Detection without rules.
Routing without loss.
SIET watches what talks to what. An attacker does not need to match a pattern anyone has written down; they just need to do something, and doing something shows up in the shape of your estate.
No signatures. No rules to write. No threat feed, no training runs. All it needs is a sense of what your estate normally looks like, and it works that out on its own.
Core detects. Enterprise also routes.
Same detector in both. Enterprise adds the layer that decides what your SIEM ever has to index in the first place.
SIET-Core
DetectionOne annual fee, whole estate
A detection layer that bolts on to the SIEM you already run. SIET models the estate, learns what each part of it normally does, and raises a case when something departs from its own history. Cases land in your SIEM; nothing else changes.
- /One annual fee covering the whole estate. Nothing metered: not users, endpoints or GB
- /No signatures, no rules, no attack knowledge, no model training
- /Cases arrive correlated, with the timeline and evidence attached
- /Zero-knowledge architecture: only anonymised metric vectors leave the environment
- /Runs on commodity hardware, in memory, with no cloud dependency
19 / 19
Attacked hosts surfaced
18 in cases, 1 as an observation
<1 min
Median time to detect
3
Cases on a benign day
0
Signatures written
SIET-Enterprise
Detection and routingLicence plus a share of what it saves you
Everything in Core, plus the routing layer. SIET sits in front of your SIEM and forwards only what is structurally significant. Everything else goes to archive-class object storage at full fidelity, not into a per-GB index. This is where the money is.
- /Priced against the saving, so we are paid for the reduction we deliver
- /The remainder goes to Glacier-class archive, not a cheaper SIEM tier
- /Improves detection quality, because the SIEM only sees what matters
- /Full retention is unchanged: 100% of raw logs reach cold storage
- /Not sampling. Every event is evaluated and folded into the baselines
99.4%
Never reaches the index
72.9%
Avoided, full test week
100%
Raw logs retained
None
Events sampled away
Measured on a benchmark you can check.
SIET was evaluated against CICIDS2017, the intrusion dataset published by the Canadian Institute for Cybersecurity. The baseline is warmed on two benign days and frozen, then every attack day is replayed independently against that identical state. A benign control day runs on every replay, and its output is the false positive figure.
The dataset is public, so every figure can be reproduced rather than taken on trust.
100%
Attacks detected
every attack in the dataset
19 / 19
Attacked hosts surfaced
18 in cases, 1 as an observation
<1 min
Median time to detect
most inside the first minute
3
Cases on a benign day
not thousands of alerts
Shape is the signal.
SIET learns your estate at a finer grain than the machine. It is not just what a server does, but what each part of it does: the services it offers, the accounts that appear on it, the machines it talks to. Normal is held per thing, not averaged across the network.
That resolution is what lets it say something a coarser model cannot: SMB is normal on the file server, and has never once happened on the printer. Both are true at the same time, and only one of them is worth waking someone up for.
01
It grows
Something does far more than it has ever done. Load, brute force, floods.
02
It spreads
Something reaches further than it has ever reached. Scanning, propagation.
03
It appears
Something happens that has never happened here at all. The strongest signal of the three.
Isn’t this just anomaly detection?
Every detection is anomaly detection. A rule that fires on PowerShell spawning from a document is somebody’s claim about what is abnormal. The difference is that they made that claim once, in a different environment, and froze it.
So the real distinction is not rules against anomalies. It is static against derived. A rule library was written against someone else’s estate and has not moved since. SIET works out what is normal here, and keeps working it out as here changes. That is also why rules decay: not because the technique changed, but because the environment did and the constant did not.
Derived, not chosen
This is the opposite of a rule of thumb. Nobody picks a number, so there is nothing for you to set and nothing shipped as a default you later discover was wrong for your estate. What counts as unusual is computed from what that part of your estate has actually done, which is why a quiet controller and a busy one are each judged on their own terms without anyone configuring either.
Something with no history is not given a free pass. A machine nobody has seen before is precisely what should fire, and it does.
Architecture
- /In memory. No disk-bound graph database in the detection path
- /Commodity hardware, deployed inside your environment
- /No cloud dependency and no payload string inspection
- /Zero-knowledge: only anonymised metric vectors leave the environment
UK patent pending, application GB2619729.3, filed 24 August 2026, covering the derivation of per-component thresholds from recorded history and the selection of storage tier from the resulting structural state.
Deterministic detection, adaptive interpretation
SIET is not an AI that detects attacks. Detection is structural and deterministic. A learned model sits downstream of it, where being wrong is recoverable, and it never decides whether something is an attack.
01
Structural detection
“What changed?”
The estate’s own history, at a per-component grain.
02
Evidence
“What supports this?”
Corroborating structure, assembled into one case with its timeline.
03
Adjudication
“Seen this here before?”
A per-endpoint disposition memory that weighs weak signals in context.
04
Analyst
“What should I do?”
A case, in the SIEM you already run.
Why learning is kept out of the detection path
A learned model that decides what counts as an attack can be argued into a relaxed state, and an attacker resident while it trains becomes part of what it considers normal. Detection therefore stays entirely in the graph.
The adjudication layer exists because the false positives share no property that a single global constant could catch. Five global mechanisms were tried against them and four made things worse. A small memory per endpoint, protected from every other endpoint, outperformed a fitted model across fourteen features.
There is no console to learn.
SIET is deployed as a closed appliance inside your environment. It consumes telemetry, maintains the structural model in memory, and emits cases into the SIEM your analysts already use. There is no separate dashboard for them to live in and no second queue to work.
That is deliberate. A detection product that requires its own console competes with the tool the team is measured on. SIET is judged by what arrives in the SIEM.
Runs where the data is
Inside your environment, on commodity hardware, in memory. No cloud dependency and no payload string inspection.
Outputs into your SIEM
Cases land in their own index and are alerted on unconditionally. No new interface, no rule logic to write around them.
Zero-knowledge by architecture
Only anonymised metric vectors ever leave the monitored environment. The estate is never reconstructable from what exits.
The structural state decides what your SIEM sees.
Events implicated in a structural departure go to the hot index. Everything else goes to archive-class object storage at full fidelity, not into a per-GB index. Nothing is dropped, trimmed or sampled: every event is read before the decision is made.
On the benign control day of the benchmark, 99.4% of events never reached the hot index. A year of 1 TB/day costs about £1,750 to hold in deep archive and about £886,000 to index.
The full cost model →Where the data goes
See it against your own data.
The honest test is an A/B: run SIET alongside your existing alerting, switch nothing off, and after a month compare cases raised, alerts missed by each, and actual indexed volume.