Six stages from raw log to a case your team can act on.

Collection and personal-data removal happen on your site. Detection, reasoning and response run on clean, structured events, and every step leaves a record.

The six stages, and what runs in each.

Watch an event move from your devices to Mission Control. The labels under each stage are the parts that do the work.

  1. Step 1SidecarCollects logs inside your network and strips personal dataOn-site collectorPersonal data scrub
  2. Step 2ParserReads every source into one standard formatUniversal Log ParserOCSF format
  3. Step 3iNTelligenceDetects, triages and reasons with Sovereign AIThree detectorsTriageSovereign AI
  4. Step 4ExAIExplains every verdict in plain wordsPlain-language verdictMITRE mapping
  5. Step 5FabricBlocks at your firewall once an analyst approvesAnalyst approvalFirewall block
  6. Step 6Mission ControlShows your team what needs attention nowThreat scoreCasesReports

Stages 1 and 2: collected and read on your site.

The Sidecar runs on a server inside your network. It receives logs from every device, reads each vendor's format into one standard, removes personal data and sends only cleaned events out.

  • No inbound firewall changes
  • Device credentials stay on the collector
  • Built-in device discovery and reachability checks
Connectivity: the on-premises Sidecar collects and cleans logs, then connects outbound only over mTLS on TCP 443 to the sovereign cloud in Kuala Lumpur; raw logs stay on premises
Outbound only, mTLS on TCP 443. Raw logs stay on premises.Open full size

Stage 3: three ways of spotting an attack, run side by side.

Each detector looks for something different. An attack that hides from one method is still in view of the others.

Detection pipeline: three detectors, triage, sovereign reasoning, frontier reasoning and shared learning, from data sources to outcomes
Three detectors run in parallel, triage merges them, sovereign AI gives the first verdict and only confirmed threats go further. Shared learning carries patterns only.Open full size

Sovereign AI writes the first verdict.

  • First pass in your jurisdiction

    An open-weight model on the sovereign cluster decides: escalate, monitor or dismiss.

  • Personal data removed first

    Only high-signal incidents get deeper reasoning, and personal data is removed before any of it is sent.

  • Every verdict explained

    Plain-language narrative, evidence trail and the MITRE ATT&CK technique it matches.

Stages 4 to 6: explained, approved, shown.

The case arrives with its reasoning. A response such as a firewall block waits for an analyst to approve it. Mission Control shows the whole estate on one screen.

Explore Mission Control
Mission Control with threat score, active cases and reasoning stream

MITRE ATT&CK coverage, by tactic.

The 14 enterprise tactics in attack order, with the detection methods that look for each one.

RulesLearned normalBehaviourShared patternsTriage
  • Reconnaissance
  • Resource Development
  • Initial Access
  • Execution
  • Persistence
  • Privilege Escalation
  • Defense Evasion
  • Credential Access
  • Discovery
  • Lateral Movement
  • Collection
  • Command and Control
  • Exfiltration
  • Impact

This shows which methods look for each tactic. It is not a promise that every technique within a tactic is detected.

Watch the six stages run on your logs.

60-day full-platform trial. No credit card. No inbound firewall changes. Live in under an hour.