Ask your security data anything, in plain language

Imperum AI Assistant is a natural-language interface to your security environment. Ask about alerts, entities, cases, threat intelligence and history. Every answer is built from your own data and cites the alerts, cases and events it came from.

Book a Demo Watch Tour

Answers cite what they came from 29 forensic tools, 1,500+ connectors Risky actions wait for approval

The questions analysts ask all day

None of these questions is hard. They are just slow. The answer to one of them sits in the SIEM, the next one in the EDR console, the third in a case somebody closed in March. Each tool wants the question in its own query language, and by the time an analyst has asked all three, the thread they were pulling has gone cold.

The Assistant takes the question as it was asked. It searches your alerts, events, cases and threat intelligence, reads what your own team decided about alerts like this one before, and answers with links back to every record it used. The analyst stays in the chair: they ask, they read the answer, they decide what to look at next.

  • What other hosts has this user accessed?
  • Has this file hash appeared on another endpoint?
  • Which alerts have been associated with this IP address across connected sources?
  • Which MITRE ATT&CK techniques have been associated with this host?

What happens between
the question and the answer

If you have used a chat assistant before, the first two steps will look familiar. Steps three, four and five are the ones that make this one a security tool.

  1. 01

    You ask

    Type the question the way you would say it to a colleague. Pin a host, a user, a MITRE technique, a severity, a case or a time window and the question stays on that subject for the rest of the conversation.

    You
  2. 02

    It writes a plan, and you watch it run

    Before anything else happens the Assistant lists the steps it intends to take. The plan streams as it works, so you can see which step is running and stop it at any point.

    Model
  3. 03

    It runs your own tools, with your permissions

    Platform tools query your alerts, events, cases, triage decisions and detection rules. Forensics tools reach the endpoints. Connector actions call the products you already own. Every call is tagged with where it came from, and every call runs with your permissions, not with an administrator's.

    Tools
  4. 04

    The answer names its sources

    Each answer carries citations: the alert, the case, the event, the document. Click one and you land on the record itself. When the answer is long enough to be worth keeping it becomes an Investigation Report you can attach to a case.

    Model
  5. 05

    Anything risky stops and asks

    Reading is free. Isolating a host, blocking an address, killing a process or resetting a password is not. Those actions pause with their parameters shown and wait for you to approve or deny them. The Assistant cannot talk its way past that.

    You approve

It is already open,
wherever you are working

The Assistant sits in three places, and in the product it carries the Virtus name, so that is the button your team will be looking for.

A button in the header

On every screen in the platform, next to your profile. Press it, or use the keyboard shortcut, and the question box opens on top of whatever you were reading.

A page of its own, with your threads

Longer investigations get a full window and a thread list. Threads are saved per analyst, so yesterday's hunt is still there this morning and nobody else in the tenant can read it.

A tab inside every case

Open a case and the Assistant is one of its tabs, already holding the case as context. Ask about this case without repeating which case you mean.

Inside your permissions,
not a chat window to the internet

The question you can ask is not the limit. What you are allowed to see, and what the platform is allowed to do without a person, is the limit.

Anything that changes a host or an account waits for a person

One list decides which tool calls are risky, and both the badge you see and the gate on the server read from it. Isolate, block, quarantine, terminate, disable an account, reset a password, run a command: all of them stop and show you what they are about to do.

It sees what you see, and nothing else

Every query inherits your role and your tenant. An analyst who cannot open a customer's cases cannot ask the Assistant to read them either, and a service provider's tenants never share an answer.

Your choice of model, and it never sees names

Run on a cloud provider, on a model you host yourself, or on both at once. Veil masks addresses, hostnames, usernames, email addresses, API keys and file paths before the call and restores them in the answer.

It reads what your team already worked out

Alongside the live search, the Assistant retrieves from your own indexed history. That is why an answer can tell you how this kind of alert was handled the last four times, and cite the decisions it is quoting.

The same tools, opened to other agents

MCP Gateway is how a tool outside Imperum reaches these same actions, under the same permissions and the same approval rule. The Assistant can use it too. It is off until you turn it on.

See MCP Gateway

Different from the agents, on purpose

Virtus Triage and Virtus Pilot work the queue on their own, all night, whether anyone is watching. The Assistant does nothing until an analyst asks. Both read the same data.

See Virtus Triage

Questions about the AI Assistant

1How is this different from a general chat assistant?

It answers from your data, not from what a model remembers about the world. Every answer carries links to the alerts, cases and events behind it, so you can check the work. And it can act on your tools, which is why anything risky waits for your approval first.

2What data can the Assistant see?

The alerts, entities, cases, threat intelligence, techniques and history in your own environment, limited to what your role and tenant allow. A source that has not been connected and indexed is not searchable, and the Assistant says so rather than filling the gap.

3Does our data go to a public model?

Only if you choose that. Cloud, self-hosted and hybrid are all supported, and air-gapped deployments run a model you host. Whichever you pick, Veil masks identifiers before the call and puts them back in the answer, and which categories are masked is your setting.

4What can it do beyond answering?

Run forensic collections and hunts across your endpoints with 29 tools, call actions on more than 1,500 connected products, build an attack timeline, and write an Investigation Report onto a case. Read-only work runs when you ask. Anything that changes a host or an account waits for approval.

5How is it different from the Virtus agents?

Who starts the work. Virtus Triage and Virtus Pilot run on their own inside limits you configure, and you read the result afterwards. The Assistant is analyst-led: it waits for your question, and it hands the next decision back to you.

Have any other questions?
Read the full question library

Bring one question your team answers by hand

Pick the question that takes three tools and twenty minutes. We will ask it in the Assistant on a live environment and show you the answer with its sources attached.

Book a 30-minute demo Watch the platform tour