AI Incident Response Kit

Detection is not understanding.

AIR-Kit provides persistent autonomous investigation with local control and operational clarity.

AIR-Kit is a local, frontier-class AI inference engine for incident response. When a breach locks you out of cloud-based AI — and responders are denied access because the vendor cannot distinguish attackers from defenders — AIR-Kit keeps running on your hardware, wired into your telemetry and incident reporting, so you can still investigate, understand, and act.

Capabilities

Investigate

Read from your existing EDR, SIEM, identity, and cloud telemetry. Correlates evidence even when external services are unreachable.

Understand

A frontier-class model reasons over your data, ranks hypotheses, and explains how it reached each conclusion.

Respond

Evidence-backed recommendations for containment, eradication, and recovery with full provenance for incident reports.

Evidence flow

BYOT. Built on the signals you already generate.

AIR-Kit is bring-your-own-telemetry. It connects to the security infrastructure you already trust—including your SIEM, EDR, identity provider, cloud audit logs, observability platform, and AI infrastructure—and continuously ingests events into a unified local investigation graph. Rather than replacing your existing detection stack, AIR-Kit builds on top of it, preserving every observation, correlation, and artifact within your security boundary. A persistent open-weight reasoning model operates alongside this graph, constructing and revising hypotheses as new evidence arrives, recommending containment actions with transparent, evidence-backed justification.

Methodology

The Investigation Cycle

Investigate

Ingest raw signals and automatically extract entities and timelines locally.

Understand

Correlate events across disparate telemetry sources using isolated models.

Respond

Generate precise, targeted remediation actions backed by concrete evidence.

Control

Keep all sensitive data inside your perimeter with zero cloud dependencies.

Learn

Retain persistent context across investigations for rapid future matches.

Architecture

Deployment

Offline inference. Operational continuity.

01

Self-hosted

Single binary or container. Wired into your existing telemetry, incident reporting, and response workflows.

02

Zero-egress

No network dependency. No cloud callback. Models and indexes live on hardware you control, ready when external AI is unreachable.

03

Auditable

Every hypothesis, experiment, and action is written to an append-only case record. Full replay and team simulation support.

Start Your Own Investigation.

Deploy AIR-Kit locally in minutes. Connect your telemetry sources and let the AI build the evidence graph.

Download AIR-Kit Release