SEAGULL / TECHNICAL DOCUMENTATION
Understand the platform.
Follow every signal.
The engineering guide to Seagull V2. From endpoint identity and durable telemetry to detection, investigation, and the systems behind them.
A durable backbone. Independent responsibilities.
Trace an event →- Endpoint agentCollection & delivery · planned
- ingest-gatewayVerified identity · durable ACK
- RedpandaIndependent consumer groups
- Analysis & writersDetection · analytical storage
The control plane manages agents, certificates, rulesets, and triage. The query plane reads analytical evidence. The V2 frontend is planned.
Explore the documentation
Concepts → guides → referenceArchitecture
Follow the data, the control plane, and the decisions that keep them separate.
System boundaries →02Seagull Agent
Understand endpoint identity today and the path to durable collection and delivery.
Endpoint foundations →03Detection & correlation
Work with typed rules, event-time windows, evidence, and operator-owned incidents.
Detection lifecycle →04Security
Trace certificate trust, tenant authority, permissions, and their explicit limits.
Trust boundaries →05Operate the platform
Bring up the development stack, inspect health, and diagnose failures by boundary.
Operator guides →06Build with Seagull
Navigate repository ownership, contracts, architecture tests, and contribution workflows.
Developer guides →KEEP THE DETAILS CLOSE