Cloud or fully on-premise had to remain a customer choice.
The evaluation explicitly required a deployment path inside the enterprise environment, with telemetry retained within the selected boundary.
A regulated industrial enterprise evaluated TandemTrace as its autonomous Tier 1 and threat-hunting layer. The requirement was explicit: production telemetry stays in the customer-controlled environment, integrations remain read-only, and analysts retain approval over every escalation and response.
The evaluation explicitly required a deployment path inside the enterprise environment, with telemetry retained within the selected boundary.
The architecture allowed an approved private frontier-model deployment instead of requiring inference through a shared public service.
TandemTrace could retrieve SIEM alerts, search underlying events, and enrich from EDR—but could not change production security controls.
These bars show requirements and targets—not claimed achieved outcomes. The customer defined the gates before evaluating the system.
One or several SIEMs, endpoint platforms, identity systems, cloud logs, and internal sources.
Investigates, correlates, hunts, and builds evidence without rerouting logs or installing endpoint agents.
Auditable findings enter existing workflows. Response remains human-approved and policy-controlled.
Autonomy applies to investigation. Authority over containment and response stays with your team.
The formal target was at least 95% agreement on sampled alert verdicts—not an unmeasured claim of autonomous accuracy.
Queries, pivots, evidence, reasoning, and escalation context had to be available for analysts to review and challenge.
The initial scope established the investigation path; later phases added direct EDR, threat intelligence, and additional telemetry without replacing the existing stack.
Walk through deployment boundaries, private-model options, integrations, audit requirements, and response controls with our team.