Secure AI Agent · Incident Response

AI applied to running security incidents

A specialist configured to build the timeline, gather evidence, and prepare incident communication within the rules, permissions, and deadlines your company defines.

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Capabilities

What the Incident Response Agent can do

Main areas of work for the Incident Response AI Agent in your operation.

Incident triage

Assesses the initial scope and classifies severity according to company criteria.

Timeline

Reconstructs the sequence of events from the records in the connected sources.

Evidence collection

Gathers and organizes the relevant artifacts, preserving the source reference.

Ransomware cases

Organizes indicators, affected systems, and what is already known about the extent.

Notification deadlines

Points out the deadlines that apply to the case for the responsible person to decide.

Incident memo

Drafts the summary of facts in a format ready for legal or DPO review.

Skills

Capabilities that compose the specialist

Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.

Timeline reconstruction
Orders events from different sources into a single, dated sequence.
Evidence collection
Gathers artifacts and records while preserving the source reference.
Incident memo
Drafts the summary of facts for legal or DPO review.
How it works

From the first indicator to the memo, with review at every step

Connect your sources, define what the agent can do, and let reconstruction and documentation happen within your company's limits.

01

Connect the incident sources
The agent works where the records already live.Connect SIEM, EDR, identity, and your ticketing system so the Secure AI Agent has access only to what it needs to reconstruct each case.

02

Ask for the work
Talk to the agent in natural language.Request the timeline, the evidence collection, or the memo through the available channels. The agent understands the context, applies the configured skills, and follows the criteria your company defines.

03

The agent prepares. You lead.
From detection to closure, with control.The agent queries the sources, correlates, and drafts within the defined permissions. Containment, eradication, and the decision to notify stay with the responsible people.

Integrations

Connected to the tools that record what happened

The Incident Response AI Agent can query your log sources and run tasks in the systems your team already uses.

  • Splunk
  • CrowdStrike
  • SentinelOne
  • Microsoft Defender
  • Okta

Flow

What goes in, what the agent does, and what comes out

From the first indicator to the memo, following your company's rules and permissions.

Inputs

  • Initial alertEvent
  • System logLOG
  • Access recordCSV

Processing

Secure AI Agent

Processing the task

  • Read
  • Correlate
  • Reconstructrunning
  • Draft
Skill appliedCriteria verified

Output

Completed

Memo prepared

  • Timeline assembled
  • Evidence referenced
  • Applicable deadline flagged

Control

You define how far the Agent can act

Different actions can operate with different autonomy levels, always within your company's rules.

  1. 1

    Query

    Reads records and answers with the source reference.

  2. 2

    Prepare

    Reconstructs the timeline and drafts the memo.

  3. 3

    Request review

    Waits for validation from whoever leads the incident.

  4. 4

    Execute

    Performs the action within the defined limits.

Levels are configured per type of action, according to each company's policy. Containment, eradication, and the decision to notify always stay under human approval.

Get started

Put a Secure AI Agent to work.

Start on the platform or choose the plan that fits the pace of your operation.

Security and compliance

Security that can be verified.

Certifications and attestations

  • SOC 2 Type II
  • ISO 27001

UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.

Privacy and regulation

LGPD
Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
Zero Data Retention
A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
Retention and deletion
The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.

Frequently asked questions

Common questions about the Incident Response Agent

What teams usually ask before putting an agent to support incident handling.

  • Does the agent contain the incident on its own?

    Not by default. Isolating a host, killing sessions, or blocking an address stay under human approval. You define per type of action what it executes directly and what requires sign-off from an authorized person.
  • Does the memo count as legal advice?

    No. The agent organizes the facts, references the evidence, and flags the deadline that applies to the case. Legal analysis and the decision to notify stay with the responsible lawyer or DPO.
  • Does it preserve chain of custody?

    The agent works on the records in the connected sources and keeps the source reference for every artifact it cites. Formal custody procedures remain the responsibility of the team and the collection tooling.
  • Does it connect to our SIEM and EDR?

    Yes. The agent works in the tools your team already uses, such as SIEM, EDR, identity providers, and ticketing systems. Permissions define which sources it can query and where it can execute actions.
  • Is incident data used to train models?

    No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.
  • Can we audit what the agent did?

    Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.
  • How long does it take to go live?

    It depends on the sources involved and your company's response process. The starting point is mapping what consumes most time while handling a case and configuring the agent for those steps.

Secure AI Agent

Bring a Secure AI Agent to your incident response

Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.