
Why ClearSkies
Coordination you don't have to build.
One data model, one workflow, one console. And no component acts on the intelligence of another except as the platform governs it.
Coordination, shipped rather than built
Six native add-ons, thousands of Marketplace products and the TDIR engine share one data model, one analyst workflow and one console. Native integration does not make each capability individually better. It makes the relationship between them computable, which is the part that was missing.
Why this architecture →Autonomy that carries its own evidence
Every autonomous conclusion carries the evidence it was reached on. Response authority is tiered per tenant, every action is logged with actor, input, decision and outcome, and governance is designed against EU AI Act obligations alongside NIS2, DORA, GDPR and ISO/IEC 27001.
How governance works →Recognized by the Industry
Odyssey Consultants has been included twice in the Gartner® Magic Quadrant™ for SIEM, most recently in May 2024 for the ClearSkies TDIR platform. Certified to ISO/IEC 27001 and SOC 2 Type II report.
See the evidence →Why it holds
Why this architecture rather than another
A benefit stated without a mechanism is indistinguishable between vendors. Each entry below carries the reason it holds.
- 01
Native rather than acquired
The six add-ons are native components built on a shared schema, not products bolted behind a connector.
- 02
Normalization at collection
The iCollector normalizes before correlation instead of translating afterwards, and AI-assisted parsing extends this to new sources without a schema project.
- 03
One explainable risk score
Prioritization is directly comparable between an identity event and an endpoint event, because both are scored by the same formula over the same model.
- 04
Exposure-led scoping
Attack Surface Monitoring establishes the real, continuously assessed exposure of each client, and that assessment determines which add-ons that tenant needs, in place of a fixed bundle sold uniformly.
- 05
Multi-tenancy as architecture
Strict per-tenant isolation, federated learning that improves detection for every tenant at once (that shared learning operates on detection logic and threat patterns, never tenant data), a branded client portal, and tenant-pool licensing that permits reallocation without per-tenant true-up.
- 06
Governed autonomy
Tiered human oversight with a complete audit trail, which is the evidence this market currently lacks and increasingly asks for.
- 07
Native measurement
Mean time to detect, mean time to respond, and SLA attainment measured inside the platform per tenant, feeding detection tuning rather than only reporting.
- 08
European delivery posture
Tenant data is held and processed in the region you specify, confirmed per deployment at scoping, with governance designed against EU AI Act obligations alongside NIS2, DORA, GDPR and ISO/IEC 27001.
Industry Recognition
Odyssey Consultants Ltd. was positioned as a Niche Player in the Gartner Magic Quadrant for SIEM in 2021 and 2024.
ClearSkies Cloud SIEM holds a rating of 4.7 out of 5 from verified reviews in the Security Information and Event Management market on Gartner Peer Insights™
The recognition described above applies to the ClearSkies SIEM and TDIR platform. The ClearSkies iISOC platform has not been separately evaluated by Gartner within the Integrated Security Operations Center systems category, which Gartner introduced in 2026.
Recognized in 2024, architectural today
Three capabilities noted in that evaluation are the same three this platform is built on: the Marketplace, the add-on ecosystem, and consumption-based licensing. What has been added since, the iCollector, the Centric-AI Fabric, and governed autonomy extends that architecture rather than replacing it.
ISO/IEC 27001Information security
SOC 2 Type IIService controlsDetection coverage, reported by technique
Detection content is mapped to MITRE ATT&CK techniques and reported as current coverage with tuning recency per technique. Purple-team and penetration-test validation of detection and response is reported by technique rather than in aggregate, so coverage can be reviewed where it matters rather than accepted as a single figure.
The multi-tenant architecture of ClearSkies™ makes client management effortless. We gain unified visibility across all customer environments while ensuring strict data segregation and compliance.
From the point a log is collected to the moment a threat is contained
One system collects, correlates, decides, acts, and measures. That is the difference between owning security tools and operating security.


