FAQ

Frequently Asked Questions

Everything you need to know about the ClearSkies™ platform and how it protects your organization.

TDIR stands for Threat Detection, Investigation & Response. Unlike siloed tools, ClearSkies™ unifies these capabilities under one AI-powered platform built by security experts — transforming traditional SOC workflows with automation, contextual insight, and analyst-aware orchestration.

TDIRPlatformAI-PoweredSOC

ClearSkies™ adds AI-driven insight and context, automates repetitive tasks, and helps teams detect, investigate, and respond faster — even under pressure. It intelligently analyzes threats and empowers rapid response so your organization recovers quickly with minimal operational impact.

ResilienceAutomationThreat Response

Not at all. ClearSkies™ is fully modular. Start with what you need and expand as your operations grow — without unnecessary complexity or cost. Each module integrates seamlessly into the platform when you're ready to add it.

ModularFlexibleScalable

Yes — ClearSkies™ is built for interoperability. It integrates with third-party tools and enhances what you already use, designed to complement and elevate your existing security investments rather than replace them.

IntegrationInteroperabilityOpen Platform

ClearSkies™ is built by world-class security experts with years of hands-on experience. The platform is continuously updated against the evolving threat landscape, with regular penetration tests and security analyses. The provider holds ISO 27001, ISO 9001 and ISO 22301 certifications, and is accredited by the PCI SSC as a Qualified Security Assessor (QSA).

ISO 27001ISO 9001PCI QSAISO 22301

Since ClearSkies™ is cloud-based and delivered as-a-Service, implementation is fast and tailored to your organization's specific requirements — with near-instant results thereafter. No complex on-premises infrastructure setup or heavy administration is required.

Cloud-NativeFast DeploymentAs-a-Service

With ClearSkies™ delivered through a cloud-based SIEM-as-a-Service model, you can be up and running quickly. Organizations typically start seeing actionable results within 4 to 6 weeks — compared to legacy on-premises deployments that can take up to 18 months.

4–6 weeksvs. up to 18 months for on-premises deployments
Time-to-ValueCloudSIEM-as-a-Service

Continuously. ClearSkies™ receives regular updates — new features, enhancements, and capabilities — driven by real-world SOC experience, technological trends, and customer feedback. A dedicated team of world-class engineers, developers, and data scientists share one goal: delivering world-class, innovative protection.

Continuous UpdatesInnovationExpert-Driven

An Integrated Security Operations Center (ISOC) platform converges detection, investigation, response, telemetry, threat intelligence, automation and AI into one operating workflow — replacing the SIEM-plus-point-tools architecture with a single control plane. Instead of stitching consoles together by hand, an analyst works one enriched, prioritized incident from alert to containment, with the AI’s reasoning visible at every step.

ISOCPlatformTDIR

Both. The same core ships as the Client Platform for organizations that run their own SOC, and as a multi-tenant, white-label MSSP Platform for providers delivering managed security to many clients. You can also have us run it for you through Managed Services.

Client PlatformMSSPManaged Services

No. The Centric AI Fabric runs on a private, offline LLM purpose-built for cybersecurity. Telemetry and prompts are never exposed to public AI services, and every AI decision stays explainable and auditable inside your boundary.

Private AICentric AI FabricExplainable AI

Across endpoint, identity, network, DNS, cloud and external exposure — from insider threats and credential abuse to advanced threats like APTs, zero-days and ransomware — all correlated on one core and contained through native automation.

DetectionResponseCoverage

Typically 4–6 weeks, depending on environment complexity and module scope. Our Professional Services team handles architecture, migration and tuning.

4–6 weekstypical deployment, depending on environment complexity and scope
DeploymentTime-to-Value

ClearSkies™ iISOC is the Intelligent - Integrated Security Operations Platform: detection, investigation, response, telemetry, threat intelligence, automation and AI converged into one governed workflow. Instead of stitching consoles together by hand, an analyst works one enriched, prioritized incident from alert to containment, with the AI’s reasoning visible at every step.

It stands for both Intelligent and Integrated. Intelligence without integration is a clever tool that still stands alone; integration without intelligence is a shared console that still leaves your analysts to correlate by hand. ClearSkies™ iISOC holds both at once: an intelligent orchestration layer acting across a fully integrated set of capabilities.

It carries those capabilities, but as coordinated functions of one platform rather than separate products. Next-Gen SIEM, SOAR, endpoint and network telemetry, threat intelligence and an AI SOC analyst all work from one data model, one workflow and one console - and if you want it operated for you, it is also delivered as a managed service.

No - ClearSkies™ is built for interoperability. It integrates with third-party tools and enhances what you already use, designed to complement and elevate your existing security investments rather than replace them. New coverage never means another console to watch.

Your data is signed and encrypted inside your own boundary at the point of collection and stays resident in your region. The Centric AI Fabric runs on a private, offline LLM purpose-built for cybersecurity - telemetry and prompts are never exposed to public AI services, and every AI decision stays explainable and auditable.

Both. The same core ships as the Client Platform for organizations that run their own SOC, and as a multi-tenant, white-label MSSP Platform for providers delivering managed security to many clients. You can also have us run it for you through Managed Services.

Typically 4–6 weeks, depending on environment complexity and module scope. ClearSkies™ is cloud-based and delivered as-a-Service, so no complex on-premises infrastructure is required - our Professional Services team handles architecture, migration and tuning.

The platform measures itself natively: one audit-ready record per incident, SLA and service dashboards, and outcome-based reporting on the metrics that matter - fewer false positives, faster detection and response, and less analyst time spent on investigations.

It is the multi-tenant, white-label edition of the ClearSkies™ ISOC platform. It gives a provider one deployment, one analyst workflow and one branded client experience across every tenant.

Service Providers

Yes. Existing partners can speak with the partner team to review delivery capabilities, packaging, enablement and the commercial model.

Service Providers

Yes. Tenant data, access and reporting remain strictly isolated while analysts work from one shared operational environment and reusable service workflows.

Service Providers

This page explains the provider operating model, economics and outcomes. The edition page goes deeper into packaging, capabilities and plan options for the product itself.

Service Providers

The same system records the path from collection and correlation through investigation, response and outcome, so MTTD, MTTR, evidence and service-level performance share one source of truth.

TDIR

Yes. The core can serve one enterprise or many provider tenants with strict isolation, shared operational workflows and governed learning across the platform.

TDIR

No. SIEM and SOAR capabilities participate in the lifecycle, while TDIR is the orchestration core that connects ingestion, detection, investigation, response and measurement as one governed system.

TDIR

No. XDR generally describes detection and response across selected controls. ClearSkies™ TDIR is the platform-level orchestration core through which native add-ons, third-party sources and outcomes all flow.

TDIR

Yes. Signals are normalized once, correlated in the same core and acted on through the same orchestration layer. Products do not exchange intelligence through ad-hoc point-to-point integrations.

TDIR

A false-positive mark suppresses the domain immediately and retrains the tenant baseline.

A managed device off the corporate network uses whatever DNS the local network provides unless the Agent forwards them back.

Payload content, and direct-to-address connections that issue no lookup at all. Both are the work of the firewall and endpoint layers, which is why the correlated architecture matters more than the refusal itself.

It does, and it will continue to. The question is what it is worth in three years: efficiency gains accrue to the supplier, the client relationship is shared, and the capability is not proprietary at exit. The three-routes comparison on the overview states this without arguing that every provider should switch.

Separation is enforced at the data layer, no tenant holds or infers the data of another, and hosting region is configurable per deployment. The subprocessor terms and the assurance reports are the artifacts to review.

Volume is bought in bands rather than metered without a ceiling, so a busy month meets a known band instead of an open invoice. The console reports ingestion per tenant, so a client that grows is repriced on evidence at renewal. Normalization and filtering happen at collection, so low-value telemetry is dropped before it counts against the band. Under MSSP Ultimate, capacity released by one client is reallocated to another rather than repurchased.

That is the normal case and it is not an obstacle. Endpoint telemetry from the vendor the client already runs is ingested and correlated, and response actions are executed through it where the vendor exposes them. Endpoint Threat Monitoring and Response is licensed only where a client has no incumbent or is replacing one.

An authenticated scanner covers what is already recorded, and a network scanner covers what is reachable from inside. Neither reaches an asset nobody registered, which is where most intrusions begin.

Active assessment is restricted to the confirmed band, at 70 and above on an evidence-scored model. Suspicious assets are observed passively and never probed, and every promotion and discard is recorded with its reasoning.

In this category those are almost always attribution errors rather than detection errors: shared addresses, parked domains and hosting ranges swept in by resemblance. That is the problem ClearSkies ASM is built around, and the first confirmed scan is run as an attribution review so the evidence model is visible before any finding reaches a report.

ClearSkies ASM does not run inside the OT segment and does not need to. It works the boundary: the internet-facing jump hosts, remote-access services and engineering workstations an attacker would use to reach control systems, discovered without installing anything. Coverage of the operational infrastructure itself is integration-based.

The platform is opinionated about the data model and open about the infrastructure. Thousands of third-party products are normalized to the same schema through the Marketplace, detection logic is portable through Sigma, intelligence exchanges through STIX and TAXII, and customer data remains exportable under documented terms.

A SIEM is a destination for logs. The distinction here is where correlation happens and what acts on the result: normalization occurs at collection, correlation and investigation occur inside the platform, and response executes back through every integrated control under governed authority.

It is translated and validated against the normalized model during a parallel run, with detection parity demonstrated before the incumbent is decommissioned.

Authority is tiered and configurable per tenant. Low-risk containment executes automatically, higher-impact action requires human authorisation, and every action is logged with actor, input, decision, and outcome.

Through banded ingestion and retention by tier, add-on licensing tied to protected surface rather than log volume, and exposure-led scoping.

Deployment supports data residency and sovereignty requirements, with governance mapped to NIS2, DORA, GDPR, ISO/IEC 27001, and the EU AI Act. Residency is confirmed per deployment at scoping.

No. TDIR is the Orchestration Layer of the ClearSkies iISOC platform. It is not licensed, tiered or bought separately and has no standalone deployment.

In that arrangement each product holds its own data model and its own console, and work passes between them at every step. Here telemetry is normalized once, correlated in one core, investigated in one workflow and responded to through one orchestration engine, so there is no hand-off, no data-model mismatch and no separate console.