Questions detection teams ask us.
Short answers on data, the product and working together. If yours is not here, write to us.
Security & data
Does the agent write to my SIEM?
No. Agents use read-only search access, scoped to the indexes you choose.
Changes reach your SIEM only through a merge request that your engineer approves, then through your own deploy process.
Does my data leave my environment?
Partly, and we want to be plain about it. To do a task, the agents send the query results, rule text and report text that task needs to the model provider. They do not get raw index access.
Deployment options and data terms are agreed per engagement, before any access is set up. See Security.
Who owns the detections?
You do. Detections, macros and runbooks land in your repository, and they stay yours if the engagement ends.
Is everything logged?
Yes. Every query, model call, proposal and approval is logged and can be exported.
Product
Is it Splunk only?
Splunk comes first, and that is where the agents are built and tested today. Other SIEMs are on request.
Can the output include Sigma?
Yes, where it is relevant. The primary output follows your repository format; a Sigma version can be added alongside it.
Do I need a lab?
Only for attack simulation. Research, coverage checks, drafting and tuning work without one. Without a lab, validation relies on your historical data and is marked that way.
What if the agent is wrong?
It will be, sometimes. That is why the workflow has engineer approval gates and why every claim links to its evidence.
When validation fails, the failure carries a typed reason, such as a telemetry gap or too many false positives, that sends the work back to the right stage. An independent review step checks the output before it reaches your engineer.
How do you avoid over-tuning a rule?
The tuning loop stops before it silences a rule. A proposal that drops a rule to zero alerts is treated as a red flag, not a success.
Every proposal must pass must-keep tests: known attack variants still fire, and alerts you marked as important are still raised. See a sample tuning diff.
Working together
Does it work for MSSPs with many tenants?
We think it is a good fit. The same rule is noisy in different ways at different customers, and the tuning loop runs per rule and per tenant, with exceptions scoped to one tenant and recorded with a justification.
What does it cost?
Design-partner pricing is scoped per engagement and agreed before work starts.
How do we start?
Write to us and book a 30-minute walkthrough. We run one technique of your choice live in our lab. Then read how a design partnership works.