Imperum FAQ
Answers for SOC teams, security leaders, and MSSPs evaluating Imperum.
Value & outcomes
4 QUESTIONSImperum helps reduce alert fatigue by using AI Agents to triage, enrich, and prioritize alerts before they reach analysts. This helps SOC teams focus on validated threats instead of manually reviewing repetitive noise.
Imperum accelerates detection and response by automating investigation steps, correlating evidence across tools, prioritizing cases, and preparing response actions. Analysts get the context they need faster, which helps them move from alert to decision more quickly.
Imperum helps reduce false positives by correlating alerts with additional context, enriching indicators, analyzing related entities, and prioritizing cases based on risk. This helps analysts focus on alerts that require real attention.
Days, not months. Install the platform, connect a handful of your priority tools, and point the AI at your live alert stream in observation mode — it reasons through everything but executes nothing. Watch the verdicts and the override rate on your own cases, then decide how much autonomy to grant.
Fit with your existing stack
5 QUESTIONSYes. Imperum is designed to work across existing security stacks, including SIEM, EDR, XDR, NDR, email, cloud, endpoint, and threat intelligence tools. The MCP Gateway helps connect approved tools and workflows so AI agents can operate within controlled boundaries.
Not necessarily. Imperum can work alongside existing SIEM and SOAR investments. It adds agentic AI, autonomous investigation, case prioritization, forensics, and response workflows to help teams reduce manual work and tool switching.
It doesn’t have to. Imperum operates on top of your environment — 1,600+ connectors across 672 vendors mean the AI works with the tools you already own. If you’d rather not change anything visible, the API-only mode adds Imperum’s AI behind the scenes and returns results into your existing systems. And if you are consolidating, the SecOps Platform tier includes the full operations suite.
Traditional SOAR depends heavily on static playbooks that must be built and maintained. Imperum uses agentic AI to reason over alert context, evidence, cases, and connected tools. With Agent Studio, teams can build and adapt AI-driven workflows with less dependence on brittle manual playbooks.
Most “AI for the SOC” is a copilot — a chatbot that suggests while your analysts still do the work. Imperum’s agents do the work: seven specialist agents triage, investigate, and resolve the routine alerts end to end, with context-aware reasoning across your environment.
Two things set it apart. Governance you can defend — deterministic policy gates, approval gates on irreversible actions, a full audit trail, and the override rate as a live trust metric. And sovereignty — on-prem, air-gap, or local LLM inference, with your data never leaving your environment. Autonomy with control, not another assistant to supervise.
Control, trust & governance
5 QUESTIONSImperum is designed with human-in-the-loop control. AI agents can investigate, enrich, recommend, and prepare actions, while analysts remain in control of critical decisions and approvals.
Three ways. First, autonomy is adjustable — per team, per action type, from “recommend only” to fully autonomous. Irreversible actions like isolating a machine or blocking traffic always wait for human approval unless you explicitly decide otherwise.
Second, the AI operates inside hard limits: policy rules gate every AI decision and any action it proposes, sensitive data is redacted before any cloud model sees it, and the AI can adjust — but never overrule — the risk math that ranks your cases.
Third, you measure it. The override rate — how often your analysts overturn the AI’s calls — is tracked continuously on your own cases. It tells you, week by week, exactly how much autonomy the AI has earned.
You measure accuracy directly, on your own cases, through the override rate — how often your analysts overturn the AI’s verdict. A low override rate means the AI is well-aligned; a rising one tells you exactly where to tighten.
The AI also runs inside guardrails. Deterministic policy gates bound every decision, the Case Prioritizer’s risk score is fixed math the AI can only nudge within a narrow band, and irreversible actions wait for approval. Every verdict carries its evidence, reasoning, and a confidence score — so a wrong call is visible, traceable, and correctable, not buried.
Imperum is built for auditability. Security teams can review the evidence, context, verdicts, and actions behind an investigation so decisions can be traced, validated, and governed.
The platform degrades gracefully. Alert collection, detection, case management, and automation keep running; AI work queues and resumes when it’s back. Your team can operate everything manually in the meantime. The AI is additive — never a single point of failure.
Your analysts
3 QUESTIONSNo — it changes what they spend their day on. The AI takes the repetitive work: triage, evidence gathering, prioritization, routing. Your analysts keep the judgment calls, the approvals, and the complex cases that actually need a human mind. Most teams find the role gets better, not smaller — and retention improves with it.
Yes. Imperum’s AI Assistant helps analysts query security data, investigations, cases, and context in natural language. This supports faster investigation without forcing analysts to switch between tools for every answer.
Yes. Imperum supports proactive threat hunting by helping teams search across security data, investigate suspicious patterns, and surface threats before they escalate into confirmed incidents.
Deployment, data & sovereignty
4 QUESTIONSYes. Imperum supports flexible deployment models, including cloud, on-premises, hybrid, and environments with stricter data control requirements. This is important for regulated industries and security teams with sensitive operational data.
Yes. Full sovereignty is a first-class option: AI models running on your own hardware, an air-gap-compatible license with no phone-home, offline installation bundles, and zero required outbound connectivity. Regulated and defense environments were design targets from day one.
Your data stays in your environment, and it isn’t used to train models. Imperum’s agents reason over your data at query time through retrieval — RAG and KAG graph context — not by training on it.
When a cloud LLM is in the loop, Veil redacts PII before anything leaves the platform and restores it on the response, so the model sees placeholder tokens, not your sensitive values. Run fully on-prem or air-gapped with local LLM inference, and there’s no outbound data at all.
Every automated action is logged with its actor, evidence, reasoning, and approval trail, so you can show an auditor exactly what the AI did and why. Access is RBAC-honoured and tenant-scoped, and credentials sit in an encrypted vault with rotation and break-glass controls.
Findings map to the frameworks your auditors expect — MITRE ATT&CK, NIST CSF, OWASP — and data residency is yours to set, from cloud to fully air-gapped.
For MSSPs & pricing
2 QUESTIONSYes. Imperum is built for both enterprise SOCs and managed security providers. MSSPs and MDR teams can use Imperum to scale investigations, standardize response quality, manage customer environments, and reduce manual workload across tenants.
Imperum is licensed by product tier and the modules you enable, through a signed entitlement file that works the same on-prem, air-gapped, or in the cloud. There are two tiers: Autonomous SOC, the multi-agent triage-investigate-resolve core, and SecOps Platform, which adds the full operations suite for teams consolidating their stack.
For pricing scoped to your environment, talk to sales.