End-to-end deployment topology, scanner capabilities, and integration ecosystem
TYCHON is a stateless, single-binary cryptographic asset scanner. No persistent agent or service required. It runs on demand (or on a schedule) and pushes findings directly to SIEM/storage targets or writes files that existing log collectors pick up.
Agentless Architecture · Dual Integration Model (Push + Pull) · No Runtime Dependencies
Management platforms that package, deploy, schedule, and orchestrate TYCHON across endpoints and infrastructure.
Pure-Go stateless binary. No embedded OpenSSL, no external runtime dependencies. Runs identically on Windows, Linux, and macOS across x64 and ARM64 architectures.
discovered, static, or both modes-enable-tracking.TYCHON has native built-in capability to push scan results directly to these platforms without any intermediate agent or file drop.
-posttoelastic — Bulk API, direct index push, ILM-aware-posttosplunk — HTTP Event Collector, token auth, index routing-posttokafka — real-time event streaming, SASL/TLS auth-upload-s3 — automatic file upload, bucket/prefix config, lifecycle management-s3endpoint; zero egress cost-outputformat eventlog — native Windows event integration, SIEM pickupThird-party collectors and schedulers that monitor TYCHON output directories and forward data to SIEM/analytics platforms.
utls + circl. No embedded OpenSSL binaries; no external library dependencies at runtime.
quantum_safe boolean, enabling policy-based alerting on non-PQC infrastructure.
-enable-tracking). Encrypted tracking database (AES-256-GCM + gzip compression, 0600 permissions) for asset baseline comparison and delta alerting. Off by default.