Eight stages from threat to verified outcome. One signature before anything changes.See the loop

Finding itisn't fixing it

StrikeSonic runs the loop from threat to verified outcome. Agents read your scanners, correlate to your estate, score the risk and draft the fix. A named person signs. Then a rescan proves it.

The loop

Threat to verified outcome, in eight stages

An agent runs every stage. A person owns the one that matters. Every stage writes to the same case file, so a finding, the decision it drove and the proof it worked stay one continuous story.

01 Observe

Agents read your scanners and the public feeds, and store what they found.

02 Understand

A vulnerability is matched to the assets that run it, and a case opens.

03 Assess

Findings rank by risk score, and each shows the multipliers behind it.

04 Decide

The agent drafts the call to take, its owner, and the evidence it cites.

05 Approve

Nothing changes until a named person signs that exact proposal.

06 Execute

Approved decisions are tracked through to the asset and the hour.

07 Measure

A rescan returns fixed, still vulnerable, or unverifiable. Never assumed.

08 Learn

Verified outcomes order the next run. They cannot change an urgency.

And back to 01

The next ingest carries the last outcome, so nothing is triaged twice.

The StrikeSonic console: the eight-stage loop from threat to verified outcome

Use cases

The questions a security team actually has to answer

Rank by what an exploit would actually reach.

Severity is one input of four, not the answer on its own.

Known-exploited findings carry the threat modifier. EPSS orders the work inside a band.

Entity resolution stops duplicate assets from double counting risk.

Why StrikeSonic

Most platforms stop at the list.

Detection tells you what is wrong. It does not decide, get a sign-off, make the change, or prove it worked. That half stays with your team, and it is the half StrikeSonic runs.

Without the loop

A prioritized list, and the real work starts after it

Severity ranking is not the same as business impact

A closed ticket is taken as proof the fix worked

AI that answers, with no record of what it read

With StrikeSonic

Eight stages from threat to verified outcome, in one case file

One published formula. Same inputs, same score, every run.

A rescan returns fixed, still vulnerable, or unverifiable

Every agent run cites the records behind it, under your tenant's row-level security

How it holds up

Rules built into the software, not into a policy document

One published formula

The agent explains and proposes. It never decides what is true. Scoring carries no learned weights, so the same inputs return the same number on every run.

99%
Precision

One workflow, not seven dashboards

A problem has one continuous story. Every stage writes to the same case timeline, and there is nowhere else to write. Context moves between tiers as it ages, from a hot in-memory cache to SSD to archived evidence.

In memory -> SSD -> Object storage

Graph
Index
Decision

Only measured results count

A rescan returns fixed, still vulnerable, or unverifiable. Only the first of those feeds learning, and the outcome is carried into the next investigation rather than re-derived.

Connected assets, alerts and decisions

Assets

Alerts

Decisions

There when your analysts are

Built to stay available, so the queue and the approval gate are there when your team is.

99.95% uptime

Agents

An agent at every stage, a signature before any change

The agent reads and drafts at every stage, and writes nowhere a person has not signed. It reads under your tenant's row-level security and cites what it read, so you check the reasoning rather than trust the verdict.

Risk
9 assets changed band in the last sync
Decisions
41 Decision Opportunities are open.

Every one has a single named owner.

41 OPEN
15 ESCALATE
Records Ingested
24.2k
Confidence
42 to 99

One graph, and every agent reads it

One graph per tenant. Risk and Decisions read the same nodes, so a fact corrected once is corrected everywhere. There is only one place to change it.

DEC-171
DECISION
Accept Risk: compensating control verified on bastion-01
Feb 26
Updated 2h
DEC-132
DECISION
Investigate: exposure change on prod-db-01 after CMDB sync
Feb 26
Updated 5h
DEC-182
DECISION
Escalate: KEV-listed remote code execution on edge-gw-02
Feb 26
Updated 8h
DEC-1
DECISION
Investigate: EPSS percentile rose above the review threshold
Feb 26
Updated 12h
DEC-170
DECISION
Accept Risk: asset offline, exposure multiplier set to one
Feb 26
Updated 20h
DEC-127
DECISION
Mitigate: restrict inbound access to api-gw-01 at the edge
Feb 26
Updated 1d
DEC-52
DECISION
Mitigate: segment mail-relay-02 pending vendor patch
Feb 26
Updated 2d
DEC-125
DECISION
Escalate: risk score 120 on prod-db-01, owner assigned
Feb 26
Updated 3d
DEC-98
DECISION
Remediate: apply vendor fix to k8s-node-04 in change window
Feb 25
Updated 4d

Decisions, not alert queues

Every decision the agent drafts carries one owner and one of five categories: Escalate, Investigate, Accept Risk, Mitigate, Remediate.

2026-02-26 03:00:11 UTC
INGEST
[NVD]
NVD sync complete, 1,284 CVE records written.
2026-02-26 03:00:48 UTC
ENRICH
[EPSS]
FIRST EPSS scores applied to 1,284 vulnerability records.
2026-02-26 03:01:02 UTC
INGEST
[KEV]
CISA KEV delivered through NVD, 41 entries flagged.
2026-02-26 03:15:26 UTC
INGEST
[CMDB]
ServiceNow CMDB sync complete, 612 assets.
2026-02-26 04:00:02 UTC
INGEST
[MISP]
MISP event 41028 correlated to 9 graph nodes.
"record_id": "rec-41028",
"provenance": {
"source": "MISP event 41028",
"retrieved": "2026-02-26 04:00:02 UTC",
"transform": "misp.attribute -> records.indicator"
}
2026-02-26 04:00:19 UTC
INGEST
[URLHAUS]
abuse.ch URLhaus matched 3 indicators on vpn-01.
2026-02-26 04:12:37 UTC
ENRICH
[OTX]
AlienVault OTX did not run. Gap recorded, no value inferred.

Every agent shows its work

Every record carries its source, retrieval time and transform chain. Where a source is silent, StrikeSonic records the gap instead of filling it.

Lifecycle

GeneratedReviewedApprovedExecutedVerifiedClosed
DECISION DEC-102
REVIEWED
SOURCEnvd.cve -> records.vulnerability
APPROVED
SCOREepss.score -> records.threat_modifier
GRAPH HITasset.node
EVIDENCEnvd.kev -> records.evidence
AUDIThash
DECISION4dDEC-102
REVIEWED2dIR Lead
SOURCE3dnvd.cve -> records.vulnerability...
APPROVED5d
SCORE1depss.score -> records...
GRAPH HIT2h
EVIDENCE2d
AUDIT1d
CLOSED9d

Every transition is on the chain

Generated, reviewed, approved, executed, verified, closed. Every transition is appended to the hash-chained audit with its actor and timestamp.

The gate

Autonomy you can govern

The agents do the work. A person owns the consequence. Every proposal stops at a named approver, and the signature binds to that exact version of the recommendation.

Tier 2 Analyst
IR Lead
Asset Owner
Vulnerability Mgr
Platform Owner
Risk Reviewer
Compliance Lead
DEC-171
DECISION
Escalate: prod-db-01 carries a KEV-listed CVE, risk 120, confidence 99
Feb 26, 2026
Updated 2h
User Avatar
DEC-102
DECISION
Remediate: edge-gw-02 exposes its admin interface, risk 80, confidence 92
Feb 28, 2026
Updated 3d
User Avatar
DEC-76
DECISION
Investigate: vpn-01 owner disputed by ServiceNow CMDB
Feb 28, 2026
Updated 6h
User Avatar
DEC-113
DECISION
Mitigate: api-gw-01 awaiting a vendor fix, risk 36
Feb 28, 2026
Updated 1d
User Avatar
DEC-182
DECISION
Escalate: k8s-node-04 CVE flagged for ransomware campaign use
Mar 2, 2026
Updated 4h
User Avatar
DEC-125
DECISION
Accept Risk: bastion-01 compensating control verified
Mar 3, 2026
Updated 2d
User Avatar
DEC-1
DECISION
Remediate: mail-relay-02 is an open SMTP relay
Mar 3, 2026
Updated 8h
User Avatar
DEC-132
DECISION
Investigate: sources disagree on api-gw-01 exposure
Mar 7, 2026
Updated 5d
User Avatar

One owner, one category, one state

Each decision names one accountable owner, one category out of Escalate, Investigate, Accept Risk, Mitigate or Remediate, and one lifecycle state. Nothing waits in the queue unowned.

Critical Risk
7 days
High Risk
14 days
Highapi-gw-01
14 days
Mediumvpn-01
30 days
Criticalprod-db-01
7 days

Published bands, not opinions

Band boundaries are published, not tuned per account: 50, 20 and 5 on a 0.25 to 120 scale. Higher bands carry shorter review windows.

StrikeSonic AlertsUpdated 4h

Risk crossed 50 on k8s-node-04. Owner set to IR Lead.

StrikeSonic: DEC-171 approvedUpdated 2h

Approved by the Risk Reviewer. Execution owner notified.

Notified when a band changes

A notification is raised at the next scheduled re-score, when a decision crosses a band boundary or a review window lapses.

Total findings ingested

1.2 Billion

Decisions per month

1 Million

Scoring precision

99%

Trusted by

2k analysts

Guardrails

Built to be checked, not taken on trust

Prompt injection is first on the OWASP Top 10 for LLM applications, and the weakness is structural: a model cannot tell an instruction from data. StrikeSonic removes the path from injected text to an action.

Split across a trust boundary

A quarantined model reads untrusted text and holds no tools. The privileged model holds the tools and never sees that text.

Tamper-evident audit

Append-only and hash-chained: any edit breaks the chain, including edits made by StrikeSonic.

Tools on an allowlist

A defined set with strict schemas, local models first. The agent plans within bounds, and it cites or declines.

SS

Pricing

Per-seat pricing that scales from a single analyst to the full enterprise.

Start free, upgrade as your graph grows.

Free

For exploring the public graph

€0

Free forever

  • 1 user
  • Public intelligence graph
  • Basic search
  • 3 saved searches
  • 3 threat actors
  • 10 AI Copilot queries/month
  • Public risk scoring
  • Curated CTI feeds

Coming soon: No credit card required

Standard

For individual analysts

€390/user/yr

Save €78 per user

  • 1 user
  • Advanced filters
  • 25 saved searches
  • 5 watchlists
  • 20 threat actors
  • Single-lens Graph Explorer
  • Full public evidence trail
  • Read-only API
  • Limited AI Workspace
  • 500 AI Copilot queries/month

Coming soon: No credit card required

Most popular

Pro

For teams running a private graph

€2,990/yr

Includes 5 seats. Save €598

  • Private graph for 100 entities
  • Multi-lens graph
  • Risk Center
  • Brand, domain, credential and dark-web monitoring
  • 50 watchlists
  • 250 saved searches
  • Read/write API
  • RBAC
  • 30-day audit logs
  • ITSM connector
  • Webhooks
  • 3,000 AI Copilot queries/month

Coming soon: Card required, cancel anytime

Enterprise

For organizations deploying at scale

Contact sales

Annual contract, priced to your estate

  • Unlimited users and the full private graph
  • Every connector, and cross-graph correlation
  • Decision Center, risk simulation and the AI agent framework
  • Workflow orchestration and regulatory intelligence
  • SSO / SAML / OIDC, SCIM, governance controls and configurable audit retention
  • Optional dedicated or on-prem infrastructure
  • 99.95% SLA, 24/7 support and a dedicated CSM

Coming soon: Custom quote and onboarding

Frequently asked questions

StrikeSonic runs the whole loop, from threat to verified outcome. Most platforms stop at a prioritized list. StrikeSonic keeps going through deciding, sign-off, execution and proof. The difference starts at the score. Risk is one published formula, risk = base severity x asset criticality x exposure x threat modifier, so the same inputs always produce the same number. A worked case on prod-db-01 reads base 10 x criticality 2 x exposure 2 x threat 3 = 120, Critical Risk, confidence 99, Escalate. Most commercial platforms treat the score as proprietary.

Close the loop

Every finding decided, signed, executed and proven.