DETECT · Every SignalCORRELATE · Across SourcesDECIDE · In SecondsACT · With EvidenceLEARN · Every OutcomePREDICT · What's NextORCHESTRATE · Agent EcosystemGOVERN · With Audit TrailsDETECT · Every SignalCORRELATE · Across SourcesDECIDE · In SecondsACT · With EvidenceLEARN · Every OutcomePREDICT · What's NextORCHESTRATE · Agent EcosystemGOVERN · With Audit Trails
Decision Intelligence Operating System™The AI layer where data, sensors, agents & humans convergeExplainable, auditable, defensible decisionsPurpose-built for government, defense & enterprise
The Platform Architecture
Five layers. One decision.
SAM integrates every signal source, intelligence module, and AI agent
into a single decision pipeline — from raw sensor data to executed
action in under 90 seconds.
Purpose-built, defensible technology — not a wrapper on someone
else's model. SAM's decision engine is the product of original
research and engineering.
Explainable decisions.
Every recommendation shows its evidence. Built for audit, liability,
and command review — so you can defend the call you made.
Converged by design.
Physical, cyber, OSINT, OT, and environmental signals treated as one
problem — because sophisticated threats are never domain-specific.
Open to your stack.
SAM Extend lets your threat feeds, sensors, analytics, and response
tools become first-class modules in the decision network.
Government-grade.
Designed for federal, state, local, and DoD deployment from day one —
with the compliance posture, audit trails, and access controls those
environments require.
Network effects.
Every deployment makes the platform smarter. The SPI learns from every
incident across the SAM Network — and every new module sharpens every decision.
SAM's platform modules are not separate products. They are facets of one
decision core — each layer adding reasoning depth that makes every other
layer sharper. Select any module below to explore.
SAM's decision engine maintains a live graph of signals, entities, risks, and outcomes. Every new signal traverses the graph, correlates with memory, and produces a ranked, explainable recommendation in seconds.
A live knowledge graph of entities, signals, risks, and causal chains — updated in real time as new evidence arrives.
🧠
Decision Memory
Every past decision and outcome informs future correlation — institutional memory that grows with every deployment.
🎯
Decision Scoring
Risk scores are not thresholds — they are continuous, multi-dimensional, and fully explainable to command staff and auditors.
📝
Decision Explainability
Every recommendation shows its complete evidence chain: which signals, which modules, which weights, and why.
🔄
Decision Automation
Rules, workflows, and AI agents execute approved actions automatically — with human override at every step.
📋
Audit Trail
Every decision, action, and override is logged with full context — who, what, when, and why — for legal and compliance review.
Agentic AI · Orchestration Layer
Agents that reason, plan, and collaborate.
SAM's agent ecosystem goes beyond retrieval-augmented generation. Each agent maintains working memory, uses tools, plans multi-step responses, and hands decisions to operators with full transparency.
Every agent is versioned, credentialed, and auditable. Deploy from the registry or certify your own through SAM Extend.
🤝
Multi-Agent Collaboration
Agents share context, delegate subtasks, and synthesize findings — the Cyber Agent can request OSINT Agent support automatically.
✋
Human-in-the-Loop
Every autonomous action has a configurable approval gate. Operators see the full reasoning chain before a single action fires.
🧬
Agent Memory
Agents maintain working memory across a session and can surface relevant past decisions when a pattern repeats.
🔒
Agent Governance
RBAC, entitlement controls, rate limits, and kill-switch capabilities on every agent — for government and enterprise deployment.
📊
Agent Analytics
Accuracy, latency, escalation rate, and false-positive metrics per agent — continuously improving the ecosystem.
Analytics Mesh · Intelligence Layer
Analytics across every data source, simultaneously.
The SAM Analytics Mesh federates computation across connected data sources — no migration, no lake, no delay. Every module contributes analytics to every decision.
Analytics run at the source — no data migration required. SAM federates across your existing stack.
📈
Real-Time Streaming
Sub-second ingestion from cameras, sensors, and feeds. Every event is processed in the context of everything SAM knows.
🔍
Semantic Search
Natural language queries across all connected sources — find the incident, asset, or pattern you need instantly.
📉
Anomaly Detection
Unsupervised and supervised models identify deviations across every connected data stream simultaneously.
📊
Executive Reporting
Board, investor, government, and operational reports generated on demand — from the same data that drives every decision.
🔗
API-First
Every analytics result is queryable via REST, GraphQL, or the SAM SDK — building your own layer is always an option.
Predictive Intelligence · SPI Engine
Know what's coming before it arrives.
The Security Predictability Index is SAM's learning engine — it scores sites, assets, sectors, and principals by their probability of experiencing a security event, based on every signal SAM has ever processed.
Each facility gets a live SPI score updated by every incident, near-miss, and threat-environment change.
👤
Principal Risk Scoring
Executives and protected individuals receive continuous exposure scores across open-source, dark-web, and physical signals.
🏭
Sector Intelligence
Industry-wide incident patterns inform every site's baseline — your risk score reflects the sector's threat environment too.
🔮
Event Forecasting
Pattern-matched historical data surfaces probable incident types and timing — not just current risk, but what's likely next.
📆
Seasonal Modeling
Event-based, seasonal, and geopolitical risk cycles are factored into every score automatically.
🎯
Pre-Emptive Alerting
When predictive scores cross configurable thresholds, SAM prompts proactive posture changes before incidents materialize.
Digital Twin · Simulation Environment
Simulate threats before they become incidents.
SAM's Digital Twin environment mirrors your physical facilities, OT systems, and personnel in a live simulation — enabling what-if analysis, tabletop exercise augmentation, and scenario planning at enterprise scale.
Physical spaces, sensor layouts, access points, and personnel movements mirrored in the twin for live and simulation use.
⚗
What-If Analysis
Inject any scenario — intrusion, cyber attack, natural disaster — and observe how SAM would respond before it happens.
📐
Scenario Planning
Build, save, and run playbooks against the twin to validate response plans and identify gaps before real incidents.
🎓
Training Augmentation
Tabletop exercises powered by live twin data — realistic scenarios without operational risk.
🔗
OT System Modeling
Operational technology, SCADA, and ICS systems modeled in the twin — identify cascade failure paths before attackers do.
📡
Predictive Overlay
SPI scores overlaid on the twin in real time — see which zones are at elevated risk before a signal is triggered.
Mission Operations · Command Grade
Command-grade decision support for every mission.
SAM Mission Operations extends the decision core into defense, intelligence, and public safety environments — with the deployment security, access controls, and audit posture those missions require.
All intelligence sources fused into one, secure, real-time operational view for command staff.
🔐
Air-Gap Capable
SAM Mission Operations can be deployed in fully disconnected environments with local model inference.
🌐
Cross-Domain Fusion
Intelligence from multiple classification levels handled through configurable domain separation controls.
📡
ISR Integration
Tactical ISR feeds, drone telemetry, and sensor networks integrated directly into the decision pipeline.
📋
Chain-of-Custody Logging
Every decision, access, and action logged to an immutable audit trail — satisfying federal records requirements.
🤝
Interagency Collaboration
Secure data-sharing frameworks for multi-agency environments — fusion center ready out of the box.
Executive Intelligence · C-Suite & Board
Intelligence for the people responsible.
Executive Intelligence distills every signal, incident, risk score, and trend into the precise view each leader needs — CEO, Board, CISO, General Counsel, or Investor — without requiring any of them to operate a security console.
Enterprise-wide risk posture, open incidents, SPI trends, and compliance status in one executive view.
🏛
Board Reporting
Automated quarterly narrative reports mapping security posture to fiduciary obligations — ready for the board packet.
⚖
General Counsel View
Decision audit trails, incident documentation, and chain-of-custody logs formatted for legal and regulatory review.
📊
Investor Intelligence
Risk-adjusted operational metrics and incident histories for due diligence, M&A review, and investor reporting.
🔔
Principal Alerting
Configurable threshold alerts delivered to executives via email, SMS, or secure messaging — no console required.
📄
Multi-Format Export
Every report exportable as PDF, Excel, PowerPoint, Word, or via the reporting API for custom destinations.
Security Operations · SOC & GSOC
The decision layer above your SOC stack.
SAM Security Operations doesn't replace your SIEM, SOAR, or XDR — it sits above them. Every alert from every tool is ingested, correlated, and returned as one ranked, explainable decision queue so your analysts act on threats, not alerts.
One screen for every feed, camera, sensor, and cyber alert — ranked by SAM's decision engine, not raw severity.
🔗
Tool Agnostic Ingestion
SAM ingests from any SIEM, XDR, SOAR, or ticketing platform — no rip-and-replace required.
📉
Alert Fatigue Elimination
Thousands of alerts per day collapsed into a ranked, correlated queue — analysts see decisions, not noise.
🎯
Shift Handover Intelligence
Structured shift-handover summaries generated by SAM — every open incident, action taken, and risk trending.
⏱
Mean-Time-to-Decide
SAM tracks mean-time-to-decide and mean-time-to-act per analyst, per shift, per site — continuously improving SOC performance.
🔄
Bi-Directional Integration
Decisions and actions written back to your SIEM, ticketing, and SOAR platforms automatically — no double entry.
Supply Chain Intelligence · Vendor & Logistics
Every vendor. Every route. Every risk decision.
Supply chain risk is security risk. SAM correlates vendor breach disclosures, logistics anomalies, geopolitical events, and physical facility signals into one decision framework — surfacing supply chain threats before they become operational disruptions.
Continuous scoring of every vendor by breach history, dependency exposure, and geopolitical risk — not just annual assessments.
🗺
Route Intelligence
Logistics routes scored against geopolitical events, weather, and regional risk — decisions made before cargo moves.
🔍
Dependency Mapping
Shared dependencies between vendors surfaced automatically — a single upstream breach mapped to every downstream risk.
📦
Cargo & Asset Tracking
Physical tracking telemetry correlated with cyber and geopolitical signals for converged supply chain defense.
📋
Third-Party Audit
Vendor security posture assessments, questionnaire tracking, and evidence collection managed in one workflow.
⚡
Disruption Response
When a supply chain risk threshold is crossed, SAM generates a ranked response plan — alternative vendors, routes, and stakeholder notifications.
Public Safety · Emergency & LE
Decisions that protect the public.
From 911 dispatch to emergency management to law enforcement operations: SAM Public Safety gives first responders, dispatchers, and incident commanders the correlated, explainable intelligence they need to make life-safety decisions under pressure.
Correlated intelligence for ICS: resource status, hazard zones, weather, and communications fused into one decision view.
🚨
CAD Integration
SAM ingests from any CAD system and enriches dispatch decisions with predictive risk and resource intelligence.
📢
Mass Notification
Multi-channel public alerting — EAS, wireless emergency alerts, social, and digital signage — triggered by SAM decisions.
🗺
Situational Mapping
Live GIS mapping of incident zones, resource positions, evacuation routes, and hazard perimeters for command staff.
🤝
Multi-Agency Fusion
Law enforcement, fire, EMS, and emergency management on one correlated picture — no radio-only coordination.
📋
Accountability Tracking
Personnel accountability systems integrated — SAM tracks check-ins, assignments, and exposure in real time.
Defense Operations · DoD & IC
Mission-grade intelligence for defense operations.
Built for the Department of Defense and the Intelligence Community: SAM Defense Operations delivers cross-domain intelligence fusion, air-gap capable deployment, and the audit posture, access controls, and chain-of-custody logging that classified environments require.
Intelligence from multiple classification levels handled through configurable domain separation — JWICS, SIPRNet, and NIPRNet aware.
✈
ISR Integration
Tactical ISR feeds, drone telemetry, satellite imagery metadata, and sensor networks integrated into the mission decision pipeline.
🔐
Air-Gap Deployment
SAM Defense can run fully disconnected — on-premises hardware, local model inference, no cloud dependency required.
🗂
Chain-of-Custody
Every intelligence artifact, decision, and action logged with immutable chain-of-custody for UCMJ and federal records compliance.
🌐
Interagency Fusion
Secure frameworks for multi-agency and coalition partner data sharing — fusion center ready, ICAM-integrated.
🛡
Zero Trust Architecture
Every request verified, every session logged. SAM Defense enforces zero trust at every layer — identity, device, network, and data.
Critical Infrastructure · CI/KR Defense
Protecting the systems society depends on.
Energy grids, water systems, pipelines, transportation networks, financial infrastructure — SAM Critical Infrastructure provides converged cyber-physical defense for the 16 CISA-designated critical infrastructure sectors, with sector-specific decision models and compliance frameworks built in.
Industrial control system and SCADA network monitoring with sector-specific anomaly models for energy, water, and pipeline environments.
🔗
Cyber-Physical Convergence
Physical perimeter events, OT anomalies, and IT network signals correlated as one converged threat picture.
📋
Sector Compliance
NERC CIP, AWIA, TSA pipeline directives, and NIST CSF compliance frameworks mapped to every decision and audit log.
🌊
Cascade Failure Modeling
Interdependency maps between critical systems — SAM models cascade failure paths before attackers exploit them.
🏛
CISA Alignment
All 16 CISA-designated CI sectors represented in SAM's sector intelligence models and decision frameworks.
📡
Information Sharing
Bi-directional ISAC/ISAO integration — SAM contributes to and consumes sector-specific threat intelligence communities.
Industries
Built for the places that can't afford to guess.
Twelve sectors. Every deployment purpose-built for the protocols, compliance
posture, and decision patterns that sector demands — not adapted from a
generic security product.
Unified decision queues for security operations centers, GSOCs, and command facilities where every feed must converge into one ranked, explainable picture.
⬗
Converged Defense
Cyber-physical integration across OT, IT, and physical infrastructure — for environments where sophisticated threats cross domain boundaries simultaneously.
➤
Response Orchestration
Notification, evacuation, and incident workflow automation — decisions that execute across every connected platform the moment the threshold is crossed.
◎
Protective Intelligence
Principal protection, brand monitoring, and OSINT-driven decisions — for environments where the threat is exposure, not intrusion.
21 certified modules across threat intelligence, physical security,
cyber-physical, OSINT, environmental, response, and risk — each one a
first-class evidence source in every SAM decision.
Aggregated IOC data from 140+ sources, normalized to the SAM schema.
★ Strategic · Threat Intelligence
VA
Video Analytics
AI-powered object, behavior, and anomaly detection across camera streams.
★ Strategic · Physical Security
OT
OT/ICS Monitor
Industrial control and OT-network anomaly detection — cyber-physical convergence.
★ Strategic · Cyber-Physical
Developer Center
Build Once. Connect Everywhere. Make Better Decisions.
The SAM SDK, CLI, Connector API, and certification sandbox give you
everything you need to build a first-class intelligence module — in the
language you already use.
Install the SAM CLI and run sam init to generate a module skeleton with schema stubs and a local test harness in your chosen language.
03
Test in the Sandbox
Run sam test to validate against real SAM decision scenarios. Get a structured report across all 6 certification dimensions.
04
Certify and Deploy
Pass certification with sam certify, then sam deploy to go live — and sam publish to list on the Marketplace.
SAM SDK
Build in the language you already know.
The SAM SDK abstracts the Connector API, handles schema normalization, and gives you a local test harness so you can develop and validate before you submit for certification.
Py
Python SDK
Full-featured SDK with async support, type hints, and built-in test fixtures. Most popular for data and analytics modules.
Build, validate, certify, and deploy from the terminal.
Install# Install the SAM CLI via pip or npm
pip install sam-cli --break-system-packages
# or
npm install -g @sam/cli
sam init
Scaffold a new SAM module with the correct directory structure, schema stubs, and test harness. Prompts for module type (Data / Sensor / Analytics / Agent / Action), language, and discipline.
sam validate
Run schema validation against the SAM Module Interface ICD — checks signal format, entitlement declarations, and metadata completeness. Returns a structured report with line-level errors.
sam test [--scenario perimeter] [--replay last]
Run your module against the certification sandbox with synthetic signal scenarios. Generates a test report covering data quality, latency, security controls, and explainability output.
sam certify [--tier listed|certified|strategic]
Submit your module for official SAM certification. Runs the full test suite, packages the ICD declaration, and opens a certification ticket with the Security 2.0 engineering team.
sam deploy [--env sandbox|production]
Deploy a certified module to the SAM network. Handles versioning, rollout configuration, and health-check registration automatically.
sam publish
Publish your module to the SAM Marketplace — sets pricing, description, screenshots, and certification badge. Requires an active Certified or Strategic tier partner agreement.
Connector API
Every protocol. One interface.
The SAM Connector API accepts signals over any transport your system already speaks — no protocol migration required.
The SAM certification sandbox runs your module against a battery of synthetic scenarios across six test dimensions. Every result is scored, logged, and returned as a structured report.
Test 01
Data Quality
Schema compliance, field completeness, value ranges, and encoding — every signal your module emits is validated against the SAM ICD.
Test 02
Security Controls
Transport encryption, credential handling, injection resistance, and rate-limiting behavior under adversarial conditions.
Test 03
Compliance
Data residency, retention, PII handling, and audit-log completeness — mapped to FedRAMP, CJIS, HIPAA, and SOC 2 controls.
Test 04
Performance
Throughput, latency at P99, behavior under surge load, and graceful degradation when upstream sources are unavailable.
Test 05
AI Safety
For modules with embedded AI: hallucination rate, bias metrics, adversarial robustness, and model-card completeness.
Test 06
Explainability
Every signal must include sufficient metadata for SAM's decision engine to attribute it in a human-readable evidence panel.
Every module in the SAM network — regardless of type or language — maps its output to the SAM Signal Schema. This is what makes cross-module correlation possible.
Module Type
Role in the Decision
Key Schema Fields
Examples
Data
Feeds structured intelligence into the correlation engine
Connectors, agents, analytics models, dashboards, decision workflows, and
mission packs — built by Security 2.0 and certified partners. Every item
is sandbox-tested, rated, and ready to deploy.
Any developer or company can build, certify, and publish a SAM module.
Certified partners earn revenue on every deployment through the SAM
Marketplace revenue-sharing program.
SAM Extend is the open partner program that brings your threat feeds, sensors,
analytics, agents, and response tools into the SAM decision network —
certified, distributed, and optionally monetized through the SAM Marketplace.
Build a data, sensor, analytics, or action module using the SAM SDK. Pass the certification sandbox. Join the integration catalog and become a source of intelligence in every SAM deployment.
Deploy a custom AI agent into the SAM agent ecosystem. Your agent reasons alongside SAM's native agents — and can be offered to the entire SAM Network through the Marketplace.
Package a complete sector deployment: pre-configured modules, agent configs, playbooks, and dashboards — sold or distributed to SAM customers as a single install.
Submit the form below. We'll provision sandbox credentials and send you the Module Interface Control Document.
02
Build with the SDK
Use sam init, code your module, and test locally. The CLI runs the full test suite against your sandbox instance.
03
Pass Certification
sam certify submits your module for the six-dimension certification review. Most modules complete in 5–10 business days.
04
Go Live & Earn
sam deploy ships your module to the SAM Network. sam publish lists it on the Marketplace with your pricing and revenue split.
Developer Toolkit
Everything you need is ready.
The SAM CLI gets you from zero to certified.
$ sam init # → scaffolds module, schema stubs, test harness $ sam validate # → schema check against the SAM ICD $ sam test --scenario perimeter # → 6-dimension sandbox test report $ sam certify --tier certified # → submits for official review $ sam deploy # → live in the SAM Network
Tell us about your module and we'll get you set up with sandbox credentials, the Module ICD, and a partner agreement in motion.
Already have credentials? Head to the Developer Center to get started immediately.
What you'll receive
✓ Module Interface Control Document (ICD)✓ Sandbox environment credentials✓ SAM SDK access in your chosen language✓ Partner agreement draft✓ Introductory call with the Security 2.0 engineering team
Application received
We'll be in touch within 2 business days.
Check your email for the Module ICD link and sandbox onboarding instructions.
Guided Demonstrations
Watch SAM decide. In your sector.
Five interactive consoles. Real scenarios. Actual decision logic — not a slide deck.
🔒 Team access required to launch consoles● Access granted
Every demo is a live, guided console session — real decision logic,
your sector's scenarios, not slides. Select your preferred format below
and we'll schedule it within 2 business days.
Choose Your Demo Format
🎯
Live Guided Session
30–45 minute guided walkthrough of the SAM console in your sector. Our team drives — you ask questions in real time.
30–45 min · Video call · Small group
🖥
Self-Guided Console
Unlock the interactive demo console now and run any of five sector scenarios at your own pace, on your own schedule.
On demand · No scheduling needed
🏛
Executive Briefing
60-minute strategic briefing for executive teams, boards, and procurement committees — platform, roadmap, and ROI.
60 min · Tailored to your leadership team
Request received
We'll confirm your session within 2 business days.
In the meantime, launch the self-guided console now using your access key below.
Your Demo Access Key
SAM-TEAM-2026
Enter this key on the Demos page → "Enter team key" to unlock all five consoles.
Security 2.0, Inc. was founded on a single observation: the security industry
had built extraordinary tools for collecting data — and almost nothing for
turning that data into decisions.
Mission
Make every security decision faster, smarter, and defensible.
SAM exists to close the gap between data and decision — across government,
defense, public safety, critical infrastructure, and enterprise.
Every deployment of SAM is a step toward a world where the right decision
is never delayed by the wrong tool.
Vision
The decision layer that connects every security tool ever built.
SAM's vision is a global intelligence network where every sensor, every feed,
every agent, and every human operator contributes to a shared decision fabric —
and every decision makes that fabric smarter for everyone on it.
Why SAM Exists
The problem no one had solved.
The security industry had invested a trillion dollars in tools that generate
alerts — and almost nothing in the question of what to do with them.
The Problem
Alert Overload
Enterprise security teams face thousands of alerts daily. No human team
can process them at the speed and scale modern threats require.
The Problem
Siloed Tools
Physical security, cyber, OSINT, OT, and response platforms operate
independently — sophisticated threats exploit the gaps between them.
The Problem
Indefensible Decisions
When incidents lead to litigation or regulatory review, security teams
cannot explain why a decision was made or what evidence supported it.
The SAM Answer
One Decision Core
SAM sits above every tool, correlates every signal, and returns one
ranked, explainable decision — with full evidence attribution.
The SAM Answer
Converged Intelligence
Physical, cyber, OSINT, OT, and environmental signals treated as
one problem — because sophisticated threats always are.
The SAM Answer
Auditable by Design
Every decision, every action, every override — logged with full
context for legal, regulatory, and command review.
The Security 2.0 Story
Built by practitioners, for the hardest environments.
The Observation
The gap between data and decision
Security 2.0 was founded after observing that the industry's hardest
environments — government, defense, critical infrastructure — were
drowning in data and starving for decisions.
The Insight
Convergence was the missing layer
No single tool saw the full picture. The intelligence needed to make
defensible decisions existed — it was just trapped in separate systems
that never spoke to each other.
The Build
SAM — the decision intelligence operating system
Security 2.0 built SAM from the ground up as a decision layer —
not another tool to generate alerts, but the platform that correlates
every alert into one explainable, defensible decision.
Today
A network that grows smarter with every deployment
Every SAM deployment contributes to the Security Predictability Index —
a shared intelligence network that makes every future decision faster
and sharper for every organization on it.
White papers, technical documentation, video walkthroughs, guided tutorials,
and the SAM Academy — everything you need to deploy, develop, or just
understand the Decision Intelligence Operating System.
Documentation
Technical documentation for every role.
📚
White Papers
Decision Intelligence Framework
The SAM decision intelligence framework — methodology, architecture,
and the evidence model behind every correlated decision.
SAM is a product of Security 2.0, Inc., based in Mesa, Arizona.
Security 2.0 builds interconnected, defensible security industry
infrastructure — combining media, intelligence, decision platforms,
and marketplace properties.