Skip to main content

Our Approach to AI

Cybersecurity is doing AI wrong

An agentic assistant isn’t the solution.
Bolting GenAI onto a broken architecture won’t fix anything.
Complete data visibility is a necessity.

Treating AI as the solution answers the wrong question.

What data can AI see, and who owns the reasoning, models, and data?

01

Data was already the biggest challenge in cyber before AI

Cyber vendors expanded their data scope over the years across identity, SaaS, cloud, and endpoint, but their architectures remained fragmented.

  • 1

    Vendors only surface and store select data. You get a fraction of what you think.

  • 2

    Getting complete data into cloud AI workflows is both technically hard and prohibitively expensive at scale.

  • 3

    The more data you route through AI pipelines, the more sensitive data leaves your environment. And it might even get used to train the AI vendors’ models.

  • 4

    AI amplified the need for complete data at exactly the moment the current architecture made it hardest to provide.

Technical drawing: the Cylake agent and rich data telemetry — endpoint, data, browser, AI, identity, SaaS, cloud, proprietary data, user files and threat intel — feeding up through a single ingestion pipeline into one complete data lake, with unified AI, detection, automation and orchestration above it.

Cloud-era architectures make sovereignty a problem

Public cloud AI doesn’t just cost more. It requires your most sensitive data to leave your environment, and AI vendors have every incentive to train their next model on it.

Keep it to yourself without trading off the cutting edge.

02

LLMs are not always the right answer

Machine Learning has been at the core of detection for years: pattern recognition, anomaly detection, signal from noise. That’s its job, and it’s really good at it. LLMs and agents are very powerful for explanation, investigation, hunting, and response.

  • 1

    An ‘Agentic SOC analyst that does everything’ sounds good on a slide. In practice it’s slow, expensive, and missing the actual signal. In other words, it’ll be wrong.

  • 2

    Adding agents doesn’t solve a data or architecture problem. It layers complexity on top of one.

  • 3

    The question isn’t which AI to use. It’s whether your data is complete enough to make any of it matter.

03

The economics of using cloud LLMs for detection don’t work

1,000

events/sec

× 100 bytes ÷ 4 bytes/token

Optimistic assumption: identifying which events to analyze is itself the detection challenge.

25,000

tokens/sec

÷ 25,000 tokens/sec

40 sec

of history per 1M-token window

× 1 inference/sec × 31.5M sec/yr × cost/1M tokens

5:1 compression extends this to ~200s, though compression in a security context carries its own risks.

$158M

per year at Claude Opus pricing

This excludes infrastructure costs, prefill latency that can reach minutes per inference, and any data you are not able to send to a public cloud.

Estimated annual cost of continuous cloud LLM inference for security detection, by model.
Model Cost / Day Cost / Month Cost / Year
Gemma3-4B $4K$129K$1.5M
GPT-5.4-nano $17K$518K$6.3M
Claude 3.5 Haiku $69K$2M$25M
Claude Opus $432K$13M$158M

Estimated cost of continuous cloud LLM inference for security detection, based on published API pricing

~$100M

That’s what it costs to build a vertically integrated, sovereign, AI-native security platform from the ground up.
We’re spending that. You don’t have to.

Your own hardware. Your own models. Your own data lake. Built so that no organization has to spend that themselves, or make the tradeoffs that come from not doing so.