Skip to content

The agentic SOC that runs on the stack you already own.

Nexus connects to your existing security tools, acts as an autonomous L1/L2 analyst, and prepares human-ready verdicts in seconds. No rip-and-replace required.

A policy engine, not the model, decides what may close.

Full triage, on own hardware
~16 s
Deterministic policy control over closures
100 %
Egress modes, chosen per tenant
3
Processing region
EU
Vendor-agnostic

Nothing to rip out.

Nexus does not replace the SIEM, EDR or ticketing you have paid for and trained people on. It reads them, adds what an analyst would look up, and hands back a decision.

01

Reads from

Alerts and telemetry from your SIEM, EDR, NDR and identity sign-ins, pulled or pushed through the connector you already have.

02

Enriches with

Asset tier from the CMDB, roles from the directory, open findings from the vulnerability scanner, indicator reputation from threat intelligence, and the runbook for this class of alert.

03

Acts through

Firewall, EDR and identity provider actions such as isolate host, disable account and block address. Anything destructive waits at an approval.

Compared with replacing your stack
Replacement platformsNexus
Keep your SIEMNoYes
Where the evidence livesVendor cloudYour hardware; cloud by your choice
Choice of modelTheirsLocal, hybrid or hosted, per tenant
Multi-tenant for MSSPsRarelyBy design

A connector that does not exist yet is written in days, not quarters.

How it works

Your stack. Nexus. Your team.

One alert, followed through the system, as your analysts actually see it.

+14 min

since the alert

Sixteen seconds of machine work. One human decision.

Alert arrivesNexus checks and decidesYour team approves
14 min later

Your stack

Nexus reads from

Alerts · SIEM · EDR · NDR

Wazuh
Elastic Security
Microsoft Defender
IBM QRadar

Assets · CMDB · IPAM

NetBox
ServiceNow CMDB

Identity · IdP · directory

Microsoft Entra ID
Okta

Vulnerabilities · scanners

Tenable Nessus
Qualys

Threat intel · CTI · reputation

VirusTotal
MISP

Encoded PowerShell on FIN-WS-014

Opened 14:18:04 · Finance VLAN · one host, one user

INC-2291

Evidence

Encoded PowerShell spawned by winword.exe
FIN-WS-014 · finance team workstation
Same user from a new ASN, 14 minutes earlier
Parent hash flagged by 41 of 72 engines
AssessmentEscalate · confidence 0.82 · 4 evidence sourcesWritten on Kybit hardware. Nothing has left your estate.
Second opinionConcurs with escalateSaw only a pseudonymised summary.second model · sees tokens only
Policy gateIsolate host: allowed, with approvalAuto-close denied. The gate is deterministic and fails closed.

Isolate FIN-WS-014

Approved by the SOC lead · 14:32:07

Your team

decides, approves, can prove it

Decision

Escalate · confidence 0.82

4 evidence sources

Approval

Isolate host · approved

SOC lead · 14:32:07

Audit trace

Appended · cannot be rewritten

14:32:07 approve isolate_host sha256 9f2c…a41e

Nexus acts through

FortiGate
OPNsense
SentinelOne
Microsoft Entra ID
Active Directory

isolate hostdisable accountblock address

  1. An alert arrives from whatever you already run.
  2. Nexus gathers what an analyst would look up: the asset, the user, the vulnerability, the indicator.
  3. A model on Kybit hardware writes the assessment. Nothing has left your estate.
  4. A second model reviews it, seeing only pseudonymised tokens.
  5. A policy engine, not the model, decides what may close.
  6. Your team approves. Nexus acts through your tools.
  7. Sixteen seconds of machine work. One human decision.
Assurance

A model proposes. Policy decides.

The platform triages every alert, gathers the evidence a human would gather, and writes a reasoned assessment. A deterministic policy engine, not the model, decides whether anything may be closed automatically, and it refuses unless the asset, severity, threat-intel and tagging facts all permit it.

From the platform's assurance architecture
01

Fail-closed auto-close

Requires a positive allowlist match, no indicator hit, non-high severity and a known asset tier. With none of that, nothing closes.

02

Judge concurrence

A second, independent model must agree before any close. Agreement between samples of the same model never authorises one.

03

Append-only investigation trace

What the agent gathered and concluded is recorded once and cannot be rewritten afterwards.

04

Kill switch

One platform setting halts every autonomous claim, and it is checked before each one.

05

Untrusted evidence is fenced

Alert text is treated as data, a detector runs on it, and a hit forces escalation and zeroes confidence.

06

Human gate on destructive actions

Isolating a host, disabling an account or blocking an address parks at an approval, including for system runs.

Deployment

Where the AI runs.

Where the reasoning runs and what leaves your estate. Chosen per tenant, changed later without a migration.

Local

The AI runs on a GPU cluster in your estate. Nothing leaves.

What leaves: nothing.

Hybrid

default

The AI runs on your server. A cloud model double-checks a summary in which hosts and addresses are tokens.

What leaves: a token summary. Raw events, identities and vulnerabilities never.

Hosted

Blocked by default. After your opt-in, the full evidence goes to a hosted model in the EU under a data-processing agreement.

What leaves: the raw evidence bundle.

Pseudonymised is not anonymised. Network identifiers and the customer name are replaced with tokens that stay stable within one triage and change in the next. Account names, group names and the incident narrative are sent as written. A tenant that cannot accept that is set to none, and nothing leaves.

Read what leaves your estate
Operations

Built for MSSPs. Usable by one SOC.

  • 01Tenant isolation by row-level security in the database, not by convention in the code.
  • 02Per-tenant budgets and reasoning tiers, so one customer's alert storm cannot spend another's quota.
  • 03Per-tenant egress policy and auto-close rules, changed without a redeploy.
  • 04SSO and SAML, with break-glass overrides that expire and are audited.
  • 05NIS2 reporting and audit export, built for the incident timelines the law asks for.
  • 06One fleet view: every tenant's queue, triage latency, agreement rate and budget.

Kybit's own SOC and MDR service runs on Nexus. About the service

Works with

Reads from and acts through what you already run.

Grouped by the role a tool plays in your estate.

Alerts

SIEM · EDR · NDR

18 tools

Wazuh
IBM QRadar
Microsoft Defender
CrowdStrike Falcon
Splunk
Progress Flowmon
GREYCORTEX Mendel
AlienVault OSSIM
Microsoft Entra sign-ins
Ingest API (any source)
Microsoft Sentinel
Elastic Security
Palo Alto Networks
Fortinet
Cisco
Sophos
Trend Micro
Google SecOps

Vulnerabilities

scanners

5 tools

Findings API (any scanner)
Tenable Nessus
Qualys
Rapid7 InsightVM
Greenbone OpenVAS

Identity

IdP · directory

5 tools

Microsoft Entra ID
Active Directory
Okta
Keycloak
Google Workspace

Assets

CMDB · IPAM

5 tools

NetBox
ServiceNow CMDB
phpIPAM
i-doit
GLPI

Threat intel

CTI · reputation

8 tools

MISP
VirusTotal
AbuseIPDB
GreyNoise
urlscan.io
OpenCTI
Shodan
Recorded Future

Response

firewall · EDR · identity · ticketing

15 tools

FortiGate
OPNsense
VyOS
SentinelOne
Microsoft Entra ID
Active Directory
Palo Alto Networks
Cisco
CrowdStrike Falcon
Microsoft Defender
Jira
ServiceNow ITSM
Microsoft Teams
Slack
PagerDuty

Running something that is not listed? Anything with an API gets a connector through the connector SDK, typically in days.

Ask for a connector
Questions

Asked before every demo.

Is Nexus a SIEM replacement?
No. Nexus reads the SIEM, EDR and ticketing you already run and adds what an analyst would look up. Nothing is migrated, and the detection content you have stays where it is.
Which models does it use?
Reasoning runs on an open-weight model on Kybit hardware. An Azure OpenAI deployment in an EU region can give a second opinion on a pseudonymised summary. A hosted frontier model is used only when a tenant explicitly opts in.
What leaves our network?
In local mode, nothing. In hybrid mode, a pseudonymised verdict summary; raw events, directory context and vulnerability context never leave. In hosted mode, the raw evidence bundle, under a data-processing agreement and after a recorded opt-in. The security page lists every data class.
Can it act on its own?
It always proposes. It closes an incident only where a deterministic policy permits it, and today that policy closes nothing without a human. It acts through your tools only after an approval, and every destructive action waits at that gate.
How is it deployed?
On your premises or Kybit's, with Docker Compose. Production runs a high-availability layout with Patroni, PgBouncer, keepalived and HAProxy, plus a dedicated inference node running Ollama. An Azure deployment defined in Bicep exists for development.
Does it help with NIS2?
It records the incident timeline, decisions and approvals on an append-only trace and exports them for reporting. Kybit runs its own NIS2-scoped SOC and MDR service on the same platform.
What is an agentic SOC?
Demo

See it on your own stack.

A Kybit engineer replies within one business day and walks you through Nexus on your SIEM and EDR in 45 minutes.

Or directly:

We use these details only to reply to this request. Privacy