Core · Pro · Elite · Available nowThe Modern Battlefield Requires a Modern Warrior.
SPARTYN is NightShade's integrated security platform — offensive testing, blue-team assessment, threat intelligence, tabletop readiness, and fleet oversight. Deployed on hardware NightShade manages, running every module locally.
Operator Led. AI Powered.
On-Device Intelligence
Every module runs on a NightShade-managed NUC with a dedicated GPU — AI-assisted analysis happens locally, not in someone else's cloud.
Your Existing Mesh
Reach every device over your organization's Tailscale mesh — no inbound firewall exposure, no separate agent framework, no new attack surface.
One Live View
SPARTYN Command polls every deployed NUC and merges liveness, utilization, and module-level findings into a single fleet model.
Five Modules. One Deployment.
Core, Pro, and Elite subscription tiers scale from a single site to full enterprise. Every module is available as an add-on — open any row for detail.
The AI proposes reconnaissance and attack-path options — the operator decides what runs against the target. Obscura runs on the same on-prem, Tailscale-connected NUC as the rest of the platform, so findings feed Shield and Command directly.
- Human-in-the-loop — AI does the heavy lifting on reconnaissance and planning; the operator stays in control of every action.
- Local execution — Reconnaissance, path-planning, and analysis run on the NUC's local GPU. No cloud dependency.
- Feeds the stack — Every discovery is available to Shield for validation and to Command for fleet-level visibility.
A full desktop or laptop scan in about four minutes. Every finding is mapped to the MITRE ATT&CK framework — you get a technique ID, not just a severity score.
- Four-minute scans — Full endpoint sweep completes in about four minutes on typical hardware.
- ATT&CK-mapped — Every finding carries a MITRE technique ID and Red Canary APT alignment.
- Real behavior — Findings are contextualized against real adversary behavior, not raw CVE dumps.
SPARTYN's threat-intelligence engine keeps Obscura, Shield, and Forgepoint current on adversary techniques and campaigns relevant to your environment. Intel surfaces inside the module that needs it — not in a separate portal you'll forget to open.
- Sector-tuned — Intelligence is filtered to the campaigns and techniques that actually target your industry.
- Feeds three modules — Athena informs Obscura's attack-path planning, Shield's detection mapping, and Forgepoint's scenario generation.
- Always current — Automatic updates keep every module aligned with the latest tradecraft.
The scenario adapts as the team responds — instead of following a fixed script. Forgepoint builds response muscle memory before a real incident tests it.
- Adaptive scenarios — AI-generated branching pathways respond to team decisions in real time.
- Rehearse the real thing — Scenarios draw from Athena's current threat feed, so exercises match the adversaries you actually face.
- Measured outcomes — Track team performance across exercises and identify decision-making gaps.
A NOC-style status board, real-time incident automation, uptime intelligence, branded SLA reporting, and role-based access with a full audit trail — all in one console that scales from a single laptop to a dedicated server.
- Multi-view operations — Status board, detailed grid, Fleet Constellation, U.S. deployment map, and a fullscreen auto-rotating Operations Wall.
- Incident automation — A device that goes dark auto-opens an incident, moves through acknowledge-to-resolve, and alerts Slack and email in real time.
- Client-facing — The Operations Wall doubles as a genuine NOC display for clients.
Every Deployed Device. One Live Console.
Command sits above the stack — a live NOC-style view of every deployment in the field. Availability, utilization, incidents, and module-level findings in one place. Runs from a single laptop today, scales to a dedicated server tomorrow.
Everything You Need to Run a Fleet.
Multi-view operations
NOC-style status board, detailed grid, radar-style Fleet Constellation, city-precise U.S. deployment map, and a fullscreen auto-rotating Operations Wall.
Live command deck
Animated fleet-wide KPIs — availability, online/degraded/offline counts, open incidents — plus aggregate CPU, memory, and disk trend charts.
Incident automation
A device that goes dark auto-opens an incident (flap-suppressed for transient blips), moves through acknowledge-to-resolve, and alerts Slack and email.
Uptime intelligence
Rolling 24-hour availability history per device with automatic outage-cause detection — host reboot vs. network vs. service — plus long-range daily rollups.
Customer & SLA reporting
Fleet health rolled up per customer, with a branded, printable 7/30/90-day availability report ready to hand a client.
Role-based access & audit
Administrators manage users and access only; operators run the fleet. Every login, device change, and remote-access launch writes to an append-only audit log.
Pull-Based, Mesh-Native, Refreshes Every 30 Seconds.
Command polls each deployed device's local API over your organization's Tailscale mesh — no inbound firewall exposure and no additional agent framework to deploy. Each poll captures liveness, CPU / memory / disk utilization, host uptime, and service status, merged into a live fleet model.
- Stack
- Backend: Python 3.12 / FastAPI. Frontend: React / Vite.
- Configuration
- Branding, polling cadence, and alert thresholds are set through configuration, not code changes — deploy under a new identity without touching source.
Five Ways to See Your Fleet.
Different views serve different jobs — from a ten-second glance at overall health to a full NOC display.
NOC status board
At-a-glance fleet-wide health.
Detailed grid
Every device, every metric.
Fleet Constellation
Radar-style topology view.
Deployment map
City-precise U.S. positioning.
Operations Wall
Fullscreen, auto-rotating NOC display.
Continuous Automated Visibility, Not Spot-Checks.
Faster response
Incidents are detected and alerted automatically — typically before a customer notices — cutting mean time to acknowledgment.
Defensible reporting
Every uptime claim is backed by a logged, branded report — availability becomes a retention and upsell asset, not a verbal assurance.
Operational scale
One console covers the whole fleet — headcount doesn't have to grow linearly with device count.
Audit-ready accountability
Role separation and an immutable action log support internal governance and client due-diligence requests without extra tooling.
Presentation-ready
The Operations Wall turns the console into a genuine NOC display — useful internally and as a client-facing demonstration of maturity.
What It Takes to Run.
- Hardware
- One NUC per site · dedicated GPU for on-device AI · Windows or Linux.
- Connectivity
- Existing Tailscale mesh · no inbound ports required on any module.
- Security
- PBKDF2 credentials · signed session tokens · role-based access · append-only audit log.
- Licensing
- Core, Pro & Elite subscription tiers · modules available as add-ons.
One Plan Doesn't Fit Every Operator.
SPARTYN scales from a single site to full enterprise. Talk to us about the tier that fits your footprint — every module is available as an add-on.
Core
Single-site deployments. Start with the modules you need.
1 site · modules à la cartePro
Multi-site with active operational oversight.
Multi-site · Command includedElite
Full enterprise footprint with all modules and priority support.
All modules · priority supportTake SPARTYN to the Table.
Two-page capability statement covering the platform doctrine, the full module map, and where SPARTYN operates. Built for procurement teams, technical evaluators, and partnership prospects.
Ready to See SPARTYN Live?
30-minute walkthrough with an operator. No slides — a real deployment demo.

