Frequently asked
questions.
Everything you need to know about GhostAnalyst. Deployment, pricing, compliance, AI capabilities, and data sovereignty.
GhostAnalyst is a sovereign Security Information and Event Management platform built for enterprises that need to keep their security telemetry in their own jurisdiction. It collects logs from your firewalls, servers, and endpoints, runs them through an autonomous AI detection engine, and delivers a short, prioritised list of real incidents instead of thousands of raw alerts.
Traditional SIEMs generate alert floods that require a fully staffed SOC to triage. GhostAnalyst runs three detection layers in parallel, an on-premise model produces the first verdict, and only high-signal cases are escalated to a deep-reasoning model. Mission Control gives your team live situational awareness without switching between screens.
No. GhostAnalyst is built for organisations without a 24/7 SOC. The iNTelligence assistant answers plain-English questions and produces auditable results. Security Posture recommendations tell your team exactly what to act on next.
Most customers are live within an hour. Download an auto-generated installer script, run it on an Ubuntu 24.04 Server (Minimal) inside your network, and the Sidecar self-enrols and starts streaming normalised events. No inbound firewall changes required.
Minimum: 2 vCPU, 4 GB RAM, 80 GB storage, 1 Gbps NIC, Ubuntu 24.04 Server (Minimal). The Sidecar runs as a Docker container and installs with a single command. Recommended for production environments handling higher event volumes: 8 vCPU, 16 GB RAM, 240 GB storage, 10 Gbps NIC, Ubuntu 24.04 Server (Minimal).
In production today: Stormshield SNS, Cisco ASA and IOS, pfSense, Windows Event Log, Linux Syslog, and 300+ additional device types, brands, and log formats supported via the Universal Log Parser, including all major firewall, switch, router, identity, cloud, and endpoint vendors. In testing: Wallix Bastion, UBIKA WAAP. On the roadmap: Check Point, Sophos, Microsoft 365, AWS CloudTrail, FortiGate, Palo Alto.
The Sidecar agent installs in under 5 minutes using a single command. Full platform setup, including device registration, log collection, and first AI analysis, typically takes under one hour. GhostAnalyst is designed for deployment without professional services.
A single Docker container installed on an Ubuntu 24.04 Server (Minimal) inside your network. It receives logs from your devices, normalises them to OCSF v1.3, scrubs PII locally, and forwards only the cleaned events to the cloud over mTLS. Device credentials are stored in a Fernet-encrypted per-device vault on the Sidecar and never reach the cloud.
Raw logs never leave your network. The on-premise Sidecar performs all PII scrubbing and OCSF normalisation before anything is forwarded. Normalised events are stored in the jurisdiction you specify. All transport is mTLS-encrypted. All data at rest is encrypted.
The first verdict is produced by Forge, our sovereign-first AI model running on our cluster in your jurisdiction, never a US-controlled cloud. Your data does not reach any external AI vendor at this stage. Only high-signal cases escalate to Apex, the latest frontier model, and only scrubbed, normalised summaries are sent. Never raw logs. Never PII. Security Posture recommendations are also generated by Forge first; Apex is used only as a fallback. (On the GA-Sovereign tier, Forge instead runs fully on-premise and air-gapped.)
The Sidecar is required for log collection. For customers with stricter data-residency requirements, a fully air-gapped deployment is available on the GA-Sovereign tier.
Your data is yours. On cancellation, you receive a full export of all events, cases, and reports in standard formats. Raw data stored on your infrastructure remains under your control at all times.
Yes. The Sovereign deployment mode runs entirely on-premise with no outbound internet connectivity required. The Forge AI engine runs locally. All detection, analysis, and reporting happens inside your network.
G-Score is our Threat Gravity Index: a single 0 to 100 number summarising your environment's threat posture in real time. It is computed deterministically every 5 minutes from the weighted severity distribution of recent security events. A G-Score of 80 or above triggers autonomous emergency response and Telegram alerts to the security team. Executives can read it at a glance.
Mission Control is the primary operational view in GhostAnalyst. It combines the live Sovereign Mesh network topology, AI Reasoning Stream, and Security Posture recommendations in one dashboard. A five-chip metric strip shows G-Score, active alerts, open cases, critical events in the last 24 hours, and IOC hits, updating automatically.
Every 24 hours, GhostAnalyst analyses your environment and generates up to two specific, actionable recommendations based on your actual threat data. Each item shows severity, category, and the affected device. Analysts mark items resolved or dismissed, building an auditable posture record over time.
A scheduled AI-generated report covering the last 24 hours or last week. Six sections: G-Score trend, top threat devices, critical events, active cases, IOC hits, and post-compromise findings. Delivered by email and stored in-platform for 30 days. Generate on demand at any time.
The Fabric Connector framework executes response actions on your existing security stack. Live today: Stormshield via SSH driver. On the roadmap: Wallix, pfSense, Linux and Windows endpoint drivers. Alerting integrates with email and Telegram. WhatsApp Business is on the roadmap.
The GhostAnalyst Sidecar includes built-in network monitoring. It performs TCP availability checks every 60 seconds and SSH-based metrics collection every 5 minutes for all registered devices. CPU, memory, disk, and network metrics are displayed in the Sidecar UI and synced to the cloud dashboard. This replaces standalone NMS tools like PRTG or Nagios for customers running the Sidecar.
The iNTelligence Framework is GhostAnalyst's proprietary AI reasoning engine. It orchestrates two AI models: Apex (cloud frontier model, high-accuracy) and Forge (sovereign-cluster, first-responder; on-premise in GA-Sovereign mode). Version 9.16 is the current production release powering autonomous threat detection, forensic analysis, and the iNTelligence Chat assistant.
Flux is our cross-tenant intelligence overlay. Anonymised detection patterns from across the GhostAnalyst fleet feed back into every tenant's engines. Never raw events. Never PII. New attack patterns observed at one customer benefit all others within the hour. Phase 2 adds federated learning with differential privacy at 10 or more active tenants.
Yes. GhostAnalyst is built multi-tenant from the ground up. Each tenant has complete data isolation: events, cases, and reports are strictly partitioned. MSSPs can manage multiple customers from a single platform instance.
GhostAnalyst is built with PDPA 2010 (Act 854) compliance as a core design requirement. Personal data is scrubbed at the Sidecar boundary before any event leaves your network. Processing is logged with a tamper-evident audit trail. A dedicated compliance module with deadline tracking and statutory submission templates is on the active development roadmap.
GhostAnalyst is structurally aligned with GDPR requirements including Articles 5 (data minimisation and storage limitation), 25 (privacy by design), and 44 (cross-border transfer restrictions). PII is scrubbed at the Sidecar boundary before any data leaves your network. This makes Article 44 compliance straightforward: raw personal data never crosses a border at all. A Data Processing Agreement is available for organisations that require one under Article 28.
GhostAnalyst is designed to meet government procurement requirements including data-residency compliance and tamper-evident audit logging. Contact our regional office for procurement assistance and formal certification documentation specific to your jurisdiction.
GhostAnalyst is sold exclusively through authorised resellers in each region. Visit our Partner Finder on the Pricing page to find a reseller in your jurisdiction. Pricing is device-based in USD with no per-seat fees and no ingestion caps; your local partner provides a quote scoped to your environment.
Yes. GA-Trial is 60 days of full-platform access for up to 3 devices with no credit card required. Extend the trial twice by 30 days each if you need more evaluation time. Maximum evaluation period: 120 days.
You will be notified 14 days before the trial expires. If you do not upgrade, the Sidecar continues to run but cloud-side ingestion is suspended. Your data is retained for a 30-day grace period. If you upgrade, everything is preserved with zero re-onboarding. If you choose not to continue, you can export your data before the account closes.
Upgrades take effect immediately and are prorated. Downgrades take effect at the next billing cycle. Device counts above the new tier limit are flagged in the admin console 30 days before the cycle change.
Trial: community forum and full documentation. Production tenants: business-hours email support, 09:00 to 18:00 MYT Monday to Friday, with priority and 24/7 SLAs available on higher tiers. Air-gapped sovereign deployments include a dedicated engineer, 1-hour SLA, 24/7, with optional quarterly on-site reviews. Your reseller is your first-line contact.
GhostAnalyst operates from two offices: Malaysia (HQ, Selangor) and Singapore. Full addresses are listed in the footer of every page.
See our detailed comparison pages. The short answer: GhostAnalyst is AI-native, deploys on infrastructure you control, and keeps your data in your jurisdiction. Splunk and Sentinel are cloud-hosted and subject to US jurisdiction under the CLOUD Act.
Do not see your question here? Contact us at hello@ghostanalyst.ai or speak to an authorised reseller in your region.
Reclaim your security data.
60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.