Joinable Security
Understand the adversary.Respond the way your organization does.
The security domain on the Joinable Platform. Turn your team’s playbooks, SOPs, and threat intelligence into governed, agent-ready knowledge, and the security agents that act on it, grounded in what your organization already knows, not the open internet.
The problem
Your response knowledge is scattered when you need it most.
A SOC’s response knowledge lives across thousands of playbooks, SOPs, and IR guides, hard to search mid-incident. Off-the-shelf agents reason from generic internet knowledge and can’t be shaped to how your organization actually responds. And building agents in-house means wiring up knowledge, models, and governance yourself.
The Joinable Security domain
Security knowledge, refined and governed, and the agents that act on it.
A domain packages the Joinable Platform for an industry: pre-built knowledge, agent templates, and integrations. Joinable Security is the first. It refines your security team’s own approved procedures into permission-governed knowledge with Propagator, and lets you build and own the response agents with the Agentic Framework, human-in-the-loop by default.
Grounded in your procedures
Agents reason from your team’s approved playbooks and SOPs, refined by Propagator, not generic internet knowledge.
Governed end to end
Every piece of knowledge carries its source permissions and provenance, all the way to the answer.
Human-in-the-loop by default
The agents you build are your organization’s own. Analysts stay in control of investigation and remediation.
The apps
Two ways to put it to work.
Both apps are built on Propagator. Start free with Threat Map, or bring your own playbooks into Runbooks.
Joinable Runbooks
BETAThe security response app. Turns your playbooks and SOPs into AI-ready knowledge, and lets your team build and own the security agents that act on it, for faster investigation and remediation with governance intact.
Explore Runbooks →
Threat Map
FREEA free community app that maps published threat reports into the MITRE ATT&CK framework, so analysts can explore, verify, and compare how adversaries operate. Adversary intelligence for defenders.
Explore Threat Map →
Built for trust
Every answer, governed end to end.
Propagator applies governance before knowledge reaches an agent, not after. Every request is authorized, scoped, and recorded, from the source's permissions all the way to the answer.
Permission-governed
Knowledge carries the same access rules as its source, all the way to the agent.
Continuously in sync
Data Cards stay in sync with the source, so answers reflect the latest version, never a stale index.
Traceable to source
Every piece of knowledge keeps its provenance, so any answer traces back to where it came from.
Tamper-evident audit log
A record of every delivery: who asked, what was returned, under whose permissions.
Access-scoped delivery
Same question, same truth, scoped to each person’s access.
Validated & scored
Checked for quality and consistency, with a confidence score, before an agent ever sees it.