AI-powered alert triage. Open source. 100% on-premise. The foundation of the sovereign SOC — built for KRITIS, NIS2 and BSI IT-Grundschutz.
Alert data, threat intelligence and AI inference run entirely inside your infrastructure — fully air-gapped if you choose.
No data leaving the building, no data processing agreements, no cross-border transfer assessments. Locality by architecture, not by contract.
A single Docker Compose stack on one server or VM. Offline release bundles via USB/SFTP for air-gapped sites.
SIEM and EDR tools generate thousands of alerts a day — most are duplicates or fragments of the same attack. SOC-Mind suppresses repeats and deterministically links related alerts into one incident before the AI runs.
A locally hosted LLM investigates every incident by playbook and writes the analyst-ready summary: what happened, evidence, kill chain, next steps. The playbooks ship with the product — carrying enough context for open-source models to master the analysis reliably.
If context on an alert is missing, SOC-Mind goes and gets it — via automated email to the responsible department. And through the chat interface, your analysts search customer data, alerts and the knowledge base in natural language.
SOC-Mind replaces nothing, it connects: the SIEM/EDR tools you already run, your own MISP instance, your case management. Delivered as a single Docker Compose stack — multi-tenant with hard per-tenant data isolation.
It works in the background and analyzes every alert in full enterprise context — with access to your internal data, your knowledge base and your SOC processes. That context is exactly what makes the analysis precise. And exactly why it must never leave the building.
SOC-Mind will be released as an open-source project: your team and your auditors can inspect every line. No vendor black box, no lock-in, no license kill-switch on critical infrastructure.
| Cloud AI-SOC vendors | SOC-Mind |
|---|---|
| Alert data leaves the network | Nothing leaves the network — air-gap capable |
| AI reasoning is a black box | Playbook-driven: your team writes the AI’s investigation steps |
| Pricing anxiety: per seat, per GB, per cloud call | Runs on your own hardware |
| Compliance assessment per data flow | Locality by architecture, not by contract |
| Closed, proprietary code | Open source — inspectable, auditable, no lock-in |
The key criteria for assessing AI-powered alert triage under NIS2, BSI IT-Grundschutz and critical-infrastructure requirements — compact, as a PDF. Not ready for a demo yet? Start here.