Ready-made agents for triage, investigation, phishing, endpoints, networks, incident response, enrichment, and forensics. They reason step by step, with human approval where the stakes are high.
Three ways to build, from a simple agent to a full drag-and-drop builder, with 100+ ready-made templates and a live view you can watch step by step.
Three modes. Ask in plain English, search past investigations, or chat and let the Assistant take action across your tools. Risky actions wait for approval, and personal data is kept private throughout.
Make every security tool you own available to your AI, both ways, separated per customer, fully governed, and logged.
Watches every detection rule across every SIEM you run, finds the silent and broken ones, and drafts fixes your analysts approve.
Onboard more customers without hiring more analysts. Imperum's AI SOC triages, investigates, and responds across every tenant so your team scales margin, not alert volume.
Run every customer's SOC from a single pane. Aggregated KPIs, live AI triage activity, and per-tenant drill-down with a Virtus Assistant scoped to the data each tenant is allowed to see.
Total alerts, MTTR, FPR, automation rate rolled up across every managed tenant with proper weighting.
Every Virtus Triage and Pilot decision streams in with its tenant tag, verdict, and confidence full audit trail in the background.
The Virtus Assistant respects the operator's tenant scope; cross-tenant queries surface only what RBAC permits.
Around-the-clock coverage without around-the-clock headcount. Human analysts run the day shift. Virtus AI agents run the night shift under risk policy and approval gates escalating to a human only when policy requires.
Four humans on duty 08:00–20:00. Skill-matched, RBAC-aware, escalation-chain ready.
Four Virtus AI agents (Enricher · Hunter · Responder · Triage) on duty 20:00–08:00. Risk-policy-gated, full audit trail, Veil PII redaction on every LLM call.
Cases triaged overnight surface in the day team's queue at 08:00 with Virtus's verdict, narrative, and recommended actions attached.
Customer-facing portal for phishing report, access request, open case, view case status, and report download branded per tenant, SSO-gated, rate-limited.
Forward .eml or paste headers · auto-investigation
Approval-gated, time-bounded, audit-logged
Status: investigation · SLA: healthy
Give every operator and agent a secure path in without the operational burden. Short-lived certificates, automatic rotation, instant revocation, and policy-enforced egress, all managed from one console.
SSO + MFA
Short-lived cert
mTLS · Egress policy
Stay online when it matters most. Every layer database, cache, message bus, search, and API runs in a multi-node cluster with automatic failover, zero-data-loss replication, and no single point of failure.
3-node cluster with synchronous replication, automatic leader election, and zero-data-loss failover.
3-node distributed cache for sessions and locks. 3-node durable event bus for inter-service messaging.
Multi-node search cluster with role separation dedicated masters, data, and coordinating nodes.
Operate everywhere your customers are without sacrificing data sovereignty or losing a beat when the link drops. Each edge runs autonomously, keeps sensitive data on-shore, and stays in lockstep with central command.
Rules · Playbooks · Agents · Connectors
That’s the point. Imperum’s agents handle triage, investigation, and routine resolution across every tenant, so each new customer adds cases, not headcount. The same architecture serves one customer or thirty; onboarding a tenant is a provisioning step, not a new deployment. Your analysts work the exceptions and escalations across your whole book of business, from one console.
Isolation is enforced at every layer, not bolted on. You choose the boundary: row-level scoping (default), a schema per tenant, or a full database per tenant for your most regulated customers. Connectors, AI agents, graph data, and MCP tool catalogues are all scoped per tenant, and document-level security means one customer’s analysts physically cannot query another customer’s data, even within a shared index. Every action is tenant-attributed and audited.
Yes: one console, every customer. Analysts switch customer context from a tenant selector, and each context carries its own connectors, AI agents, data, and scope with no deployment change. Cases are tagged by tenant so an analyst always knows whose incident they’re looking at, and KPIs roll up across your whole managed estate.
Yes. The Self-Service Portal gives each customer a view of their own cases, SLAs, and approvals. No login to your central console, and no exposure to any other customer. For a live incident that needs their CISO or an external IR firm, a time-bounded War Room link brings them into that one case only, then expires automatically.
The distributed / edge topology puts a remote instance in each geography, ingesting locally for data sovereignty, forwarding only what’s needed over mTLS, and operating offline with a store-and-forward queue that resyncs when the link returns. For a branch that just needs local ingestion, a lightweight proxy agent fronts the central cluster.
Yes. In API-only mode, your stack calls Imperum through the public API: the agents do the triage, investigation, and IR work and return results into your existing SOAR or ticketing, with no Imperum console surfaced to the customer. The same tenant isolation, RBAC, and audit guarantees apply.
Talk to our team about deploying Imperum on-prem, in your cloud, or air-gapped with the agent library, MCP integrations, and governance your auditors already trust.
