> For the complete documentation index, see [llms.txt](https://dfend.gitbook.io/documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dfend.gitbook.io/documentation/readme.md).

# DFend

DFend is an identity security platform built around one idea: **observe what identities actually do, turn that into intelligence, and help you decide what to do about it.**

DFend is offered through two products that share one platform:

* [**Route**](/documentation/overview.md) — a developer-first API for submitting identity-related activity and getting back intelligence: what was observed, what it means, and what DFend recommends.
* [**Formation**](/documentation/overview-1.md) — an Identity Defense Platform for security teams: connect your identity provider, and DFend observes, correlates, and helps you defend your organization.

Both products run on the same DFend backend, the same detection and scoring logic, and the same privacy principles. Route and Formation are ways of *using* DFend — not two different products with separate engines underneath.

## Where to start

* Not sure where to begin? Read [**Use Cases**](/documentation/readme/use-cases.md) for what people actually use DFend for.
* New to DFend? Read [**How DFend Works**](/documentation/readme/how-it-works.md) for the plain-language version of the whole pipeline — from something happening in your environment to DFend recommending a response.
* Comparing Route and Formation? Read [**Route and Formation**](/documentation/readme/route-and-formation.md).
* Integrating Route into your product? Start at [**Route Overview**](/documentation/overview.md), then the [**Quickstart**](/documentation/overview/quickstart.md) for your first working call.
* Evaluating Formation for your organization? Start at [**Formation Overview**](/documentation/overview-1.md).
* Care about how DFend handles data, security, and privacy? See [**Security & Trust**](/documentation/accounts-and-product-access/security-and-trust.md) and [**Privacy & Data Lifecycle**](/documentation/accounts-and-product-access/privacy-and-data-lifecycle.md).

## What this documentation covers

* **DFend** — what the platform is, how the two products relate, and what people actually use it for.
* **Route** — the developer-facing API, SDK, and Browser instrumentation, with a Quickstart and use cases.
* **Formation** — the Identity Defense Platform: use cases, integrations, identity defense, governed actions, and usage tracking.
* **Core Concepts** — the vocabulary DFend uses everywhere: Identity, Observations, Findings, Assessments, Recommended Responses, and Policy Evaluation.
* **Platform** — accounts and product access, where DFend can be reached from, security, and data lifecycle.
* **Reference** — canonical terminology, how DFend keeps "provenance" and "confidence" distinct, and a capability matrix showing what's live today versus planned.

We distinguish capabilities available today from architecture and planned functionality throughout these docs.
