Architecture

Telemetry in. Reasoned response out.

One continuous path: ingest signals from across your estate, reason over them, write what matters to persistent memory, and coordinate supervised response. Runs the same way whether it lives in our cloud or fully inside your perimeter.

The data flow

Ingest, reason, remember, respond

Sources stream in on the left. The reasoning core sits at the center, drawing on persistent memory and coordinating response. Every action is logged and explainable.

operational-pipeline // live data pathSTREAMING
INGESTREASONRESPOND EDR Cloud Identity Network RESPONSE ANALYSTS MEMORY REASONING CORE multi-step investigation
< 1 min
TIME TO VERDICT
Cited
REASONING CONFIDENCE
In-VPC
Runs in your cloud
Stage by stage

What happens between signal and resolution

Eight stages run continuously. Telemetry is the input; the reasoning core does the work; persistent memory and your analysts keep it sharp.

01

Telemetry ingest

Ingest

Listeners pull raw events from EDR, identity providers, container infrastructure, and multi-cloud audit logs, continuously, without manual pivoting between consoles.

Input: raw events from across your estate
02

Normalisation

Parse

Raw strings become typed records. Identities, sessions, network primitives, and binary metadata are extracted into a common schema so the rest of the pipeline can reason over them.

Schema: typed OCSF records
03

Correlation

Synthesise

Concurrent signals are correlated across time windows to cut noise, clustering thousands of low-tier events into a handful of distinct incident candidates before they reach the core.

Compression: In-VPC alert-to-incident
04

Reasoning core

Reason

The center of the platform. A continuous multi-agent layer that consumes validated telemetry to form, test, and rank attack hypotheses, coordinating specialised reasoning loops against calibrated confidence scores.

7 autonomous agentsSub-second hypothesesFull reasoning trace
05

Investigation graph

Map

Builds a timeline-ordered map of identities, file handles, and network pivots, with cryptographic provenance on each edge and mappings to MITRE ATT&CK techniques.

Assembly: automatic, in < 60 seconds
06

Response orchestration

Respond

Compiles containment tailored to the active incident. Low-risk actions like token revocation run autonomously; irreversible steps route to approval gates. Every action is reversible and logged.

Safety: rollback-verified, state-preserving
07

Persistent memory

Remember

Verified incidents, analyst overrides, and containment patterns are committed to memory unique to your environment, sharpening every future investigation against adversary adaptation.

Store: encrypted embedded vector memory
08

Analyst oversight

Supervise

Fully investigated incidents are presented with one-click approval for held actions. Your team keeps command of anything that changes the environment, with the full audit trail behind every decision.

Trace: complete auditability and provenance
Deployment models

Deploy it where your data lives

The same platform, the same reasoning, four control surfaces, from fully managed SaaS to fully air-gapped. Telemetry never has to leave your boundary.

SaaS

Fastest

Fully managed in our cloud. Connect your sources and start reasoning in hours. We handle scaling, upgrades, and uptime.

  • Zero infrastructure to run
  • Continuous updates, no maintenance windows
  • Regional data residency options

Hybrid

Balanced

Reasoning runs in our cloud; sensitive telemetry and memory stay in your environment. A thin collector bridges the two over an encrypted channel.

  • Raw telemetry never leaves your perimeter
  • Managed control plane, local data plane
  • Memory store held in your tenancy

On-premises

Sovereign

The full platform deployed inside your data center or private cloud. You own the infrastructure; we provide the software and update channel.

  • Runs entirely within your network boundary
  • Your keys, your storage, your control
  • Meets strict data-locality mandates

Air-gapped

Isolated

For classified and critical-infrastructure environments. Reasoning models ship as a sealed bundle; updates arrive through a controlled, offline channel.

  • No outbound network dependency
  • Offline model and signature delivery
  • Built for regulated and defense estates
Across every model

The same boundary guarantees

Whatever the deployment, the security posture holds. Data isolation, supervised action, and full auditability are not deployment-specific add-ons.

Tenant isolationYour telemetry, memory, and models are cryptographically isolated. Nothing is shared or trained across customers.
Supervised actionDestructive steps always pass through approval gates. Autonomy is for investigation; humans own anything that changes state.
Tamper-evident auditEvery reasoning step and action lands in an append-only log with cryptographic provenance, exportable to your SIEM.

See the architecture run live.

Book a technical briefing and watch an autonomous investigation move through the full pipeline, in the deployment model that fits your estate.

Request Blueprint Demo Security & Trust