Architecture Features AI Engine Integrations Security Pricing FAQ

The complete analyst workflow,
in one console.

Decisions come with evidence, verdicts can be overridden, and every action lands in the audit log. This page covers the full capability set, from the queue to client reporting.

πŸ”Œ

Native SIEM + XDR connectors

Live alerts from your existing stack normalized into one canonical pipeline. Defender, Sentinel, CrowdStrike, Splunk, Wazuh available today. Elastic Security in Q3. Details on the Integrations page.

🧠

Evidence-backed AI triage

The model only uses the provided evidence bundle, it never invents facts. Insufficient evidence returns inconclusive, not a confident guess. Prompt version is tracked like code.

πŸŽ›οΈ

Analyst review console

Alert summary, evidence list, confidence score, recommended verdict, and override button in one focused view. Available in English and French.

πŸ“ˆ

Three-tier confidence bands

β‰₯0.75 flows to quick confirm/deny. 0.50–0.74 flags for deeper analyst review. Below 0.50 bypasses the queue and escalates immediately, no analyst bottleneck on genuine threats.

🏒

Multi-tenant isolation

Every DB query is scoped to a tenant ID at the database layer. Customer A cannot query, see, or access Customer B's alerts, cases, or reports. Essential for MSSPs.

πŸ“‹

Full audit trail

Every verdict change, override, and escalation is logged with timestamp, actor, and reason. HMAC-chained records. Searchable history for compliance and client reporting.

πŸ“Š

Weekly client reports

Automated reports showing alerts processed, top families, override rate, and tuning changes, ready to share with clients without analyst time.

πŸ””

Escalation routing

Escalations route to Slack, PagerDuty, email, or webhook based on per-tenant configuration. Priority support channels stay separate from low-signal noise.

⏱️

SLA enforcement

A dedicated 60-second SLA watcher loop escalates cases that exceed configured response windows. No alert ages out silently.

Built around the confirm/override loop.

The console optimizes one path: from alert fired to correct decision recorded. Four views cover the whole job.

πŸ“₯

Queue

All open cases sorted by severity and SLA pressure, filterable by family, verdict, band, and connector. An analyst can clear the high-confidence tier in minutes because the evidence work is already done.

πŸ—‚οΈ

Case detail

The AI's verdict, confidence, key evidence, and reasoning next to the raw alert and every enrichment panel, IP reputation, user context, host criticality, related alerts. Confirm or override with a reason; both paths write to the audit chain.

πŸ“

Deterministic case notes

Closed cases get an auto-generated case note built from the structured verdict data rather than another model call. Notes come out consistent, audit-friendly, and free.

βš™οΈ

Tenant settings

Per-tenant confidence thresholds, disabled alert families, MFA enforcement, notification routing, and security policy, all self-serve, all versioned in the audit trail.

Five roles, least privilege by default.

RoleCanCannot
ViewerRead cases and reportsChange any verdict or setting
AnalystConfirm, override, escalate casesManage users or tenant settings
Senior AnalystEverything an Analyst can, plus deeper case actionsManage users or tenant settings
SOC LeadRun the queue: assignments, SLA oversight, team reportingChange tenant-wide security settings
AdminManage tenant users, settings, connectors, API keysAccess other tenants

Bilingual by design

The full console ships in English and French as first-class languages. For Quebec MSSPs and Law 25-regulated clients, analysts work in their language and client-facing reports match it.

MFA where you need it

TOTP-based MFA enforcement is a per-tenant switch. Turn it on for a regulated client's tenant, leave it optional elsewhere. Session tokens expire after 8 hours regardless.