The Security Lakehouse.

Detection and autonomous ransomware isolation that continue when the cloud link drops. An endpoint agent backed by cloud analytics on a columnar lakehouse. Per-tenant isolation.

Edge-Resilient  ·  Cloud-Backed  ·  Outcome-Led
The Problem

Cloud-only SIEM is breaking.

Four pressures that shape security architecture and operating cost.

Ingestion Inflation
Volume tax

Log spend is outrunning risk.

Per-GB pricing makes security spend rise with telemetry volume. Edg3 plans are priced by endpoint tier instead.

Cloud-Tethered Detection
Blinded SOCs

Severing the telemetry link is the first move.

Remote, segmented and disrupted networks cannot assume a continuous cloud path. Deterministic controls must keep operating locally.

Sovereign & Regulated
Retention + region

Retention and residency need control.

Regulated teams need clear retention policies, regional deployment choices and evidence they can inspect.

Agentic Inflection
Edge + AI

Use the right authority plane.

Deterministic detection and isolation run at the edge; contextual investigation runs through the tenant’s configured cloud services.

The Platform

Edge-resident SIEM on a columnar lakehouse.

Six architectural layers. Two of them reshape the market. The other four make sure the promise holds.

Endpoint Agent
Deterministic detection and autonomous ransomware isolation run in the endpoint agent. No LLM or cloud round trip is required for the local isolation decision.
Endpoint agent
Linux x64 · Win x64 · macOS arm64
Columnar Query Engine
Interactive investigations run against open-format Parquet data in your isolated Edg3 cloud tenant. Retention depends on the selected edition.
Cloud lakehouse
NVMe hot tier · Parquet
Detection-as-Code
A curated rule library that is forkable, diffable and auditable in git, with MITRE ATT&CK context where mapped.
Curated rules
git · ATT&CK context
Agentic Triage
The investigation service produces cited evidence, ATT&CK context and confidence through the provider configured for that tenant.
Cloud inference
Tenant-scoped context
Autonomous SOAR
Ransomware can trigger local host isolation. Non-ransomware actions are approval-gated and depend on configured integrations.
Ransomware auto-contain
Human-gated elsewhere
Cloud Lakehouse
Open-format Parquet storage in your isolated cloud tenant. Edg3 plans do not charge a per-GB ingestion fee.
Per-tenant
Parquet · open format
Technology Summary

Eight pillars. One platform.

The moving parts behind the platform. Built for operators, inspectable by architects.

Architecture

Proprietary columnar lakehouse with localised NVMe flash and cloud object-storage sync.

Detection

Curated Detection-as-Code rules with version control and ATT&CK context.

Data Pipeline

High-throughput message streaming with at-least-once delivery guarantees.

Query Engine

Reusable security queries over the columnar hot tier and Parquet history.

AI / ML

First Seen context and tenant-scoped investigations with cited evidence and a configurable inference provider.

Orchestration

Event-driven SOAR workflows following Infrastructure-as-Code principles.

Deployment

Automated provisioning with IaC templates, SSL automation and agent distribution.

Security

Dedicated tenant instances, scoped agent messaging, RBAC and configurable enterprise SSO.

Core Capabilities

Ten capabilities. One platform.

Availability varies by edition, tenant configuration and deployment stage. Core ingestion, detection and investigation share one platform.

01

SIEM & Log Management

Centralised collection, normalisation and long-term retention on an open Parquet lakehouse in your isolated cloud tenant.

02

Detection-as-Code

Curated rules are git-managed, diffable and auditable, with MITRE ATT&CK context where mapped.

03

Agentic Triage

Structured investigation proposals with cited context, confidence and deterministic gates.

04

Autonomous Response

Local ransomware isolation with a safety deadman; other actions remain approval-gated.

05

Forensics & Evidence

Investigation history, evidence collection and exportable reports for review.

06

Threat Intelligence

Threat-feed ingestion with enrichment and cross-source correlation.

07

Segmented Estates

Supported agent hosts keep deterministic controls and buffering during link interruption. A fully self-hosted, air-gapped platform is on the roadmap. Roadmap · Q4 2026

08

Cloud Security Posture

AWS posture assessment for configured tenants, with additional providers introduced through validated integrations.

09

Enterprise SSO & RBAC

SAML, OIDC and tenant roles, configured for the selected identity provider and edition.

10

Cloud Integrations

Provider-enabled integrations for cloud, identity, SaaS and operations data.

Deployment Model

What runs where. What is available now.

Edg3 separates deterministic endpoint controls from cloud analytics. Availability is stated explicitly where configuration or rollout stage matters.

Capability Edge agent Edg3 cloud Availability
Deterministic detectionLocalEnrichedAvailable
Ransomware isolation + safety deadmanLocalControlledAvailable
Native Windows, Linux and macOS telemetryCollectedAnalysedCurrent agent
Investigations with cited evidenceEvidenceReasoningTenant configuration
AWS CloudTrail analyticsN/AAnalysedNew deployments + AWS setup
MSSP control planePer tenantMulti-tenantAvailable by invitation
Fully self-hosted, air-gapped platformAgent readyNot currentRoadmap · Q4 2026
Under the Hood

Detection. Reasoning. Response. Evidence.

Four product layers, built to be inspectable by the people whose job depends on trusting them.

Detection Engine

Detection-as-code, enriched in the cloud.

  • Curated rules evaluated against endpoint, network, identity and cloud telemetry
  • MITRE ATT&CK context included where a rule has a validated mapping
  • Rules are code: forkable, diffable, auditable in git
  • Columnar Parquet lakehouse in your isolated cloud tenant
  • Cross-source correlation: logs + endpoint + network + cloud
  • Custom rules follow the version-controlled bundle and deployment path
Agentic Triage

An AI analyst that shows its work.

  • Security-focused reasoning in the Edg3 cloud, scoped to the tenant
  • Investigations preserve cited evidence, ATT&CK context and confidence
  • Analyst decisions are retained in append-only investigation history
  • Provider and model availability can vary by tenant configuration
example    Illustrative investigation output
verdict    CONFIRMED MALICIOUS  ·  95% confidence
technique  T1055.012 · Process Hollowing
evidence   explorer.exe → unsigned memory region
outbound   C2 IP matched TAG-RUBY
blast radius 4 endpoints, same tenant, 5 min
Deep dive: the AI analyst
Autonomous Response

Fast on ransomware. Gated on everything else.

  • Autonomous: ransomware containment only
  • Host network isolation runs locally when its detection policy fires
  • An isolation safety deadman restores connectivity if the control channel remains unavailable
  • Human-gated: every other response class
  • Approved response workflows can disable accounts, add network blocks and coordinate endpoint actions
  • Response actions and approval decisions are recorded for review
  • Playbooks as code: YAML-defined and version-controlled, with approval gates for non-ransomware actions.
Deep dive: the endpoint agent
Forensics & Outcomes

Evidence built for investigation and review.

  • Plan-based retention policies, with the active history searchable in the platform.
  • Append-only investigation history records evidence and analyst decisions.
  • Per-tenant storage and keys. Open Parquet in your isolated cloud tenant.
  • Evidence collection: selected workflows collect and time-stamp incident artefacts for a case.
  • Outcome-led reporting: investigation status and response outcomes remain attached to the case.
  • Case exports and reports support downstream review; available formats depend on the workflow.
  • Open format (Parquet + OCSF). Consumable without re-ingest.
Deep dive: risk & outcomes
Vertical Strongholds

Built for estates that cannot rely on a continuous cloud link.

Operational Technology

Maritime, defence, mining, utilities, manufacturing.

Regulated Finance

Regional banks, credit unions and insurers with defined retention and evidence requirements.

Healthcare

Hospital networks and supported endpoint fleets with strict access and evidence needs.

Government

Teams that require tenant isolation, controlled access and auditable operational workflows.

MSSP & MDR Partners

Invitation-only portfolio views with isolated customer data paths and scoped operations.

Sovereign & Air-Gapped Roadmap · Q4 2026

A fully self-hosted, air-gapped deployment with sovereign feeds and keys, for estates that cannot touch a public cloud.

MSSP & Multi-Tenant Available by invitation

Native MSSP economics, not a bolt-on.

A multi-tenant control plane with isolated customer data paths, currently available through a guided partner engagement.

Multi

Customers, one console

Partners can move from a customer fleet view into the selected tenant while keeping customer telemetry paths separated.

Zero

Shared storage

Each customer runs in an isolated tenant. The partner surface receives bounded summaries and queue records rather than pooled raw telemetry.

Flat

Per-endpoint economics

Price customers on endpoints, not GB. Kill the per-GB margin compression that eats MSSP books.

White-label

Console & reports

Partner branding, reports, delegated administration and RBAC are configured during the guided engagement.

Reach

Segmented and remote estates

The agent deploys into remote and segmented networks today; a fully air-gapped, self-hosted platform remains on the roadmap. Air-gapped · Q4 2026

Hosted

No infrastructure to run

Edg3 hosts the control plane while the partner keeps the customer relationship and operating model.

Deep dive: MSSP & multi-tenant
Integrations

Named integrations for the systems you run.

Integrations are enabled and scoped per tenant. Availability depends on the provider, edition and required customer configuration.

Cloud & IaaS

  • AWS CloudTrail for configured accounts
  • AWS Security Lake, provider-enabled
  • Snowflake OCSF, provider-enabled
  • Cloud posture checks for configured tenants

Endpoint & Network

  • Native Windows event collection
  • Linux eBPF process telemetry
  • macOS endpoint telemetry
  • Suricata and Syslog / CEF inputs

Identity

  • Active Directory identity inventory
  • Windows SAM and Linux local accounts
  • Entra, Okta, Duo and 1Password ingestion
  • SAML / OIDC SSO where configured

Operations

  • Slack approvals and notifications
  • Scheduled email reports
  • Tenant-scoped orchestration workflows
  • API-based export and automation

Cloud & SaaS Telemetry

  • Microsoft 365 and Entra
  • GitHub audit activity
  • AWS account telemetry
  • Provider-specific collectors where enabled

Open Data Paths

  • OCSF-normalised cloud events
  • Open Parquet storage
  • Syslog / CEF ingestion
  • Scanner uploads and API inputs
Compliance

Coverage-aware compliance evidence.

Edg3 maps evaluated checks to relevant framework controls. Unassessed controls remain visible and unscored rather than being reported as passed.

CIS Benchmarks NIST 800-53 SOC 2 TSC HIPAA 164.312 PCI DSS

Evaluated controls

Scoring is based on checks that actually ran; coverage gaps remain visible.

Platform-specific checks

Policy packs cover supported Windows, Ubuntu and macOS security settings.

Time-stamped evidence

Check results preserve the observed state and evaluation time for review.

Reports and exports

Compliance views and exports support evidence gathering; they do not replace an external audit or certification.

Editions

Simple, transparent pricing. Flat per-plan.

Annual rates below are shown as an effective monthly price. Self-service checkout is temporarily paused; contact Sales for current availability.

Annual Prices shown are billed annually. Month-to-month rates are $579 Starter, $1,149 Professional and $2,299 Enterprise.
Starter
$479/mo effective
Up to 150 endpoints
Billed annually $5,748/yr
  • 6-month cloud retention
  • Curated Detection-as-Code rules
  • Reusable security queries
  • Guided response workflows
  • Coverage-aware compliance views
  • Vulnerability intelligence
Contact Sales
Professional
$949/mo effective
Up to 500 endpoints
Billed annually $11,388/yr
  • 1-year cloud retention
  • Everything in Starter
  • SOAR workflows
Contact Sales
Enterprise Plus+
ContactSales
Unlimited endpoints
Tailored solution
  • 7+ years retention
  • Multi-site fleet management
  • Edge Extenders
  • SOAR automation
  • Air-gap & sovereign Q4 2026
  • Dedicated TAM
Talk to Sales
Annual pricing shown · Month-to-month available · No per-GB ingestion fees · Contact Sales for availability
Get Started

See Edg3 in your SOC.

One signed agent, a per-tenant cloud analytics plane and guided onboarding. Detection begins with the first supported event.

Starter Enquiry

Ask Sales about the 150-endpoint Starter edition and current onboarding availability.

Contact Sales

Book a Demo

30 minutes with the product team. We’ll walk the relevant current surfaces and availability against your use case.

edg3.io/demo

Talk to Sales

Enterprise Plus and invitation-only MSSP engagements. Tailored quoting and architecture review.

sales@edg3.io