TACTICAL OPERATIONS CENTER · V1.0 RECON
APACHE 2.0 OPEN SOURCE · FASTAPI · REACT · SWIFTUI · KOTLIN

Common Operating Picture for security ops, crisis response, and threat intel.

🤝 Collaborators wanted: I'd love to get collaborators who are interested in working on this open-source project with me — collaborate on GitHub ↗
COPTOC Tactical Operations Wall · San Francisco Watch · Posture: Elevated
LIVE WALL & CLIENT APPS
COPTOC Common Operating Picture Full Wall
01
DOCTRINE · FLASH
The FLASH Warning
A single critical alarm strip across all screens. Releases simultaneously over SMS and chat (Twilio/Slack) and demands verified human sign-off.
02
S1 PERSONNEL · S6 COMMS
Blue Force & 15-Min Rule
Automated roll-call accountability. Site present/assigned tallies, traveler check-ins, and unresponsive personnel automatically float to the top.
03
MAPLIBRE · GEOSPATIAL
Full-Bleed Vector Map
Dark vector basemap rendering corporate facilities, personnel blue-force tracks, flight corridors, and threat polygons with zero UI clutter.
04
S2 INTEL · FUSION
S2 Intel Fusion Engine
Autonomous keyless ingestion (GDACS, USGS, NOAA, FCDO), STIX 2.1 threat graphs, and collection gap tracking.
05
S3 OPERATIONS · PLANNING
90-Day Tactical Ops
90-day operation cards, executive travel schedules, security detail assignments, and active mission timelines.
06
THE WATCH · CRYPTO LOG
Battle Captain Ledger
Every status change, radio report, and handover decision stored in an immutable, cryptographically chained audit log.
01 FLASH Warning
High-priority red alert strip across all screens demanding verified human sign-off.
02 S1 & 15-Min Rule
Automated roll-call accountability. Unresponsive personnel float to top after 15 minutes.
03 Dynamic Vector Map
Dark MapLibre vector basemap rendering facility clusters, personnel tracks, and threat polygons.
04 S2 Intel Fusion
Autonomous keyless feeds (GDACS, USGS, NOAA, FCDO) mapped into STIX 2.1 threat graphs.
05 S3 Operations
90-day operation cards, travel schedules, executive protection details, and event security.
06 Battle Captain Ledger
Every status change and handover decision stored in an immutable, hash-chained audit log.
COPTOC Mobile COP Map · Live in San Francisco COPTOC S1 Personnel Roster & Roll Calls COPTOC S2 Intelligence Workbench & Warnings COPTOC S3 Operations Timeline & Travel Missions

The Common Operating Picture in your pocket. Live in San Francisco.

When an incident breaks out or an executive travels, the watch floor doesn't stay tethered to a desk. The native COPTOC mobile app renders the live operational picture natively on iOS and Android with zero cloud dependencies.

🗺️ COP Tactical Map
Live posture escalation, Bay Area geofences, facility clusters, and real-time live asset tracking.
👥 S1 Personnel Roster
Real-time emergency roll calls, duty stations, traveling protection details, and taskings.
📡 S2 Intel & INTSUM
FLASH threat alerts with SMS dispatch, 24-hour INTSUM drafts, PIR collection, and STIX 2.1 graphs.
⏱️ S3 Operations & Travel
90-day operational ribbon, active travel missions (Riyadh, Tokyo), taskings, and hash-chained Battle Log.
🚧 UNDER CONSTRUCTION · S2 INTEL FUSION ENGINE

SIGTOC is under construction.

SIGTOC is being built as an autonomous threat intelligence fusion engine. It ingests open feeds (USGS, GDACS, NOAA, WHO, FCDO), maps them into STIX 2.1 graphs, and feeds intelligence directly into the operations picture. The standalone intelligence workbench GUI and live collector pipelines are actively in development.

# sigtoc service & collectors runtime (:8002)
$ make run-s2
INFO: Started server process [sigtoc.api:app]
INFO: Waiting for application startup.
[sigtoc] 6 keyless collectors registered: usgs, gdacs, nws, who, fcdo, wiki
[sigtoc] STIX 2.1 graph mapper loaded
[sigtoc] status: under_construction — standalone analyst workbench in design
🚧 UNDER CONSTRUCTION · WE HAVEN'T BUILT THIS YET

MODTOC is under construction.

We haven't built out the MODTOC engine or GUI yet — it is currently an open-source RFC and specification. Born from years leading integrity operations and coordinated inauthentic behavior (CIB) at TikTok, MODTOC is being designed to bring policy-as-code evaluations (make diff), severity × reach queue gating, and hash-chained audit trails to platform safety teams. We are looking for practitioners and engineers to collaborate with us.

# modtoc/policies/hate_speech.yaml (RFC Specification Draft)
policy: hate_speech_v2
status: under_construction
eval_dataset: modtoc/evals/golden_sets/hate_speech_golden.json
reach_routing:
severity_threshold: 0.85
velocity_gate: fast_path_human_review
"The entire concept of this COP was born from my years working in 24/7 tactical operations centers in the US Army. In Iraq, I worked as the S2 hand-in-hand with Ops. Ops feeds Intel and Intel feeds Ops. TOC brings that discipline to corporate security."
Hayden Lee · Creator of TOC
Former US Army Military Intelligence Officer (S2, Battle Captain) · Former TikTok Trust & Safety
01
Separate Source Reliability & Analytic Confidence

Never blend them into an opaque machine score. Humans make the call; machines gather the signal.

02
Brief What Would Have to be True to be Wrong

Every assessment includes alternative hypotheses and indicators that would falsify the current read.

03
Hand Over on the Record

No loose shift handoffs. Incoming officers acknowledge the delta so accountability never lapses.