AI Security Operations · Microsoft-Native
AI Security Operations for the Microsoft Cloud
The model reads the evidence. The verdict is math.
Knows your environment. Judges every alert against what's normal. Surfaces the posture gaps that matter — and shows its work.
Security teams are drowning in their own alarms.
Detection got cheap. Investigation didn't. Every tool ships more alerts than any team can read, and nearly half lead nowhere — so the real attack waits in a queue no one finishes. This is the gap every breach walks through.
The model proposes. The code decides — and the code acts.
Every competitor lets a language model reason its way to a conclusion, then act on it. That's fast — and unauditable. When a regulator, a client, or a courtroom asks why an alert was closed or an account was disabled, "the model decided" is not an answer. Legion splits the engine into two deterministic stages, and the model is shut out of both decisions.
LLMWhat the model does
- Reads each signal against a fixed evidence taxonomy
- Scores it: which axis, which direction, how much weight
- Grounds every signal to a real Microsoft source field
- Explains its reasoning, one sentence per signal
CODEWhat only the code does
- Computes four independent axes from the scored evidence
- Resolves the verdict from a deterministic matrix
- Rejects any verdict that can't cite its evidence
- Never lets model text become the decision
The highlighted cell is the password spray from the demo above: high threat, ambiguous intent. Code routes it to a human instead of forcing a call. Every weight feeding it is logged — a verdict you can't reconstruct is one you can't defend.
A verdict on its own changes nothing. The dangerous part of any autonomous SOC is what it does — disable an account, revoke a session, quarantine a host, or simply close the ticket. So the action stage gets the same treatment as the verdict: the model may propose, but a deterministic policy gate decides whether anything runs.
Two engines. One brain above them, one gate below them.
Legion isn't a single triage tool. It's an autonomous security operation: one engine that responds to attacks in flight, one that closes the gaps that let them in — and both share the same two pieces of infrastructure. Above them, god's Eye supplies graded evidence and known-good baselines. Below them, the Law / Policy Gate authorizes every action. The reactive engine is live today; the proactive engine is the expansion that roughly doubles the surface Legion owns.
The autonomous analyst. It detects an alert, investigates it, scores the evidence, and computes a cited verdict — then recommends the action and routes it for response. This is the beachhead, and it's running against live clients today.
Goal-driven hardening. It takes the org's intent — Secure Score, HIPAA, CMMC — reads the actual state of the tenant, finds the gaps, and proposes graded fixes through the same safety gate. Report-only first. This turns Legion from incident response into continuous prevention.
One reputation brain feeds both engines: graded evidence into the reactive verdict, and a known-good baseline into the proactive engine. It deepens with every tenant and every day, and it cuts both ways — vouching for what it trusts, flagging what it has learned to distrust. Detailed in the next section.
The brain that sits between both engines — and compounds.
Most AI-SOC tools have no memory: every alert is judged cold. god's Eye is Legion's institutional memory — a reputation engine that remembers every entity it has ever seen across every tenant, and grades how far to trust it. It never decides a verdict and never closes a ticket; it produces graded, cited evidence and hands it to the deterministic engine. But because it feeds both the reactive and proactive engines, it's the one component that makes the whole platform smarter over time.
Auto-close that survives an audit
god's Eye supplies a graded trust signal on every entity — vouching for known-good software and devices, flagging what keeps appearing next to trouble. Fewer false escalations, and an auto-close you can defend with cited history.
One shared memory
Evidence producer, never an authority. Grounds both engines from the same earned history.
A baseline the proactive engine can act on
god's Eye holds the pre-compromise known-good baseline. The proactive engine diffs current state against it to scope remediation precisely — and a confirmed incident re-anchors the baseline so cleanup doesn't absorb the attacker's changes as "normal."
Reputation that can't be spoofed
Reputation strength scales with how unspoofable the match is. A name-only match earns a little; a verified code signature seen across the fleet over months of clean history earns a lot — because an impostor can't fake the signature, the fleet-wide prevalence, and the clean record all at once.
The moat compounds with every tenant
Confidence ramps as clean history accrues — every tenant-day makes the brain sharper. A better-funded latecomer can copy the code, but not the earned memory across a fleet of live environments. The moat is the history, and the history compounds.
Cuts both ways
Reputation isn't one-directional. An entity that keeps surfacing next to suspicious behaviour sees its trust shrink and then flip into a flag. Good standing is earned and revocable — the same mechanism that suppresses noise also catches the thing that learned to look normal.
Not a demo. The reactive engine is in production.
The first of the three layers — detection to cited verdict — is live across multiple production MSP tenants on different Microsoft licensing tiers. It runs on a five-minute cadence against real client environments. The deployment gate is a passing test suite, not a slide.
Multi-tenant from day one
One engine serves several live MSP clients in parallel, each isolated, each on its own Microsoft tier. Built for the channel, not a single in-house SOC.
Sits on the Microsoft stack
Reads Sentinel, Defender XDR, Defender for Cloud Apps, Purview, Intune and Entra directly. No rip-and-replace, no new agent to deploy.
Every five minutes
Core detection queries run continuously off the live tree. Saving a validated change deploys it next tick. The test suite is the safety rail.
Honest build state, not a wish. The proven reactive front is the asset today; the raise funds the memory wiring, the shared gate, and the proactive engine — exactly the layers that turn a triage tool into an autonomous platform.
It gets harder to copy the longer it runs.
Speed is table stakes in this category. Legion's edge is structural — and it compounds with every tenant and every day in production.
Auditability as a product
Deterministic, evidence-cited verdicts are a compliance asset for regulated clients — HIPAA, CMMC. "The model decided" doesn't pass an audit. A reconstructable verdict does. No incumbent is built this way.
MSP-native distribution
The incumbents sell to enterprises with in-house SOCs. Legion was built inside an MSP, for the MSP channel — the fastest path to the thousands of mid-market environments the funded players skipped.
Compounding memory
god's Eye is a data network effect: every tenant-day of clean history makes every verdict and every posture check sharper. That earned memory can't be bought off the shelf or backfilled by a better-funded latecomer.
A category the market has already bet on — at the enterprise end.
The spend is large and growing, the analyst shortage is structural, and capital is pouring in. The opening Legion takes is the segment the funded players skipped: the channel, and verdicts that survive an audit.
Why the timing is right
Investors have already validated the thesis at the high end: Dropzone AI has raised $57M and runs in 300+ enterprises; Prophet Security took a $30M Series A from Accel; TENEX.AI raised a $250M Series B. The demand is proven and the buyers are educated.
Every one of them sells autonomous triage to enterprises with their own analysts, and every one lets the model reach the conclusion. Legion's wedge is the part they left open: the MSP channel that protects the mid-market, and a verdict architecture built to be defended rather than trusted on faith — delivered by a team that reached production on a fraction of the capital.
The result: a production system reached on a fraction of the capital the funded category leaders have consumed.
AI Security Operations you can put under audit.
Project Legion is raising to harden the response layer, open the MSP channel, and turn the reputation engine into a moat no competitor can backfill. The data room — architecture, live deployment detail, and round terms — is available under NDA.
