Product docs
How kymeer breaks the mould
Every SOC platform on the market was cast from the same mould: a place to store logs, a threshold-alert engine bolted on top, and a human being expected to do the actual thinking. kymeer was built the other way round — the thinking comes first.
Why kymeer is different
Legacy SIEMs ask you to accept cloud lock-in, consumption billing that surprises you at scale, and AI you can't audit. kymeer is built around three commitments instead: sovereignty, governed AI, and evidence you can defend.
Meet Kymeer Tao.
Kymeer Tao is the analyst that never clocks out — it reads evidence, reaches a verdict, triages the alert, closes the case, and remediates, independently. Every action it takes is traceable back to the evidence row that justified it: nothing it says is unfounded, and nothing it does is invisible.
And unlike every other "AI SOC" pitch on the market, we don't tell you which model is behind Kymeer Tao — on purpose. You get outcomes, not a dependency on one LLM vendor's brand, pricing, or roadmap. Tao is engineered to reach a verdict a strong analyst would reach — not to imitate a specific chatbot's writing style.
The result: search that answers in under a second instead of timing out, an AI workforce that actually closes the loop instead of just flagging it for you, and an evidence trail rigorous enough to defend in front of a board or a regulator.
Governed AI, on your terms
Every AI-driven feature in kymeer — search, Kymeer Tao's investigations, autonomous rule authoring — answers to one control you own. It lives at Administration → Platform Config → AI / LLM (/admin/settings/ai_llm), and it's a live setting: flip it and it takes effect in under a minute, no restart, no ticket to your vendor.
That's what "governed" actually means here — not a marketing word, a real switch, in your hands.
Roles & navigation
No more juggling access control across three different tools. One role model, cumulative by tier — Analyst → Senior Analyst → Tenant Admin → MSSP Admin → Platform Admin — enforced server-side on every single action, not just hidden menu items.
Agents
Rolling out endpoint visibility usually means chasing installers across three operating systems and hoping the deployment token didn't just leak in a Slack channel.
Add an agent, pick a platform — Linux, Windows, macOS — and get a one-time, tenant-scoped token plus a copy-paste install one-liner. Shown once, revocable any time, never sitting around waiting to be stolen.
Collectors
Most platforms make you pick a log format up front and hope every device on your network agrees to speak it.
A kymeer Collector takes raw Syslog, CEF, LEEF, key=value, or JSON from as many devices as you point at it — parsing happens centrally, not on the box, so the collector never becomes the bottleneck.
Connectors
Waiting on a vendor's next quarterly release to finally ship the parser for a tool you're already running is not a plan.
Pick a connector from the catalog, or build a custom one in minutes: connection, auth, a live test pull against the real target before anything saves. If it doesn't work, you know immediately — not three weeks later in a support ticket.
Ask kymeer
Ask your current SIEM a real question over 90 days of history and watch the spinner. Most analysts just stop asking.
Ask kymeer the same question in plain English and get an answer in under a second — tested, not a marketing number. Complex questions run as a sequence of steps automatically, and you can see every step it took to get there.
Alert triage
Your queue never goes down, and most of what's in it is noise nobody has time to confirm.
Kymeer Tao triages independently — every alert gets read, assessed, and acted on before a human ever has to look at it. Your team stops drowning in a queue and starts working the incidents that actually matter.
AI SOC Analyst
Junior analysts don't have ten years of pattern recognition, and your senior analyst doesn't have time to look at every single alert personally.
The AI SOC Analyst Worker reads the enriched evidence, forms a verdict, and shows its work with citations back to the evidence itself — the way your best analyst would, on every alert, every time, at 3am included.
Entity-Graph UEBA
An attacker with valid credentials, behaving almost normally, doesn't trip a single signature rule.
kymeer baselines every user, host, and service on a living relationship graph — not in isolation, but against who and what they actually talk to — so a first-ever connection between a service account and a database it's never touched lights up immediately.
Passive Auditor
The slow campaigns — spread across days, never crossing any one rule's threshold — do the most damage precisely because nothing ever fires.
Passive Auditor clusters weak signals across days and entities into full attack-path cases, and — like Kymeer Tao — closes and remediates independently once it has the picture. The analyst that never sleeps and never lets a low-and-slow campaign finish quietly.
Cases
Evidence lives in the SIEM, the ticket lives in Jira, and the actual timeline lives in someone's memory by the time the report is due.
kymeer cases sit natively next to the evidence — assignments, comments, verdicts, and the full audit trail in one place, so nothing gets lost in a copy-paste between tools.
MITRE ATT&CK coverage
Most teams don't find out what they're blind to until an auditor asks and everyone scrambles.
kymeer's coverage map is live — every rule, every case, every AI-authored proposal mapped to ATT&CK in real time, version-pinned to the current framework, exportable straight to Navigator.
Detection rules & Sigma import
Writing new detection content from scratch for every emerging TTP is slow — and most platforms go completely dark the moment OT or ICS enters the picture.
Full manual rule authoring, native Sigma import (drop in a file or paste YAML, get an import report back), and detection coverage that speaks industrial protocols — Modbus and others — on the same schema as your IT estate. One platform watching both worlds.
AI-authored rules
kymeer drafts candidate detection rules from attacks your existing rules missed, backtests them against your own data, and queues them for review — closing your coverage gaps before the next auditor conversation, not after.
Automation & remediation
Response playbooks that live in a wiki nobody updates are not a response plan.
An Action Registry, a Playbook Designer, an AI-draft-playbook assistant, and a remediation catalog — the actions your team actually takes, versioned and ready to fire the moment Kymeer Tao or Passive Auditor calls for them.
Reporting engine
Audit season usually means a week of manual screenshot-and-paste before the board deck is ready.
Report Packs, Templates, Saved Views, Dashboard Snapshots, Incident and Executive Summaries — a real DSL-to-document pipeline with dozens of built-in packs, plus a prompt-to-report flow for anything bespoke.
Users & roles
"Who touched what, and can you prove it?" is unanswerable in most platforms.
Every role change, every access grant, every action is server-enforced and logged — invite by email and role, and know exactly who can see what, always.
Parser Studio
A format nobody's ever seen before usually means weeks of back-and-forth with a vendor before it's usable.
Point-and-bind parser authoring against your own raw, unparsed payloads — build a working parser against real samples in minutes, not a support ticket.
Data rights
A single data-subject request can eat two weeks of engineering time by hand.
A self-serve maker → checker → cooling-off → crypto-shred workflow for erasure requests, with a visible countdown and full audit trail — compliance you don't have to build a project plan around.
Dashboards
Command Center, Firewall Overview, Incident Response, Vulnerability Exposure, Computed Metrics, Health, Threat Intel, and a hash-chained Audit Log — every number on every one of them computed live from your actual data. No placeholders, no "coming soon" tiles.