AI security & operations for MSPs

The AI security and operations platform for MSPs.

Hal is an intelligence, built on Anthropic's Claude models. He ingests every client's Microsoft 365, Google Workspace and infrastructure logs into a SIEM (read-only), then watches, reasons over and alerts on them around the clock, and answers when you ask. Four roles, one hire, billed per identity.

  1. 01 Every log source from every client, retained and audit-trailed to satisfy the carrier letter.
  2. 02 Every alert ships with the recommended fix, not just the warning.
  3. 03 Advises your techs in plain English. Doesn't bill by the hour.
  4. 04 Reads across every integration. Ask anything. Hal already knows.

Four roles. Watching every client every few minutes. One hire: Hal.

$5 per identity per month, list price · $600 monthly minimum · no setup fee · no charge by ingestion volume · AI usage billed separately by Anthropic to your own account · MSP partner pricing on request. Full terms

portal · events The Hal portal events list: five alerts, each with its severity, its report number, the client it belongs to and which model judged it
One alert, judged and written up. That is the whole argument: severity, the client it belongs to, which model reached the conclusion, and a numbered report behind every row. Open it for the reasoning and the remediation.

01 The position you are in

Your carrier wants logs. Your clients want answers. Answering both is a full-time job you cannot hire for.

Every renewal questionnaire now asks what you collect and how long you keep it. Most SIEM quotes price that by the gigabyte, so the bill moves when a client has a noisy week. And the alerts that come back are raw: someone on your team still has to decide whether each one matters.

Hiring a SOC analyst fixes the third problem and none of the first two. Hal is built for the shape of the actual job: many clients, one team, and a carrier letter with a deadline on it.

The carrier letter
Retention you can point at. 365-day searchable retention across every source on every client, with every source's status and silence threshold in one view. The SIEM
The alert pile
Conclusions, not tickets. An event passes Sigma detection and two independent model judgments before it reaches you. What lands has the fix in it. How triage works
The bill
$5 per identity per month, list price. MSP partner pricing is available on request. Not per gigabyte, not per log source, not per integration, and no setup fee. A noisy client does not change our invoice. Hal's AI usage runs on your own Anthropic account and is billed to you by Anthropic, not by us. Ask us and the first 14 days are free, with no obligation. The full terms

02 One hire, four roles

Hal isn't four products. He reads each environment once, then plays whichever role the moment calls for.

Whichever role he is playing, he reads the same environment: the logs in the SIEM plus live context from your RMM, documentation and network. Which is also why you can open a chat and ask about one client and get an answer about that client.

The SIEM your insurer wants.

Every log source from every client, ingested every few minutes and held for the retention window your carrier asks about. Priced by identity, so one client's noisy month does not move the invoice.

  • Microsoft 365, Google Workspace, Entra ID, Windows endpoints, network gear
  • 365-day searchable retention, across every source on every client
  • Every source's status, last activity and silence threshold, per tenant

See the SIEM

The Hal portal log sources table: every client tenant listed with the source type, whether it is active or aging, when it last reported, how much it has stored, and the silence threshold past which a quiet source becomes a flag

Every alert arrives with the fix in it.

An event passes Sigma detection and two independent model judgments before it reaches you. What lands is the analyst summary, the affected identity and the steps in the order you would take them.

  • Severity, affected identity, and the exact remediation
  • 24×7 across every connected tenant, with no rota to staff
  • Reports your team acts on, signed for when a client needs the evidence

See how triage works

The Hal portal events list with one alert expanded, showing the reasoning behind a cross-tenant OAuth consent grant and four numbered remediation steps

A senior engineer for your MSP team.

Hand him a hard question and he works through the client's actual environment: the licensing, the sign-in history, the service accounts nobody documented. Then he comes back with a recommendation you can act on.

  • Migration and rollout planning against what is really in the tenant
  • A second opinion on a risky change, before you make it
  • Walks a junior through a problem without tying up a senior

Ask him a hard question

A two-turn chat exchange in the Hal portal: asked what to fix in a client's sign-in data before an on-prem AD to Entra-only migration, he returns legacy auth still live on a copier fleet, a service account signing in from the old domain controller and MFA at 94 per cent, then identifies token replay

A knowledge worker over your whole stack.

Through your integrations he has already read every client's tenant, every PSA ticket, every documented runbook. Ask in plain English and the answer comes from across all of it at once.

  • RMM, PSA, documentation, network and every connected tenant, together
  • Per-client memory that survives the person who knew it
  • Ask which of a client's machines are out of warranty, in those words

See what he knows

A chat exchange in the Hal portal: asked which of a client's machines are out of warranty or low on disk, he pulls the device inventory from NinjaOne and flags three of 31 managed endpoints with the reason for each

How the four roles fit together

03 One portal, every client

Your whole book of business in one place, updated as Hal works.

Source health, the triage pipeline, this month's cost and every open alert, across every client, without switching tenants. A source that goes quiet shows up here as a flag rather than as a gap you find during an incident.

portal · dashboard The Hal portal dashboard: infrastructure and API reliability per integration down the left, sources active and healthy with the client count, the 24-hour pipeline showing events processed, noise filtered and alerts raised, this month's projected cost with a fourteen-day trend, and the three most recent alerts with their report numbers
The whole book on one screen. 47 of 49 sources active across 14 clients, 3,356 events processed in a day and six alerts out of them, and what the month is projected to cost. No tenant switching to assemble any of it.

Why multi-tenancy from day one changes this

04 How an event becomes a conclusion

Two independent judgments stand between a log line and your inbox.

Most platforms send you everything and call the volume "visibility." Hal runs every event through a multi-tier pipeline, and an escalation has to survive two separate model judgments before he writes it up.

01 Collection every few minutes
02 Sigma detection rules
03 Tier 1 triage Haiku
04 Second-opinion gate Sonnet
05 Investigation and conclusion Opus by default, your choice in Settings

What each stage does, and how the second-opinion gate reaches a verdict, is on the AI SOC page.

05 Read-only by architecture

Hal can watch everything and break nothing.

Every credential you connect is read-only and scoped by you, and nothing Hal deploys can execute code pushed to it. There is no write path back into the environment, which means there is no version of this that takes a client down.

The full architecture argument

A log shipper, not an EDR

Microsoft 365, Google Workspace and Entra ID connect by API, nothing installed. For Windows event logs, the optional agent is a Fluent Bit forwarder that reads and ships. It never executes code pushed to it.

No kernel drivers

Nothing Hal installs runs in ring 0. A bad update to a userspace log shipper can at worst stop log collection. It cannot crash the machine.

You hold the keys

You grant the read-only scopes in your own Microsoft or Google admin console, and you can revoke or verify exactly what Hal can see, yourself, at any time.

Why this is the first thing we tell you

In July 2024 a faulty CrowdStrike kernel-driver update crashed an estimated 8.5 million Windows machines worldwide, grounding flights and halting hospitals. Every MSP that shipped that agent spent the week rebuilding machines by hand. That class of outage is architecturally impossible here, for the reason above: there is no kernel driver to update.

06 What Hal connects to

Events tell you what happened. Context tells you whether it matters.

Hal reads both together. Events without context are noise; context without events is a static inventory. Reading them together is why an alert arrives as a conclusion rather than a question.

Every integration in detail

07 The questions you're actually asking

Is this a SIEM, or a SOC, or an AI assistant?

One system that does all three, because for an MSP they are the same data asked three different questions. The SIEM is the store and the retention your cyber-insurance carrier asks about. The AI SOC is what watches it around the clock. The chat is what happens when you ask him something. Nothing is bolted on. Hal reads each environment once. How the four roles fit together →

What do I actually have to install?

Nothing, for the cloud sources: you grant read-only scopes and Hal reads. Windows event logs need a log forwarder, which is optional and per client, so a client who will not have software installed runs cloud-only. Why that matters →

What stops him from flooding my team with alerts?

The pipeline above, and your own tuning on top of it. Every source has a threshold you set, and anything you decide is not worth hearing about can be silenced per source and per client. See noise tuning.

What happens when the model gets something wrong?

You see the reasoning, not just the verdict. Every escalation records which model judged it, on what evidence, and what it concluded, and every action Hal takes against a tenant is written to the audit log. A wrong call is visible and correctable rather than silent. Audit logging →

Does my clients' data sit next to another MSP's?

No. Every customer gets a dedicated instance, and inside it each of your clients is kept under its own permanent identifier. One client’s logs stay walled off from the next. Built for MSPs →

Can I hand the output to a client's auditor or cyber-insurance carrier?

That is what it is for. Every PDF Hal generates is cryptographically signed, and anyone (you, your client, their auditor) can confirm it is genuine and unaltered without taking our word for it. Verify a report →

What is this going to cost me at my size?

Under 120 identities you pay the monthly minimum, and above it the count is what moves the number. Nothing else does: not how many clients, not how many log sources. MSP partner pricing is available on request. Run your own numbers →

See what Hal surfaces on your own clients.

No deck. Ask us anything first. When you want to see Hal on your own tenants, we sign a short evaluation agreement and stand up your instance; you connect one tenant read-only, Hal watches it for 14 days, and we walk you through what he found.

  1. 01You ask us your questions. No deck, no demo dataset.
  2. 02You sign a short evaluation agreement, and we stand up your own instance.
  3. 03You grant read-only scopes on one tenant in your own admin console. Hal watches it for 14 days.
  4. 04We walk through what he found. Keep going month to month, or revoke the scopes yourself and stop.