Proof and ROI

Measured by users across key metrics

Five evaluators scored LogLM on false negatives, false positives, time to detect and time to adapt. Below, their results, their words, and a model that converts them into the return for your own SOC.

Relative detection qualityIllustrative
Policy & signaturesFP: Brittle
Precision
Recall
LLM wrappersFP: 30%+ — too high
Precision
Recall
LogLMFP: Low
Precision
Recall
Evaluations

Across four key measurements

Thanks to the rise of AI powered attackers, the still important false positive rate is no longer sufficient to determine the effectiveness of a cybersecurity system. Today the ability of a system to detect all attacks, quickly, with a minimal amount of time and money required for ongoing operations has become equally important.

EvaluatorFalse negFalse posMTTDTo adapt
BNYGlobal custodian bank0.9%2.1%from 52%<3 min15 minfine tuning
Deutsche TelekomTelecommunications2.1%NGFW 72%~1.3%<1 min0 to 5 minfine tuning
Top four bankGlobal bank0.7%<1%from 73%<1 min0 minzero shot
TAC for OTOperational technology0%NGFW saw none2%2 min0 minzero shot
On TAC's WS3 water-plant range, LogLM surfaced a rogue HMI with no signature, device rule, or fine tuning written for that endpoint. The TAC independently confirmed that endpoint as the source of the malicious behavior.
Mega CDN vendorInternet infrastructure2.1%0.08%1 min0 minzero shot

Scores reported at zero shot unless the time to adapt column shows fine tuning. False negatives measured against the labelled evaluation set for each environment. Next generation firewall comparison shown where the customer ran one in parallel.

Rather score it yourself? SOCBench is an open benchmark for security operations, created by DeepTempo and free for anyone to run against any tool, ours included. socbench.org
In their words

DeepTempo is delivering a powerful analyst-assistant capability that adds true plant-operating-state semantic analysis, pairing its established IT analysis with meaningful, plant-aware OT analysis.

Steve Hutchinson, Director of Research, Technology Advancement Center

LogLM bested our in-house models before fine tuning, and once fine tuned it performed at well below a 1% false positive rate.

Analytics lead, cyber, top four bank

Vigil is simple to customize, and has allowed us to use our own AI models for reasoning, saving costs and increasing our confidence versus the black box AI SOCs we evaluated.

Threat investigation lead, North American carrier
Graduated BNY's 2025 Ascent Program, a six month proof-of-concept program run by BNY's Strategic Partnerships, Investments and Innovation team.
Tokenomics

Cost per event as volume climbs

A SOC metered by token spend can be attacked through its own bill. Bounded inference at the data layer and routed execution in Vigil close that path.

Token-metered agents
Spend climbs with every event
Bounded LogLM inference
Flat across four volume steps
Event volume, left to right: 1x · 2x · 4x · 8x
Return model

Your environment, against the evaluations

Defaults come from the sector nearest yours. Change any of them.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Other. BNY.
Missed 0.9% of the evaluation set. False positives fell from 52% to 2.1%, with detection in under three minutes after fifteen minutes of fine tuning.
Annual value
$3,104,091
0 alerts a day go untriaged at this staffing level
Missed attacks
$0
coverage of what goes untriaged
SIEM ingest
$0
45% less reaching the SIEM
AI SOC tokens
$0
noise never reaches an agent
Analyst time
$0
0 hours reclaimed
Dwell time
$0
hours to minutes
Adaptation
$0
tuning and rule upkeep avoided

Triage at 20 minutes per alert, analyst capacity 1,800 hours, loaded rate $85. Residual false positives at the rate measured in your sector. SIEM and inference at $2,000 per TB per year. AI SOC investigation at $0.40 per alert. Detection engineering at 0.12 FTE per analyst. Breach cost and frequency scaled by site size. Conservative applies a 0.6 factor throughout.

Take the numbers with you

A one-page business case carrying your inputs, our assumptions and the arithmetic. Pricing is small, medium or large, and every license carries LogLM, Vigil and the management code.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Sent
Your business case is on its way

The one-page business case for is heading to , carrying every input from the model above.

Request a Demo

See what LogLM and Vigil add to your stack

Run a 30-day assessment. LogLM analyzes your operational telemetry and reports what your stack missed. Vigil, the open source AI SOC, turns the findings into action.