SWISS POST GROUP · SOVEREIGN BY DESIGN
AI Matrix
Platform
Solutions
Switch to OS
Resources
Partner
Company
Operating model · AIOps

Security that runs itself.

Detect threats, automate policy and respond, autonomously, in real time. Powered by 35 years of operational data and Lucy, our AI operator, with Level-3 humans on override.

What runs autonomously

From alert to resolution, hands-off.

Threat Intelligence

Continuous, correlated intel across your whole estate, not siloed feeds.

Policy Automation

Policies that tune themselves, with human-in-the-loop approval where it counts.

Digital Experience Monitoring

See and fix experience issues before users raise a ticket.

Detection & Response

Autonomous detection and response, escalated to Level-3 when it matters.

Capabilities in depth

AIOps, grounded in 35 years of operations.

Where the incumbents bolt on a chatbot, we run operations, detection, response and optimization, with humans on the gate.

Threat intelligence

correlated, not siloed
  • Continuous intel correlated across network, access & cloud
  • STIX/TAXII feeds & custom IoCs ingested automatically
  • Reputation & behavioural signals fused with your own telemetry

Detection & Response

Roadmap
NDR + autonomous response
  • Network Detection & Response across east-west & north-south
  • MITRE ATT&CK-mapped detections, Sigma-compatible rules + ML
  • Automated containment within HITL (Human-in-the-loop) approval boundaries
  • Cloud sandbox & advanced threat protection for unknown files

Policy automation

self-tuning, supervised
  • Self-tuning policy with conflict & shadow-rule detection
  • Dry-run & simulation before any change goes live
  • Versioned policy, instant rollback, full provenance

Digital Experience Monitoring

Roadmap
DEM · proactive ops
  • Hop-by-hop experience telemetry, app & SaaS reachability
  • Proactive signals, bandwidth trends, policy drift, cert expiry
  • Predictive bandwidth & WAN what-if (with NetFabric)
Always-on, both sides

Red team and blue team.
Same platform. Never off.

The classic deep-learning security loop: an AI red team attacks you continuously, an AI blue team defends, and each makes the other smarter. We run both, on your side, 24/7.

Red team, Nemesis

offence, on your side
  • Probes continuously, finds new attack paths the way a real adversary would
  • Grounded in attacker tradecraft & your live attack surface
  • Proves exploitability safely, no damage, full audit
  • Meet Nemesis →

Blue team, Lucy + MDR

defence, around the clock
  • Detects, validates & responds across your whole estate
  • Learns from every Nemesis finding, closes the path it just found
  • Level-3 humans on override for the calls that matter
  • See MDR / MXDR →

▸ Every attack Nemesis invents trains the defence; every defence sharpens the next attack. A flywheel, not a once-a-year pentest.

The proof

Agents that replicate the L3 workflow.

"Replicated" means the agent would have executed the exact same steps and tools as a human Level-3 engineer, trained on real ticket data, validated against decades of outcomes. This is autonomy, not autocomplete.

35
years of operational training data
L3
workflow replicated by agents
24/7
autonomous, with human override
Detection & response engine

Built for the engineers who read the logs.

Detection engine
Telemetry ingest
OpenTelemetrysyslogNetFlow/IPFIX, normalized schema
Correlation
35y operational baselines + UEBA, streaming analytics
Detection content
MITRE ATT&CK mapped, Sigma-compatible rules + ML models
Response actions
Agentic containment within HITL (Human-in-the-loop) boundaries, instant rollback
Integrations & standards
SIEM / SOAR
SplunkMicrosoft SentinelQRadar, bi-directional
Threat intel
STIX 2.1TAXII, custom IoC feeds
Detection model
MITRE ATT&CK coverage mapping, measurable
Export
syslogCEFOpenTelemetry, webhooks

Let it run itself.

Watch autonomous operations resolve a live incident.

Already a customerEverything you use today keeps running.