Book a demo

Agentic AI for cyber defence in sensitive environments

We stop cyber attacks. In any environment.

CloudPeek is an agentic AI platform for security operations. It triages, investigates, hunts and contains across your existing stack, at the level of autonomy you set, with your data and your models under your control, whether you run cloud first, hybrid or fully disconnected.

CloudPeek WORKSPACE Dashboard Investigations Incidents Incidents 27 KNOWLEDGE Artifacts Wiki RECENT Recent Investigations Token reuse, finance site OAuth consent review Recent Priority Incidents P1 Suspicious OAuth grant P2 Impossible travel: o.reed C Craig Hollington craig@cloudpeek.io Blue Harbour Operations Live view of incidents, triage performance, and agent activity Range Last 30 days MANAGEMENT · VALUE DELIVERED 456.8 hrs human hours returned 97% time reduction 938 triages · avg 45s · baseline 30 min TECHNICAL · TRIAGE HEALTH 98.6% triage success rate 41s p95 triage 925 succeeded / 938 attempted Open incidents 27 of 938 P1 / critical 3 P2: 7 · P3: 14 SLA 15m 96% 2 breached Triage p50 38s avg 45s LLM tokens 1.2M 4,318 calls HITL backlog 4 18 decided Daily throughput Last 30 days Incidents Triage Investigations Mar 1 Mar 8 Mar 15 Mar 22 Mar 29 Severity breakdown Critical 12 High 31 Medium 64 Low 48 Info 29 Incidents / alertId: EVT-9f21c4 ACTION NEEDED AI TRIAGED HUMAN REQUIRED Impossible travel: o.reed Microsoft · Entra ID · Credential Access · eventTime 14:02:11Z HIGH · 87/100 mitreTechniques T1078 T1114 T1567 T1070 AI Analysis triageMode: alert · schemaVersion 1.0 Threat Summary timeline 14 nextSteps 5 iocs 4 DESCRIPTION Sign-ins from Lagos then London 29 minutes apart on one refresh token, replayed across both sessions. Source address flagged by 9 of 94 engines. NEXTSTEPS · status PENDING NS-001 Revoke active sessions for o.reed HIGH dataSources: Identity Provider AUTOMATABLE NS-002 Pull 30 days of sign-in history HIGH dataSources: SIEM AUTOMATABLE NS-003 Sweep mailbox for forwarding rules MEDIUM dataSources: Microsoft 365 read only so far · nothing has been changed IOCS · type / value / role / risk USER HIGH o.reed SOURCE IP CRITICAL 198.51.100.7 SOURCE HOSTNAME MEDIUM edge-gw-02 TARGET DOMAIN HIGH mail-fwd.io RELATED every IOC cited to the query that found it Ask CloudPeek INC-2418 Implement the remediation plan Runbook sign-in-compromise v4 matched. Three steps, two of them automatable. Nothing runs until you approve it. REMEDIATION STEPS 1 Revoke sessions and refresh tokens 2 Reset credentials, re-enrol MFA 3 Remove the mailbox forwarding rule ACTIONS · 3 QUEUED revoke_sessions held identity reset_credentials held identity remove_forwarding_rule held m365 write tools stay unloaded until the gate clears APPROVAL REQUIRED ? Apply 3 actions to o.reed? revoke_sessions { user.name: "o.reed", scope: "all" } ARGS FROZEN what you approve is what runs Deny Approve read only until you say otherwise
swipe to see the full console

Trusted by security teams operating in high-sensitivity, high-security environments

Mastek
HMG
AWS Qualified Software

Sample CloudPeek’s capability via our MCP server

The problem

Detection was never the problem. Acting on it is.

40–67% of alerts are never investigated

Source: SACR AI SOC Market Landscape 2025

Your stack already flags more than any rota can work through. What it will not do is gather the context, decide what an alert actually means and close it out. That work is still manual, still queued, and it is why real incidents sit untouched for days.

And virtually every AI security product assumes it can send your data to someone else’s cloud and someone else’s model. For defence, critical national infrastructure and classified networks, that rules it out entirely. For everyone else, it is a decision about data and model control that most vendors never let you make.

Who we build for

Different estates, different constraints.

Defence and national security

Classified, deployed, disconnected

Autonomy on networks that never reach the internet, built for your accreditation route rather than a generic stack.

Critical national infrastructure

Where IT meets OT

One reasoning layer across converged estates, with the blast radius of every action declared before it runs.

Regulated Industries

Financial services and beyond

Machine speed operations with the evidence trail your regulator, your auditor and your board expect.

Security operations

The work it does, in your tools, on your data.

CloudPeek sits above the stack you already run as a reasoning and orchestration layer. Here is what that looks like on a normal shift.

Alert triage

Every alert worked, not just the top of the queue

Each detection is enriched, correlated against estate context and prior incidents, and either escalated with evidence or closed with a written reason.

pull detection · enrich indicators · resolve entities · correlate history · verdict with reasoning

Identity compromise

Session and access abuse, worked end to end

Impossible travel, token reuse, suspicious consent grants and privilege escalation, investigated against sign in history, device posture and known travel patterns.

sign in review · device posture · consent audit · session revocation · forced reauthentication

Exposure and vulnerability

What is actually exploitable, on what actually matters

Findings assessed against exposure, exploit availability and business criticality, rather than a severity score in isolation.

asset ownership · internet exposure · known exploited status · patch route · verification

Threat hunting

Hypotheses run continuously, not quarterly

Hunts expressed as playbooks, run on a schedule across the estate, mapped to ATT&CK techniques, with findings written back to the knowledge layer.

hypothesis · query across sources · cluster results · technique mapping · record

Containment

Prepared end to end, executed where you allow it

Isolation, revocation, blocking and patching prepared as a plan with scope declared, held for approval unless you have set the workflow to act.

scope declared · blast radius bounded · approval gate · execute · verify

Assurance and audit

Evidence produced as work happens

Every investigation and action is a timestamped record, mapped to your control framework and exportable for internal assurance, regulators and auditors.

append only trail · control mapping · export pack · retention under your policy

Each of these is worked through in full, with its own action trail, on the use cases page.

Flexible automation

Cyber is not linear. Neither are we.

Build and test your own workflows from the pieces the analysts already use: a trigger, read only stages that gather, a plan the agent proposes, a gate where a human approves, and only then the stages that act. Run it against real data first, promote it when it behaves.

STAGES YOUR ANALYSTS ALREADY USEbudget: 3 steps · 60s · 2 retries · snapshotted at publishneeds more evidencereject, replanTRIGGERschedule / alertGATHERread onlyPLANagent proposesGATEa human approvesACTdeclared scopeRECORDappend onlyNOTHING IS WRITTEN HEREONLY THESE STAGES ACTdenyHOLDnothing runsTEST RUN, real dataclean runs, reviewedPROMOTED TO LIVE
swipe to see the full workflow

Every autonomous action is traceable, policy bounded and explainable. Nothing happens that you cannot account for afterwards.

A workflow is not a straight line, because the work is not. A plan can send the agent back for more evidence. A gate can reject it and ask for a different one. A denial holds the whole thing rather than proceeding with a smaller version of it. What never changes is the order: nothing writes until the reading, the planning and the deciding are done.

Safety, control and assurance

Autonomy is only valuable if you can trust it.

Set the dial per workflow, per environment and per action type, and adjust as confidence builds. Guardrails, escalation paths and the kill switch stay with the operator, not the vendor. Move the dial and watch what changes in the record.

CloudPeek // action trail · illustrative entriesLevel 1 · advise
09:12:04TRIAGE2,306 alerts correlated against estate context. 3 escalated, 2,303 closed with reasoning.
09:26:41ENRICHIndicator 198.51.100.24 checked against threat intelligence and 14 months of local history.
09:26:58DETECTCVE-2026-1187 on internet facing host edge-gw. Known exploited, exploit code public.
09:27:02MAPATT&CK T1190, exploit public facing application. Initial access, external asset.
09:27:15ADVISERecommended: isolate edge-gw, apply vendor patch, rotate service account. Nothing staged to run.
09:27:16RECORDInvestigation archived with evidence and reasoning, mapped to your control set.
CloudPeek investigates and recommends. Your operators decide and act.All actions traced

Read only default

Anything that writes to a production system is declared, scoped and separately enabled.

Policy bounded

Step budgets, timeouts, retry limits and blast radius set before a workflow is allowed to run.

Tested first

Playbooks run against real data in test, and are promoted only once they behave.

Explainable

Every verdict carries its evidence and its reasoning, in a record your auditor can read.

Deploy anywhere

Built for the hardest environments. All of them.

Engineering for classified and disconnected networks is the discipline; every deployment benefits from it, including cloud first. Sovereign to the operator: your data, your model, your deployment, your control.

Cloud

Alongside your stack

Multi tenant and managed, with tenant isolation enforced per transaction.

On premises

Your data centre

Your infrastructure, your keys, your retention policy, your network boundary.

Air gapped

Zero external connectivity

Operates with no phone home, no sync and nothing to reconnect. Proven in a UK Government proof of concept.

Deployed

Denied environments

Disconnected operation for deployed and classified networks, with one reasoning layer across the estate.

CloudPeek // model layermix per environment · calling out is a choice
YOUR BOUNDARYCloudPeek reasoning layerREASONING MODEL · YOUR CHOICEFrontierprovider hosted, called over an APILocalsovereign or open source, inside your boundaryincluding CloudPeek's own SLMsExternal model APIa choice, not requiredby your choiceno path out
swipe to see the full diagram

Model agnostic

Any model. Your call.

Choose per environment and change it later. The platform, the record and the controls stay identical whichever model reasons underneath.

Sovereign

Yours to accredit

Engineered for assurance from the ground up, with an accreditation route built for your environment rather than a generic stack.

Architecture

One layer above the stack. Nothing leaves the boundary.

CloudPeek reads from the tools you already run, reasons inside your boundary, and acts back into those same tools at the autonomy level you set. The model runs where you put it.

YOUR NETWORK BOUNDARYnothing crosses unless you allow itYOUR EXISTING STACKSIEMEDRCloudIdentityVuln mgmtITSMREAD · ACTCloudPeek reasoning and orchestration layerKNOWLEDGEentity pages, history,estate contextORCHESTRATIONagents, playbooks,connectors, schedulingPOLICY AND AUDITautonomy dial, guardrails,append only trailMODEL LAYER · YOU CHOOSEFrontier modelwhere connectivity allowsSovereign / localin your jurisdiction or yourboundaryCloudPeek SLM, localno external model calls requiredRUNS WHERE YOU PUT ITCloud · on premises · air gapped · deployed and disconnected
swipe to see the full architecture

Technical answers // the ones a security review asks first

Where the model runs

Wherever you deploy it. Frontier, sovereign or CloudPeek’s own small language models inside your boundary. No external model call is required at any point.

What leaves your network

Nothing, by default. In a disconnected deployment there is no phone home, no telemetry, no licence check and nothing to reconnect.

How scope is enforced

Every workflow declares its tools, its step budget, its timeout, its retry limit and its blast radius before it is allowed to run. Read and write are separated at connector level.

What happens when it is wrong

It stops. A workflow that exceeds its budget, hits an unexpected state or cannot evidence its reasoning escalates to a human rather than retrying. The full trail is preserved either way.

Who can stop it

The operator. Guardrails, escalation paths and the kill switch sit with your team, not the vendor.

Tenant isolation

In the managed service, isolation is enforced per transaction rather than per session.

Data retention

Your policy. The record is append only for integrity, retained and disposed of on your schedule.

Integrations

It works in the tools and data you already run.

Native connectors across SIEM, EDR, cloud, identity, vulnerability management, ticketing and threat intelligence. Then the ones only you run.

Point the connector builder at an API specification and it drafts the tools, scopes the authentication, separates read from write and runs a security scan before anything joins your catalogue. Namespaced, versioned, sandboxed.

No vendor ticket. No integration project. Your tool, in the workflow.

Microsoft Sentinel

Splunk

CrowdStrike

Wiz

Tenable

Qualys

Entra ID

ServiceNow

Jira

MISP

AWS

Azure

Google Cloud

+ your homegrown asset database

+ the ticketing system nobody else runs

+ the script only your team understands

Connector builder // draft

INPUT

assets-api.yaml, OpenAPI 3.1

DRAFTED

assets_lookup (read) · assets_owner (read) · assets_tag (write)

AUTH

API key, scoped read

WRITE

1 tool, approval required

SCAN

passed · sandboxed · plugin_7f3a2b9c

Knowledge and intelligence

A dynamic knowledge layer.

Every user, host, address, incident and vulnerability has an entity page, backlinked to everything that touched it, with an append only history of what was known and when. Select an entity to see its page.

CloudPeek // knowledge graphINC-2418 and everything it touched
usero.reedhostedge-gwip198.51.*incidentINC-2418cve2026-1187
select an entitythe agent reads this first
Wiki // entity page · user: o.reed
TEAMFinance · MFA enrolled
NOTEtravels often, expect odd hours
LINKSINC-2418 · INC-2103 · runbook: travel
History // append only14:34 · triage worker added indicator14:02 · sign in anomaly noted12 Mar · baseline written

The agent reads the entity page before it starts work and writes back what it learned. The reason investigations are sharper in month six than in month one is not a better model. It is a better record of your environment.

Get started

Operate at machine speed. Safely. In any environment.

Book a demo or a scoping conversation. Bring a week of alerts nobody got to, and we will run them at the autonomy level you choose.

Specialists are available alongside the platform, never instead of it. How we engage

Accredited & recognised