SAM Platform

Twelve capabilities.
One decision core.

SAM's platform modules are not separate products. They are facets of one decision core — each layer adding reasoning depth that makes every other layer sharper. Select any module below to explore.

12
Platform Modules
From decision intelligence to defense operations
21+
Live Integrations
Threat, physical, cyber, OSINT, and response
< 90s
Signal to Decision
From raw sensor data to executed action
100%
Explainability
Every decision fully attributed and auditable
Decision Intelligence · Core

The decision graph at the center of everything.

SAM's decision engine maintains a live graph of signals, entities, risks, and outcomes. Every new signal traverses the graph, correlates with memory, and produces a ranked, explainable recommendation in seconds.

Signal Ingestion · Every Source
Decision Graph · Correlation Engine
Explainable Decision · Evidence Attributed
Action · Executed & Logged
🔗
Decision Graph

A live knowledge graph of entities, signals, risks, and causal chains — updated in real time as new evidence arrives.

🧠
Decision Memory

Every past decision and outcome informs future correlation — institutional memory that grows with every deployment.

🎯
Decision Scoring

Risk scores are not thresholds — they are continuous, multi-dimensional, and fully explainable to command staff and auditors.

📝
Decision Explainability

Every recommendation shows its complete evidence chain: which signals, which modules, which weights, and why.

🔄
Decision Automation

Rules, workflows, and AI agents execute approved actions automatically — with human override at every step.

📋
Audit Trail

Every decision, action, and override is logged with full context — who, what, when, and why — for legal and compliance review.

Agentic AI · Orchestration Layer

Agents that reason,
plan, and collaborate.

SAM's agent ecosystem goes beyond retrieval-augmented generation. Each agent maintains working memory, uses tools, plans multi-step responses, and hands decisions to operators with full transparency.

🛡 Cyber Agent
Network · Identity · Endpoint
🔍 OSINT Agent
Open Web · Dark Web · Social
🎯 Mission Agent
Operations · Infrastructure
📊 Risk Agent
Scoring · Modeling · SPI
SAM Decision Core · Agent Orchestration
🧩
Agent Registry

Every agent is versioned, credentialed, and auditable. Deploy from the registry or certify your own through SAM Extend.

🤝
Multi-Agent Collaboration

Agents share context, delegate subtasks, and synthesize findings — the Cyber Agent can request OSINT Agent support automatically.

Human-in-the-Loop

Every autonomous action has a configurable approval gate. Operators see the full reasoning chain before a single action fires.

🧬
Agent Memory

Agents maintain working memory across a session and can surface relevant past decisions when a pattern repeats.

🔒
Agent Governance

RBAC, entitlement controls, rate limits, and kill-switch capabilities on every agent — for government and enterprise deployment.

📊
Agent Analytics

Accuracy, latency, escalation rate, and false-positive metrics per agent — continuously improving the ecosystem.

Analytics Mesh · Intelligence Layer

Analytics across every data source, simultaneously.

The SAM Analytics Mesh federates computation across connected data sources — no migration, no lake, no delay. Every module contributes analytics to every decision.

Cameras
OT Systems
Threat Feeds
Identity
OSINT
Weather
SAM Analytics Mesh · Federated Query & Compute
Unified Intelligence · Decision Ready
🕸
Federated Compute

Analytics run at the source — no data migration required. SAM federates across your existing stack.

📈
Real-Time Streaming

Sub-second ingestion from cameras, sensors, and feeds. Every event is processed in the context of everything SAM knows.

🔍
Semantic Search

Natural language queries across all connected sources — find the incident, asset, or pattern you need instantly.

📉
Anomaly Detection

Unsupervised and supervised models identify deviations across every connected data stream simultaneously.

📊
Executive Reporting

Board, investor, government, and operational reports generated on demand — from the same data that drives every decision.

🔗
API-First

Every analytics result is queryable via REST, GraphQL, or the SAM SDK — building your own layer is always an option.

Predictive Intelligence · SPI Engine

Know what's coming
before it arrives.

The Security Predictability Index is SAM's learning engine — it scores sites, assets, sectors, and principals by their probability of experiencing a security event, based on every signal SAM has ever processed.

8.4
Security Predictability Index
PERIMETER · Gate B7.2
INSIDER · Data Hall 26.1
OSINT · External Actor4.8
📍
Site Risk Scoring

Each facility gets a live SPI score updated by every incident, near-miss, and threat-environment change.

👤
Principal Risk Scoring

Executives and protected individuals receive continuous exposure scores across open-source, dark-web, and physical signals.

🏭
Sector Intelligence

Industry-wide incident patterns inform every site's baseline — your risk score reflects the sector's threat environment too.

🔮
Event Forecasting

Pattern-matched historical data surfaces probable incident types and timing — not just current risk, but what's likely next.

📆
Seasonal Modeling

Event-based, seasonal, and geopolitical risk cycles are factored into every score automatically.

🎯
Pre-Emptive Alerting

When predictive scores cross configurable thresholds, SAM prompts proactive posture changes before incidents materialize.

Digital Twin · Simulation Environment

Simulate threats before
they become incidents.

SAM's Digital Twin environment mirrors your physical facilities, OT systems, and personnel in a live simulation — enabling what-if analysis, tabletop exercise augmentation, and scenario planning at enterprise scale.

Live Digital Twin — Campus A
Gate A
SECURE
Gate B
ALERT
Lobby
SECURE
Data Hall
ELEVATED
Sub-4
SECURE
Roof
SECURE
Simulation: Perimeter Probe Scenario — injecting...
🏢
Facility Mirror

Physical spaces, sensor layouts, access points, and personnel movements mirrored in the twin for live and simulation use.

What-If Analysis

Inject any scenario — intrusion, cyber attack, natural disaster — and observe how SAM would respond before it happens.

📐
Scenario Planning

Build, save, and run playbooks against the twin to validate response plans and identify gaps before real incidents.

🎓
Training Augmentation

Tabletop exercises powered by live twin data — realistic scenarios without operational risk.

🔗
OT System Modeling

Operational technology, SCADA, and ICS systems modeled in the twin — identify cascade failure paths before attackers do.

📡
Predictive Overlay

SPI scores overlaid on the twin in real time — see which zones are at elevated risk before a signal is triggered.

Mission Operations · Command Grade

Command-grade decision
support for every mission.

SAM Mission Operations extends the decision core into defense, intelligence, and public safety environments — with the deployment security, access controls, and audit posture those missions require.

Mission Command · Unified COP
Tactical ISR
Feed Integration
Cross-Domain
Intelligence Fusion
Air-Gapped
Deployment Option
RBAC / ABAC
Access Controls
FedRAMP · CMMC · CJIS · Zero Trust
🎖
Unified Common Operating Picture

All intelligence sources fused into one, secure, real-time operational view for command staff.

🔐
Air-Gap Capable

SAM Mission Operations can be deployed in fully disconnected environments with local model inference.

🌐
Cross-Domain Fusion

Intelligence from multiple classification levels handled through configurable domain separation controls.

📡
ISR Integration

Tactical ISR feeds, drone telemetry, and sensor networks integrated directly into the decision pipeline.

📋
Chain-of-Custody Logging

Every decision, access, and action logged to an immutable audit trail — satisfying federal records requirements.

🤝
Interagency Collaboration

Secure data-sharing frameworks for multi-agency environments — fusion center ready out of the box.

Executive Intelligence · C-Suite & Board

Intelligence for the
people responsible.

Executive Intelligence distills every signal, incident, risk score, and trend into the precise view each leader needs — CEO, Board, CISO, General Counsel, or Investor — without requiring any of them to operate a security console.

CEO View · Enterprise Risk Summary
Board Report
Quarterly risk narrative
CISO View
Technical posture detail
General Counsel
Audit & liability log
Investor Brief
Risk-adjusted metrics
Export: PDF · Excel · PowerPoint · Word · API
👔
CEO Dashboard

Enterprise-wide risk posture, open incidents, SPI trends, and compliance status in one executive view.

🏛
Board Reporting

Automated quarterly narrative reports mapping security posture to fiduciary obligations — ready for the board packet.

General Counsel View

Decision audit trails, incident documentation, and chain-of-custody logs formatted for legal and regulatory review.

📊
Investor Intelligence

Risk-adjusted operational metrics and incident histories for due diligence, M&A review, and investor reporting.

🔔
Principal Alerting

Configurable threshold alerts delivered to executives via email, SMS, or secure messaging — no console required.

📄
Multi-Format Export

Every report exportable as PDF, Excel, PowerPoint, Word, or via the reporting API for custom destinations.

Security Operations · SOC & GSOC

The decision layer
above your SOC stack.

SAM Security Operations doesn't replace your SIEM, SOAR, or XDR — it sits above them. Every alert from every tool is ingested, correlated, and returned as one ranked, explainable decision queue so your analysts act on threats, not alerts.

SIEM
Alerts
XDR
Events
SOAR
Cases
SAM Decision Core · Correlation & Ranking
Ranked Decision Queue · Analyst-Ready
🖥
GSOC Command View

One screen for every feed, camera, sensor, and cyber alert — ranked by SAM's decision engine, not raw severity.

🔗
Tool Agnostic Ingestion

SAM ingests from any SIEM, XDR, SOAR, or ticketing platform — no rip-and-replace required.

📉
Alert Fatigue Elimination

Thousands of alerts per day collapsed into a ranked, correlated queue — analysts see decisions, not noise.

🎯
Shift Handover Intelligence

Structured shift-handover summaries generated by SAM — every open incident, action taken, and risk trending.

Mean-Time-to-Decide

SAM tracks mean-time-to-decide and mean-time-to-act per analyst, per shift, per site — continuously improving SOC performance.

🔄
Bi-Directional Integration

Decisions and actions written back to your SIEM, ticketing, and SOAR platforms automatically — no double entry.

Supply Chain Intelligence · Vendor & Logistics

Every vendor. Every route.
Every risk decision.

Supply chain risk is security risk. SAM correlates vendor breach disclosures, logistics anomalies, geopolitical events, and physical facility signals into one decision framework — surfacing supply chain threats before they become operational disruptions.

Vendor
Breach Feeds
Geopolitical
Risk Scores
Logistics
Telemetry
Physical
Facility Signals
SAM Supply Chain Risk Model
RISK 8.1 · Vendor Alpha — breach 9d ago, 3 shared deps
RISK 5.4 · Route 14 — geopolitical elevation +2.1
🏭
Vendor Risk Scoring

Continuous scoring of every vendor by breach history, dependency exposure, and geopolitical risk — not just annual assessments.

🗺
Route Intelligence

Logistics routes scored against geopolitical events, weather, and regional risk — decisions made before cargo moves.

🔍
Dependency Mapping

Shared dependencies between vendors surfaced automatically — a single upstream breach mapped to every downstream risk.

📦
Cargo & Asset Tracking

Physical tracking telemetry correlated with cyber and geopolitical signals for converged supply chain defense.

📋
Third-Party Audit

Vendor security posture assessments, questionnaire tracking, and evidence collection managed in one workflow.

Disruption Response

When a supply chain risk threshold is crossed, SAM generates a ranked response plan — alternative vendors, routes, and stakeholder notifications.

Public Safety · Emergency & LE

Decisions that protect
the public.

From 911 dispatch to emergency management to law enforcement operations: SAM Public Safety gives first responders, dispatchers, and incident commanders the correlated, explainable intelligence they need to make life-safety decisions under pressure.

CAD
System
Body Cam
Feeds
Weather
& Hazmat
SAM Incident Command Intelligence
LIFE-SAFETY · Evacuation threshold in 14 min
ROUTE CLEAR · Primary egress confirmed
🚒
Incident Command Support

Correlated intelligence for ICS: resource status, hazard zones, weather, and communications fused into one decision view.

🚨
CAD Integration

SAM ingests from any CAD system and enriches dispatch decisions with predictive risk and resource intelligence.

📢
Mass Notification

Multi-channel public alerting — EAS, wireless emergency alerts, social, and digital signage — triggered by SAM decisions.

🗺
Situational Mapping

Live GIS mapping of incident zones, resource positions, evacuation routes, and hazard perimeters for command staff.

🤝
Multi-Agency Fusion

Law enforcement, fire, EMS, and emergency management on one correlated picture — no radio-only coordination.

📋
Accountability Tracking

Personnel accountability systems integrated — SAM tracks check-ins, assignments, and exposure in real time.

Defense Operations · DoD & IC

Mission-grade intelligence
for defense operations.

Built for the Department of Defense and the Intelligence Community: SAM Defense Operations delivers cross-domain intelligence fusion, air-gap capable deployment, and the audit posture, access controls, and chain-of-custody logging that classified environments require.

⬛ Classified Domain
⬛ Sensitive Domain
⬛ Unclassified Domain
SAM Cross-Domain Intelligence Fusion
FedRAMP · CMMC · CJIS · IL4/IL5 Aligned · Air-Gap Capable
🎖
Cross-Domain Fusion

Intelligence from multiple classification levels handled through configurable domain separation — JWICS, SIPRNet, and NIPRNet aware.

ISR Integration

Tactical ISR feeds, drone telemetry, satellite imagery metadata, and sensor networks integrated into the mission decision pipeline.

🔐
Air-Gap Deployment

SAM Defense can run fully disconnected — on-premises hardware, local model inference, no cloud dependency required.

🗂
Chain-of-Custody

Every intelligence artifact, decision, and action logged with immutable chain-of-custody for UCMJ and federal records compliance.

🌐
Interagency Fusion

Secure frameworks for multi-agency and coalition partner data sharing — fusion center ready, ICAM-integrated.

🛡
Zero Trust Architecture

Every request verified, every session logged. SAM Defense enforces zero trust at every layer — identity, device, network, and data.

Critical Infrastructure · CI/KR Defense

Protecting the systems
society depends on.

Energy grids, water systems, pipelines, transportation networks, financial infrastructure — SAM Critical Infrastructure provides converged cyber-physical defense for the 16 CISA-designated critical infrastructure sectors, with sector-specific decision models and compliance frameworks built in.

Energy
Grid
Water
Systems
Pipelines
Transport
Networks
Financial
Systems
Comms
Networks
SAM CI/KR Decision Engine
NERC CIP · AWIA · TSA Pipeline · NIST CSF · CISA Aligned
OT/ICS Defense

Industrial control system and SCADA network monitoring with sector-specific anomaly models for energy, water, and pipeline environments.

🔗
Cyber-Physical Convergence

Physical perimeter events, OT anomalies, and IT network signals correlated as one converged threat picture.

📋
Sector Compliance

NERC CIP, AWIA, TSA pipeline directives, and NIST CSF compliance frameworks mapped to every decision and audit log.

🌊
Cascade Failure Modeling

Interdependency maps between critical systems — SAM models cascade failure paths before attackers exploit them.

🏛
CISA Alignment

All 16 CISA-designated CI sectors represented in SAM's sector intelligence models and decision frameworks.

📡
Information Sharing

Bi-directional ISAC/ISAO integration — SAM contributes to and consumes sector-specific threat intelligence communities.

Industries

Built for the places
that can't afford to guess.

Twelve sectors. Every deployment purpose-built for the protocols, compliance posture, and decision patterns that sector demands — not adapted from a generic security product.

12
Sectors Served
Government to enterprise, aviation to data centers
4
Decision Archetypes
Command · Converged Defense · Response · Protective Intel
5
Live Demo Consoles
Interactive decision scenarios per sector
21+
Sector-Tuned Modules
Pre-configured for each deployment environment
Command Operations

Unified decision queues for security operations centers, GSOCs, and command facilities where every feed must converge into one ranked, explainable picture.

Converged Defense

Cyber-physical integration across OT, IT, and physical infrastructure — for environments where sophisticated threats cross domain boundaries simultaneously.

Response Orchestration

Notification, evacuation, and incident workflow automation — decisions that execute across every connected platform the moment the threshold is crossed.

Protective Intelligence

Principal protection, brand monitoring, and OSINT-driven decisions — for environments where the threat is exposure, not intrusion.

All Sectors

Filter by decision type.

See it in action

Five live consoles. Your sector, your scenarios.

GSOC Command · Aerospace · Critical Infrastructure / OT · Executive Protection · Emergency Management

Integrations Catalog

Every integration.
One decision core.

21 certified modules across threat intelligence, physical security, cyber-physical, OSINT, environmental, response, and risk — each one a first-class evidence source in every SAM decision.

21
Certified Modules
All passing the 6-dimension sandbox test
5
Module Types
Data · Sensor · Analytics · Agent · Action
3
Partner Tiers
Listed · Certified · Strategic
100%
Schema Compliant
Every module normalized on ingest
Open
SAM Extend
Submit your module for certification
Developer Center

Build Once.
Connect Everywhere.
Make Better Decisions.

The SAM SDK, CLI, Connector API, and certification sandbox give you everything you need to build a first-class intelligence module — in the language you already use.

6
SDK Languages
Python · TypeScript · Go · Java · C# · Rust
6
CLI Commands
init · validate · test · certify · deploy · publish
8
API Protocols
REST · GraphQL · Kafka · MQTT · STIX/TAXII and more
5
Module Types
Data · Sensor · Analytics · Agent · Action
6
Certification Dimensions
Quality · Security · Compliance · Performance · AI · Explainability
Get Started

From idea to certified module
in four steps.

01
Request Access

Submit the SAM Extend application. We'll provision sandbox credentials and send you the Module ICD — usually within 2 business days.

Apply via SAM Extend →
02
Scaffold with sam init

Install the SAM CLI and run sam init to generate a module skeleton with schema stubs and a local test harness in your chosen language.

03
Test in the Sandbox

Run sam test to validate against real SAM decision scenarios. Get a structured report across all 6 certification dimensions.

04
Certify and Deploy

Pass certification with sam certify, then sam deploy to go live — and sam publish to list on the Marketplace.

SAM SDK

Build in the language
you already know.

The SAM SDK abstracts the Connector API, handles schema normalization, and gives you a local test harness so you can develop and validate before you submit for certification.

Py
Python SDK

Full-featured SDK with async support, type hints, and built-in test fixtures. Most popular for data and analytics modules.

Request access →
TS
TypeScript SDK

First-class TypeScript with generated types from the SAM schema. Ideal for action and workflow modules.

Request access →
Go
Go SDK

High-throughput sensor and streaming modules. The Go SDK is optimized for low-latency signal ingestion.

Request access →
Ja
Java SDK

Enterprise Java with Spring Boot starters. For large-scale data and analytics platforms integrating into SAM.

Request access →
C#
.NET / C# SDK

Full .NET SDK with NuGet package support. Designed for enterprise and government environments on Windows.

Request access →
Rs
Rust SDK

For performance-critical sensor modules and embedded environments. Minimal overhead, maximum throughput.

Request access →
Python SDK · Quick Start from sam_sdk import Module, Signal, Decision # Initialize your module with credentials from the SAM Developer Portal module = Module( module_id="your-module-id", api_key="sk-sam-...", environment="sandbox" # or "production" ) # Define a signal emitter async def emit_threat_signal(event: dict) -> Signal: return Signal( source="my-threat-feed", severity=event["severity"], confidence=event["confidence"], entities=event["indicators"], raw=event ) # Register and start streaming module.on_event(emit_threat_signal) await module.stream()
SAM CLI

Build, validate, certify,
and deploy from the terminal.

Install # Install the SAM CLI via pip or npm pip install sam-cli --break-system-packages # or npm install -g @sam/cli
sam init
Scaffold a new SAM module with the correct directory structure, schema stubs, and test harness. Prompts for module type (Data / Sensor / Analytics / Agent / Action), language, and discipline.
sam validate
Run schema validation against the SAM Module Interface ICD — checks signal format, entitlement declarations, and metadata completeness. Returns a structured report with line-level errors.
sam test [--scenario perimeter] [--replay last]
Run your module against the certification sandbox with synthetic signal scenarios. Generates a test report covering data quality, latency, security controls, and explainability output.
sam certify [--tier listed|certified|strategic]
Submit your module for official SAM certification. Runs the full test suite, packages the ICD declaration, and opens a certification ticket with the Security 2.0 engineering team.
sam deploy [--env sandbox|production]
Deploy a certified module to the SAM network. Handles versioning, rollout configuration, and health-check registration automatically.
sam publish
Publish your module to the SAM Marketplace — sets pricing, description, screenshots, and certification badge. Requires an active Certified or Strategic tier partner agreement.
Connector API

Every protocol.
One interface.

The SAM Connector API accepts signals over any transport your system already speaks — no protocol migration required.

ProtocolUse CaseLatencyStatus
REST / HTTPSEvent-driven integrations, webhook receivers< 200msLive
GraphQLStructured queries, relationship data< 200msLive
Kafka / StreamsHigh-volume sensor and log feeds< 50msLive
MQTTIoT and OT sensor networks< 20msLive
STIX / TAXII 2.1Threat intelligence sharing< 300msLive
Syslog (UDP/TLS)Network devices, firewalls, appliances< 100msLive
Webhooks (inbound)Third-party alerting systems< 200msLive
gRPCLow-latency binary streaming< 10msIn Certification
REST · Emit a Signal POST https://api.sam.consulting/v1/signals Authorization: Bearer sk-sam-... Content-Type: application/json { "module_id": "your-module-id", "source": "perimeter-sensor-node-22", "severity": 7.4, "confidence": 0.91, "category": "physical.perimeter", "entities": [{ "type": "location", "id": "gate-b-north" }], "timestamp": "2026-06-11T22:14:07Z", "raw": { "vibration_db": 84, "duration_ms": 340 } }
Certification Sandbox

Test against real scenarios
before you go live.

The SAM certification sandbox runs your module against a battery of synthetic scenarios across six test dimensions. Every result is scored, logged, and returned as a structured report.

Test 01

Data Quality

Schema compliance, field completeness, value ranges, and encoding — every signal your module emits is validated against the SAM ICD.

Test 02

Security Controls

Transport encryption, credential handling, injection resistance, and rate-limiting behavior under adversarial conditions.

Test 03

Compliance

Data residency, retention, PII handling, and audit-log completeness — mapped to FedRAMP, CJIS, HIPAA, and SOC 2 controls.

Test 04

Performance

Throughput, latency at P99, behavior under surge load, and graceful degradation when upstream sources are unavailable.

Test 05

AI Safety

For modules with embedded AI: hallucination rate, bias metrics, adversarial robustness, and model-card completeness.

Test 06

Explainability

Every signal must include sufficient metadata for SAM's decision engine to attribute it in a human-readable evidence panel.

Sandbox Test Report (truncated) { "module_id": "my-threat-feed", "certification_tier": "certified", "overall_score": 94.2, "results": { "data_quality": { "score": 98, "status": "pass" }, "security": { "score": 96, "status": "pass" }, "compliance": { "score": 91, "status": "pass", "flags": ["CJIS: PII field review recommended"] }, "performance": { "p99_latency_ms": 38, "throughput_eps": 12400, "status": "pass" }, "explainability":{ "score": 95, "status": "pass" } }, "next_step": "sam certify --tier certified" }
Module Schema

Five module types.
One shared schema.

Every module in the SAM network — regardless of type or language — maps its output to the SAM Signal Schema. This is what makes cross-module correlation possible.

Module TypeRole in the DecisionKey Schema FieldsExamples
DataFeeds structured intelligence into the correlation enginesource, indicators, confidence, timestampThreat Feed, Dark Web Monitor, Geopolitical Risk
SensorEmits real-world physical or digital eventslocation, entity_id, reading, calibrationPerimeter Sensor, Drone Detection, LPR
AnalyticsTransforms raw signals into scored intelligenceinput_signals[], output_score, model_id, explanationVideo Analytics, OT/ICS Monitor, SPI
AgentReasons across multiple signals and produces structured findingsplan[], tools_used[], findings[], confidenceOSINT Agent, Risk Agent, Predictive Agent
ActionExecutes a response when a decision firesaction_type, target_entity, parameters, resultMass Notification, Lock Door, Dispatch Patrol
Request the full Module Interface ICD →
Ready to build?

Your module. SAM's decision network.

Get sandbox credentials, the Module ICD, and SDK access — and start building the integration SAM is missing.

SAM Marketplace

The decision intelligence
marketplace.

Connectors, agents, analytics models, dashboards, decision workflows, and mission packs — built by Security 2.0 and certified partners. Every item is sandbox-tested, rated, and ready to deploy.

39+
Items Available
Across 9 categories — growing weekly
9
Categories
Connectors to Mission Packs
100%
Sandbox Certified
Every item passed the 6-dimension test
Open
Revenue Sharing
Certified partners earn on every deployment
All
items
🔌
Connectors
21
🤖
Agents
6
📊
Analytics
12
🖥
Dashboards
8
Workflows
5
🧠
Decision Models
4
🔮
Digital Twins
3
🎖
Mission Packs
4
🏭
Industry Packs
6
Build & Publish

Don't see the integration you need?

Any developer or company can build, certify, and publish a SAM module. Certified partners earn revenue on every deployment through the SAM Marketplace revenue-sharing program.

SAM Extend

Your intelligence.
SAM's decision core.

SAM Extend is the open partner program that brings your threat feeds, sensors, analytics, agents, and response tools into the SAM decision network — certified, distributed, and optionally monetized through the SAM Marketplace.

21+
Modules in Network
3
Partner Tiers
6
SDK Languages
Open
Revenue Sharing
Three paths. One network.

How partners extend SAM.

Pillar 01

Certify a Connector

Build a data, sensor, analytics, or action module using the SAM SDK. Pass the certification sandbox. Join the integration catalog and become a source of intelligence in every SAM deployment.

Browse live integrations →
Pillar 02

Publish an Agent

Deploy a custom AI agent into the SAM agent ecosystem. Your agent reasons alongside SAM's native agents — and can be offered to the entire SAM Network through the Marketplace.

Explore agent marketplace →
Pillar 03

Build a Mission Pack

Package a complete sector deployment: pre-configured modules, agent configs, playbooks, and dashboards — sold or distributed to SAM customers as a single install.

Browse mission packs →
Process

From idea to the SAM Network in four steps.

01
Apply & Get the ICD

Submit the form below. We'll provision sandbox credentials and send you the Module Interface Control Document.

02
Build with the SDK

Use sam init, code your module, and test locally. The CLI runs the full test suite against your sandbox instance.

03
Pass Certification

sam certify submits your module for the six-dimension certification review. Most modules complete in 5–10 business days.

04
Go Live & Earn

sam deploy ships your module to the SAM Network. sam publish lists it on the Marketplace with your pricing and revenue split.

Developer Toolkit

Everything you need is ready.

The SAM CLI gets you from zero to certified.

$ sam init
# → scaffolds module, schema stubs, test harness
$ sam validate
# → schema check against the SAM ICD
$ sam test --scenario perimeter
# → 6-dimension sandbox test report
$ sam certify --tier certified
# → submits for official review
$ sam deploy
# → live in the SAM Network
Full Developer Center →

Six SDK languages. Your choice.

Py
Python SDK — most popular for data & analytics modules
TS
TypeScript SDK — action & workflow modules
Go
Go SDK — high-throughput sensor streams
Rs
Rust SDK — embedded & low-latency sensors
Partner Tiers

Three tiers. Escalating benefits.

Tier 01

Listed

For newly certified modules entering the SAM Network.
  • Listing in the integration catalog
  • SAM sandbox access
  • Basic certification badge
  • Community support
  • Schema & CLI documentation
Apply →
Tier 02

Certified

For production-grade modules with proven deployment quality.
  • All Listed benefits
  • Marketplace listing with monetization
  • Co-marketing opportunities
  • Priority certification queue
  • Joint solution briefs
  • SAM Partner badge
Apply →
Tier 03

Strategic

For partners driving enterprise and government deployments.
  • All Certified benefits
  • Co-sell & referral program
  • Joint government proposals
  • Dedicated partner success manager
  • SAM Platform API — extended access
  • Strategic & Mission Pack eligibility
Contact us →
Partner Application

Start your SAM Extend application.

Tell us about your module and we'll get you set up with sandbox credentials, the Module ICD, and a partner agreement in motion.

Already have credentials? Head to the Developer Center to get started immediately.

What you'll receive
Module Interface Control Document (ICD) Sandbox environment credentials SAM SDK access in your chosen language Partner agreement draft Introductory call with the Security 2.0 engineering team
Application received

We'll be in touch within 2 business days.

Check your email for the Module ICD link and sandbox onboarding instructions.

Please complete the required fields above.
By submitting, you agree to the SAM Partner Program terms. Security 2.0 will respond within 2 business days.
Guided Demonstrations

Watch SAM decide.
In your sector.

Five interactive consoles. Real scenarios. Actual decision logic — not a slide deck.

🔒 Team access required to launch consoles
SAM-DEMO SAM Console
RISK
1.8
--:--:-- 0 open 0 signals
Inject scenario →

Decision Queue

Signal Feed

Connected Sources

Action Log
Book a Demo

Watch SAM make
your sector's decisions.

Every demo is a live, guided console session — real decision logic, your sector's scenarios, not slides. Select your preferred format below and we'll schedule it within 2 business days.

Choose Your Demo Format
🎯
Live Guided Session

30–45 minute guided walkthrough of the SAM console in your sector. Our team drives — you ask questions in real time.

30–45 min · Video call · Small group
🖥
Self-Guided Console

Unlock the interactive demo console now and run any of five sector scenarios at your own pace, on your own schedule.

On demand · No scheduling needed
🏛
Executive Briefing

60-minute strategic briefing for executive teams, boards, and procurement committees — platform, roadmap, and ROI.

60 min · Tailored to your leadership team
Request received

We'll confirm your session within 2 business days.

In the meantime, launch the self-guided console now using your access key below.

Your Demo Access Key
SAM-TEAM-2026
Enter this key on the Demos page → "Enter team key" to unlock all five consoles.
Launch Demo Console →
Please enter your name and email to continue.
Or go straight to the self-guided console — launch it now →
What to Expect
Real decision logic

Not a slide deck. The SAM console makes live decisions using actual signal correlation, scoring, and evidence attribution — in front of you.

🎯
Your sector's scenarios

Choose from GSOC Command, Aerospace, Critical Infrastructure, Executive Protection, or Emergency Management — or request a custom scenario.

🔬
Evidence-level transparency

Every decision shows which signals contributed, their weights, and the reasoning chain — so you can evaluate explainability firsthand.

📋
No commitment required

The demo is yours to ask questions, challenge the logic, and evaluate whether SAM belongs in your stack. Zero sales pressure.

5
Demo Consoles
2d
Scheduling SLA
Free
No Cost
< 90s
First Decision
No scheduling needed

Launch the interactive console now.

Five live decision consoles available on demand — GSOC Command, Aerospace, Critical Infrastructure, Executive Protection, and Emergency Management.

About SAM

We built the platform
the industry was missing.

Security 2.0, Inc. was founded on a single observation: the security industry had built extraordinary tools for collecting data — and almost nothing for turning that data into decisions.

Mission

Make every security decision faster, smarter, and defensible.

SAM exists to close the gap between data and decision — across government, defense, public safety, critical infrastructure, and enterprise. Every deployment of SAM is a step toward a world where the right decision is never delayed by the wrong tool.

Vision

The decision layer that connects every security tool ever built.

SAM's vision is a global intelligence network where every sensor, every feed, every agent, and every human operator contributes to a shared decision fabric — and every decision makes that fabric smarter for everyone on it.

Why SAM Exists

The problem no one had solved.

The security industry had invested a trillion dollars in tools that generate alerts — and almost nothing in the question of what to do with them.

The Problem

Alert Overload

Enterprise security teams face thousands of alerts daily. No human team can process them at the speed and scale modern threats require.

The Problem

Siloed Tools

Physical security, cyber, OSINT, OT, and response platforms operate independently — sophisticated threats exploit the gaps between them.

The Problem

Indefensible Decisions

When incidents lead to litigation or regulatory review, security teams cannot explain why a decision was made or what evidence supported it.

The SAM Answer

One Decision Core

SAM sits above every tool, correlates every signal, and returns one ranked, explainable decision — with full evidence attribution.

The SAM Answer

Converged Intelligence

Physical, cyber, OSINT, OT, and environmental signals treated as one problem — because sophisticated threats always are.

The SAM Answer

Auditable by Design

Every decision, every action, every override — logged with full context for legal, regulatory, and command review.

The Security 2.0 Story

Built by practitioners,
for the hardest environments.

The Observation

The gap between data and decision

Security 2.0 was founded after observing that the industry's hardest environments — government, defense, critical infrastructure — were drowning in data and starving for decisions.

The Insight

Convergence was the missing layer

No single tool saw the full picture. The intelligence needed to make defensible decisions existed — it was just trapped in separate systems that never spoke to each other.

The Build

SAM — the decision intelligence operating system

Security 2.0 built SAM from the ground up as a decision layer — not another tool to generate alerts, but the platform that correlates every alert into one explainable, defensible decision.

Today

A network that grows smarter with every deployment

Every SAM deployment contributes to the Security Predictability Index — a shared intelligence network that makes every future decision faster and sharper for every organization on it.

Get Started

The Decision Intelligence
Operating System™ is ready.

Resources

Learn the platform.
Master the decision.

White papers, technical documentation, video walkthroughs, guided tutorials, and the SAM Academy — everything you need to deploy, develop, or just understand the Decision Intelligence Operating System.

Documentation

Technical documentation
for every role.

📚
White Papers

Decision Intelligence Framework

The SAM decision intelligence framework — methodology, architecture, and the evidence model behind every correlated decision.

Request white paper →
🛠
Developer Docs

SDK & API Reference

Complete reference documentation for the SAM SDK, CLI, Connector API, and Module Interface Control Document.

Developer Center →
🏛
Compliance Guides

FedRAMP, CMMC & CJIS

Compliance mapping guides for federal, defense, and public safety deployments — control-by-control documentation.

Request guide →
📐
Architecture Guides

Deployment Architecture

Reference architectures for cloud, hybrid, on-premises, and air-gapped SAM deployments across Azure, AWS, and GCP.

Request guide →
🗂
Solution Briefs

Industry Solution Briefs

One-page solution briefs for every industry — designed for procurement teams, executives, and government evaluators.

Browse industries →
📜
Case Studies

Deployment Case Studies

Real-world deployment scenarios — decision outcomes, integration approaches, and measurable results from SAM environments.

Request case study →
Videos & Tutorials

See SAM in action.

Platform Overview

SAM DIOS™ Platform Tour

A 12-minute walkthrough of the full SAM platform — decision engine, agent ecosystem, catalog, and demo console.

Launch live demo instead →
Developer Tutorial

Building Your First Module

End-to-end walkthrough: scaffold with sam init, code in Python, test in the sandbox, and publish to the marketplace.

Go to Developer Center →
Scenario Demos

Decision Scenarios by Sector

Guided video demos for GSOC Command, Aerospace, OT/ICS, Executive Protection, and Emergency Management environments.

Run live demos →
SAM Academy

Certify your team on
Decision Intelligence.

The SAM Academy is coming for security operators, analysts, developers, and executives — structured learning paths leading to SAM certification.

Track 01

Operator

For security operations center staff and analysts.
  • Decision queue management
  • Scenario investigation
  • Evidence review and action
  • Shift handover best practices
Join waitlist →
Track 02

Developer

For engineers building SAM modules and integrations.
  • SDK and CLI fundamentals
  • Module schema and ICD
  • Certification sandbox
  • Marketplace publishing
Developer Center →
Track 03

Executive

For CISOs, executives, and security leaders.
  • Decision Intelligence strategy
  • SAM ROI and deployment models
  • Board and regulatory reporting
  • Compliance posture
Join waitlist →
Contact

Let's talk about
your decision problem.

Demo requests, partnerships, investor inquiries, government evaluations — send us a message and we'll route it to the right person immediately.

Send a Message
Message sent

We'll respond within one business day.

For urgent inquiries, email admin@security20.com directly.

Please fill in the required fields above.
We respond to every message within one business day. For immediate assistance, email admin@security20.com.
Direct Channels
Security 2.0, Inc.

The company
behind SAM.

SAM is a product of Security 2.0, Inc., based in Mesa, Arizona. Security 2.0 builds interconnected, defensible security industry infrastructure — combining media, intelligence, decision platforms, and marketplace properties.

Security 2.0 Properties

The Security 2.0 Network

SAM™ Decision Intelligence Operating System
Security Television Network (STN)
Security Search · Security Directory
Security Marketplace