Secure AI Agent · Security Operations

AI applied to daily security operations

A specialist configured to triage alerts, analyze indicators, and prepare shift handovers within the rules, permissions, and tools your team defines.

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Capabilities

What the Security Operations Agent can do

Main areas of work for the Security Operations AI Agent in your operation.

Alert triage

Classifies alerts by criticality, following your team's P1–P4 criteria.

Phishing analysis

Examines headers, sender, and message indicators, without executing attachments or links.

Event correlation

Cross-references records from different sources to assemble the context of one occurrence.

Detection review

Flags noisy, redundant, or uncovered rules for the team to assess.

Shift handover

Consolidates what stayed open, what was closed, and what needs follow-up.

Indicator enrichment

Gathers what is known about an indicator from the connected sources.

Skills

Capabilities that compose the specialist

Skills add specific capabilities to the Secure AI Agent according to the processes it needs to execute.

Alert triage
Classifies and prioritizes alerts according to the criteria your team defines.
Phishing analysis
Assesses message indicators without executing attachments or opening links.
Event correlation
Brings records from different sources into a single timeline.
How it works

From alert to conclusion, with review at every step

Connect your detection sources, define what the agent can do, and let triage and analysis happen within your team's limits.

01

Connect the detection sources
The agent works where the alerts already land.Connect SIEM, EDR, identity, and your ticketing system so the Secure AI Agent has access only to what it needs to run each triage.

02

Ask for the work
Talk to the agent in natural language.Request a triage, an indicator analysis, or the shift handover through the available channels. The agent understands the context, applies the configured skills, and follows the criteria your team defines.

03

The agent prepares. The analyst decides.
From detection to conclusion, with control.The agent queries the sources, correlates, and prepares the material within the defined permissions. Containment, blocking, and host isolation stay with the responsible person.

Integrations

Connected to the tools that are part of your security operation

The Security Operations AI Agent can query your detection sources and run tasks in the systems your team already uses.

  • Splunk
  • CrowdStrike
  • SentinelOne
  • Microsoft Defender
  • Okta

Flow

What goes in, what the agent does, and what comes out

From the raw alert to a classification, following your team's rules and permissions.

Inputs

  • SIEM alertEvent
  • EDR telemetryLOG
  • Access recordCSV

Processing

Secure AI Agent

Processing the task

  • Read
  • Correlate
  • Classifyrunning
  • Prepare
Skill appliedCriteria verified

Output

Completed

Triage prepared

  • Suggested priority
  • Evidence gathered
  • Ticket ready for review

Control

You define how far the Agent can act

Different actions can operate with different autonomy levels, always within your team's rules.

  1. 1

    Query

    Reads alerts and records and answers with the evidence.

  2. 2

    Prepare

    Classifies the occurrence and gathers the context.

  3. 3

    Request review

    Waits for validation from the shift owner.

  4. 4

    Execute

    Performs the action within the defined limits.

Levels are configured per type of action, according to each company's policy. Containment, blocking, and host isolation always stay under human approval.

Get started

Put a Secure AI Agent to work.

Start on the platform or choose the plan that fits the pace of your operation.

Security and compliance

Security that can be verified.

Certifications and attestations

  • SOC 2 Type II
  • ISO 27001

UPX maintains SOC 2 Type II and ISO 27001, with independent audit over its information security controls.

Privacy and regulation

LGPD
Operations follow Brazil's Law 13.709/2018. In AI Agent contracts, UPX acts as data processor; the legal basis remains with your company.
Zero Data Retention
A product policy, not a certification: with compatible providers and configurations, processed content is not retained after execution.
Retention and deletion
The retention policy is defined by contract. Once the contract ends, data is deleted within the agreed period.

Frequently asked questions

Common questions about the Security Operations Agent

What security teams usually ask before putting an agent to work.

  • Does the agent block or isolate a host on its own?

    Not by default. Response actions, such as blocking an address, killing a session, or isolating a host, stay under human approval. You define per type of action what it executes directly and what requires sign-off from an authorized person.
  • Does it replace the analyst on shift?

    No. The agent takes on repetitive triage and the reading work, so the analyst reaches the case with the context already assembled. The response decision stays with the person responsible for the shift.
  • How does it analyze phishing without exposing itself?

    The agent examines headers, sender, reputation, and the message text from what is already recorded. It does not open links or execute attachments: the analysis is done on indicators, not by running the artifact.
  • Does it connect to our SIEM and EDR?

    Yes. The agent works in the tools your team already uses, such as SIEM, EDR, identity providers, and ticketing systems. Permissions define which sources it can query and where it can execute actions.
  • Are our alerts and logs used to train models?

    No. Content processed by Secure AI Agents is not used to train UPX models or third-party models.
  • Can we audit what the agent did?

    Yes. Every action is logged: what was queried, what was proposed, when, in which system, and under which permission. The history stays available for review and auditing.
  • How long does it take to go live?

    It depends on the sources involved and your team's criteria. The starting point is mapping the alerts that consume most triage time and configuring the agent for those, expanding the scope as results come in.

Secure AI Agent

Bring a Secure AI Agent to your security operation

Talk to our specialists and see how to adapt this AI Agent to your processes, systems, and needs.