Collect
Authorized signals from identity, endpoints, networks, cloud, IoT and physical systems.
Harpia connects digital, physical and connected evidence so Bellot services can detect behavior, establish context, prioritize risk and support controlled action.
The operating problem
Security evidence is distributed across systems owned by different teams. Bellot connects that evidence without pretending every environment is identical or every decision can be automated.

Intelligence pipeline
Authorized signals from identity, endpoints, networks, cloud, IoT and physical systems.
Preserve provenance while translating different formats into a consistent evidence model.
Connect entities, behavior and time to reveal relationships that isolated alerts cannot show.
Relate technical evidence to the asset, process and operational consequence.
Rank investigations by evidence, exposure and business relevance—not alert volume.
Recommend or execute governed actions according to explicit policy and human authority.
Harpia
Harpia provides the shared intelligence architecture for SOC/MDR, threat detection, networks, IoT and computer vision. It organizes normalized events, findings, cases, risk, policy and auditable response while keeping available capability, scoped engineering and research distinct.
Explore HarpiaTraceable inputs and preserved provenance.
Human authority over consequential actions.
Operational, engineering and research claims remain distinct.
Cyber-physical evidence
The value is not collecting everything. It is preserving provenance and relating only the signals that change a defensive decision.
Sessions, privilege and access behavior
Process, file and host evidence
Flow, DNS and communication behavior
Device identity, state and deviations
Zones, objects and physical events
Assets, processes and consequence
Embedded intelligence
Prioritize cases, enrich investigations and improve detection coverage.
Model behavior, identify anomalies and support threat hunting.
Relate communication, device identity and operational context.
Convert visual events into governed evidence for correlation.
Connect physical and digital signals into one incident hypothesis.
Support discovery, classification and migration prioritization.
One environment. One exposure. Clear priorities.