TandemTraceTandemTrace
// Anonymized customer evaluation · Regulated industrial enterprise

Autonomous security operations.
Inside the customer boundary.

A regulated industrial enterprise evaluated TandemTrace as its autonomous Tier 1 and threat-hunting layer. The requirement was explicit: production telemetry stays in the customer-controlled environment, integrations remain read-only, and analysts retain approval over every escalation and response.

2 initial data pathsSIEM alerts and raw-event search, plus EDR telemetry feeding the evaluation.
≥95% agreement targetVerdicts measured against sampled analyst judgment as a formal acceptance criterion.
Human approval retainedEvery ambiguous escalation and consequential response remains analyst-gated.
// 01

The customer constraint.

Real evaluation scope
// Hosting

Cloud or fully on-premise had to remain a customer choice.

The evaluation explicitly required a deployment path inside the enterprise environment, with telemetry retained within the selected boundary.

// Model access

A private model endpoint was part of the design.

The architecture allowed an approved private frontier-model deployment instead of requiring inference through a shared public service.

// Production access

Read-only scopes, no write access.

TandemTrace could retrieve SIEM alerts, search underlying events, and enrich from EDR—but could not change production security controls.

// Evaluation gates

What had to be true before production.

These bars show requirements and targets—not claimed achieved outcomes. The customer defined the gates before evaluating the system.

Read-only access
Required
Human approval
Required
Data isolation
Required
Verdict agreement
≥95% target
0Evaluation threshold100%
// 02

Connect without surrendering control.

Architecture
// Existing stack

SIEM · EDR · Identity

One or several SIEMs, endpoint platforms, identity systems, cloud logs, and internal sources.

// Read-only layer

TandemTrace AI SOC

Investigates, correlates, hunts, and builds evidence without rerouting logs or installing endpoint agents.

// Controlled output

Verdicts · Evidence · Actions

Auditable findings enter existing workflows. Response remains human-approved and policy-controlled.

// Operating principle

Autonomy applies to investigation. Authority over containment and response stays with your team.

// 03

What the evaluation had to prove.

Acceptance criteria
// Quality

Agreement with analyst judgment.

The formal target was at least 95% agreement on sampled alert verdicts—not an unmeasured claim of autonomous accuracy.

// Auditability

Every conclusion had to be inspectable.

Queries, pivots, evidence, reasoning, and escalation context had to be available for analysts to review and challenge.

// Expansion path

Start with SIEM and EDR, then add context.

The initial scope established the investigation path; later phases added direct EDR, threat intelligence, and additional telemetry without replacing the existing stack.

Bring the AI SOC to your environment.

Walk through deployment boundaries, private-model options, integrations, audit requirements, and response controls with our team.

Discuss your architecture ↗