Agentic SOC · built for MSSPs
Trikeph connects to the tools a SOC already runs, works each alert into a decision with the evidence attached, and acts only inside defined limits — with an analyst in the loop wherever it counts.
Three heads, one watch
The name says it: three heads on one watch. Each owns a stage of the work — see it, work it out, act on it — and together they carry an alert from the moment it lands to the moment it's closed.
Reads every signal the second it arrives, cuts the noise, and decides what deserves a real look — so nothing sits in a queue going stale.
Builds the case the way a senior analyst would — pulls the evidence, correlates across tools, and writes a verdict that reads clearly and holds up.
Closes it out inside the bounds it's given — contain, notify, ticket — and stops at the gate for a human on anything that carries weight.
Between them, the three heads cover the full SOC workload — from triage and detection, through investigation, hunting and forensics, to response, reporting and quality — as one continuous operation.
How it runs
Whether it lands from SIEM, EDR, or straight off the SOAR, every alert takes the same route: watched, worked, decided, and acted on where the mandate allows.
Reads from existing tools — no rip-and-replace.
Every signal triaged and put in context.
Evidence pulled and correlated across sources.
A verdict, with confidence weighed against the set limits.
Contained where allowed, gated where it counts.
Per-tenant log of every step and outcome.
One set of limits · one record · one path, kept apart tenant by tenant.
The Mandate Model
An agent that can act is only safe if what it can touch, how far it can go, and when it must stop are written down first. In Trikeph that's a mandate: four limits, operator-set and platform-enforced.
Only ever touches the tenant, data and tools its mandate names — nothing beyond.
No verdict without the evidence behind it. If it can't show its work, it doesn't act.
Anything it does can be stopped or undone. No one-way doors without a human.
Anything with weight waits for human approval — until the operator decides it no longer needs to.
Reversible at any point, set tenant by tenant, and never wider than the mandate allows.
What we solved first
Governed against MITRE ATLAS, the NIST AI RMF, the OWASP LLM risks, and the EU AI Act — because letting software act inside a client's environment is a promise that has to be kept.
An AI can state a firm conclusion that simply isn't true. Every Trikeph verdict is tied to the evidence behind it and scored for confidence — when the evidence is thin, it stops and asks instead of guessing.
An attacker can plant text inside an alert or log that tries to give the AI orders. Trikeph treats that content as evidence to examine — never as a command to obey.
Each client's data stays with that client. Trikeph reaches in to read only what a case needs, keeps nothing that isn't its to keep, and never pools data across clients.
An AI's accuracy can slip as the environment changes. Each agent's accuracy is tracked continuously, so a decline is caught early — not discovered during an incident.
Why an MSSP runs it
See it on real alerts
Trikeph runs against alerts like the ones a team sees every day — and shows the exact point where it stops and hands the call back to a human.