Threat verdicts you can prove
Why every score is explainable and reproducible — and why we won't let the AI pull the trigger.
A threat score you can't explain is a liability, not intelligence. When leadership asks why an indicator is critical, or an auditor asks how a decision was reached, "the tool said so" is not an answer. If you can't see why a verdict is what it is, you can't defend it — and you can't catch it when it's wrong.
The market has split into two camps, and neither solves this. Older platforms give you mountains of data and a score that arrives with little explanation. The newer wave of AI tools investigate well, but their verdict is a model's judgment — run it twice and the reasoning reads differently each time. One is opaque. The other isn't reproducible. For a decision your team is accountable for, both are a problem.
We take a different position: use AI where it is trustworthy, and not where it isn't. The agent does the research a good analyst would — it gathers the sources, reads them, pulls out the indicators, and shows its work. But the verdict itself is derived the same way every time. AI does the legwork. The decision is something you can inspect.
That means a verdict is reproducible by design. The same evidence produces the same result, and you can look at a past verdict and see exactly what drove it — which sources reported the indicator, how much each was trusted, and where they agreed. Reproducibility is what turns a score into something you can stand behind in a review, a report, or a courtroom.
It also means we don't pull the trigger for you. We surface the decision with the evidence and our confidence attached, and we stop there. We don't auto-block. A false block at 3am is its own incident, and the enforcement call — along with the accountability that comes with it — belongs to your team, not to a model.
This is built for people who have to defend their decisions: regulated industries, incident responders, and anyone who has ever been asked to prove that an alert was real. The bar for a threat verdict should be the same as the bar for evidence. You should be able to see where it came from, and you should be able to reproduce it.
- Every verdict shows the evidence behind it, weighted by source and recency.
- The same evidence produces the same verdict — reproducible, not a guess that changes each run.
- We alert on our decision; whether to enforce stays your call.