Agentic AI for cyber defence in sensitive environments
We stop cyber attacks. In any environment.
CloudPeek is an agentic AI platform for security operations. It triages, investigates, hunts and contains across your existing stack, at the level of autonomy you set, with your data and your models under your control, whether you run cloud first, hybrid or fully disconnected.
Trusted by security teams operating in high-sensitivity, high-security environments



Sample CloudPeek’s capability via our MCP server
The problem
Detection was never the problem. Acting on it is.
40–67% of alerts are never investigated
Source: SACR AI SOC Market Landscape 2025
Your stack already flags more than any rota can work through. What it will not do is gather the context, decide what an alert actually means and close it out. That work is still manual, still queued, and it is why real incidents sit untouched for days.
And virtually every AI security product assumes it can send your data to someone else’s cloud and someone else’s model. For defence, critical national infrastructure and classified networks, that rules it out entirely. For everyone else, it is a decision about data and model control that most vendors never let you make.
Who we build for
Different estates, different constraints.
Defence and national security
Classified, deployed, disconnected
Autonomy on networks that never reach the internet, built for your accreditation route rather than a generic stack.
Critical national infrastructure
Where IT meets OT
One reasoning layer across converged estates, with the blast radius of every action declared before it runs.
Regulated Industries
Financial services and beyond
Machine speed operations with the evidence trail your regulator, your auditor and your board expect.
Security operations
The work it does, in your tools, on your data.
CloudPeek sits above the stack you already run as a reasoning and orchestration layer. Here is what that looks like on a normal shift.
Alert triage
Every alert worked, not just the top of the queue
Each detection is enriched, correlated against estate context and prior incidents, and either escalated with evidence or closed with a written reason.
pull detection · enrich indicators · resolve entities · correlate history · verdict with reasoning
Identity compromise
Session and access abuse, worked end to end
Impossible travel, token reuse, suspicious consent grants and privilege escalation, investigated against sign in history, device posture and known travel patterns.
sign in review · device posture · consent audit · session revocation · forced reauthentication
Exposure and vulnerability
What is actually exploitable, on what actually matters
Findings assessed against exposure, exploit availability and business criticality, rather than a severity score in isolation.
asset ownership · internet exposure · known exploited status · patch route · verification
Threat hunting
Hypotheses run continuously, not quarterly
Hunts expressed as playbooks, run on a schedule across the estate, mapped to ATT&CK techniques, with findings written back to the knowledge layer.
hypothesis · query across sources · cluster results · technique mapping · record
Containment
Prepared end to end, executed where you allow it
Isolation, revocation, blocking and patching prepared as a plan with scope declared, held for approval unless you have set the workflow to act.
scope declared · blast radius bounded · approval gate · execute · verify
Assurance and audit
Evidence produced as work happens
Every investigation and action is a timestamped record, mapped to your control framework and exportable for internal assurance, regulators and auditors.
append only trail · control mapping · export pack · retention under your policy
Each of these is worked through in full, with its own action trail, on the use cases page.
Flexible automation
Cyber is not linear. Neither are we.
Build and test your own workflows from the pieces the analysts already use: a trigger, read only stages that gather, a plan the agent proposes, a gate where a human approves, and only then the stages that act. Run it against real data first, promote it when it behaves.
Every autonomous action is traceable, policy bounded and explainable. Nothing happens that you cannot account for afterwards.
A workflow is not a straight line, because the work is not. A plan can send the agent back for more evidence. A gate can reject it and ask for a different one. A denial holds the whole thing rather than proceeding with a smaller version of it. What never changes is the order: nothing writes until the reading, the planning and the deciding are done.
Safety, control and assurance
Autonomy is only valuable if you can trust it.
Set the dial per workflow, per environment and per action type, and adjust as confidence builds. Guardrails, escalation paths and the kill switch stay with the operator, not the vendor. Move the dial and watch what changes in the record.
Read only default
Anything that writes to a production system is declared, scoped and separately enabled.
Policy bounded
Step budgets, timeouts, retry limits and blast radius set before a workflow is allowed to run.
Tested first
Playbooks run against real data in test, and are promoted only once they behave.
Explainable
Every verdict carries its evidence and its reasoning, in a record your auditor can read.
Deploy anywhere
Built for the hardest environments. All of them.
Engineering for classified and disconnected networks is the discipline; every deployment benefits from it, including cloud first. Sovereign to the operator: your data, your model, your deployment, your control.
Cloud
Alongside your stack
Multi tenant and managed, with tenant isolation enforced per transaction.
On premises
Your data centre
Your infrastructure, your keys, your retention policy, your network boundary.
Air gapped
Zero external connectivity
Operates with no phone home, no sync and nothing to reconnect. Proven in a UK Government proof of concept.
Deployed
Denied environments
Disconnected operation for deployed and classified networks, with one reasoning layer across the estate.
Model agnostic
Any model. Your call.
Choose per environment and change it later. The platform, the record and the controls stay identical whichever model reasons underneath.
Sovereign
Yours to accredit
Engineered for assurance from the ground up, with an accreditation route built for your environment rather than a generic stack.
Architecture
One layer above the stack. Nothing leaves the boundary.
CloudPeek reads from the tools you already run, reasons inside your boundary, and acts back into those same tools at the autonomy level you set. The model runs where you put it.
Technical answers // the ones a security review asks first
Where the model runs
Wherever you deploy it. Frontier, sovereign or CloudPeek’s own small language models inside your boundary. No external model call is required at any point.
What leaves your network
Nothing, by default. In a disconnected deployment there is no phone home, no telemetry, no licence check and nothing to reconnect.
How scope is enforced
Every workflow declares its tools, its step budget, its timeout, its retry limit and its blast radius before it is allowed to run. Read and write are separated at connector level.
What happens when it is wrong
It stops. A workflow that exceeds its budget, hits an unexpected state or cannot evidence its reasoning escalates to a human rather than retrying. The full trail is preserved either way.
Who can stop it
The operator. Guardrails, escalation paths and the kill switch sit with your team, not the vendor.
Tenant isolation
In the managed service, isolation is enforced per transaction rather than per session.
Data retention
Your policy. The record is append only for integrity, retained and disposed of on your schedule.
Integrations
It works in the tools and data you already run.
Native connectors across SIEM, EDR, cloud, identity, vulnerability management, ticketing and threat intelligence. Then the ones only you run.
Point the connector builder at an API specification and it drafts the tools, scopes the authentication, separates read from write and runs a security scan before anything joins your catalogue. Namespaced, versioned, sandboxed.
No vendor ticket. No integration project. Your tool, in the workflow.
Microsoft Sentinel
Splunk
CrowdStrike
Wiz
Tenable
Qualys
Entra ID
ServiceNow
Jira
MISP
AWS
Azure
Google Cloud
+ your homegrown asset database
+ the ticketing system nobody else runs
+ the script only your team understands
Connector builder // draft
INPUT
assets-api.yaml, OpenAPI 3.1
DRAFTED
assets_lookup (read) · assets_owner (read) · assets_tag (write)
AUTH
API key, scoped read
WRITE
1 tool, approval required
SCAN
passed · sandboxed · plugin_7f3a2b9c
Knowledge and intelligence
A dynamic knowledge layer.
Every user, host, address, incident and vulnerability has an entity page, backlinked to everything that touched it, with an append only history of what was known and when. Select an entity to see its page.
The agent reads the entity page before it starts work and writes back what it learned. The reason investigations are sharper in month six than in month one is not a better model. It is a better record of your environment.
Get started
Operate at machine speed. Safely. In any environment.
Book a demo or a scoping conversation. Bring a week of alerts nobody got to, and we will run them at the autonomy level you choose.
Specialists are available alongside the platform, never instead of it. How we engage
Accredited & recognised

