Investigate
Read from your existing EDR, SIEM, identity, and cloud telemetry. Correlates evidence even when external services are unreachable.
AI Incident Response Kit
AIR-Kit provides persistent autonomous investigation with local control and operational clarity.
AIR-Kit is a local, frontier-class AI inference engine for incident response. When a breach locks you out of cloud-based AI — and responders are denied access because the vendor cannot distinguish attackers from defenders — AIR-Kit keeps running on your hardware, wired into your telemetry and incident reporting, so you can still investigate, understand, and act.
Capabilities
Read from your existing EDR, SIEM, identity, and cloud telemetry. Correlates evidence even when external services are unreachable.
A frontier-class model reasons over your data, ranks hypotheses, and explains how it reached each conclusion.
Evidence-backed recommendations for containment, eradication, and recovery with full provenance for incident reports.
Evidence flow
AIR-Kit is bring-your-own-telemetry. It connects to the security infrastructure you already trust—including your SIEM, EDR, identity provider, cloud audit logs, observability platform, and AI infrastructure—and continuously ingests events into a unified local investigation graph. Rather than replacing your existing detection stack, AIR-Kit builds on top of it, preserving every observation, correlation, and artifact within your security boundary. A persistent open-weight reasoning model operates alongside this graph, constructing and revising hypotheses as new evidence arrives, recommending containment actions with transparent, evidence-backed justification.
Ingest raw signals and automatically extract entities and timelines locally.
Correlate events across disparate telemetry sources using isolated models.
Generate precise, targeted remediation actions backed by concrete evidence.
Keep all sensitive data inside your perimeter with zero cloud dependencies.
Retain persistent context across investigations for rapid future matches.
Architecture
Deployment
Single binary or container. Wired into your existing telemetry, incident reporting, and response workflows.
No network dependency. No cloud callback. Models and indexes live on hardware you control, ready when external AI is unreachable.
Every hypothesis, experiment, and action is written to an append-only case record. Full replay and team simulation support.
Deploy AIR-Kit locally in minutes. Connect your telemetry sources and let the AI build the evidence graph.
Download AIR-Kit Release