SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Layer 2 · Intelligence

Not automation. Decision Intelligence.

Most "AI security" is a chatbot bolted onto automation. Ours is a team: Lucy, the one agent you talk to, and the named specialists behind her, learned from 35 years of running complex networks. One door, sovereign, human-accountable.

The thesis

Everyone has models.
Almost no one has the data to teach them.

The biggest wins in AI don't come from generic automation, they come from learning a company's own know-how into the model. The frontier proved it: a system that learned to reason over real code found thousands of flaws humans missed. The lesson for security is the same, the moat isn't the model, it's the experience you can teach it.

Ours is 35 years of operating complex environments across hundreds of customers, millions of real decisions, incidents and resolutions. That is the fuel. Here is how we turn it into intelligence.

▸ Operational Intelligence, built-in, expertise embedded in the platform, not locked behind the managed-service layer. The design principle: centralize the foundation, distribute the intelligence, and make every capability operable by AI workflows, not only by expert humans.

How 35 years becomes foresight

Three ingredients make an AI that learns.

A learning AI needs more than logs. It needs static know-how, live transactional data, and an ontology that connects them by meaning, so agents reason about what's actually happening, not match strings.

Static know-how

35y of playbooks, firewall configs, L3 resolutions, architectures & threat knowledge

Transactional telemetry

Live logs, NetFlow, firewall & proxy events, identity & SASE traffic

Threat & world context

CVEs, MITRE ATT&CK, sovereign threat-intel feeds, asset & business context

The Open Systems Security Ontology

A living knowledge graph that links assets ↔ identities ↔ traffic ↔ threats ↔ resolutions. Static experience and live telemetry become one semantic model the agents can reason over.

Predict

See the incident before it happens

Validate

Tell real risk from the noise

Act

Resolve inside your boundary

▸ Static + transactional + ontology, the three things a genuinely learning AI requires. This is the part competitors can't shortcut.

The proof

It replicates the
L3 workflow.

Our Mission Control engineers and tech partners train agents on real ticket data for automated root-cause analysis. "Replicated" means the agent would have executed the exact same steps and tools as a human Level-3 engineer.

  • Trained on logs, firewall & ticket data from 35 years of operations
  • Human-in-the-loop approval boundaries
  • Runs 24/7, escalates when it matters
# lucy · autonomous root-cause lucy > investigating ticket #91044 › replaying 35y baseline patterns… match 98.2% → known failure class ✓ root cause isolated · BGP flap upstream act reroute --path optimal confidence 0.91, L3 review ✓ replicated human L3 in 37s
L3
agent level on root-cause analysis
35
years of training data
24/7
autonomous operation, escalates on demand
AI moves the goalposts

The questions keeping CISOs up since Mythos.

AI didn't just help defenders, it rewrote the attacker's economics. Here are the three problems every CISO now has, and how we answer them.

The patch race is now hours

AI finds and weaponises flaws faster than you can patch. Our answer: virtual patching at the SASE edge, we neutralise an exploit path on the network before you can deploy the fix.

edge mitigation · roadmap

The false-positive flood

AI scanners drown dev teams, reported false-positive rates near 70%. Our answer: validation grounded in decades of triaged incidents, so only real, reachable risk ever reaches a human. The backlog stops growing.

risk validation · roadmap

The flaw is at your supplier

Most exposure now lives in your supply chain, and you can't make them patch. Our answer: we contain at the edge so an unpatched vendor flaw simply can't be reached, and assess critical suppliers continuously, pre-vetted with frontier-lab tooling.

supply-chain assurance · roadmap

▸ Because we own the network and the security, we can act where others can only alert, the SD-WAN traffic itself becomes an AI asset.

Not autonomous-washing

A compound system, not a chatbot in a wrapper.

Model-agnostic, sovereign-first

No single-LLM lock-in. The best model per task, deployable inside your region, so your data stays in your jurisdiction.

Grounded, not guessing

Every answer is grounded on the ontology, real telemetry and historical evidence, with citations, not free-form generation.

Bounded autonomy

Propose → approve → act within limits. Dry-run before apply, instant rollback, full decision provenance.

▸ Proof, not promise: agents are replayed against thousands of historical L3 incidents, did they do what the human did?

Where the intelligence goes next

Built for the next security era. Roadmap

The threats of the AI era need new layers. These are the positions we're building toward, grounded in the same ontology.

AI Control Tower

Roadmap
govern the agents inside your business

Soon every team runs its own autonomous agents with their own permissions. We govern them, what they may do, how they behave, and stop them when they drift. Zero-trust, applied to AI itself.

Identity Governance Layer

Roadmap
misuse stays hard, even after a breach

Internal identities are the next front line. A continuous governance layer checks intent and context on every privileged action, so stolen credentials still can't do real damage.

Cyber-Resilience

Roadmap
contain the blast, roll back to known-good

When you're hit, speed of recovery beats everything. AI-driven containment limits the spread and restores a verified safe state, resilience as a first-class capability, not an afterthought.

Threat-Intel Sovereignty

Roadmap
your advantage when sharing is restricted

As nations restrict intel-sharing across borders, your threat-intel supply chain is both an asset and an exposure. We curate sovereign feeds that respect your jurisdiction, and manage the dependency so it can't become a single point of failure. A geopolitical risk, turned into an edge.

Check our homework

Three questions for every AI vendor.
Ours included.

Nobody should buy "we have AI" on trust. These three questions separate a real system from a wrapper, and here is where we answer each one in writing, no gate, no demo required.

▸ Every answer above is public and unpaywalled. When a vendor can only answer these three under NDA, that is an answer too.

Straight answers

What our AI is made of.

The questions a CISO asks the moment somebody says autonomous.

What makes your AI different from everyone's "AI"?

The teaching material. Ours learns 35 years of real operational data: playbooks, firewall configs, NetFlow, proxy events and every Level-3 resolution from running complex environments for hundreds of enterprises. A model is a commodity; the experience you can teach it is not. No competitor can buy ours, and one that started collecting last quarter cannot replay it.

Is this a chatbot with a wrapper around a foundation model?

No, and the design is the proof. It is a compound system: an ontology that links assets, identities, traffic, threats and resolutions by meaning, a team of task-specific specialist agents that reason over it, and grounding on real telemetry with citations rather than free-form generation. It is model-agnostic by design, the best model per task, deployable inside your region, so there is no single-LLM lock-in.

Does my data train a model that other customers benefit from?

Not your raw data, ever. The learning layer and the interface are separated on purpose. The specialist agents learn the full 35-year corpus inside the Open Systems boundary; no customer touches them directly. Lucy is the agent you talk to, scoped strictly to your tenant, drawing on the specialists' distilled playbooks and models but never on another customer's data. Cross-customer learning happens as patterns only, and only where compliance allows.

Can the AI change my network on its own?

Only within bounds you set. The pattern is propose, approve, act: Lucy diagnoses, explains and drafts the change with a stated confidence, and a human approves anything consequential. Dry-run before apply, instant rollback and full decision provenance are part of the loop. Bounded, reversible actions inside your tenant run without waiting; a change to a production path does not.

Which agents can I actually use today?

Lucy is live, and so is Nemesis. Hermes, Argus and Lex are rolling out; they ship with Lucy. Atlas, Prometheus, Calli and Kratos are coming soon and are labelled exactly that wherever they appear, including in the roster above. We would rather lose a deal on that answer than win one on a demo of something that does not ship.

How do you know the agent is right? What happens when it is wrong?

Agents are replayed against thousands of historical Level-3 incidents and scored on whether they would have taken the same steps and tools as the human who actually resolved it. That is what "replicated the L3 workflow" means here. When an agent is unsure or wrong, it escalates rather than acts, and a Level-3 engineer owns the outcome, 24/7.

Where do the models run, and in which jurisdiction?

In the region you require. Model-agnostic and sovereign-first means the inference can be pinned to your jurisdiction rather than following a vendor's default cloud. Your model provider is a jurisdiction question, not only a procurement one, and the audited perimeter the agents run inside is documented in the Trust Center.

We already have a SIEM and a SOC. Where does this fit?

In front of them. The problem in most estates is not missing alerts, it is that reported false-positive rates near 70 percent bury the people who have to act. Argus triages what the gateways caught so only what mattered reaches a human, and Prometheus aims one step earlier, at the incident that has not happened yet. What arrives in your SIEM gets smaller and more true.

How do I check any of this without signing an NDA?

Ask the three questions in the section above, of us and of every vendor: what is it made of, who is accountable when it acts, and where does your data end up. Our answers are public and unpaywalled, with the evidence linked. When a vendor can only answer those three under NDA, that is an answer too.

Ask what our AI is made of.

35 years, learned into an ontology and a roster of agents, sovereign, grounded, human-accountable.

Already a customerEverything you use today keeps running.