Malware detected on workstation
Host isolated
The autonomy-control paradox
Everyone is building the autonomous SOC
The models are good enough. The trust isn't there. Autonomy was never the hard part. Control was.
We will be in touch personally.
What we believe
The answer to the autonomous SOC was never a smarter model. It was control. But control is a claim until it’s enforced. Anyone can promise it.
The allowance
Governance is what makes it real: you decide what an agent may do before it acts, and it cannot act outside what you allowed, on any asset, every time.
Not guardrails, the barrier you hit once it’s already gone wrong. Trust doesn’t come from hoping the AI behaves. It comes from knowing it can only ever act inside your rules, and seeing every move it makes.
That is governed autonomy. Autonomy you can finally trust to act.
The paradox
Hesitation
A breach
Governed autonomy
Error
An outage
In the middle of the night, a wrong call either lets an attacker keep moving or takes down production. Security teams live inside that gap, and there are never enough experienced people to close it.
That tension has a name.
We call it the Autonomy-Control Paradox.
Independently arrived at
The national cyber authorities landed on the same line this year: keep a human accountable for what can’t be undone, and automate only what’s narrow and reversible. We built the platform that enforces it.
We think the whole industry has the problem backwards.
AI-driven detection and response, governed.
Two audiences. One mission.
The protected business
For the businesses that can’t defend themselves.
Small and medium businesses with something worth stealing and no security operations centre of their own. You get machine-speed detection, governed response on the assets where it is safe, a human on the loop on the assets where it is not, and you can see exactly what it did, on every action.
Protection you could never staff for on your own.
Request early accessThe partner
For the partners who protect them.
MSPs and MSSPs run on people, and people are both the bottleneck and the cost. The platform takes the human arbitrage out of the SOC: machine-speed triage and governed autonomous response for every client you serve, with the same governance rigour applied consistently, so you grow accounts without growing headcount at the same rate.
Become a launch partnerThe partner is how we reach them. The protected business is the point.
The category
getsoteria.ai governs how AI acts inside the security operations centre. It is a governance layer that wraps probabilistic AI in deterministic rules, so a machine acts only when every check passes and its confidence clears the bar set for that asset. This is a security offering for the SOC, not a general-purpose AI governance tool.
It acts where policy allows, and escalates where it does not.
Control, not guardrails
Being right and being allowed are different things. Confidence is how sure the system is. Permission is what your policy allows on this asset. Both have to pass, and high confidence never buys its way past permission.
How much a mistake would cost depends on what it touches, not on how sure the system was. The more a mistake would cost, the less the machine may do on its own.
When anything is uncertain or unavailable, the system steps back to recommending and waits for a person. Degradation always moves towards more oversight, never less.
The ladder of trust
Autonomy is not switched on. It is climbed, one rung at a time, and only as far as you let it go.
Shadow
Watch.
It observes and recommends while it learns how your team decides. No autonomous action.
Recommend
Suggest.
It surfaces the action it would take. Analysts keep the click.
Limited
Act narrowly.
It handles low-blast-radius cases on its own, inside tight and monitored limits.
Governed
Act at speed.
It operates at machine speed where policy allows, with humans on the exceptions.
The proof
The platform writes a tamper-evident journal of every call it makes: what it saw, what it was allowed to do, and what it did. Compliance stops being a project and becomes a by-product of running.
Decision journal
Malware detected on workstation
Host isolated
Vendor neutral
Your tools detect everything and decide nothing.
One common picture
Detects
The platform sits on top of the security tools you already have and ingests telemetry from all the major EDR and XDR vendors into one common picture, so governance and autonomy are identical no matter who you buy your tooling from. Nothing to rip out to adopt it. Your data stays inside your own boundary.
Natively multi-tenant by design.
The team

Co-founder and CEO
25+ years in cybersecurity. Former CTO, CX at Cisco (APJC), former VP and Regional Chief Security Officer at Palo Alto Networks (APJ), and former CTO APAC at Intel Security. Published author on cybersecurity. Based in Singapore.

Co-founder and CRO
25+ years in enterprise technology sales. Former MD Global Security Sales at Cisco (APJC) and former RVP SASE Sales at Palo Alto Networks (JAPAC). A retired Australian Army Major, active startup investor and board advisor. Based in Singapore.
Combined 50+ years across the world’s largest security vendors. Both left to build what the industry needs next.
We are onboarding a small group of design partners and channel operators before launch.