Capabilities

The full capability surface, stated precisely.

Where a capability is gated to a higher plan, it says so. Where it requires your own API key, it says that too.

Detection

  • Tiered EDR: Microsoft Defender for Endpoint, native OS tooling, or the built-in heuristic engine
  • 12 MITRE ATT&CK rule families — encoded PowerShell, living-off-the-land binaries, ransomware behaviour, lateral movement, persistence
  • Behavioural engine for activity that matches no signature
  • YARA scanning, with a graceful fallback when the module is unavailable
  • Threat-intel enrichment via VirusTotal, AbuseIPDB and AlienVault OTX (your keys, your bill)
  • Your own detection rules: regex, keyword or threshold

Automatic response

  • New workspaces start in detect only: nothing is stopped or isolated automatically until you choose detect and block
  • Playbooks for ransomware canaries and credential dumping, which act automatically only in detect-and-block mode
  • Isolate a host, lock the screen, kill a process, quarantine a file — one click, or automatic by your settings
  • Volume Shadow Copy rollback on Windows
  • USB mass-storage block and unblock by policy
  • Ransomware canary files: a tripped canary raises a critical alert, and in detect-and-block mode isolates the device
  • Every command signed, time-limited and replay-proof

Data loss prevention

  • Patterns for payment card numbers, National Insurance numbers and other personal and client data
  • Watches email, cloud upload, USB, print and network shares
  • Blocks or allows by severity, and records a business justification you can show an auditor
  • Full file-transfer history, whether or not a pattern matched

Visibility

  • Geo threat map by country, with a filterable detection feed underneath
  • Kill-chain stories: alerts inside one window stitched into a single timeline
  • Per-device activity summary — applications, documents and sites, with time spent
  • Persistent foothold hunter: Run keys, scheduled tasks, services, WMI, LaunchAgents, cron, systemd
  • LAN discovery for unmanaged devices, plus application inventory and a CVE scanner

AI, on your terms

  • Bring your own provider — OpenAI, Anthropic, Google, Mistral, Groq, Azure, or a model you host yourself
  • Written assessment of your security state, from your model or from the product's own rules
  • Public advisories scouted, filtered to what you actually run, and rewritten as advice
  • Log analysis is off until you switch it on, and redaction is on by default
  • No model is ever in the path of a blocking decision

Staff awareness

  • Phishing simulations using realistic pretexts
  • Restricted to email domains your organisation uses (public webmail domains excluded), and to administrators
  • Open and click tracking — no password or other form input is collected
  • Anyone who clicks lands on a short training page

Reporting and export

  • Eleven datasets, each exportable as PDF, Excel or CSV
  • One-click export of everything as a single workbook
  • Every export written to the audit log with who took it
  • Preview before you download, so nothing is a surprise

Integration

  • HMAC-SHA256 signed webhooks with retry and a delivery log
  • Scoped REST API at /api/v1/*, keys hashed with Argon2id
  • Microsoft 365 identity threat detection: risky sign-ins, risky users, OAuth grants
  • PSA ticketing for Halo, ConnectWise and Autotask
  • OIDC single sign-on: Entra ID, Okta, Google Workspace
  • Prometheus metrics at /metrics

Compliance

  • UK GDPR self-service export and an audited erasure workflow
  • Append-only, hash-chained audit log
  • Agent secrets and integration credentials encrypted in the database
  • Cyber-insurance evidence pack per kill-chain story
  • Cyber Essentials readiness view
  • Retention configurable per data type, with aggregate-only workforce mode

Running it

  • Agents for Windows, macOS, Linux, and anything running Python 3.9+
  • No kernel driver on any platform
  • Offline buffering — detection continues without a connection
  • Tamper protection: stopping or editing the agent raises a critical alert
  • Run by us on UK hosting; self-hosting by agreement

Run it against your own endpoints.

Fourteen-day trial, every capability above unlocked.

Start the trial See pricing