AI-native security triage for SOC teams, built on Claude.
PurifySec turns raw SIEM and EDR alerts into structured, evidence-backed triage notes, MITRE ATT&CK mappings and incident summaries. Claude does the reading, querying and drafting. Your analysts approve every output.
Built on Anthropic's Claude API (Messages API, tool use, structured outputs). Defensive use only, on systems customers own or are authorized to manage. No customers yet.
// Illustrative example with fictional sample data { "alert": "Multiple failed logins, then success", "sources": ["edr", "identity_provider"], "summary": "14 failed sign-ins for one account from a new IP, then a successful login.", "suggested_priority": "high", "attack_candidates": [ { "id": "T1110", "name": "Brute Force" } ], "evidence": ["idp event #1-14: auth_failure", "idp event #15: auth_success"], "next_steps": ["Verify with account owner", "Review MFA logs for the session"], "status": "awaiting_analyst_approval" }
The problem
SOC analysts spend much of their day on repetitive triage and write-ups.
Alert queues from SIEM and EDR tools keep growing, while the people who investigate them are few. A lot of analyst time goes into reading raw logs, pulling context from several consoles and writing the same kinds of summaries and reports.
Alert fatigue
Large volumes of alerts, many of them low-risk, make it hard to focus on the ones that matter.
Scattered context
Evidence sits across log sources, hosts, identities and tickets, and must be pieced together by hand.
Reporting overhead
Incident summaries, ATT&CK mappings and remediation notes take time to write consistently.
Our approach
Claude at the core, analysts in control.
PurifySec is an application built on Anthropic's Claude API, not a general chatbot. Claude reads alerts, calls read-only tools to gather related events, and returns a structured triage record your team can check, edit and approve. Every suggestion is designed to link back to the evidence it came from.
Our product work is the workflow around the model: connectors, tool definitions, output schemas, model routing, evaluations, prompt-injection defenses, review queues and audit history.
- Structured, not free text. Triage results come back as schema-validated JSON: verdict, priority, evidence, ATT&CK candidates, next steps.
- Evidence-linked. Each claim is designed to cite the source events it relies on, so analysts can verify it quickly.
- Read-only by design. Claude's tools can query data; they cannot change your systems.
- Human approval gate. Nothing leaves draft state without an analyst's sign-off.
How it works
From raw alert to approved triage in four steps
This is the workflow our prototype is built around. Some parts are still being completed; see the Technology page for the full planned design.
- 1
Ingest alerts
Read-only connectors pull SIEM/EDR alerts and logs from systems the customer owns. Data is normalized, secrets are redacted and log text is marked as untrusted.
- 2
Claude analysis with tool use
Claude, via the Anthropic Messages API, reads the alert and calls read-only tools (event search, host and user context) to gather what it needs.
- 3
Structured triage & ATT&CK mapping
Output is a schema-validated JSON record: suggested verdict and priority, evidence, candidate MITRE ATT&CK techniques and next steps.
- 4
Analyst approval
An analyst approves, edits or rejects the draft. Only approved outputs become tickets or reports, and every decision is audit-logged.
Capabilities
A defensive assistant for the SOC workflow
We have a working prototype and are preparing early-access pilots. The capabilities below describe the product we are building; some are still being completed and refined.
Alert triage
Summarizes SIEM/EDR alerts, groups related events and drafts a suggested priority for analyst review.
Incident summaries
Turns raw alerts and analyst notes into clear timelines and summaries for handoffs and management.
Log analysis
Explains suspicious patterns in logs from customer-owned systems in plain language.
MITRE ATT&CK mapping
Suggests candidate ATT&CK techniques for observed behavior, with reasoning analysts can verify.
Secure code review
Reviews code the customer owns for common security weaknesses and drafts remediation reports.
Remediation & reports
Drafts remediation guidance and incident reports in English or Korean for analysts to edit and approve.
Built on Claude
How we plan to use the Claude API
Claude is the core of PurifySec: the product's AI features are designed to run on Anthropic's Claude models. Read the technical design →
Messages API + tool use
Claude calls typed, read-only tools to query SIEM/EDR data during an investigation instead of guessing.
Structured JSON outputs
Every triage result follows a fixed schema that is validated before it reaches the review queue.
Prompt caching
Stable instructions, tool definitions and long log context are cached to control cost and latency.
Model routing
A smaller Claude model for high-volume first-pass triage; a larger Claude model for deep investigations.
Evaluation harness
Planned regression tests for triage accuracy, ATT&CK mapping and evidence faithfulness on every prompt or model change.
Prompt-injection defenses
Log content is treated as untrusted data, never as instructions, with read-only tools and human approval as backstops.
Human-in-the-loop by design
PurifySec suggests. People decide.
✓ In scope (defensive)
- Alert triage and incident summaries for SIEM/EDR
- Log analysis on customer-owned or authorized systems
- MITRE ATT&CK mapping
- Secure code review of customer-owned code
- Remediation guidance and report drafting
✕ Out of scope
- Penetration testing or attacking any system
- Writing exploits or proof-of-concept attack code
- Malware analysis or creation
- Automated actions without analyst approval
- Use on systems without the owner's authorization
Aligned with Anthropic's Usage Policy. Read our Responsible Use policy for details.
Roadmap
Where we are, and what is planned
We only list dates for things that have happened. Everything after the current stage is a plan, not a commitment.
- Current stage
1. Working prototype
- Working prototype built on the Claude API
- Completing connectors, output schemas and the review queue
- Evaluation harness in design (synthetic and sample data)
- Planned
2. Design-partner pilots
- Early access for a small number of SOC teams
- Read-only connectors to their SIEM/EDR tools
- Measure triage quality against analyst decisions
- Tune model routing, prompt caching and cost per alert
- Planned
3. Enterprise readiness
- SSO and role-based access for analyst teams
- Audit-log export and data-retention controls
- Security documentation for enterprise review
- More connectors, guided by pilot feedback
Status: working prototype — preparing early-access pilots
PurifySec is the AI division and first AI product of Purify Solution Co., Ltd., a Korean solutions company incorporated in March 2026. We have a working prototype and are preparing an early-access pilot program with a small number of security teams. We have no customers yet and no outside funding, and we will say so plainly until that changes. PurifySec is not affiliated with Anthropic.
Interested in an early-access pilot?
Tell us about your team, the SIEM/EDR tools you use and the triage work you would like help with. We will reply by email.
Email [email protected]