The autonomy-control paradox

Everyone is building the autonomous SOC

Almost no one has switched it on

The models are good enough. The trust isn't there. Autonomy was never the hard part. Control was.

We will be in touch personally.

What we believe

You can’t switch on what you can’t control.

The answer to the autonomous SOC was never a smarter model. It was control. But control is a claim until it’s enforced. Anyone can promise it.

The allowance

Governance is what makes it real: you decide what an agent may do before it acts, and it cannot act outside what you allowed, on any asset, every time.

Not guardrails, the barrier you hit once it’s already gone wrong. Trust doesn’t come from hoping the AI behaves. It comes from knowing it can only ever act inside your rules, and seeing every move it makes.


That is governed autonomy. Autonomy you can finally trust to act.

The paradox

The cost of hesitation is a breach. The cost of error is an outage.

Hesitation

A breach

Governed autonomy

Error

An outage

In the middle of the night, a wrong call either lets an attacker keep moving or takes down production. Security teams live inside that gap, and there are never enough experienced people to close it.

That tension has a name.
We call it the Autonomy-Control Paradox.

Independently arrived at

The national cyber authorities landed on the same line this year: keep a human accountable for what can’t be undone, and automate only what’s narrow and reversible. We built the platform that enforces it.

We think the whole industry has the problem backwards.

AI-driven detection and response, governed.

Two audiences. One mission.

Who it’s for.

The protected business

For the businesses that can’t defend themselves.

Small and medium businesses with something worth stealing and no security operations centre of their own. You get machine-speed detection, governed response on the assets where it is safe, a human on the loop on the assets where it is not, and you can see exactly what it did, on every action.

Protection you could never staff for on your own.

Request early access

The partner

For the partners who protect them.

MSPs and MSSPs run on people, and people are both the bottleneck and the cost. The platform takes the human arbitrage out of the SOC: machine-speed triage and governed autonomous response for every client you serve, with the same governance rigour applied consistently, so you grow accounts without growing headcount at the same rate.

Become a launch partner

The partner is how we reach them. The protected business is the point.

The category

Not faster automation. Governed autonomy for security operations.

getsoteria.ai governs how AI acts inside the security operations centre. It is a governance layer that wraps probabilistic AI in deterministic rules, so a machine acts only when every check passes and its confidence clears the bar set for that asset. This is a security offering for the SOC, not a general-purpose AI governance tool.

  • Not a SIEM
  • Not a SOAR
  • Not a smarter model

It acts where policy allows, and escalates where it does not.

Control, not guardrails

How it holds the line.

Two gates, not one.

Being right and being allowed are different things. Confidence is how sure the system is. Permission is what your policy allows on this asset. Both have to pass, and high confidence never buys its way past permission.

Blast radius decides.

How much a mistake would cost depends on what it touches, not on how sure the system was. The more a mistake would cost, the less the machine may do on its own.

It never fails open.

When anything is uncertain or unavailable, the system steps back to recommending and waits for a person. Degradation always moves towards more oversight, never less.

The ladder of trust

It earns the right to act.

Autonomy is not switched on. It is climbed, one rung at a time, and only as far as you let it go.

  1. Shadow

    Watch.

    It observes and recommends while it learns how your team decides. No autonomous action.

  2. Recommend

    Suggest.

    It surfaces the action it would take. Analysts keep the click.

  3. Limited

    Act narrowly.

    It handles low-blast-radius cases on its own, inside tight and monitored limits.

  4. Governed

    Act at speed.

    It operates at machine speed where policy allows, with humans on the exceptions.

The proof

See exactly what it did. Prove every action.

The platform writes a tamper-evident journal of every call it makes: what it saw, what it was allowed to do, and what it did. Compliance stops being a project and becomes a by-product of running.

Decision journal

02:14:31Z

Recorded

Malware detected on workstation

Permission grantedGoverned

Host isolated

Vendor neutral

Works with the stack you already run.

Your tools detect everything and decide nothing.

DecidesA governance layer

One common picture

EDRXDREDRXDR

Detects

  • No vendor lock-in
  • Nothing to rip out
  • One common picture
  • Multi-tenant

The platform sits on top of the security tools you already have and ingests telemetry from all the major EDR and XDR vendors into one common picture, so governance and autonomy are identical no matter who you buy your tooling from. Nothing to rip out to adopt it. Your data stays inside your own boundary.

Natively multi-tenant by design.

The team

Operators who have built what we are replacing.


Sean Duca

Co-founder and CEO

25+ years in cybersecurity. Former CTO, CX at Cisco (APJC), former VP and Regional Chief Security Officer at Palo Alto Networks (APJ), and former CTO APAC at Intel Security. Published author on cybersecurity. Based in Singapore.

Peter Molloy

Co-founder and CRO

25+ years in enterprise technology sales. Former MD Global Security Sales at Cisco (APJC) and former RVP SASE Sales at Palo Alto Networks (JAPAC). A retired Australian Army Major, active startup investor and board advisor. Based in Singapore.


Combined 50+ years across the world’s largest security vendors. Both left to build what the industry needs next.

Governed autonomy for security operations.

We are onboarding a small group of design partners and channel operators before launch.