Works with the stack
you already run.
Triage Beacon plugs into the tools your team already runs. We issue you an ingestion API key; you add one forwarding rule in your SIEM. Setup takes minutes per connector.
Enrichment sources are enabled per tenant based on the API keys you hold. Every lookup tolerates failure independently, and the pipeline reports an evidence-coverage score so a missing source can never silently inflate confidence.
One API key, one forwarding rule,
alerts start flowing.
Tenant-scoped API keys
We generate ingestion keys per tenant and send them to you at onboarding. Your SIEM forwards alerts to Triage Beacon with the key; Triage Beacon never needs credentials into your environment.
Keys hashed, never stored
Ingestion keys are hashed (SHA-256 + bcrypt) before they touch the database, the same way passwords are. A leaked database dump reveals no usable key, and any key can be revoked and reissued per tenant in seconds.
Validated at the door
Every forwarded payload is schema-validated, size-capped, and rate-limited before it enters the queue. Malformed alerts are rejected with a clear error instead of being half-processed.
Alert families, V1 launch scope.
Eight families cover the bulk of a typical tier-1 queue, each with its own AI playbook and MITRE ATT&CK mapping. Twelve more are scheduled across Q3/Q4. Alerts outside a known family are handled conservatively and never confidently closed.
Your SOAR picks up
where triage ends.
SOAR automates your playbooks; Triage Beacon produces the verdict your playbook needs as its first input. Escalations carry the full case record (verdict, confidence, evidence, policy trail) over webhook into your existing automation.