FAQ
Common questions.
The questions SOC managers actually ask on discovery calls, answered the same way we answer them there.
No. Every verdict is a recommendation. The analyst confirms or overrides before any case is closed. This constraint is enforced at the application layer, the AI output enters a review queue, not a close action. "No autonomous closures, ever" is a design requirement, not a configurable option.
The analyst overrides with one click and selects a reason. The override is logged to the audit trail with the analyst's identity, timestamp, and the original recommendation. Override patterns are reviewed in weekly tuning sessions and fed back into prompt calibration, the system improves on your specific alert mix over the engagement.
You shouldn't trust it alone, and the system doesn't. Three layers sit between the model and a closed case: the model proposes a verdict from the evidence bundle only; deterministic policy rules override it in code wherever a hard invariant applies (known-malicious IPs, privileged criticals, thin evidence); and a human confirms every case. The full trust model is on the AI Engine page.
Every database query carries a mandatory
tenant_id scope enforced at the query layer. There is no application-level bypass. Customer A cannot query, see, or access Customer B's alerts, cases, enrichment data, or reports. Platform staff access for support is limited and every cross-tenant action lands in the audit log. Per-tenant settings (confidence thresholds, disabled alert families, MFA policy) are stored and enforced independently.All production data, alerts, cases, audit records, enrichment results, and connector credentials, is stored in AWS
ca-central-1 (Canada). This aligns with PIPEDA, OSFI B-13, and Quebec Law 25 obligations. Cross-region deployments are available by arrangement but require explicit approval. Full posture on the Security page.Onboarding call within 5 business days of signature; alerts flowing within 10. We generate your tenant's ingestion API keys, and you add a forwarding rule in your SIEM or XDR that sends alerts to Triage Beacon with that key. Setup takes minutes per connector, and we walk through it together on the onboarding call. The 90-day pilot clock starts from first live triage.
V1 connectors: Microsoft Defender (Identity, Endpoint, Office 365, Cloud Apps), Microsoft Sentinel, CrowdStrike Falcon, Splunk Enterprise Security, and Wazuh. Elastic Security is on the Q3 roadmap; push-based webhook ingestion is planned for Q4. If your stack isn't listed, ask, custom connector development is scoped per engagement. Full list on the Integrations page.
No. Alert data is sent to the Anthropic API at inference time only, we call the model, receive a response, and do not retain the payload on Anthropic's infrastructure. Anthropic's API terms explicitly prohibit using customer data for model training. No alert content is logged on the Anthropic side.
The model returns a 0–1 probability estimate representing how strongly the evidence supports the verdict. Three bands govern routing: ≥0.75 (high, goes to analyst for quick confirm/deny), 0.50–0.74 (medium, flagged for deeper review), <0.50 (low, bypasses the queue and escalates immediately). The policy engine can also override confidence, POL-003 raises it to ≥0.95 when a known-malicious IP is confirmed, and POL-004 caps it when enrichment coverage is thin.
CAD $6,000 flat for 90 days, fully credited against your first annual contract if you convert within 30 days of pilot end. Success criteria are agreed in writing within the first ten business days, and the day-60 review measures against exactly those numbers with annual pricing already on the table. If the pilot doesn't meet the criteria, you walk away with the data and no further obligation. Details on the Pricing page.
No, it's upstream of it. SOAR automates response playbooks; Triage Beacon produces the verdict your playbook needs as its first input. Escalations carry the full case record (verdict, confidence, evidence, policy trail) over webhook, so your existing automation picks up where triage ends. Most pilots run alongside the customer's existing SOAR unchanged.
Yes. The full analyst console ships in English and French as first-class languages, which matters for Quebec MSSPs and any client with Law 25 obligations or francophone analysts. Language is a per-user preference, not a tenant-wide switch.
Question not answered here?