UPX

UPX AI Agent · SOC

AI agent, built for your security operation

Triages the alert, correlates the signal, builds the incident timeline and drafts the report inside the SIEM and tools you already use. The autonomy is yours to grant, and to limit.

  • Splunk
  • CrowdStrike
  • SentinelOne
  • Microsoft Defender
  • Datadog
  • Jira

+1,400 integrations available

One agent. Different operations.

Connect your company systems and define what the agent can consult, decide and execute. See examples of processes that can be automated.

Today
With the UPX AI Agent

Alert triage

Alerts arrive from several tools, mixed between noise, recurring events and real incidents.

The agent correlates the authorized signals, classifies priority and gathers the evidence for the analyst to validate.

Incident investigation

The team searches logs, recent changes and tickets across separate sources to build the timeline.

The agent organizes the timeline, relates the signals and presents hypotheses, without stating a cause as fact.

Response tracking

Containment actions and owners are followed in chat, with the risk of missing a deadline.

The agent follows the plan, flags blockers and records every response for the team to decide.

Security reporting

The incident and evidence summary is assembled at the end of the period, after many manual lookups.

The agent prepares the report with source, impact and open items, always subject to human review.

Integrations

Connected to the tools your team already uses

The agent reads data and runs tasks in the systems already in place, within the scope your company defines.

An action in the environment lands immediately, so it comes with a limit.

Containment under approval

Isolation, blocking and revocation go through a human approval point, at the level of autonomy you define.

Scope per asset

Allowed actions defined per asset and per environment. Critical assets stay out of automation, except under a documented scope.

A hypothesis is not a conclusion

The agent presents the hypothesis with the evidence and its confidence. Cause, attribution and closure stay with the analyst.

Logs do not become training

Telemetry, logs and evidence stay isolated per environment and are not used to train models or shared.

Auditable trail

Every lookup, hypothesis and action logged with previous state, new state, timestamp and approver.

Escalation guaranteed

Signs of personal-data exposure, legal risk or regulatory impact leave the automation and go to a human, at any level of autonomy.

Interface

It works where your team already talks.

No new portal to learn. You ask, follow along and approve in the app that is already open. Scope, limits and audit trail are the same in every interface.

Telegram

Questions and approvals from your phone, with answers in natural language. Useful for people who decide away from their desk.

Slack and Teams

The agent replies in the team's thread, flags what needs attention and takes approvals in one click.

Discord

For teams that already operate there. Commands, alerts and approvals inside the squad's channel.

Web console

Where you configure the rules, set the autonomy level per task, review the audit trail and browse the full history.

Switching interfaces does not switch the rules. Same scope, same limits, same log in all of them.

Security by default

The limits don't change with the level.

UPX treats every access to real systems as a privileged credential. You change the autonomy; isolation, traceability, safeguards, and scope remain in force across all four levels.

Layer 04

Permissions and limits

You define the scope by integration, task, and spending limit. Reduce, expand, or revoke it at any time — effective on the next action.

Start free. Scale when you need more.

Choose the plan that matches the pace of your operation.

Team
US$ 100/ month

One shared AI employee for your entire team.

Click to see all available plans.

Everything on the platform, plus:

  • Create up to 1 AI agent.
  • 40,000 shared credits per month; increase them as your usage grows
  • Shared across your entire workspace
  • Unused credits roll over to the next month
  • Add credits on demand when a major project comes up
  • Automatic top-ups with a monthly spend cap

*The 7-day free trial is available exclusively on the US$ 100 plan. All other plans start with immediate subscription.

Frequently asked questions

Common questions about the Security Operations Agent

What security teams usually ask before putting an agent to work.

  • Who has access to what the agent processes?

    Access is restricted to the UPX operations teams assigned to your contract, with an audit log of every access. UPX runs its own SOC, with no outsourcing. Whoever accesses your operation is accountable for it.
  • Who operates the Secure AI Agent after deployment?

    Operation is run by UPX's own SOC, 24/7, under the Managed Operation model. Nothing is handed off to third parties. Whoever operates is accountable.
  • Does the agent act on its own or is there human oversight?

    You define the level of autonomy. The agent can execute actions within the agreed limits, and higher-impact actions go through validation by the operations team before execution.
  • How do I set the limits of what the agent can and cannot do?

    Limits are defined in the agent's configuration: which actions it executes, which require validation and which are out of scope. These limits are operating rules, not suggestions.
  • Can I audit the agent's decisions and actions?

    Yes. Every action the agent takes is logged, with an audit trail available for review. You have visibility into what was executed, when and under which criteria.
  • How is it different from a generic AI assistant?

    A generic assistant answers questions. The Secure AI Agent operates inside your infrastructure, under defined security rules, with UPX's own SOC behind it. The difference is not the AI model, it is who operates and answers for it: over 20 years in critical infrastructure, with security as the rule, not a module.
  • Do I need to know how to code?

    In self-managed, no: setup is done through the interface. In managed, development and integrations are handled by UPX.
  • Who defines what the agent can do?

    The company, always. Tasks, access, limits and human approval points are set in the agent's design, by you in the interface, or with UPX guidance in the managed model.
  • Do I need to replace the systems the company already uses?

    No. The agent works on the systems that are already part of the operation, subject to the feasibility of each integration.
  • Which tools can be connected?

    The available integrations are the same in both models. In self-managed, you connect through the interface. In managed, UPX assesses feasibility and executes the integrations defined in scope.
  • How soon can it start operating?

    In self-managed, it depends on how long your team takes to connect the tools and configure the rules. In managed, the timeline is defined after the diagnostic, based on scope, integrations and the level of customization.
  • Can I build my own skills?

    Yes. You can combine your own skills with those in the UPX library. In managed, UPX also develops skills specific to the project.
  • How will we know it worked?

    The metrics are defined before go-live and compared against the initial scenario: execution capacity, time spent on the process and quality of the result. In the managed model, this definition is part of the diagnostic.
  • Who operates the agent after it goes to production?

    Configuration, rules and usage stay under the company's control in both models. In managed, UPX monitors performance and refines the agent according to usage and the limits set.
  • What if the agent stops working?

    UPX maintains the platform infrastructure and acts on technical outages. Configuration, rules and usage remain under the customer's control.
  • Can we start with a single agent?

    Yes, and that is the recommendation. Start with a process of clear impact and expand from the result.
  • How many agents can I have?

    As many as you need. Each agent is contracted individually and operates in its own environment.

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Ready to put your agents to work?

Start free for 7 days* and see how an agent can operate within your company’s rules.

Start free for 7 days*

*Credit card required for activation. Free trial available exclusively on the US$100 plan.

UPX

© 2026 UPX. Todos os direitos reservados.