What "managed" means here
- No infrastructure: no indexer, no manager node, no storage cluster to size, upgrade and back up.
- No rule maintenance: detections, the rating policy and the vulnerability data are kept current by the platform.
- No agent maintenance: the agent verifies and installs its own updates, by signature, after they have run on SecAI's own production server.
- No tuning project before it is useful: the first report is the baseline, and findings are rated by context rather than by thresholds you have to set.
- What stays yours: the decisions. Approving a change, deciding what a finding means for your business, fixing what it points at.
What it is not
SecAI is not a managed detection and response service and not a security operations centre. Nobody at SecAI triages your alerts, calls you at three in the morning or investigates an incident on your behalf. If that is what you need, because a contract requires a staffed SOC or because nobody on your side can act on a finding, buy that service, and consider running SecAI under it: several of the providers who deliver it use a platform like this one to do it.
What replaces the people
The work a small team cannot staff is the routine part: reading authentication logs, noticing the same address failing forty times, remembering to check whether the new CVE affects anything installed, looking at what changed on the server last week. SecAI does that continuously and handles the one response that is safe to automate, blocking an attacking address, on its own. What reaches you is what needs a decision, in plain words, with the evidence and the undo; a daily summary says what was handled, what is being watched and what needs an expert.
Compared with running it yourself
An open-source SIEM is free to download and expensive to run: servers to host it, storage that grows, rules to write and tune, upgrades to plan, and a person who understands all of it. For an organisation that needs wide log correlation and has that person, it is the right tool. For a team whose problem is a handful of Linux servers and whose security person is also the developer, the operating cost is the whole cost, and it is what a managed platform removes.
What you still have to do
- Install the agent, once per server, with one command.
- Choose each server's mode: Automatic, or Awaiting Approval.
- Read the findings that ask for a decision, and decide.
- Keep backups, updates and access hygiene in order; SecAI tells you when they are not, and does not do them for you.
What it costs
Plans start at $69 a month per server, with a 14-day free trial and no card to start. There is no per-gigabyte ingestion charge and no infrastructure bill of your own, because there is no infrastructure of your own.