← TensorOne for Government  ·  This page is the one-page PDF: print it, or choose “Save as PDF” in the print dialog.

TensorOne

Capability StatementAgentless Datacenter Detection & Response · September 2026

Detection and response for the layer endpoint tools cannot reach, across every virtualization platform an agency runs at once. TensorOne receives hypervisor and management-plane syslog passively, polls each platform's management API read-only, and applies ATT&CK-mapped behavioral detections, kill-chain correlation, and response playbooks. For government deployments the console runs on-premises by default; no telemetry leaves the customer's network.

Core capabilities

  • Multi-platform control-plane detection. VMware (Broadcom) vSphere/ESXi, Nutanix AHV, Red Hat OpenShift, KVM/libvirt and AWS CloudTrail in one console with one inventory. Organizations run several at once, for years; a single-platform tool covers a fraction of the estate.
  • Behavioral detections, ATT&CK-mapped. Unauthorized management-plane access, snapshot and datastore manipulation, log tampering, unsigned VIB installation, configuration drift, off-hours authentication, collector silence. Each carries a technique ID and a severity with an expected response window.
  • Kill-chain correlation and response playbooks. A brute force, the login that follows, and the high-risk command after it become one incident with evidence attached to every stage, and a playbook stating what to contain, preserve, and verify.
  • Edge filtering. Up to 99% of datacenter log volume dropped inside the customer's network before the SIEM bills for it, with a live meter of the effect.

Differentiators

  • Nothing on the hosts. One collector VM. No agents, VIBs, kernel modules, or change window on hypervisors. Never reads guest memory, disks, or application data.
  • Console on-premises by default for government deployments; not a paid upgrade. An on-premises deployment is not a cloud service offering, so the FedRAMP path does not apply to it. TensorOne holds no FedRAMP or GovRAMP authorization and claims none.
  • Read-only, documented first. Named read-only roles per platform, published at tensorone.cloud/permissions/ and sent before anything is provisioned.
  • Isolated networks. Detection content ships compiled into each versioned release, carried in on the customer's media and schedule. A fully disconnected first install is staged during scoping. Optional AI features (third-party model API) are off by default and stay off when isolated.
  • Written by the offensive side. Detections engineered by former NSA operators; the platform designed from the ground up by one of them.

Platform coverage & detection depth

VMware vSphere / ESXi (Broadcom): vCenter events, ESXi syslog, read-only vSphere API. Deepest behavioral content. Nutanix AHV (Prism syslog and audit, Viewer role), Red Hat OpenShift (Kubernetes events, view ClusterRole), KVM / libvirt (host syslog, read-only connection), AWS CloudTrail (management events, read-only IAM role): collection, inventory, exposure matching, and a growing behavioral set. Depth is stated per platform, in writing, before purchase.

How government buys TensorOne

  • Through a reseller, on a vehicle the agency already holds: a partner's GSA Multiple Award Schedule, NASA SEWP, or an agency BPA. We work with agency-specific resellers and with the incumbent the agency already uses.
  • Direct, below the Simplified Acquisition Threshold. Under $350,000, FAR Part 13 procedures; micro-purchases under $15,000 on a government purchase card. A first deployment can be scoped to fit.
  • SDVOSB set-aside or sole source, once SBA VetCert certification is issued. Confirmed in writing the day it changes.

Security review pack

Sent before a buyer asks:

  • Read-only permission list, per platform
  • Data flow diagram
  • Section 889 representation
  • Country-of-origin / TAA statement
  • Software bill of materials (SBOM)
  • SOC 2 status, stated accurately

Start with a seven-day log assessment on your own telemetry: no cost, no procurement, no commitment.

Leadership

James Ball
Founder · Director of Security
U.S. Army veteran. Eight years at the National Security Agency in Computer Network Operations, Exploitation Analysis. Designed the TensorOne platform; owns detection engineering and security operations.
Sean Byrd
Director of Strategic Engagement
Decorated U.S. Marine Corps veteran; nearly two decades designing security protocols for U.S. government agency facilities at home and abroad. Owns growth and reseller relationships.