Working prototype — some features are still being completed

Product

PurifySec helps security operations teams move from raw alerts to reviewed, documented decisions. It is an application built on Anthropic's Claude API and keeps a human analyst in control of every outcome.

SIEM/EDR alert triage

Reads alerts and the surrounding events, highlights the key indicators, groups related alerts and drafts a suggested priority with a short rationale. Analysts confirm or change it.

Incident summaries & timelines

Builds a readable timeline from alerts, logs and analyst notes, suitable for shift handoffs, tickets and management updates.

Log analysis

Explains what a set of log lines likely shows, points out anomalies and suggests what to check next, on systems the customer owns or is authorized to manage.

MITRE ATT&CK mapping

Proposes candidate ATT&CK tactics and techniques for observed behavior, with the evidence behind each suggestion so analysts can verify it.

Secure code review

Reviews source code owned by the customer for common weaknesses (for example injection, insecure deserialization, hard-coded secrets) and drafts remediation reports with safe fixes.

Remediation & report drafting

Drafts remediation steps, post-incident reports and executive summaries in English or Korean. Everything is editable and requires analyst approval.

Architecture overview

How it fits together

  • Read-only connectors bring in alerts and logs that the customer chooses to share.
  • Claude API (Messages API with tool use) for reading, querying, structured extraction, reasoning and drafting.
  • Schema validation so every result follows the same structured triage format.
  • Review queue where analysts approve, edit or reject each output.
  • Audit history of what was suggested and what was decided.

See the full technical design →

Design principles

Safe by default

  • Defensive only. No offensive tooling, exploit code or malware analysis.
  • Authorized data only. Customers confirm they own or are authorized to manage the systems involved.
  • No autonomous actions. The assistant drafts; people decide and act.
  • Treat logs as untrusted input. Log content is handled as data, not instructions, to reduce prompt-injection risk.
  • Data minimization. We encourage customers to share only what is needed and to redact personal data where possible.

Help shape the first version

We are looking for a small number of security teams to pilot PurifySec and give feedback.

Request early access