Product of Purify Solution Co., Ltd. · Working prototype

PurifySec: a SOC alert-triage assistant built on the Claude API

Claude is the engine of the product, not a side tool. By design, PurifySec sends each alert to Claude through Anthropic’s Messages API; Claude uses read-only tools to pull related SIEM/EDR events and returns a schema-validated JSON triage note that a human analyst approves, edits or rejects.

In one paragraph: PurifySec is a defensive security triage product for SOC teams, built by the AI division of Purify Solution Co., Ltd. (주식회사 퓨리파이솔루션), a Korean corporation incorporated on March 13, 2026. Its working prototype runs on the Claude API. Claude calls read-only tools to query SIEM/EDR data, maps findings to MITRE ATT&CK and drafts incident summaries and remediation reports as structured JSON; analysts approve every output. Defensive use only. No customers or outside funding yet.

triage.json · illustrative example
// Illustrative example with fictional sample data
{
  "alert": "Multiple failed logins, then success",
  "sources": ["edr", "identity_provider"],
  "summary": "14 failed sign-ins for one account from
              a new IP, then a successful login.",
  "suggested_priority": "high",
  "attack_candidates": [
    { "id": "T1110", "name": "Brute Force" }
  ],
  "evidence": ["idp event #1-14: auth_failure",
               "idp event #15: auth_success"],
  "next_steps": ["Verify with account owner",
                 "Review MFA logs for the session"],
  "status": "awaiting_analyst_approval"
}
Sample output for illustration only. Not a real customer or incident.

The problem

Triage and write-ups take a large share of SOC analyst time.

For each alert, an analyst reads raw events, pulls context from several consoles (SIEM, EDR, identity provider), decides on a priority and writes it up. PurifySec targets that loop: Claude does the first read, the context queries and the draft; the analyst makes the decision.

Our product work is the workflow around the model: connectors, tool definitions, output schemas, model routing, evaluations, prompt-injection defenses, review queues and audit history.

  • Structured, not free text. Triage results come back as schema-validated JSON: verdict, priority, evidence, ATT&CK candidates, next steps.
  • Evidence-linked. Each claim is designed to cite the source events it relies on, so analysts can verify it quickly.
  • Read-only by design. Claude’s tools can query data; they cannot change your systems.
  • Human approval gate. Nothing leaves draft state without an analyst’s sign-off.

How it works

From raw alert to approved triage in four steps

This is the workflow our prototype is built around. Some parts are still being completed; see the Technology page for the full planned design.

  1. 1

    Ingest alerts

    Read-only connectors pull SIEM/EDR alerts and logs from systems the customer owns. Data is normalized, secrets are redacted and log text is marked as untrusted.

  2. 2

    Claude analysis with tool use

    Claude, via the Anthropic Messages API, reads the alert and calls read-only tools (event search, host and user context) to gather what it needs.

  3. 3

    Structured triage & ATT&CK mapping

    Output is a schema-validated JSON record: suggested verdict and priority, evidence, candidate MITRE ATT&CK techniques and next steps.

  4. 4

    Analyst approval

    An analyst approves, edits or rejects the draft. Only approved outputs become tickets or reports, and every decision is audit-logged.

Capabilities

A defensive assistant for the SOC workflow

The capabilities below describe the product we are building; some are still being completed and refined.

SIEM/EDR alert triage

Reads alerts and the surrounding events, highlights the key indicators, groups related alerts and drafts a suggested priority with a short rationale. Analysts confirm or change it.

Incident summaries & timelines

Builds a readable timeline from alerts, logs and analyst notes, suitable for shift handoffs, tickets and management updates.

Log analysis

Explains what a set of log lines likely shows, points out anomalies and suggests what to check next, on systems the customer owns or is authorized to manage.

MITRE ATT&CK mapping

Proposes candidate ATT&CK tactics and techniques for observed behavior, with the evidence behind each suggestion so analysts can verify it.

Secure code review

Reviews source code owned by the customer for common weaknesses (for example injection, insecure deserialization, hard-coded secrets) and drafts remediation reports with safe fixes.

Remediation & report drafting

Drafts remediation steps, post-incident reports and executive summaries in English or Korean. Everything is editable and requires analyst approval.

Built on Claude

Claude is part of the product’s runtime

Our application calls the Claude API for each alert it processes: Claude reads the alert, decides which read-only tools to call, and returns the structured triage record. The cards below describe that design; some parts are still being built. Read the technical design →

Messages API + tool use

Claude calls typed, read-only tools to query SIEM/EDR data during an investigation instead of guessing.

Structured JSON outputs

Every triage result follows a fixed schema that is validated before it reaches the review queue.

Prompt caching

Stable instructions, tool definitions and long log context are cached to control cost and latency.

Model routing

A smaller Claude model for high-volume first-pass triage; a larger Claude model for deep investigations.

Evaluation harness

Planned regression tests for triage accuracy, ATT&CK mapping and evidence faithfulness on every prompt or model change.

Prompt-injection defenses

Log content is treated as untrusted data, never as instructions, with read-only tools and human approval as backstops.

Human-in-the-loop by design

PurifySec suggests. People decide.

✓ In scope (defensive)

  • Alert triage and incident summaries for SIEM/EDR
  • Log analysis on customer-owned or authorized systems
  • MITRE ATT&CK mapping
  • Secure code review of customer-owned code
  • Remediation guidance and report drafting

✕ Out of scope

  • Penetration testing or attacking any system
  • Writing exploits or proof-of-concept attack code
  • Malware analysis or creation
  • Automated actions without analyst approval
  • Use on systems without the owner’s authorization

Aligned with Anthropic’s Usage Policy. Read our Responsible Use policy for details.

Roadmap

Where we are, and what is planned

Everything after the current stage is a plan, not a commitment.

  1. Current stage

    1. Working prototype

    • Working prototype built on the Claude API
    • Completing connectors, output schemas and the review queue
    • Evaluation harness in design (synthetic and sample data)
  2. Planned

    2. Design-partner pilots

    • Early access for a small number of SOC teams
    • Read-only connectors to their SIEM/EDR tools
    • Measure triage quality against analyst decisions
    • Tune model routing, prompt caching and cost per alert
  3. Planned

    3. Enterprise readiness

    • SSO and role-based access for analyst teams
    • Audit-log export and data-retention controls
    • Security documentation for enterprise review
    • More connectors, guided by pilot feedback

Status: working prototype

PurifySec is a product of the AI division of Purify Solution Co., Ltd. (주식회사 퓨리파이솔루션), a Korean company incorporated on March 13, 2026 whose existing business is water purification. We have a working prototype and are preparing an early-access pilot program with a small number of security teams. We have no customers yet and no outside funding. PurifySec is not affiliated with Anthropic. The company’s other product is AI Date.

Interested in an early-access pilot?

Tell us about your team, the SIEM/EDR tools you use and the triage work you would like help with. We will reply by email.

hello@purifysec.com · JisubLee@purifysec.com (Head of AI)

Email hello@purifysec.com