AIDR Security Flywheel .
Learns from your historical incidents & empowers you to make informed decisions.
* In preview — generally available in H2 2026.
An executive view that scores organization-wide risk only on what agents actually verified in your environment — with the evidence one click away.
One 0–100 number across active threats and standing exposure — and unverified findings never touch it. When the score moves, it names the investigation event that moved it. Findings still under review are listed — and refused at the door.
Low 0–24
Moderate 25–49
High 50–74
Critical 75–100
The ledger ranks every scored item by its exact contribution — critical assets and internet exposure flagged in place, rising items carrying their cause. Suspicious and needs-review findings are listed but never scored, and each row opens its evidence trail: what the agent verified, and when.
Ranked by contribution
Unverified — listed, not scored
Evidence trail per row
Findings from every scanner land in one queue, and AIDR judges each one against your environment: what exploitation requires versus what actually exists. Not exploitable is deprioritized, exploitable is remediated — and closed only by a clean rescan.
Every scanner finding lands in a single queue, ranked by risk with its severity, AI verdict, and SLA clock on the row. Open any vulnerability and the full picture is there — why it’s exploitable in your environment, which assets are hit, and how the fix is tracked to a verified close.
One risk-ranked queue
Verdict on every row
Assessment to verified close
When one of four confirmed signals fires, AIDR opens a hunt on its own, works it to a conclusion, and proposes the rule — sweeping telemetry nobody flagged, lighting up hosts that never raised an alert.
A confirmed signal opens the session and AIDR does the rest — hypothesis, DataLake queries, and a threat surfacing on a host that never raised an alert. You confirm the rule; it lands as THR-1 with a daily routine already attached. Guardrails hold the whole way: query and analysis only, sensitive reads wait for approval, workspace limits cap how many hunts can run.
Query & analysis only
Sensitive reads wait for approval
Workspace hunt limits
Proof, not promises.
Detection that catches what your tools miss
Hunts that start themselves — and end as standing rules
A score where every point carries agent-verified evidence
Closure that only a clean rescan can grant
We use analytics cookies to understand how the site is used. Essential cookies keep it working. Read our Cookie Policy.