aid: deepwatch name: Deepwatch description: 'Deepwatch is a US managed security services provider delivering AI-native managed detection and response (MDR) governed by human security experts. Its Guardian platform and Security Center console aggregate and correlate telemetry from a customer''s existing SIEM, EDR, cloud, identity, network and vulnerability tooling — Splunk, CrowdStrike Falcon Next-Gen SIEM, Microsoft Sentinel, Google SecOps, SentinelOne, Microsoft Defender, Carbon Black, Okta, Entra ID, Tenable, Qualys, Wiz, Palo Alto and Fortinet among them — rather than requiring a rip-and-replace. Services span MDR, managed endpoint detection and response, continuous threat exposure management, vulnerability management, managed firewall, dark web monitoring and active response, with the NEXA agentic-AI ecosystem layered across detection, investigation and response. Deepwatch publishes contractual service-level commitments (99.9% platform uptime, 10-minute critical MTTD), a SafeBase trust center and an llms.txt, but exposes no public API documentation: the customer-facing surface is an authenticated GraphQL API behind the Security Center console.' url: https://raw.githubusercontent.com/api-evangelist/deepwatch/refs/heads/main/apis.yml x-type: company x-source: harvest:secondary-market x-harvest-source-url: https://forgeglobal.com/deepwatch_stock/ x-tier: profiled x-tier-reason: enrichment-pipeline specificationVersion: '0.20' created: '2026-08-01' modified: '2026-08-01' image: https://www.deepwatch.com/wp-content/uploads/cropped-DeepWatch-Guardian-Orange-192x192.png tags: - Company - Cybersecurity - Managed Detection and Response - Security Operations - Threat Intelligence - Vulnerability Management - Managed Security Services - Agentic AI apis: - name: Deepwatch Security Center API description: 'The authenticated GraphQL API behind the Deepwatch Security Center console (devportal.deepwatch.com). The endpoint is an AWS AppSync GraphQL service at devportalapi.deepwatch.com/graphql/ with a realtime subscription channel advertised over wss://*.deepwatch.com/graphql/realtime. Deepwatch publishes no public schema, reference documentation or OpenAPI: anonymous introspection is refused by a WAF rule (HTTP 403 WAFForbiddenException) and access is gated behind Okta-brokered single sign-on. Recorded here as an evidenced, auth-gated contract surface, not a public API.' humanURL: https://devportal.deepwatch.com/ baseURL: https://devportalapi.deepwatch.com/graphql/ tags: - Security Operations - GraphQL - Managed Detection and Response properties: - type: Login url: https://login.deepwatch.com/ - type: Authentication url: authentication/deepwatch-authentication.yml x-evidence: fetched: '2026-08-01' endpoint_discovered_in: https://devportal.deepwatch.com/main.js csp_realtime_channel: wss://*.deepwatch.com/graphql/realtime introspection_http_status: 403 introspection_error: WAFForbiddenException access: authenticated maintainers: - FN: Kin Lane email: kin@apievangelist.com - FN: APIs.json email: info@apis.io common: - type: TrustCenter url: security/deepwatch-trust-center.yml - type: Website url: https://www.deepwatch.com/ - type: Blog url: https://www.deepwatch.com/blog/ - type: BlogRSS url: https://www.deepwatch.com/feed/ - type: Support url: https://www.deepwatch.com/support/ - type: GitHubOrganization url: https://github.com/deepwatch - type: Login url: https://login.deepwatch.com/ - type: TermsOfService url: https://legal.deepwatch.com/tscs-2025-2 - type: PrivacyPolicy url: https://www.deepwatch.com/privacy-policy/ - type: Compliance url: https://www.deepwatch.com/trust/ - type: Security url: https://www.deepwatch.com/trust/ - type: StatusPage url: https://status.deepwatch.com/ - type: SLA url: https://legal.deepwatch.com/sla-102025 - type: Partners url: https://www.deepwatch.com/technology-partners/ - type: LLMsTxt url: llms/deepwatch-llms.txt - type: WellKnown url: well-known/deepwatch-well-known.yml - type: OpenIDConnect url: well-known/deepwatch-openid-configuration.json - type: Authentication url: authentication/deepwatch-authentication.yml - type: OAuthScopes url: scopes/deepwatch-scopes.yml - type: Conventions url: conventions/deepwatch-conventions.yml - type: Conformance url: conformance/deepwatch-conformance.yml - type: Lifecycle url: lifecycle/deepwatch-lifecycle.yml - type: DomainSecurity url: security/deepwatch-domain-security.yml - type: VulnerabilityDisclosure url: security/deepwatch-vulnerability-disclosure.yml x-enrichment: date: '2026-08-01' status: enriched artifacts_added: 11 pass: local-v1