AI SECURITY TEAM

Enterprise-grade AI security agents

AI-driven security operations.

Drop our agents into any app, online shop, social platform or website. They watch every login, payment and data request in real time and tell you exactly who is attacking, how, and what to do next.

  • Detect break-ins — spots brute-force logins, credential stuffing and account takeovers.
  • Catch transfer fraud — flags suspicious payments, new payees and money moved after a password reset.
  • Protect personal data — detects data scraping, mass exports and leaks of card or ID numbers.
  • Spot bots and probes — recognises bots, vulnerability probes and injection attempts.
  • Connect the dots — links related alerts across agents into one incident with a clear timeline.
  • Explain and alert — an AI Analyst writes a plain-English brief and alerts you in the console, Slack or your SIEM.

Nothing is deployed without the owner’s personal approval.

LEDGER · just nowcritical

Transfer right after password reset

customer_4821 reset their password and sent 18,500 to a payee added 3 minutes earlier.

Owner alerted

The roster

Five specialists. One mission.

Each agent inspects every event your application reports, in real time, and files an incident when something looks wrong.

01

Sentinel

Intrusion detection

  • Brute-force and password-spraying attempts
  • Credential stuffing across many accounts
  • SQL injection, XSS, path traversal and command injection payloads
  • Unexpected privilege escalation
  • Password resets and security-setting changes (MFA off, email changed)
02

Ledger

Transfer & payment fraud

  • Transfers above your risk threshold
  • Rapid-fire transfer velocity
  • Money sent to a payee added minutes earlier
  • Transfers right after a password reset (account takeover)
  • Amounts far outside a user’s normal behaviour
03

Vault

Personal data protection

  • Bulk exports of user records
  • Scraping of many customer profiles in a short window
  • Card numbers or national ID numbers leaking into logs and payloads
04

Watchtower

Bots, probes & account takeover

  • Known attack tooling (sqlmap, nikto, hydra, nuclei…)
  • Request floods from a single address
  • Probing of secret files and admin panels
  • Logins from a never-before-seen country or device
05

Analyst

AI incident triage

  • Explains what happened in plain language
  • Rates confidence and likely intent
  • Recommends defensive next steps for your team

How to get access

Get your keys in four steps.

Every deployment is approved by hand, so nothing is watched until you’ve agreed the scope. Here’s what to do.

  1. STEP 1

    Send a request

    Fill in the request form below with your name, work email, organization, the website or app you want protected and what worries you most.

  2. STEP 2

    Get approved

    We review every request personally and email you with terms. Once you agree, we set up your deployment for the domains you named.

  3. STEP 3

    Receive your keys

    We send you a public key for your website and a secret key for your servers, and your email is added so you can sign in to the console. Keep the secret key private — it’s shown only once.

  4. STEP 4

    Install and go live

    Add one script tag to your site or one API call to your server. Alerts then reach you in the console and by Slack, Discord, email or SMS.

Enterprise

Enterprise-level security, from a single shop to a global SOC.

The same controls large security teams expect — identity, isolation, auditability and integrations — are built in for every customer, not sold as an upgrade.

Multi-tenant isolation

Every organization’s deployments, events and incidents are walled off from every other tenant, with per-tenant rate limits so one customer can never starve another.

SSO, SCIM and role-based access

SAML single sign-on, SCIM user provisioning and one role per member — admin, analyst, viewer and more — scoped to each organization.

Tamper-evident audit trail

Every privileged action is written to a hash-chained audit log that cannot be edited or deleted, and can be verified end to end.

Encryption at rest

Connector credentials and queued telemetry are sealed with AES-256-GCM envelope encryption, with master-key rotation.

Plugs into your SOC

Incidents stream to Splunk, Datadog or any signed webhook, mapped to MITRE ATT&CK, with retries and a dead-letter queue so nothing is lost.

SLAs, retention and legal hold

Response clocks per severity, per-organization data retention windows and legal hold for incidents under investigation.

Built to keep up under load

A durable ingest queue with idempotency keys, fair scheduling across tenants and automatic recovery of stuck work.

Scoped service keys and REST API

Org-scoped service accounts for the incidents, reports and audit APIs — hashed at rest and shown only once.

Rules of engagement

No going rogue. Built in, not bolted on.

These aren’t promises in a policy document — they’re how the system is engineered. The team works for the people it protects.

Observe and report — never act on its own

The agents watch, detect and alert. They cannot block users, move money, delete data or touch anything in the protected application. A human always makes the call.

Deployed only with the owner’s permission

Every deployment starts as pending. Nothing is watched until the owner personally activates it, and the owner can pause or revoke it at any time.

Scope-locked

Each deployment only accepts telemetry from the domains and keys it was issued. The team cannot wander into systems it wasn’t invited into.

Minimum data, maximum privacy

Raw form values and payloads are scanned in memory and discarded. Card and ID numbers are redacted from evidence before anything is saved.

One-touch kill switch

The owner can stand the entire team down across every client in one click. Ingestion and alerts stop immediately.

Every permission change is on the record

Activations, revocations, key rotations and drills are written to an audit log that shows who did what and when.

Defensive only, for the good of all

The AI Analyst is instructed to recommend only lawful, proportionate defense — no hacking back, no doxxing, no exploit code.

Borrow the team

Put the team on your side.

Tell us what you run and what keeps you up at night. The owner reviews every request personally and replies with terms and next steps.

AI Security Team · Defensive monitoring for the good of everyone online.