FAQ

Questions buyers and builders ask

Deployment, data handling, LogLM, Vigil, the assessment, and how DeepTempo compares with the alternatives. Each answer has a link you can share.

Data and deployment

Does our data leave our environment?

Not in production. LogLM, Vigil, telemetry, model weights, and findings run inside your boundary: on premises, fully air-gapped, in your data lake, or in your own cloud or Kubernetes. There is no hosted tier. The one exception is your choice during an assessment: send us a sample to score, or run the assessment on premises so nothing leaves.

What AI model does Vigil use?

You choose it. With a local model through Ollama, nothing leaves the machine. With Claude or OpenAI, requests go to the endpoint you configure, under your keys and your policies. LogLM itself never calls a hosted model.

Do we need special hardware?

No. LogLM runs on infrastructure you already operate, and many deployments need no GPU. It scores telemetry in batches or as a continuous stream.

Does DeepTempo replace our SIEM?

No. LogLM runs upstream of the SIEM, surfaces the attacks rules miss, and lets bulk telemetry move to lower-cost storage. Teams that do this report SIEM savings of up to 45%.

Do we have to disrupt operations to start?

No. DeepTempo runs in your data lake or Cribl pipeline and inside the workflows your SOC already runs. Nothing is ripped out.

LogLM

Do we need labeled data or months of tuning?

No. LogLM is pretrained on security telemetry and works zero-shot, with no baselining period. Where an environment warrants it, your team adapts the classifiers in minutes, inside your boundary.

Why an encoder rather than a large language model?

Volume. An encoder scores the full telemetry stream on fixed compute; a generative model is priced per token and suits the rare, semantically strange case. Teams run LogLM on the stream and reserve reasoning models in Vigil for escalations.

What telemetry does LogLM read?

Security logs and telemetry broadly: flow records, Zeek, firewall, DNS, proxy, identity, cloud, and endpoint sources. Normalization is automatic.

Does it work in OT environments?

Yes. The Technology Advancement Center evaluated LogLM on its water-plant range: passive, on premises, with no special-purpose hardware. See the OT page.

Vigil

Is Vigil really free?

Yes. Vigil is open source under Apache 2.0, and it is not open core. Vigil Assured, the maintained and hardened track for production, comes with the Intelligent Defense Platform license.

Can we run Vigil without LogLM?

Yes. LogLM is an optional integration. Vigil runs your existing detections, including federated detections in Splunk and Elastic, on its own.

Can our team read the code?

Yes. Agents are readable Python, workflows are Markdown files under your change control, and integrations use the open Model Context Protocol.

How does automation earn trust?

Vigil may demote itself; only people promote it. Before an automation runs, Vigil checks projected cost and confidence against thresholds your team sets, and asks a person when either drifts. The approach comes from a decade of StackStorm deployments.

Assessment and pricing

What does the assessment involve?

You choose the path: send us a sample of historical telemetry, or run the assessment on premises. Either way you receive a findings report with evidence, a comparison with what your current tools alerted on, and a readout with our engineers. It is free. Request one.

How is DeepTempo priced?

Per site, with Small, Medium, and Large options sized by telemetry volume and an enterprise option for many sites. One license covers LogLM, Vigil Assured, and platform support; you deploy either or both as you see fit.

How do you prove an AI SOC works?

With open measurement. SOCBench scores any detection stack, ours included, on precision, recall, false positives, MITRE coverage, cost, and drift. Our evaluation results, with definitions and conditions, are on the results page.

Comparison

Three ways to run a modern SOC

Rules and SOAR, an AI SOC built as prompts over someone else's model, or a detection model plus an open AI SOC your team owns.

 

Rules and SOAR

LLM-wrapper AI SOC

LogLM and Vigil

Detection basis

Signatures and correlation rules

Prompts over alerts produced by other tools

A foundation model on raw telemetry, plus your rules

Novel attacks

Missed until someone writes a rule

Missed when no upstream alert fires

Detected as concerning sequences, zero-shot

Time to value

Rule-writing projects

Quick setup, bounded by input quality

Findings from the first sequences scored

Cost at volume

SIEM ingest and analyst hours

Per-token fees that rise with alert volume

Fixed compute; reasoning reserved for escalations

Where data goes

Your SIEM

Often a vendor cloud and a hosted model

Stays inside your boundary

Inspectability

Rules readable; playbooks often proprietary

Agent logic opaque

Apache 2.0 code and Markdown workflows

Learning loop

Vendor content updates

Owned by the vendor

Owned by your team

Still have a question?

Ask an engineer, or test LogLM on your own telemetry.