Imperum
Autonomous SOC
Company
News
For Managed Security Service Providers

One console.
Every customer.

Onboard more customers without hiring more analysts. Imperum's AI SOC triages, investigates, and responds across every tenant so your team scales margin, not alert volume.

Multi-Tenant Isolation 24/7 Human + AI Roster One Pane, Every Tenant
mssp/tenant-fleet · liveLIVE
SOC · EU-WEST
GLOBAL SIGNAL MAP
42,499 signals · last 60s
14 regions · 600+ collectors147 tenants · isolated
● LIVETenant signals
Virtus AI · cross-tenant
TRIAGEVirtus Triage · verdict: escalate (conf 0.92)t/tenant-01 · CASE-2025-AUTO-04812
PILOTVirtus Pilot · phase 5/8 · plan executedt/tenant-02 · run #14117
KAGKAG merged 4-hop graph context · 28 entitiest/tenant-03 · CASE-…04795
MODUSModus rule fired: severity≥high → auto-caset/tenant-01 · 12 alerts grouped
PLAYBOOKPlaybook contain-ransomware · isolated 4 hostst/tenant-02 · auto/run#9812
Unified Dashboard

Every customer's SOC, in one live view.

Run every customer's SOC from a single pane. Aggregated KPIs, live AI triage activity, and per-tenant drill-down with a Virtus Assistant scoped to the data each tenant is allowed to see.

MSSP Unified Dashboard· 12 tenants
TenantsTelemetryConnectorsSLAs
tenant-alpha
EPS 2.4kCases 12
tenant-bravo
EPS 5.1kCases 9
tenant-charlie
EPS 8.2kCases 24
tenant-delta
EPS 1.8kCases 3
tenant-echo
EPS 3.6kCases 7
tenant-foxtrot
EPS 6.4kCases 15
tenant-golf
EPS 950Cases 4
tenant-hotel
EPS 4.2kCases 11
tenant-alpha
EPS 2.4kCases 12
tenant-bravo
EPS 5.1kCases 9
tenant-charlie
EPS 8.2kCases 24
tenant-delta
EPS 1.8kCases 3
tenant-echo
EPS 3.6kCases 7
tenant-foxtrot
EPS 6.4kCases 15
tenant-golf
EPS 950Cases 4
tenant-hotel
EPS 4.2kCases 11
+4
+4
Total Alerts (24h)
184k
aggregated · all tenants
MTTR · avg
4.6m
weighted across tenants
FPR · avg
13%
weighted across tenants
Auto Rate
82%
platform-wide
Tenants Healthy
12 / 12
health summary
AI Activity · live
tenant-bravo· Triaged: Script execescalated
tenant-foxtrot· Triaged: Login anomalyneeds human
tenant-alpha· Triaged: Phishing URLauto-closed
tenant-delta· Pilot: 8-phase investigationcompleted
Virtus Assistant
Show all critical cases across tenants this week
23 critical · 4 tenants affected
top: tenant-bravo (9), tenant-foxtrot (7).
Open list?
Tools · RAG · KAG · Veil · per-tenant scope
Aggregated, weighted

Total alerts, MTTR, FPR, automation rate rolled up across every managed tenant with proper weighting.

Live AI activity

Every Virtus Triage and Pilot decision streams in with its tenant tag, verdict, and confidence full audit trail in the background.

Per-tenant scope on the Assistant

The Virtus Assistant respects the operator's tenant scope; cross-tenant queries surface only what RBAC permits.

24/7 cover
AM
a.morgan
L1
KS
k.silva
L2
MO
m.okafor
L3
LF
l.fischer
IR
0006121824
VT
Triage
Triage
VE
Enricher
Enrichment
VH
Hunter
Hunting
VR
Responder
Response
08:00–20:00 humans·20:00–08:00 Virtus AI agents
1229
alert triage
978
enriched
206
contained
5
woke an analyst
Last night, across all tenants
Roster

Human by day, Virtus AI Agent by night

Around-the-clock coverage without around-the-clock headcount. Human analysts run the day shift. Virtus AI agents run the night shift under risk policy and approval gates escalating to a human only when policy requires.

Day shift

Four humans on duty 08:00–20:00. Skill-matched, RBAC-aware, escalation-chain ready.

Night shift

Four Virtus AI agents (Enricher · Hunter · Responder · Triage) on duty 20:00–08:00. Risk-policy-gated, full audit trail, Veil PII redaction on every LLM call.

Handover

Cases triaged overnight surface in the day team's queue at 08:00 with Virtus's verdict, narrative, and recommended actions attached.

Self-Service Portal

A dedicated front door for every tenant.

Customer-facing portal for phishing report, access request, open case, view case status, and report download branded per tenant, SSO-gated, rate-limited.

Per-tenant brandingSSO-gatedRate-limitedReports
Customer Portal
Report a phishing email

Forward .eml or paste headers · auto-investigation

Request access

Approval-gated, time-bounded, audit-logged

Open a case · CASE-2026-AUTO-00482

Status: investigation · SLA: healthy

VPN Profile

Managed secure access, end to end.

Give every operator and agent a secure path in without the operational burden. Short-lived certificates, automatic rotation, instant revocation, and policy-enforced egress, all managed from one console.

Operator

SSO + MFA

VPN Profile

Short-lived cert

Tenant Edge

mTLS · Egress policy

Modern cipher suitesAuto-rotationRevocationBreak-glassEgress policy
High Availability

Cluster-grade resilience, by default.

Stay online when it matters most. Every layer database, cache, message bus, search, and API runs in a multi-node cluster with automatic failover, zero-data-loss replication, and no single point of failure.

Database

Clustered Database

3-node cluster with synchronous replication, automatic leader election, and zero-data-loss failover.

node-01LEADER
node-02SYNC
node-03SYNC
Cache + Bus

Cache · Event Bus

3-node distributed cache for sessions and locks. 3-node durable event bus for inter-service messaging.

cache-01MASTER
cache-02REPLICA
bus-01QUORUM
Search

Search Cluster

Multi-node search cluster with role separation dedicated masters, data, and coordinating nodes.

search-master3 nodes
search-dataN nodes
search-coord2 nodes
Remote Instances

Central command. Sovereign edges.

Operate everywhere your customers are without sacrificing data sovereignty or losing a beat when the link drops. Each edge runs autonomously, keeps sensitive data on-shore, and stays in lockstep with central command.

Edge EU-West
Local ingest · 12k EPS
Edge APAC
Offline · S&F: 4.2GB
Edge Air-gap
Manual sync · daily

Central Imperum

Rules · Playbooks · Agents · Connectors

Edge US-East
mTLS · 28k EPS
Edge LATAM
mTLS · 8k EPS
Edge MEA
mTLS · 15k EPS
FAQ

Frequently asked questions

That’s the point. Imperum’s agents handle triage, investigation, and routine resolution across every tenant, so each new customer adds cases, not headcount. The same architecture serves one customer or thirty; onboarding a tenant is a provisioning step, not a new deployment. Your analysts work the exceptions and escalations across your whole book of business, from one console.

Isolation is enforced at every layer, not bolted on. You choose the boundary: row-level scoping (default), a schema per tenant, or a full database per tenant for your most regulated customers. Connectors, AI agents, graph data, and MCP tool catalogues are all scoped per tenant, and document-level security means one customer’s analysts physically cannot query another customer’s data, even within a shared index. Every action is tenant-attributed and audited.

Yes: one console, every customer. Analysts switch customer context from a tenant selector, and each context carries its own connectors, AI agents, data, and scope with no deployment change. Cases are tagged by tenant so an analyst always knows whose incident they’re looking at, and KPIs roll up across your whole managed estate.

Yes. The Self-Service Portal gives each customer a view of their own cases, SLAs, and approvals. No login to your central console, and no exposure to any other customer. For a live incident that needs their CISO or an external IR firm, a time-bounded War Room link brings them into that one case only, then expires automatically.

The distributed / edge topology puts a remote instance in each geography, ingesting locally for data sovereignty, forwarding only what’s needed over mTLS, and operating offline with a store-and-forward queue that resyncs when the link returns. For a branch that just needs local ingestion, a lightweight proxy agent fronts the central cluster.

Yes. In API-only mode, your stack calls Imperum through the public API: the agents do the triage, investigation, and IR work and return results into your existing SOAR or ticketing, with no Imperum console surfaced to the customer. The same tenant isolation, RBAC, and audit guarantees apply.

Get started

Ready to build your autonomous SOC?

Talk to our team about deploying Imperum on-prem, in your cloud, or air-gapped with the agent library, MCP integrations, and governance your auditors already trust.

Made with a lot of cheese in the Netherlands