Working prototype — preparing early-access pilots

AI-native security triage for SOC teams, built on Claude.

PurifySec turns raw SIEM and EDR alerts into structured, evidence-backed triage notes, MITRE ATT&CK mappings and incident summaries. Claude does the reading, querying and drafting. Your analysts approve every output.

Built on Anthropic's Claude API (Messages API, tool use, structured outputs). Defensive use only, on systems customers own or are authorized to manage. No customers yet.

triage.json — illustrative example
// Illustrative example with fictional sample data
{
  "alert": "Multiple failed logins, then success",
  "sources": ["edr", "identity_provider"],
  "summary": "14 failed sign-ins for one account from
              a new IP, then a successful login.",
  "suggested_priority": "high",
  "attack_candidates": [
    { "id": "T1110", "name": "Brute Force" }
  ],
  "evidence": ["idp event #1-14: auth_failure",
               "idp event #15: auth_success"],
  "next_steps": ["Verify with account owner",
                 "Review MFA logs for the session"],
  "status": "awaiting_analyst_approval"
}
Sample output for illustration only. Not a real customer or incident.

The problem

SOC analysts spend much of their day on repetitive triage and write-ups.

Alert queues from SIEM and EDR tools keep growing, while the people who investigate them are few. A lot of analyst time goes into reading raw logs, pulling context from several consoles and writing the same kinds of summaries and reports.

1

Alert fatigue

Large volumes of alerts, many of them low-risk, make it hard to focus on the ones that matter.

2

Scattered context

Evidence sits across log sources, hosts, identities and tickets, and must be pieced together by hand.

3

Reporting overhead

Incident summaries, ATT&CK mappings and remediation notes take time to write consistently.

Our approach

Claude at the core, analysts in control.

PurifySec is an application built on Anthropic's Claude API, not a general chatbot. Claude reads alerts, calls read-only tools to gather related events, and returns a structured triage record your team can check, edit and approve. Every suggestion is designed to link back to the evidence it came from.

Our product work is the workflow around the model: connectors, tool definitions, output schemas, model routing, evaluations, prompt-injection defenses, review queues and audit history.

  • Structured, not free text. Triage results come back as schema-validated JSON: verdict, priority, evidence, ATT&CK candidates, next steps.
  • Evidence-linked. Each claim is designed to cite the source events it relies on, so analysts can verify it quickly.
  • Read-only by design. Claude's tools can query data; they cannot change your systems.
  • Human approval gate. Nothing leaves draft state without an analyst's sign-off.

How it works

From raw alert to approved triage in four steps

This is the workflow our prototype is built around. Some parts are still being completed; see the Technology page for the full planned design.

  1. 1

    Ingest alerts

    Read-only connectors pull SIEM/EDR alerts and logs from systems the customer owns. Data is normalized, secrets are redacted and log text is marked as untrusted.

  2. 2

    Claude analysis with tool use

    Claude, via the Anthropic Messages API, reads the alert and calls read-only tools (event search, host and user context) to gather what it needs.

  3. 3

    Structured triage & ATT&CK mapping

    Output is a schema-validated JSON record: suggested verdict and priority, evidence, candidate MITRE ATT&CK techniques and next steps.

  4. 4

    Analyst approval

    An analyst approves, edits or rejects the draft. Only approved outputs become tickets or reports, and every decision is audit-logged.

Capabilities

A defensive assistant for the SOC workflow

We have a working prototype and are preparing early-access pilots. The capabilities below describe the product we are building; some are still being completed and refined.

⚑

Alert triage

Summarizes SIEM/EDR alerts, groups related events and drafts a suggested priority for analyst review.

≡

Incident summaries

Turns raw alerts and analyst notes into clear timelines and summaries for handoffs and management.

⌕

Log analysis

Explains suspicious patterns in logs from customer-owned systems in plain language.

◎

MITRE ATT&CK mapping

Suggests candidate ATT&CK techniques for observed behavior, with reasoning analysts can verify.

{ }

Secure code review

Reviews code the customer owns for common security weaknesses and drafts remediation reports.

✎

Remediation & reports

Drafts remediation guidance and incident reports in English or Korean for analysts to edit and approve.

Built on Claude

How we plan to use the Claude API

Claude is the core of PurifySec: the product's AI features are designed to run on Anthropic's Claude models. Read the technical design →

Messages API + tool use

Claude calls typed, read-only tools to query SIEM/EDR data during an investigation instead of guessing.

Structured JSON outputs

Every triage result follows a fixed schema that is validated before it reaches the review queue.

Prompt caching

Stable instructions, tool definitions and long log context are cached to control cost and latency.

Model routing

A smaller Claude model for high-volume first-pass triage; a larger Claude model for deep investigations.

Evaluation harness

Planned regression tests for triage accuracy, ATT&CK mapping and evidence faithfulness on every prompt or model change.

Prompt-injection defenses

Log content is treated as untrusted data, never as instructions, with read-only tools and human approval as backstops.

Human-in-the-loop by design

PurifySec suggests. People decide.

✓ In scope (defensive)

  • Alert triage and incident summaries for SIEM/EDR
  • Log analysis on customer-owned or authorized systems
  • MITRE ATT&CK mapping
  • Secure code review of customer-owned code
  • Remediation guidance and report drafting

✕ Out of scope

  • Penetration testing or attacking any system
  • Writing exploits or proof-of-concept attack code
  • Malware analysis or creation
  • Automated actions without analyst approval
  • Use on systems without the owner's authorization

Aligned with Anthropic's Usage Policy. Read our Responsible Use policy for details.

Roadmap

Where we are, and what is planned

We only list dates for things that have happened. Everything after the current stage is a plan, not a commitment.

  1. Current stage

    1. Working prototype

    • Working prototype built on the Claude API
    • Completing connectors, output schemas and the review queue
    • Evaluation harness in design (synthetic and sample data)
  2. Planned

    2. Design-partner pilots

    • Early access for a small number of SOC teams
    • Read-only connectors to their SIEM/EDR tools
    • Measure triage quality against analyst decisions
    • Tune model routing, prompt caching and cost per alert
  3. Planned

    3. Enterprise readiness

    • SSO and role-based access for analyst teams
    • Audit-log export and data-retention controls
    • Security documentation for enterprise review
    • More connectors, guided by pilot feedback

Status: working prototype — preparing early-access pilots

PurifySec is the AI division and first AI product of Purify Solution Co., Ltd., a Korean solutions company incorporated in March 2026. We have a working prototype and are preparing an early-access pilot program with a small number of security teams. We have no customers yet and no outside funding, and we will say so plainly until that changes. PurifySec is not affiliated with Anthropic.

Interested in an early-access pilot?

Tell us about your team, the SIEM/EDR tools you use and the triage work you would like help with. We will reply by email.

Email [email protected]