Designing for Convergence: Architectural Patterns for Unifying Independently Built Security Data Platforms Across Organizational Boundaries
Keywords:
platform convergence; security data platform; data mesh; domain-driven design; entity resolution; schema matching; artificial intelligence; machine learningAbstract
Cloud-scale security organizations routinely accumulate independently built data platforms for vulnerability management, application security, compliance, and threat detection, each optimized for a specific team's mandate but collectively unable to provide the cross-domain visibility that modern defense requires. This fragmentation follows directly from Conway's Law: system boundaries mirror the organizational boundaries that produced them. This article develops an architectural framework for converging such platforms without disruptive replacement, and argues that a canonical data model becomes practically maintainable only when paired with machine learning-based entity resolution and schema matching, which turn cross-domain data reconciliation from a brittle manual exercise into a scalable, continuously adapting process. Drawing on domain-driven design, data mesh architecture, and the software engineering literature on organizational alignment, the framework positions convergence along a spectrum from loose federation to full unification and specifies four architectural mechanisms a canonical schema layer, machine learning-based entity and schema matching, API-first domain gateways, and progressive migration under federated governance that organizations can combine according to their technical debt and readiness for change. An illustrative application to the convergence of vulnerability management, application-security, and compliance data platforms shows how these mechanisms interact in practice. The analysis also identifies the limits of machine learning-based matching in security-critical contexts, where a false merge of unrelated findings carries operational risk that differs from typical data-integration use cases. The framework contributes a synthesis that existing literature, which treats organizational design, data architecture, and automated entity matching as separate concerns, has not yet provided for security data specifically.





