It sits in the middle of the stack you already have.
The signals you already buy become inputs to a decision here, and the decision goes back out to your own systems.
A service you deploy.
What plugs in, and which way it points
| Yours | Direction | What it does here |
|---|---|---|
| Identity provider | in | operators sign in over OIDC; roles come from your groups |
| DLP, classifiers, fraud and sanctions vendors | in | become inputs to a rule; the vendor is recorded with the decision |
| SIEM | out | a decision a rule sends, over syslog in RFC 5424 — Splunk, IBM QRadar, or whatever else reads it |
| Your ticket tracker | both | a review case goes out, the resolved decision comes back |
| Anything else | out | webhooks |
We are not competing with your detector
Swiftward is where a detector's output turns into an action you can defend. When you swap a vendor, the rule stays and the input changes.