Platform

How it works The analyst team Trust & audit Integrations Deployment Evidence

Solutions

Defense & suppliers Government Healthcare Financial services MSSPs

Company

About Partners Resources Contact Responsible disclosure
Home/MSSPs

Managed security providers

The tier-one queue is where
your margin goes to die

You are paid per tenant and you pay per analyst hour. The alerts that consume the most hours are the ones that resolve to nothing, and you cannot stop investigating them without accepting the risk you were hired to carry.

measured Our production deployment is an MSSP · July 2026

98.1% of 728 alerts resolved without an analyst

Median AI triage time of 48 seconds. 617 of 619 impossible-travel alerts traced to one root cause, with zero alerts dropped to get there. The analyst who reviewed that month's 14 escalations did not re-investigate a single one.

Multi-tenancy

Isolation is a property of the schema

Not a filter somebody remembered to add to a query. This is the part your client's security questionnaire is going to ask about.

Row-level isolation

Organization scoping is enforced throughout the data layer, with PostgreSQL row-level security behind it on alerts, incidents and narratives.

Per-tenant credentials

Each client's integration keys are encrypted at rest and scoped to that client. Their threat-intelligence keys are theirs, and their spend is theirs.

Per-tenant cost observability

Model spend is attributable at alert, agent and tenant level. You can price a client because you can see what a client actually costs to run.

Built for the questionnaire your client will send you

Every managed provider eventually has to answer, in writing, how one client's data is kept away from another's. Ours is answerable at the schema level rather than in prose: scoping is enforced in the data layer, row-level security backs it in the database, and credentials are encrypted per tenant.

We will get on a call with your client's security reviewer and walk them through it directly. That tends to shorten the conversation considerably.

Unit economics

Smaller clients become profitable to serve

The clients you cannot profitably serve are the small ones: too little alert volume to justify a dedicated analyst, too much obligation to ignore. Automated triage with a defensible record changes which accounts are worth signing.

It also changes what you can offer upmarket. A client asking for evidence of review (for HIPAA, for CMMC, for an insurer, for their own board) is asking for something you can now produce as a by-product rather than as a project.

What changes per tenant

  • SLA thresholds, configured per organization
  • Confidence thresholds and whether any autonomy is enabled at all
  • Threat-intelligence sources and keys
  • Escalation destinations: their inbox, their Slack, your queue
  • Knowledge base contents, isolated per tenant

What does not change

The approval gate. No automated response action fires without a human, in any tenant, regardless of configuration. The threshold that would permit one defaults to unset and has to be deliberately enabled.

Per-tenant correlation

Forty alerts become one incident

Within each tenant, alerts that share indicators are grouped into a single attack narrative with a kill-chain timeline and the correlation factors written out. Your analyst opens one incident instead of working forty rows that turn out to be the same story.

Correlation is scoped to the tenant, which is what your clients' contracts require: one client's indicators never inform another's analysis, and there is no shared pool to explain away in a due-diligence review.

Bring us an alert you already know the answer to

Hand it something from last week and read the reasoning. If the verdict is wrong, you will see exactly where it went wrong, which is the whole point.