Architecture

xorappsec is one process with four roles. Inspection is a library. I/O lives in the attachment and the management plane.

Request path Client xorappsec process Attachment Handler / ML Orchestrator Watchdog Management Origin

Crate map

CrateRole
xorsec-corePolicy, events, verdicts, runtime config
xorsec-inspectDecode, indicators, ML, engines, pipeline
xorappsecProxy, management, CLI, demo origin

Failure modes

Deeper design notes live in the repository Architecture.md.