Guided Unified SecOps · SOC in a box

Stop playing whack-a-mole with your alerts.

GUS is a security-hardened AI analyst that works your queue across the platforms you already run. It enriches every alert, cross-correlates it against the history of your fleet — workstations, servers, users — and never forgets an investigation. Repeat offenders surface as trends, not tickets.

11platform add-ons
6-phasetriage loop
0open network ports
Cross-correlation

One alert is a data point. Your history is the evidence.

Every tool in your stack scores alerts one at a time. GUS reads each one against everything it already knows about the entity — and about the rest of your fleet — so the pattern is the deliverable, not the ticket count.

altitude 01 · today

The alert

What every console shows: one medium-severity EDR detection on ws-fin-0417. On its own it gets triaged, closed, and forgotten — and the next one starts from zero.

single signal
altitude 02 · 90 days

The entity

What memory shows: the same workstation carried a credential-phish click in June and beaconing to a rare domain in May — plus the correction you logged when IT renamed the asset.

prior casesyour corrections
altitude 03 · your fleet

The trend

What correlation surfaces: three platforms, one story — staged credential access. And two more finance hosts already match the first half of the same pattern. That's a hunt, not a ticket.

cross-platformcross-entity
The triage loop

It works the alert, not just displays it.

An alert lands. Instead of a human pivoting between six consoles, GUS runs the same investigation every time — deterministically, read-first, and with every step on the audit trail.

01

Identify

read-only

Ingests the alert from your SIEM, EDR, NDR, or firewall and extracts the entities — host, user, IP, hash, domain.

02

Enrich

across your add-ons

Fans out to every connected platform — reputation from threat intel, device posture from EDR, identity risk from UEBA, exposure from your scanner — and to what your environment already knows.

03

Correlate

the differentiator

Cross-references the signals against each other, against prior cases for the same workstation, server, or user, and against the rest of your fleet — not one tool's opinion, the whole picture over time.

04

Classify

Reaches a verdict — true positive, benign true positive, or false positive — with the evidence that drove it, and validates IOCs before it ever escalates.

05

Recommend

gated

Proposes containment. It never executes a response action on its own — writes are dry-run previewed, confirmed, and audited, and OT assets are guarded fail-closed.

06

Persist

Writes the finding, the reasoning, and the outcome back to memory so the next alert on the same entity starts where this one ended.

Enriched, company-specific memory

Memory that knows your environment — and corrects itself.

Most tools forget every alert the moment it closes. GUS doesn't. It keeps a temporal knowledge graph of your world and gets less wrong over time, because it learns from you.

Enriched memory

Every investigation compounds.

Workstations, servers, users, prior cases, IOCs, and attacker techniques accumulate in a temporal graph. Triage #100 is sharper than triage #1 because it stands on the ninety-nine before it — no re-deriving what's already known.

Domain & company specific

It learns your normal.

Your asset naming, your service accounts, your maintenance windows, your business context. A pattern that's benign at your org isn't flagged and re-investigated every single time — GUS knows it's you.

Auto-correcting

Tell it once.

Overturn a verdict, or mark an activity authorized, and GUS stores the correction and injects it at the top of the next relevant investigation. You stop repeating yourself; the system stops repeating the mistake.

Auditable

Every fact has a source.

Memory is classified, timestamped, and cited. Indicators age out on their own schedule. Nothing is asserted that can't be traced back to the case, feed, or correction it came from.

Why you can let it touch your stack

Put the controls around the model, not inside it.

Prompting a model to "be safe" is a request, not a guarantee. GUS keeps the language model in the center as a capable but untrusted engine — and enforces safety in the deterministic shell that surrounds it.

Every action the assistant proposes passes through code that runs whether or not the model cooperates: pattern deny-lists, OT safety gates, credential brokering, and an append-only audit trail. The model reasons; the shell decides what actually runs.

Guardrails

Six controls that don't trust the model.

Each is deterministic code in the execution path — enforced at the seam between what the assistant wants and what the system allows.

01 · enforcement

Lifecycle hooks

A compiled hook judges every command before it runs. rm -rf, pipe-to-shell, and chmod 777 are blocked at the argv layer — a decision, not a suggestion.

PreToolUseargv-level
02 · privilege

Break-glass profiles

Dangerous capabilities stay locked behind an explicit, time-boxed elevation — a code word entered out-of-band, a TTL, and an owner alert. Least privilege is the default state.

TTL 60mout-of-band
03 · data

Local-first memory

A temporal knowledge graph lives on-device — thousands of facts and corrections, full-text searchable. No vendor cloud holds your investigation history.

on-deviceFTS
04 · safety

OT-aware gates

Built for IT/OT convergence. GUS can read and validate an industrial proxy config, but restarting a live OT service is hard-blocked — the bounce is handed to a human with a maintenance window.

ICS-safehuman-in-loop
05 · surface

Standalone Rust MCP

Integrations are single-binary services speaking JSON-RPC over stdio — no HTTP listener, no exposed port, immune to DNS-rebinding. Credentials resolve from a vault, never a config file.

stdio-onlyno listener
06 · accountability

Append-only audit

Every gated action and elevation writes a JSONL line — names and references, never secret values. A blocked command leaves a trail; so does the reason it was blocked.

JSONLtamper-evident
How it works

Every action passes through a gate.

The assistant never touches your systems directly. Its intent is intercepted, judged, and logged before a single byte of it executes.

01

Propose

The model reasons over the task and proposes a concrete action — a command, an API call, a file edit.

02

Judge

A PreToolUse hook inspects the raw argv against deny-lists, OT rules, and the active privilege profile.

03

Enforce

Allowed actions run; risky ones are blocked or routed to break-glass. The model's cooperation is never assumed.

04

Record

The decision and its rationale are appended to the audit trail — an evidence trail you can replay later.

Architecture · Praxis

Eight components, four disciplines.

GUS runs on Praxis — an architecture that turns doctrine into deterministic execution, grouped as foundation, knowledge, action, and reflection.

FoundationIdentitymission, beliefs, mental models
FoundationRulesguardrails, gates, deny-lists
KnowledgeContextcompiled knowledge base
KnowledgeDatalocal temporal graph
ActionOrchestrationthe response engine
ActionNetworkscoped agents & MCP mesh
ReflectionLearningcorrection & self-tuning
ReflectionAuditcompliance & dissent log
Data handling

Four classification levels, enforced by default.

Every piece of context carries a level. Actions touching higher tiers demand confirmation — and the highest tier assumes an air-gapped, offline posture.

L0Public

General knowledge and public documentation. No gate.

L1Internal

Work context and project detail. Routine handling.

L2Confidential

Infrastructure and credentials. Confirmation required.

L3Restricted / OT

Control-system detail and vulnerabilities. Offline, deny-by-default.

Get started

Give your assistant a shell it can't talk its way out of.

GUS is in limited access for security teams working across IT and OT. Bring your stack; keep your guardrails.

heygusai.io · info@heygusai.io · deterministic by design

Named for Gus — a standard poodle, and the original guardian of the door.