Questions buyers and builders ask
Deployment, data handling, LogLM, Vigil, the assessment, and how DeepTempo compares with the alternatives. Each answer has a link you can share.
Data and deployment
Does our data leave our environment?
Not in production. LogLM, Vigil, telemetry, model weights, and findings run inside your boundary: on premises, fully air-gapped, in your data lake, or in your own cloud or Kubernetes. There is no hosted tier. The one exception is your choice during an assessment: send us a sample to score, or run the assessment on premises so nothing leaves.
What AI model does Vigil use?
You choose it. With a local model through Ollama, nothing leaves the machine. With Claude or OpenAI, requests go to the endpoint you configure, under your keys and your policies. LogLM itself never calls a hosted model.
Do we need special hardware?
No. LogLM runs on infrastructure you already operate, and many deployments need no GPU. It scores telemetry in batches or as a continuous stream.
Does DeepTempo replace our SIEM?
No. LogLM runs upstream of the SIEM, surfaces the attacks rules miss, and lets bulk telemetry move to lower-cost storage. Teams that do this report SIEM savings of up to 45%.
Do we have to disrupt operations to start?
No. DeepTempo runs in your data lake or Cribl pipeline and inside the workflows your SOC already runs. Nothing is ripped out.
LogLM
Do we need labeled data or months of tuning?
No. LogLM is pretrained on security telemetry and works zero-shot, with no baselining period. Where an environment warrants it, your team adapts the classifiers in minutes, inside your boundary.
Why an encoder rather than a large language model?
Volume. An encoder scores the full telemetry stream on fixed compute; a generative model is priced per token and suits the rare, semantically strange case. Teams run LogLM on the stream and reserve reasoning models in Vigil for escalations.
What telemetry does LogLM read?
Security logs and telemetry broadly: flow records, Zeek, firewall, DNS, proxy, identity, cloud, and endpoint sources. Normalization is automatic.
Does it work in OT environments?
Yes. The Technology Advancement Center evaluated LogLM on its water-plant range: passive, on premises, with no special-purpose hardware. See the OT page.
Vigil
Is Vigil really free?
Yes. Vigil is open source under Apache 2.0, and it is not open core. Vigil Assured, the maintained and hardened track for production, comes with the Intelligent Defense Platform license.
Can we run Vigil without LogLM?
Yes. LogLM is an optional integration. Vigil runs your existing detections, including federated detections in Splunk and Elastic, on its own.
Can our team read the code?
Yes. Agents are readable Python, workflows are Markdown files under your change control, and integrations use the open Model Context Protocol.
How does automation earn trust?
Vigil may demote itself; only people promote it. Before an automation runs, Vigil checks projected cost and confidence against thresholds your team sets, and asks a person when either drifts. The approach comes from a decade of StackStorm deployments.
Assessment and pricing
What does the assessment involve?
You choose the path: send us a sample of historical telemetry, or run the assessment on premises. Either way you receive a findings report with evidence, a comparison with what your current tools alerted on, and a readout with our engineers. It is free. Request one.
How is DeepTempo priced?
Per site, with Small, Medium, and Large options sized by telemetry volume and an enterprise option for many sites. One license covers LogLM, Vigil Assured, and platform support; you deploy either or both as you see fit.
How do you prove an AI SOC works?
With open measurement. SOCBench scores any detection stack, ours included, on precision, recall, false positives, MITRE coverage, cost, and drift. Our evaluation results, with definitions and conditions, are on the results page.
Three ways to run a modern SOC
Rules and SOAR, an AI SOC built as prompts over someone else's model, or a detection model plus an open AI SOC your team owns.
Rules and SOAR
LLM-wrapper AI SOC
LogLM and Vigil
Detection basis
Signatures and correlation rules
Prompts over alerts produced by other tools
A foundation model on raw telemetry, plus your rules
Novel attacks
Missed until someone writes a rule
Missed when no upstream alert fires
Detected as concerning sequences, zero-shot
Time to value
Rule-writing projects
Quick setup, bounded by input quality
Findings from the first sequences scored
Cost at volume
SIEM ingest and analyst hours
Per-token fees that rise with alert volume
Fixed compute; reasoning reserved for escalations
Where data goes
Your SIEM
Often a vendor cloud and a hosted model
Stays inside your boundary
Inspectability
Rules readable; playbooks often proprietary
Agent logic opaque
Apache 2.0 code and Markdown workflows
Learning loop
Vendor content updates
Owned by the vendor
Owned by your team
Still have a question?
Ask an engineer, or test LogLM on your own telemetry.
