Aurex Sentinel 3.0 is generally available

Defense that thinks
at machine speed

AurexAI builds autonomous security intelligence — models that observe your infrastructure, reason about intent, and neutralise threats in the milliseconds before they execute.

SOC 2 Type II ISO/IEC 27001 GDPR aligned Regional data residency

0B
Signals analysed daily
0ms
Median time to verdict
0%
Platform availability, 12 mo
0%
False positives vs. rule engines
sentinel · decision stream sample
Illustrative sample. Verdicts, thresholds and actions are configured per environment.
Financial services Payments & fintech iGaming Healthcare Critical infrastructure SaaS platforms Logistics Public sector

The platform

Four systems, one decision loop

Aurex replaces the stack of disconnected detection tools with a single reasoning layer that sees the whole environment — and is accountable for every action it takes.

Sentinel Core

Streaming behavioural inference across identity, network and workload telemetry. Aurex learns what normal looks like in your environment, then flags intent — not signatures.

  • Per-entity baselines, retrained hourly
  • Lateral-movement and privilege-drift graphs
  • Detection-as-code with versioned policies

Aegis Model Guard

Security for the AI you ship. A policy gateway in front of every model and agent, enforcing what may be asked, retrieved, and acted upon.

  • Prompt-injection and jailbreak interception
  • Egress control for RAG and vector stores
  • Least-privilege scoping for agent actions

Helix Data Fabric

One queryable graph for logs, traces, identities and assets. Normalised on ingest, retained for 400 days, searchable in seconds — without a second warehouse bill.

  • Agentless connectors for cloud and SaaS
  • Schema-on-ingest normalisation
  • Regional storage, customer-held keys

Pulse Response

Graded autonomy: observe, challenge, or contain. Aurex isolates hosts, revokes sessions and rolls back changes — and writes an immutable record of why.

  • Human-in-the-loop thresholds you set
  • One-click rollback on every action
  • Evidence bundle attached to each verdict

Architecture

From raw signal to proven verdict

Every event travels the same four stages. No black boxes: each stage exposes its inputs, its confidence, and the evidence behind the call.

  1. 01

    Ingest

    Agentless connectors stream telemetry from cloud accounts, identity providers, endpoints and your own services. Data stays inside the region you choose.

  2. 02

    Reason

    An ensemble of sequence and graph models scores each event against behavioural baselines learned from your environment — not from a shared threat feed.

  3. 03

    Decide

    A deterministic policy engine turns model output into graded action. You define the thresholds; Aurex never escalates past the autonomy you granted it.

  4. 04

    Prove

    Every verdict ships with feature attribution, the raw evidence, and a signed audit record — ready for your board, your auditor, or your regulator.

Aegis Model Guard

Your AI is now
part of the attack surface

Every model you deploy is a new door into your data. Aegis sits in front of it — inspecting prompts, constraining retrieval, and approving agent actions before they reach production systems.

  • Prompt-injection defenceAdversarial input classified at the gateway, before it reaches the model context.
  • Retrieval boundariesRow-level policy on vector stores, so a model can only recall what the caller may see.
  • Agent action controlTool calls scoped, rate-limited and reversible — with approval gates on the sensitive ones.
  • Continuous red-teamingAutomated adversarial suites run against your deployed models on every release.

Trust & compliance

Built for environments that get audited

Aurex is deployed inside regulated infrastructure. The controls below are not a roadmap — they are how the platform is operated today.

SOC 2 Type II

Audited annually across security, availability and confidentiality criteria.

ISO/IEC 27001

Certified information security management system covering all production services.

Regional residency

Choose EU, US or LATAM. Telemetry never leaves the region it was collected in.

Customer-held keys

Bring your own KMS. Aurex cannot read stored telemetry without your key material.

Zero standing access

No engineer holds persistent production access. Every elevation is time-boxed and logged.

No training on your data

Customer telemetry is never used to train shared models. Baselines stay in your tenant.

Questions

Answers before the call

How long does deployment take?

Connectors are agentless and read-only by default. Most environments are streaming telemetry within a day, with behavioural baselines stabilising over the first two weeks.

Where is our data stored?

In the region you select at provisioning — EU, US or LATAM. Telemetry, baselines and evidence bundles stay within that boundary, encrypted with keys you control.

Do you train models on customer data?

No. Detection baselines are tenant-local and never leave your environment. Shared models are trained on synthetic and licensed corpora only.

Can Aurex act without a human?

Only as far as you allow. Autonomy is graded per action class — observe, challenge, contain — and every automated action is reversible with a single click.

How does it fit alongside our SIEM?

Aurex sits upstream as the reasoning layer and forwards enriched verdicts to your existing SIEM or SOAR. Teams typically retire rule packs gradually rather than replacing tooling on day one.

How is it priced?

By ingested volume and protected model endpoints, with an annual commitment. There is no per-seat charge and no premium for retention up to 400 days.

Get started

Run Aurex against
your own telemetry

A 30-minute technical session, then a scoped pilot on a slice of your traffic. No agents to install, no rip-and-replace.

We reply within one business day. No newsletters.