An AI analyst that argues in the open, gets fact-checked, and never holds the keys.
SIROC is the reasoning layer of the Cyber Decision Center: an embedded second-line analyst that reads a case and proposes a verdict, wrapped in the governance a European operator actually needs — inference on your own box by default, redaction before anything leaves, a tamper-proof record of every cloud-bound call, spend caps your clients can only tighten, and destructive actions that always wait for a person.
Inside the platform
Your analyst presses AI triage on a case. SIROC reads what the Correlation Engine built — the alerts, the entities, the storyline, what the platform already knows about this client — and returns a verdict it has to justify. It reads the case, not the sensor, so it works the same whether your alerts come from Wazuh, OpenSearch, Elastic, Splunk, Sentinel, CrowdStrike, Defender or a connector we built for you. Runs on a local open-licence model, on CPU, out of the box.
Outside the platform, on better hardware
A governed gateway lets an external agent — Claude Desktop, or your own orchestrator — work your queue: read cases, run triage, submit verdicts and reviews. The agent connects in. The platform never opens an inbound port, never lets the agent choose which client it is looking at, and redacts every result on the way out.
The verdict comes last. On purpose.
Before SIROC commits to a verdict it has to write down the benign explanations it considered, the evidence for, the evidence against, and what would change its mind. The order is deliberate: a model that answers first and explains afterwards is decorating a guess. A model that argues first is reasoning — and your analyst can read the argument, not just the conclusion.
Then the evidence is checked.
Every value SIROC cites is checked against the case's own alerts. A confident verdict built on evidence that is not in the case is downgraded — visibly, with the reason beside it. No check catches every fabrication and we do not claim otherwise; it catches the common ones, in front of the analyst, before anyone acts on them.
A first pass that needs no model
Every case is rated deterministically from severity, history and signals before any AI runs, so your queue keeps moving when the model is slow, busy or switched off.
Every review makes it better
When an analyst agrees, disagrees or corrects a verdict, that judgement is kept as a lesson for the model you run — on your box. If you ever export that corpus, it goes through the same redaction, sovereignty check and ledger as any cloud call.
You decide what the AI may consult
Past analyst lessons, verdict history, suppression history and prior cases are each a switch you control. Every triage records which were open, so you can tell an AI that reasoned from evidence apart from one that agreed with the humans it was just shown.
Named incident playbooks
Ransomware variants, phishing, brute force, exfiltration, cloud, insider, supply chain: SIROC plans a response against a known storyline with pre-defined action recipes, rather than improvising one.
Local by default. Cloud by choice. Every choice on the record.
On-box inference
Ships with a local open-licence model running on CPU. No GPU, no API key, no egress. A CISO can sign off on the default configuration without reading a data-processing agreement.
Strict mode outranks everything
A deployment-wide strict mode refuses any public-cloud AI call, whatever an individual client has selected. Clients who want sovereignty on their own tenant alone have their own switch. Both are reported by an attestation you can read at any time.
Your own cloud key, per task
Bring the cloud provider of your choice and bind it per task, so a large model can own case triage while a cheaper one writes summaries. Nothing is reachable until an administrator approves it.
Redaction before anything leaves
Cloud credentials, tokens, certificates, bank identifiers and personal data are replaced before any cloud call — including SIRET and RIB for the French market. Each value gets one stable placeholder, so “the same host failed three times” still reads as a story after redaction.
A tamper-proof ledger
Every cloud-bound call is recorded before it leaves: where it went, what posture applied, how much was redacted, and a fingerprint of exactly what was sent. The record cannot be edited or deleted afterwards. Export it for your DPO or your auditor.
Spend caps & circuit breakers
Each client has a monthly AI budget; reaching it switches SIROC off until a person restores it. Repeated failures trip a breaker instead of burning budget. Every ceiling can be lowered by a client, never raised.
The rule no playbook can override.
Isolating a host. Resetting a credential. Blocking an address. Quarantining a mailbox. Whatever a playbook or a client allow-list says, actions like these are proposed by SIROC and executed only after a person approves them.
A playbook author can make an action stricter. Nobody can make one of these automatic.
A short list of catastrophic actions is refused outright — from anyone, in any mode.
SIROC can plan the response. It cannot pull the trigger.
SIROC plans a response from a playbook's action recipes, then a policy gate pins a floor beneath it: destructive actions always require a human, whatever the playbook or the client allow-list says. On a typical intrusion the reversible, low-blast-radius steps proceed under your policy; the irreversible ones wait for a name in the approval queue.
Every release is checked against a fixed set of action-safety, evidence-faithfulness and prompt-injection scenarios before it ships. A SIROC that fails any of them does not ship.
Give an external agent a seat in your SOC — without giving it your platform.
The governed gateway lets an AI agent running on your hardware, or on your cloud key, work the queue: read alerts and cases, run triage, submit verdicts, write analyst reviews, close in bulk. Every write goes through the platform's own authorisation, client scoping, role checks and audit trail. The agent gets a seat, never the keys.
- Read
- Search and read alerts and cases, see which detections are noisiest, look up observables, match against threat intelligence, find the right runbook.
- Triage
- Run SIROC's own triage on a case, or bring the agent's reasoning and submit a verdict the platform records exactly as it would an analyst's.
- Decide
- Update cases, enrich observables, act on many cases at once — each write authorised and audited on the platform side, under the same rules as a human user.
- Review
- Submit an analyst review, hand off a long-running triage and come back for the result: the same feedback loop your team uses, open to the agent.
- Identity
- Every agent presents its own credential and appears by name in the audit trail. No agent can name the client it wants to look at; that is fixed on the platform side.
- Egress
- Every result is redacted before it leaves the platform, refusals included. In strict sovereignty mode the gateway does not start at all.
Response agents hold the credentials. The platform never does.
When a decision needs a hand on your identity provider, your firewall or your Microsoft 365 tenant, a small response agent on your own hosts does the work. It reaches out to the platform; the platform never reaches in. Vendor credentials stay in an encrypted vault on your side, every instruction is signed so the agent executes only what the platform genuinely issued, and the outcome is posted back into the case. A compromise of the platform cannot reach your vendor APIs.
Honesty rails.
- Triage is analyst-initiated. Nothing decides cases on a schedule, and we do not sell an “autonomous SOC”.
- Destructive actions always wait for a person. That is not something a setting can remove.
- The deeper multi-step investigation mode is optional and costs several times a single pass. Turn it on when your hardware justifies it.
- The ledger records cloud-bound calls. Local inference stays local and is deliberately not ledgered.
- We publish no accuracy or false-positive number of our own. No cross-vendor benchmark exists yet; building a reproducible one is on our roadmap.
- On a CPU-only box a full triage takes minutes, not seconds. Bring a GPU or a cloud key if you need faster; we will not pretend otherwise.
See SIROC triage one of your cases, live.
We run it on a case from your own telemetry — local model or your own cloud key — and show you the reasoning, the evidence check and the ledger entry it left behind. Thirty minutes, your data.