Product
PurifySec helps security operations teams move from raw alerts to reviewed, documented decisions. It is an application built on Anthropic's Claude API and keeps a human analyst in control of every outcome.
SIEM/EDR alert triage
Reads alerts and the surrounding events, highlights the key indicators, groups related alerts and drafts a suggested priority with a short rationale. Analysts confirm or change it.
Incident summaries & timelines
Builds a readable timeline from alerts, logs and analyst notes, suitable for shift handoffs, tickets and management updates.
Log analysis
Explains what a set of log lines likely shows, points out anomalies and suggests what to check next, on systems the customer owns or is authorized to manage.
MITRE ATT&CK mapping
Proposes candidate ATT&CK tactics and techniques for observed behavior, with the evidence behind each suggestion so analysts can verify it.
Secure code review
Reviews source code owned by the customer for common weaknesses (for example injection, insecure deserialization, hard-coded secrets) and drafts remediation reports with safe fixes.
Remediation & report drafting
Drafts remediation steps, post-incident reports and executive summaries in English or Korean. Everything is editable and requires analyst approval.
Architecture overview
How it fits together
- Read-only connectors bring in alerts and logs that the customer chooses to share.
- Claude API (Messages API with tool use) for reading, querying, structured extraction, reasoning and drafting.
- Schema validation so every result follows the same structured triage format.
- Review queue where analysts approve, edit or reject each output.
- Audit history of what was suggested and what was decided.
Design principles
Safe by default
- Defensive only. No offensive tooling, exploit code or malware analysis.
- Authorized data only. Customers confirm they own or are authorized to manage the systems involved.
- No autonomous actions. The assistant drafts; people decide and act.
- Treat logs as untrusted input. Log content is handled as data, not instructions, to reduce prompt-injection risk.
- Data minimization. We encourage customers to share only what is needed and to redact personal data where possible.
Help shape the first version
We are looking for a small number of security teams to pilot PurifySec and give feedback.
Request early access