Frequently asked questions

17 answers in five groups. Type to filter.

The platform

What is GhostAnalyst?

A SIEM with a licensed SOC behind it. It collects logs on your site, reads them, detects threats, explains each verdict in plain language and opens a case your team can act on. That is six stages, from raw log to case.

What does it read?

300+ integrations across firewalls, endpoints, servers, identity, network gear and cloud services. See the integrations page for the list.

What is Sovereign AI?

The AI that reasons about your threats runs under your data rules. Personal data and anything that identifies a person, host or tenant stays inside the platform. You can also require that all reasoning stays on infrastructure you control.

Does the platform block traffic on its own?

No. It can prepare a firewall block and shows you which firewall would carry it. An analyst approves the block before anything changes on your network.

Your data

Where do my raw logs live?

They are collected by an on-site collector inside your network. The collector connects out over HTTPS on port 443, so you make no inbound firewall changes.

Which deployments are there?

Two. Hybrid Sovereign keeps collection on your site and runs the platform in our Malaysian region. Sovereign Edition runs the whole platform on infrastructure you control. See deployment options.

How long do you keep my data?

As long as your subscription terms say. Retention is set per customer and the platform enforces it. You can also download a record when personal data is removed.

Which regulations do you align with?

The platform is aligned with Malaysia's Personal Data Protection Act 2010 (Act 709) and with GDPR. Our SOC and VAPT services are licensed by NACSA. See compliance.

Trial

How does the free trial work?

Sign up directly with us. You get your own analyst console at yourname.ghostanalyst.ai for 60 days, with up to three connected devices. No credit card.

What do I need for the trial?

One machine for the on-site collector: 8 vCPU, 16 GB RAM, 240 GB disk and Ubuntu 22.04 or 24.04 Server.

What happens when the trial ends?

Talk to an authorised partner about a subscription. If you do not continue, the trial console is closed.

Buying and pricing

How is it priced?

Per monitored device. A subscription includes the full platform and a licensed SOC. We do not publish prices because quotes depend on your devices and service tier. To see what false alarms cost your team today, try the ROI calculator.

Can I buy directly from you?

Buying goes through an authorised partner near you. The trial is the one thing you start directly with us. Start with the scoping questionnaire.

How do you compare with other SIEMs?

See compare. Where a competitor does not offer something in the product itself, we say so as "Not natively".

Service and support

What do the service tiers cover?

Two tiers, GA-SOC Standard and GA-SOC Premium. Both are SOC and MDR: detection, validation, escalation and response, with on-site support included. Premium responds faster. See service tiers.

How fast do you tell me about a critical incident?

Within 120 minutes of the verdict on Standard, and within 60 minutes on Premium.

How do I reach support?

Through the guides and support section of your console, or the contact page. We respond within one business day to general enquiries.

Still have a question?

60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.