Detection and autonomous ransomware isolation that continue when the cloud link drops. An endpoint agent backed by cloud analytics on a columnar lakehouse. Per-tenant isolation.
Four pressures that shape security architecture and operating cost.
Per-GB pricing makes security spend rise with telemetry volume. Edg3 plans are priced by endpoint tier instead.
Remote, segmented and disrupted networks cannot assume a continuous cloud path. Deterministic controls must keep operating locally.
Regulated teams need clear retention policies, regional deployment choices and evidence they can inspect.
Deterministic detection and isolation run at the edge; contextual investigation runs through the tenant’s configured cloud services.
Six architectural layers. Two of them reshape the market. The other four make sure the promise holds.
The moving parts behind the platform. Built for operators, inspectable by architects.
Proprietary columnar lakehouse with localised NVMe flash and cloud object-storage sync.
Curated Detection-as-Code rules with version control and ATT&CK context.
High-throughput message streaming with at-least-once delivery guarantees.
Reusable security queries over the columnar hot tier and Parquet history.
First Seen context and tenant-scoped investigations with cited evidence and a configurable inference provider.
Event-driven SOAR workflows following Infrastructure-as-Code principles.
Automated provisioning with IaC templates, SSL automation and agent distribution.
Dedicated tenant instances, scoped agent messaging, RBAC and configurable enterprise SSO.
Availability varies by edition, tenant configuration and deployment stage. Core ingestion, detection and investigation share one platform.
Centralised collection, normalisation and long-term retention on an open Parquet lakehouse in your isolated cloud tenant.
Curated rules are git-managed, diffable and auditable, with MITRE ATT&CK context where mapped.
Structured investigation proposals with cited context, confidence and deterministic gates.
Local ransomware isolation with a safety deadman; other actions remain approval-gated.
Investigation history, evidence collection and exportable reports for review.
Threat-feed ingestion with enrichment and cross-source correlation.
Supported agent hosts keep deterministic controls and buffering during link interruption. A fully self-hosted, air-gapped platform is on the roadmap. Roadmap · Q4 2026
AWS posture assessment for configured tenants, with additional providers introduced through validated integrations.
SAML, OIDC and tenant roles, configured for the selected identity provider and edition.
Provider-enabled integrations for cloud, identity, SaaS and operations data.
Edg3 separates deterministic endpoint controls from cloud analytics. Availability is stated explicitly where configuration or rollout stage matters.
| Capability | Edge agent | Edg3 cloud | Availability |
|---|---|---|---|
| Deterministic detection | Local | Enriched | Available |
| Ransomware isolation + safety deadman | Local | Controlled | Available |
| Native Windows, Linux and macOS telemetry | Collected | Analysed | Current agent |
| Investigations with cited evidence | Evidence | Reasoning | Tenant configuration |
| AWS CloudTrail analytics | N/A | Analysed | New deployments + AWS setup |
| MSSP control plane | Per tenant | Multi-tenant | Available by invitation |
| Fully self-hosted, air-gapped platform | Agent ready | Not current | Roadmap · Q4 2026 |
Four product layers, built to be inspectable by the people whose job depends on trusting them.
Maritime, defence, mining, utilities, manufacturing.
Regional banks, credit unions and insurers with defined retention and evidence requirements.
Hospital networks and supported endpoint fleets with strict access and evidence needs.
Teams that require tenant isolation, controlled access and auditable operational workflows.
Invitation-only portfolio views with isolated customer data paths and scoped operations.
A fully self-hosted, air-gapped deployment with sovereign feeds and keys, for estates that cannot touch a public cloud.
A multi-tenant control plane with isolated customer data paths, currently available through a guided partner engagement.
Partners can move from a customer fleet view into the selected tenant while keeping customer telemetry paths separated.
Each customer runs in an isolated tenant. The partner surface receives bounded summaries and queue records rather than pooled raw telemetry.
Price customers on endpoints, not GB. Kill the per-GB margin compression that eats MSSP books.
Partner branding, reports, delegated administration and RBAC are configured during the guided engagement.
The agent deploys into remote and segmented networks today; a fully air-gapped, self-hosted platform remains on the roadmap. Air-gapped · Q4 2026
Edg3 hosts the control plane while the partner keeps the customer relationship and operating model.
Integrations are enabled and scoped per tenant. Availability depends on the provider, edition and required customer configuration.
Edg3 maps evaluated checks to relevant framework controls. Unassessed controls remain visible and unscored rather than being reported as passed.
Scoring is based on checks that actually ran; coverage gaps remain visible.
Policy packs cover supported Windows, Ubuntu and macOS security settings.
Check results preserve the observed state and evaluation time for review.
Compliance views and exports support evidence gathering; they do not replace an external audit or certification.
Annual rates below are shown as an effective monthly price. Self-service checkout is temporarily paused; contact Sales for current availability.
One signed agent, a per-tenant cloud analytics plane and guided onboarding. Detection begins with the first supported event.
Ask Sales about the 150-endpoint Starter edition and current onboarding availability.
30 minutes with the product team. We’ll walk the relevant current surfaces and availability against your use case.
Enterprise Plus and invitation-only MSSP engagements. Tailored quoting and architecture review.