Glossary
How Dralvia words relate
One noun per concept, everywhere in the product and docs:
| Word | What it means in Dralvia |
|---|---|
| Workspace | Your isolated Dralvia environment: data, quotas, members, billing. API paths may say tenant for compatibility; it means your workspace. |
| Account | One person's sign-in identity. An account belongs to one or more workspaces. |
| Organization | Your company. An organization can run one workspace or several (for example per team or region). |
| API key | A workspace-scoped credential for programmatic access. Not a sign-in; accounts sign in, keys authenticate automation. |
| EvidencePack | Dralvia's exportable evidence report: a signed bundle of scan inputs, outputs, and metadata for audit and sharing. |
| Report | A human-readable summary generated from scan results (executive, technical, or compliance views). |
| Export | Any file you take out of Dralvia: reports, EvidencePacks, SARIF, SBOM, invoices, or usage data. |
Terms
API key A credential used to authenticate workspace API requests.
Autonomous readiness probe A non-destructive check that validates whether workspace controls and data paths are healthy enough for autonomous workflows.
BAS (Breach and Attack Simulation) Controlled attack simulations run under an approved engagement to validate detection coverage.
CSPM (Cloud Security Posture Management) Rule-pack checks over cloud asset inventories (AWS, Azure, GCP) that flag risky configuration.
Dry-run A simulation mode that evaluates policy decisions without enforcing a block/allow action on live traffic.
EDR (Endpoint Detection and Response) The host security module that collects endpoint telemetry and supports response actions like host isolation.
EvidencePack A signed bundle of scan inputs, outputs, and metadata intended for audit and sharing.
Guest mode A public scan flow with limited capability and global aggregation.
Idempotency key A unique request key used to make retries safe by preventing duplicate workflow execution.
MCP (Model Context Protocol) A standard that lets AI agents connect to tools and data sources; governed by AI Agent Safety on Enterprise plans.
MDR (Managed Detection and Response) A support-led service model where Dralvia analysts help triage and respond to detections.
NDR (Network Detection and Response) Detection built on network traffic signals.
OAuth scope A permission requested by an application to access specific identity/provider capabilities.
OSINT (Open-Source Intelligence) Information gathered from public sources during reconnaissance or investigation.
OT (Operational Technology) Industrial and physical-process systems, monitored with passive sensors.
Quota The plan-based usage allowance for a workspace feature within a billing/reset window.
Rate limit The maximum request rate accepted by an API or workflow endpoint during a short time window.
Risk level A qualitative label derived from the risk score (Safe, Caution, Avoid).
Risk score A numeric score derived from the signals collected during a scan.
SLO (Service Level Objective) A target reliability goal (for example freshness, latency, or error-rate thresholds) used to measure service quality.
SWG (Secure Web Gateway) The policy engine that evaluates web requests and returns allow/warn/block outcomes with coaching.
Workspace An isolated customer workspace with its own data and quotas. See the terminology map at the top of this page.
ZTNA (Zero Trust Network Access) Access control that verifies every session against identity and policy instead of trusting the network.
TicketBridge The incident and escalation workflow that tracks security tickets.
Transparency Log A tamper-evident log of EvidencePack entries.
Unified scan A single API entry point that accepts multiple input types (URL, domain, IP, wallet, hash).