Documentation
SecAI documentation
What SecAI installs, collects, watches, blocks and changes, written from the implementation and dated. Start with the quickstart; the Trust Center holds the same facts with their sources.
Getting started
The agent
The agentOne static binary, reporting every minute, verified by signature.Data collectedThe telemetry categories, from the agent's payload, and what never leaves the server.PermissionsWhy root, what it reads, and the short list of what it may change.Network requirementsOutbound HTTPS to one host. No inbound port.
Detection
Threat detectionWhat the agent watches for, by signal, and how findings are rated.File integrityThe paths, the hashes, and the two cases where text travels.CVE monitoringInstalled packages, matched against OSV.dev every twelve hours.AI auditsWeekly and on demand, evidence attached, within your plan's allowance.
Response
IP blockingThree sightings in thirty minutes, one firewall rule, gone in 24 hours.Automatic modeAdds exactly one thing: blocking attacking addresses without asking.Approval modeAwaiting Approval: everything waits, including a block.RollbackEvery configuration change keeps a copy first; undo is one click.
Integrations
Help
Reviewed against the implementation on 2026-09-20.