AI Security Operations · Microsoft-Native

AI Security Operations for the Microsoft Cloud

The model reads the evidence. The verdict is math.

Knows your environment. Judges every alert against what's normal. Surfaces the posture gaps that matter — and shows its work.

Project

LEgion

AI Security Engine

80–90%

alerts auto-resolved with cited evidence

5 min

detection cadence on the live tree

24/7

multi-tenant autonomous coverage

<10%

reach a human — only the ambiguous ones

Every alert. Same pipeline.

Live today

1
Detect · evidence
Correlation rule fired
An OAuth token was replayed from a new ASN minutes after a clean sign-in.
08:42:01
2
Investigate · evidence
7 signals gathered
Sign-in logs, device state, mailbox rules and file activity pulled across Entra, XDR and Cloud Apps.
08:42:03
3
god's Eye · memory
Reputation checked
Device never seen on the fleet · IP has no clean history · a new inbox-forwarding rule is flagged hostile.
08:42:05
4
LLM · scores evidence
Per-signal scoring → axes
Each signal graded against the taxonomy; code computes Threat 92 · Detection 95 · Maliciousness 88.
08:42:06
5
Code · verdict
Matrix → CONFIRMED_MALICIOUS
Deterministic, cited from 7 signals. No model text reaches the decision.
08:42:07

Roadmap — not yet live

6
LLM · advisory
Action will be proposed
The model recommends a response — revoke sessions, disable the account, remove the attacker's inbox rule. It only ever recommends. It never executes.
7
Code · law / policy gate
Every action evaluated against policy
The gate is built and logging real decisions in production today. It returns one of four states — PERMIT, REQUIRE_APPROVAL, DENY, BLIND — judging the properties of an action (reversibility, blast radius, privilege scope), not its name. Today it authorizes auto-close only.
8
Execute · authorized
Containment, once earned
Autonomy is earned per action type, per tenant — unlocked only after accumulated human-approved precedents in the gate ledger. Not a toggle. Not configured. Earned.
9
Audit · evidence
Logged & reconstructable
The full signal array, verdict and gate decision are written to an immutable trail today. Executed actions join that trail when the executor ships.
Autonomy is earned, not configured. Detection through verdict runs autonomously today, with every decision cited and reconstructable. Action authority unlocks per action type only after earned precedent — recorded in an immutable gate ledger.

Engine Verdict

Engine Verdict
CONFIRMED MALICIOUS
Severity: Critical · cited from 7 signals
Confidence96%
Time to verdictunder 10 sec
A human analyst~30 min
Held for human review1 step

Reads the whole Microsoft stack — no new agent

Sentinel
Defender XDR
Defender for Cloud Apps
Purview
Intune
Entra ID

Deploy

AI Security Operations you can put under audit.

Fast enough to clear the queue. Defensible enough to defend in front of a regulator. Multi-tenant from day one, live across MSP clients today.

Read the system brief