platform
early
MIT
ssdf
MCP-first security data platform
Sovereign Security Data Fabric: vendor syslog normalised by Vector into ClickHouse, self-hosted, with an MCP tool surface as the primary product.
About
ssdf is a minimal, AI-native security data platform for conversational and agent-based management of security products through MCP tools driven by multiple LLMs. The MCP tool surface is the primary product; human UIs are secondary.
It is sovereign: all data and inference stay under the operator's control, with no mandatory SaaS and swappable LLM and storage backends.
Features
- Vector VRL transforms normalise vendor syslog at ingest
- ClickHouse stores events, an entity graph, topology observations and a hash-chained audit table
- Python services and FastMCP tools in two tiers, sovereign and public
- Ingest from SRX, PAN-OS, UniFi, Proxmox and Junos syslog
- Audit records from the rust*mcp servers land in ssdf.audit as hash-chained rows