Row-level isolation
Organization scoping is enforced throughout the data layer, with PostgreSQL row-level security behind it on alerts, incidents and narratives.
Managed security providers
You are paid per tenant and you pay per analyst hour. The alerts that consume the most hours are the ones that resolve to nothing, and you cannot stop investigating them without accepting the risk you were hired to carry.
Median AI triage time of 48 seconds. 617 of 619 impossible-travel alerts traced to one root cause, with zero alerts dropped to get there. The analyst who reviewed that month's 14 escalations did not re-investigate a single one.
Multi-tenancy
Not a filter somebody remembered to add to a query. This is the part your client's security questionnaire is going to ask about.
Organization scoping is enforced throughout the data layer, with PostgreSQL row-level security behind it on alerts, incidents and narratives.
Each client's integration keys are encrypted at rest and scoped to that client. Their threat-intelligence keys are theirs, and their spend is theirs.
Model spend is attributable at alert, agent and tenant level. You can price a client because you can see what a client actually costs to run.
Every managed provider eventually has to answer, in writing, how one client's data is kept away from another's. Ours is answerable at the schema level rather than in prose: scoping is enforced in the data layer, row-level security backs it in the database, and credentials are encrypted per tenant.
We will get on a call with your client's security reviewer and walk them through it directly. That tends to shorten the conversation considerably.
Unit economics
The clients you cannot profitably serve are the small ones: too little alert volume to justify a dedicated analyst, too much obligation to ignore. Automated triage with a defensible record changes which accounts are worth signing.
It also changes what you can offer upmarket. A client asking for evidence of review (for HIPAA, for CMMC, for an insurer, for their own board) is asking for something you can now produce as a by-product rather than as a project.
The approval gate. No automated response action fires without a human, in any tenant, regardless of configuration. The threshold that would permit one defaults to unset and has to be deliberately enabled.
Per-tenant correlation
Within each tenant, alerts that share indicators are grouped into a single attack narrative with a kill-chain timeline and the correlation factors written out. Your analyst opens one incident instead of working forty rows that turn out to be the same story.
Correlation is scoped to the tenant, which is what your clients' contracts require: one client's indicators never inform another's analysis, and there is no shared pool to explain away in a due-diligence review.
Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.