Skip to content
Explore platformAI Fabric
AI Fabric

Your Autonomous SOC in a Box

Sovereign AI infrastructure for in-house SOCs and MSSPs. Scale thousands of AI agents across local cybersecurity LLMs with intelligent routing, balancing, pooling, failover and high availability — from one appliance to a fleet. Air-gapped, local-first and under your control.

9 native agents on-prem 35B params · ~3B active 250K token context ~50 tok/s per stream Sovereign AI agents Local LLM · Apache 2.0
Imperum
DSLLM APPLIANCEIMP-NODE1
CybersecurityLLM v1.0 · Q4INFER
48 tok/s · 3 analysts
41°C
PWR
AI
NET
DISK
USB 3.2 · USB-C
INTAKEFRONT-TO-BACK AIRFLOW
01 - The model

Trained on 500K+ security datasets.

Curated cybersecurity instruction data, SOC and SIEM operations, detection engineering, DFIR, malware analysis, threat intelligence, cloud, OT and ICS.

35B / ~3B
Total params / active per token
250K
Token context per request
~50/s
Tokens per second, single stream
5,000+
Live Triage decisions · 0.46% timeout rate
Hugging FaceIMPERUMImperum-CybersecurityLLM-v1.0-GGUF
Downloads last month5,985
All time7,572
Likes21
02 - Fleet & capabilities

Built for large in-house SOCs and MSSPs moving to autonomous, agentic operations.

Start with one appliance and grow to a fleet without changing a route. Every added node, GPU or pool joins the same balancer; every tenant keeps its own data, credentials and AI resources — and every prompt stays on your hardware unless you decide otherwise.

Start1 node · 8 slots
One appliance
All 9 native agents on-prem from day oneTriage, Pilot and native agents for a single SOCUp to 4 analysts served concurrently per modelAir-gapped — no egress, no per-token bill
Grow3 nodes · 24 slots
Stack & pool
Add appliances; the balancer spreads load by live capacityPool replicas of one model into a single endpointPer-feature fallback chains keep every agent runningOptional cloud overflow, redacted by Veil
FleetN nodes · multi-tenant
MSSP / MDR scale
Per-tenant isolation: data, credentials, permissions, AI routesDedicated or shared appliances per customerPriority bands: interactive analysts never wait behind batchCustomer portal, reporting and audit per tenant
Multi-LLM
Several models per appliance — any mix of Imperum and open models, each routed per feature.
Auto-Tune
Probed capacity and windows, evidence chunking, measured timeouts and fit verdicts per feature.
LLM Balancer
One visible queue: priority bands, pools, shed instead of hang, median-wait telemetry.
Pools
Replicas of one model on separate GPUs act as a single endpoint with combined capacity.
Fallback Switch
Every route carries an ordered chain; on 429, unreachable or full slots the switch moves to the next provider within a second — no operator action.
High Availability
Stack appliances and each one joins the balancer with +8 slots; a node down means calls move to the next healthy appliance — no lost call.
Veil
PII redactor on every cloud-bound prompt; identities become stable tokens, re-hydrated on return.
Hybrid by choice
Cloud LLMs join the same router as a last resort — and only through Veil.
Cloud Tokenomics
Tokens, requests and spend metered per agent, provider and tenant — on-prem included at $0.
03 - Agent forge

Your sovereign agent forge. 2,770+ agents, running on this device.

Agent Studio ships on the appliance: pick an agent from the library, tune it to your stack, run it on the local DSLLM — no data leaves the box. Nine native agents are pre-wired and tested end to end at production scale.

Agent StudioYour factory for building, testing, and running AIOps agents — ships on the appliance
Couldn’t find it in the library?Create your Agent
SecOps ·291
DevOps ·112
ITOps ·116
Technology Agents ·2,251
2,770 ready-to-run agents · 2,750 structured · 20 advanced · all run on the local DSLLM · click a library to see the business value
SecOps291 agents · 32 categories
Alert TriageIncident ResponseDetection EngineeringThreat HuntingThreat IntelligenceForensicsCloud SecurityEmail SecurityEndpoint SecurityNetwork SecurityIdentity ThreatComplianceDLPMSSP OperationsSOC OperationsOT/ICS SecurityVulnerability MgmtWeb App SecurityPurple TeamDeception
DevOps112 agents · 12 categories
CI/cdGitOpsSource ControlKubernetesIaCConfig ManagementBuild ArtifactDatabase DevOpsFinOpsObservabilityPerformanceSRE / SLO
ITOps116 agents · 12 categories
Asset / CMDBBackup & DRCapacity & PerformanceCompliance Audit OpsEndpoint HealthIdentity HelpdeskMail & CollabMonitoring & AlertingNetwork OpsServer LifecycleService DeskStorage Ops
Technology Agents2,251 agents that operate your security stack · 15 tool categories
SIEMEDR / XDRSOARFirewall / NGFWAntivirusCloud SecurityData Security & DLPDNS SecurityEmail SecurityIdentityITSM / Service DeskNetwork SecurityMalware AnalysisThreat IntelligenceVulnerability & Exposure
Native Agents9 features
Virtus Pilot
Runs a full investigation end to end — gathers evidence, decides, acts and reports — so analysts review outcomes instead of doing the legwork
Virtus Triage
Clears alert noise automatically: closes false positives, escalates real threats and flags only what needs a human
Email – Phishing
Handles every reported email from headers to attachments and verdicts it in minutes — no analyst time on routine phishing
Endpoint
Picks up every AV, EPP and EDR alert the moment it fires and investigates it without waiting in a queue
Network
Turns scattered network alerts from Vectra, Sentinel and Defender into one clear incident with the full picture
Incident Response
Takes an incident from first alert to notified stakeholders on its own — consistent, documented and fast
Endpoint Investigation
Investigates endpoint alerts across EDR, SIEM and threat intel and delivers a verdict with a recommended response
Threat Enrichment
Adds the who, what and how-serious to every alert so analysts decide with context, not guesswork
Forensics
Collects and analyses digital evidence and finds the root cause — days of forensic work in hours
04 - LLM Balancer

One appliance, or a rack of them — one balancer.

Each appliance hosts several models. Imperum's LLM Balancer spreads every feature call across the fleet by live slot capacity, probes each endpoint's real throughput, and auto-tunes context windows and fallbacks per feature.

Auto-tune
Measure6.4k p95
FIT · 16k
Fits
Timeout~45 s
LW fallback off
AI agents
Virtus routing · multi-LLM
Virtus Pilot0 calls
Virtus Triage0 calls
Email Phishing0 calls
Endpoint0 calls
Network0 calls
Incident Response0 calls
Endpoint Investigation0 calls
Threat Enrichment0 calls
Forensics0 calls
Pool · capacity
2 GPUs → 1 endpoint0/8 live · least in-flight
LLM Balancer
Virtus Router
Active
0
Waiting
0
Capacity
24 +64
Median wait
2 ms
Auto-tune · least-loaded wins
Fallback · HA
All healthy
node-1
Primary
node-2
Primary
Cloud
Standby via Veil
DSLLM appliance stack · high availability
Imperum
node-1
Healthy
imperum-cybersecurity-35b51 tok/s · 4 · Operator
qwen3.6-35b-a3b23 tok/s · 4 · Probed
Imperum
node-2
Healthy
imperum-cybersecurity-35b47 tok/s · 4 · Probed
gpt-oss-120b44 tok/s · 4 · Assumed
Pool · Imperum-35b · 2 appliances · 8 slots · capacity
Imperum
gpu-0
Healthy
imperum-cybersecurity-35b49 tok/s · 4 · one pool, 8 slots
Imperum
gpu-1
Healthy
imperum-cybersecurity-35b47 tok/s · 4 · one pool, 8 slots
VeilPII redactor0 redacted
Veil Audit0
Cloud LLMs · fallback 216 slots · tokenomics
Anthropic claude-sonnet-4-6
0/16
156.1M tok$468.4145,109 req · 30d
OpenAI gpt-4o
0/16
3.6M tok$36.062,765 req · 30d
Azure OpenAI gpt-4o · EU
0/16
0 tok$0.000 req · 30d
Mistral mistral-large
0/16
0 tok$0.000 req · 30d

See the AI Fabric run
on your own alerts.

Bring one alert queue, one investigation that takes too long or one tenant you need to isolate. We’ll route it through the appliance, balance it across the fleet and keep every prompt on your hardware.