HIKMA|Documentation
API Reference
01 — Overview

What is HIKMA?

HIKMA (Arabic: حكمة — wisdom) is a Cyber Defense Platform — a unified operating model for modern security operations teams. It is not a single tool. It is the infrastructure layer that connects your people, processes, and technologies into one coherent defense posture.

Traditional security stacks accumulate over years: a SIEM here, a SOAR there, separate case management, disconnected threat intel feeds. The result is tool fatigue, context loss, and blind spots. HIKMA replaces this fragmentation with a structured operating model.

PLATFORM TAGLINE

"Not a tool. An intelligence platform."

02 — Architecture

Platform Architecture

HIKMA is organized around three horizontal layers and a scope-aware permission system that spans from platform-wide configuration down to individual users.

LAYER 1

Control Plane

The administrative layer. Platform operators, company admins, and department leads configure the system here. No operational data lives in the Control Plane.

Tenant managementRBAC configurationIntegration registryPlatform health
LAYER 2

Module Layer

The capability layer. Each module is independently deployed and scoped. Modules share a common data model but can be activated per-tenant or per-department.

SOARThreat IntelCase ManagementAsset ManagementComplianceAnalytics
LAYER 3

Data Plane

The operational layer. Analysts, incident responders, and threat hunters live here. Real-time events, alerts, and case data flow through the Data Plane.

Event ingestionAlert triageInvestigation workflowsEvidence chain
03 — Modules

Capability Modules

SOAR

Security Orchestration, Automation & Response. Build playbooks, automate response workflows, and coordinate actions across your security stack.

Threat Intelligence

Aggregate, normalize, and correlate threat data from multiple sources. IOC management, threat actor tracking, and intelligence-driven detections.

Case Management

Full evidence chain management, investigation workflows, timeline reconstruction, and analyst assignment with full audit trail.

Asset Management

Complete asset inventory with risk scoring, vulnerability tracking, ownership assignment, and lifecycle management.

Compliance

Framework mapping (NIST, ISO 27001, SOC 2, PCI DSS), automated evidence collection, audit trails, and gap analysis reporting.

Advanced Analytics

AI-powered behavioral analysis, anomaly detection, risk scoring, and executive-level reporting dashboards.

Identity Risk

Account compromise detection, privilege abuse monitoring, impossible travel alerts, and identity threat scoring.

Control Plane

Multi-tenant administration, RBAC configuration, department management, integration registry, and platform health monitoring.

04 — Getting Started

Getting Started

HIKMA is invite-only during the current access phase. If your organization has been onboarded, follow these steps.

01

Request credentials from your platform administrator

02

Log in at the platform URL provided to your organization

03

Complete the onboarding wizard to configure your tenant

04

Activate the modules relevant to your security program

05

Connect your data sources via the Integration Registry

06

Configure your first SOAR playbook or create a case

05 — Access Control

Scope-Aware RBAC

HIKMA implements a hierarchical, scope-aware Role-Based Access Control system. Permissions cascade down the hierarchy — a role at a higher scope can be restricted but not expanded at a lower scope.

Platform
└── Company
└── Department
└── Team
└── User
06 — API Reference

API Reference

HIKMA exposes a RESTful API built on FastAPI with automatic OpenAPI documentation. All endpoints require authentication via JWT bearer tokens.

Open Interactive API Docs
BASE URL
http://2.25.184.240:8000/api/v1
POST/auth/loginAuthenticate and receive JWT tokens
GET/tenants/List accessible tenants
GET/modules/List available platform modules
GET/healthPlatform health status