Local
The AI runs on a GPU cluster in your estate. Nothing leaves.
What leaves: nothing.
Nexus connects to your existing security tools, acts as an autonomous L1/L2 analyst, and prepares human-ready verdicts in seconds. No rip-and-replace required.
A policy engine, not the model, decides what may close.
Impossible travel, then a new inbox rule
INC-4417 · Triaged in 16 s. Approved by a SOC lead 14 min later.
Nexus does not replace the SIEM, EDR or ticketing you have paid for and trained people on. It reads them, adds what an analyst would look up, and hands back a decision.
Alerts and telemetry from your SIEM, EDR, NDR and identity sign-ins, pulled or pushed through the connector you already have.
Asset tier from the CMDB, roles from the directory, open findings from the vulnerability scanner, indicator reputation from threat intelligence, and the runbook for this class of alert.
Firewall, EDR and identity provider actions such as isolate host, disable account and block address. Anything destructive waits at an approval.
| Replacement platforms | Nexus | |
|---|---|---|
| Keep your SIEM | Replacement platformsNo | NexusYes |
| Where the evidence lives | Replacement platformsVendor cloud | NexusYour hardware; cloud by your choice |
| Choice of model | Replacement platformsTheirs | NexusLocal, hybrid or hosted, per tenant |
| Multi-tenant for MSSPs | Replacement platformsRarely | NexusBy design |
A connector that does not exist yet is written in days, not quarters.
One alert, followed through the system, as your analysts actually see it.
+14 min
since the alert
Sixteen seconds of machine work. One human decision.
Your stack
Nexus reads from
Alerts · SIEM · EDR · NDR
Assets · CMDB · IPAM
Identity · IdP · directory
Vulnerabilities · scanners
Threat intel · CTI · reputation
Opened 14:18:04 · Finance VLAN · one host, one user
Evidence
Isolate FIN-WS-014
Approved by the SOC lead · 14:32:07
Your team
decides, approves, can prove it
Decision
Escalate · confidence 0.82
4 evidence sources
Approval
Isolate host · approved
SOC lead · 14:32:07
Audit trace
Appended · cannot be rewritten
14:32:07 approve isolate_host sha256 9f2c…a41e
Nexus acts through
isolate hostdisable accountblock address
The platform triages every alert, gathers the evidence a human would gather, and writes a reasoned assessment. A deterministic policy engine, not the model, decides whether anything may be closed automatically, and it refuses unless the asset, severity, threat-intel and tagging facts all permit it.
Requires a positive allowlist match, no indicator hit, non-high severity and a known asset tier. With none of that, nothing closes.
A second, independent model must agree before any close. Agreement between samples of the same model never authorises one.
What the agent gathered and concluded is recorded once and cannot be rewritten afterwards.
One platform setting halts every autonomous claim, and it is checked before each one.
Alert text is treated as data, a detector runs on it, and a hit forces escalation and zeroes confidence.
Isolating a host, disabling an account or blocking an address parks at an approval, including for system runs.
Where the reasoning runs and what leaves your estate. Chosen per tenant, changed later without a migration.
The AI runs on a GPU cluster in your estate. Nothing leaves.
What leaves: nothing.
The AI runs on your server. A cloud model double-checks a summary in which hosts and addresses are tokens.
What leaves: a token summary. Raw events, identities and vulnerabilities never.
Blocked by default. After your opt-in, the full evidence goes to a hosted model in the EU under a data-processing agreement.
What leaves: the raw evidence bundle.
Pseudonymised is not anonymised. Network identifiers and the customer name are replaced with tokens that stay stable within one triage and change in the next. Account names, group names and the incident narrative are sent as written. A tenant that cannot accept that is set to none, and nothing leaves.
Read what leaves your estateKybit's own SOC and MDR service runs on Nexus. About the service
Grouped by the role a tool plays in your estate.
SIEM · EDR · NDR
18 tools
scanners
5 tools
IdP · directory
5 tools
CMDB · IPAM
5 tools
CTI · reputation
8 tools
firewall · EDR · identity · ticketing
15 tools
Running something that is not listed? Anything with an API gets a connector through the connector SDK, typically in days.
Ask for a connectorA Kybit engineer replies within one business day and walks you through Nexus on your SIEM and EDR in 45 minutes.
Or directly: