Autonomous cyber defence for environments that cannot call out. The whole loop, ingestion through response, runs inside the customer controlled data centre, and SAGE™ reasons about the evidence without any of it leaving.
SAGE™ is served inside the environment. No public model API is called at any point.
Detection, investigation and response all complete with the network disconnected.
AuraXP™ agents covering detection, investigation, correlation, hunting and response.
Endpoint, identity, firewall, proxy, email, cloud, SaaS, database, DNS, VPN, WAF and OT.
A typical autonomous cycle, against 60 to 90 minutes for the same work by hand.
Most platforms described as on-premises run their collectors and their console locally while the reasoning happens somewhere else, behind a model API. For a bank, a defence network or a plant under restricted connectivity, that is the entire objection, and moving the user interface inside the perimeter does not answer it.
Sphere On-Premises moves the reasoning. The practical test is simple: unplug the environment and see what stops. Here, investigations, detections and response workflows continue. What pauses is the arrival of new threat content, and that has its own controlled path.
The capability set is the platform's, not a reduced edition of it. What changes is location and how content reaches it.
SAGE™ is deployed and served locally. No alert, log, prompt, evidence, embedding or investigation context is sent outside the customer environment.
AuraXP™ runs inside the on-premises platform and actively queries local data stores, connected log sources and entity context.
Ingestion, parsing, normalisation, detection, enrichment, investigation, case management and response all remain within the customer controlled network.
Threat content, parsers, model updates and product upgrades arrive through controlled offline packages, approved transfer media or private update channels.
Actions execute through local sensors, local connectors and local approval workflows, human-in-the-loop controls included.
Six stages, every one of them completing inside the customer controlled network.
Events from endpoint, identity, firewall, proxy, email, cloud, SaaS, database, web, OT and network sources collected through local sensors, APIs and syslog collectors.
Rule-based, behaviour-based and correlation detections generate alerts carrying entity and event context.
AuraXP™ forms hypotheses, requests the evidence each one needs, queries local telemetry and iterates until it reaches a verdict.
Users, hosts, IPs, processes, emails, domains and assets enriched from local historical data, directory context and environment baselines.
A verdict, an evidence trail, an attack timeline, the affected entities, the risk and the recommended response.
Approved containment and remediation executed through local sensors and integrations.
A single-pass explanation or confidence score, dependent on whatever context the pipeline packaged with the alert. The analyst still decides what evidence was missing, still opens the other consoles, and still forms the hypothesis. The paperwork got faster; the bottleneck did not move.
Competing hypotheses, tested by actively querying local logs, timelines, profiles and connected sources. Multi-step investigation with evidence, pivots and entity context, ending in a complete report with a verdict, an attack timeline, the affected entities and the response actions.
Collects and normalises security events from 250+ log sources across endpoint, identity, network, cloud, SaaS and security tools.
Every qualified alert investigated with evidence collection, validation, correlation and an explainable verdict.
Context-rich profiles for users, hosts, IPs, processes, email addresses and domains, built from local historical activity.
Validated behaviour mapped to lateral movement, persistence, privilege escalation, exfiltration and defence evasion.
SOC-ready investigation reports with summary, malicious behaviour, evidence, timeline, impact and recommended remediation.
Local agent capabilities providing process, network and operating system telemetry alongside prevention and response controls.
Response is based on investigation evidence rather than static playbooks, and every recommendation is tied to the evidence and affected entities that produced it. AirWatch™ validates each action against verified evidence and customer policy before it executes.
Isolate hosts, terminate malicious processes, block files or run controlled remediation.
Disable accounts, force password reset, revoke sessions or flag risky users for review.
Block malicious IPs, domains or URLs through firewall, proxy, DNS or gateway integrations.
Quarantine messages, remove malicious mail and flag suspicious senders.
Telemetry, cases, entity history, model inputs and investigation outputs remain inside the customer environment.
Local inference removes reliance on public model providers and external API calls entirely.
Investigations, detections and response workflows continue while the environment is disconnected from the internet.
Every investigation step, evidence query and response action is traceable for governance, compliance and SOC review.
Not a summary and a score. A complete investigation, with the reasoning chain that produced it, in a typical cycle of 60 to 120 seconds.
Threat, suspicious or benign, based on validated evidence.
The specific events, queries, pivots and observations used during the investigation.
A chronological reconstruction across users, hosts, IPs, processes and services.
Prioritised containment and remediation, with approval or autonomous execution options.
Strict data residency, audit and third-party risk requirements, where an external inference call is itself a finding.
Disconnected or classified environments where internet access and external model calls are not acceptable.
Manufacturing, energy, healthcare and OT estates that require local control and operational continuity.
Multi-tenant autonomous investigation with tenant-level data separation and reporting.
Yes. Sphere On-Premises is designed for on-premises, private cloud, secure enclave and fully air-gapped deployment. Ingestion, detection, investigation, decision and response all complete inside the customer controlled network, and SAGE™ inference runs locally, so investigations continue while the environment is disconnected from the internet.
No. SAGE™ is deployed and served locally. No alert, log, prompt, evidence, embedding or investigation context is sent outside the customer environment, and there is no public model API dependency to call.
Through controlled offline packages, customer approved transfer media or private update channels. Threat content, parsers, model updates and product upgrades all follow that path, so the environment stays disconnected and new content arrives on terms the customer sets.
No. The capability set is the same: autonomous investigation through AuraXP™, local SAGE™ reasoning, 250+ log sources, entity profiling, attack correlation, case summarisation, EdgeProtect™ endpoint visibility, and governed SOAR response. What changes is where each part runs and how content is delivered, not what the platform can do.
An AI-assisted tool summarises the alert and whatever context it was handed, in a single pass. AuraXP™ forms competing hypotheses and then actively queries local logs, timelines, profiles and connected sources for the evidence needed to validate or disprove each one, iterating until it reaches a verdict. The output is a full investigation report with evidence, timeline and affected entities rather than a summary and a score.
AirWatch™, the governance layer, validates AI reasoning against verified evidence, enforces customer policy and prevents unsafe actions while preserving auditability. Low-risk and pre-approved actions run automatically; high-impact actions can require analyst, manager or customer approval. Escalation, deferral and override are tunable controls rather than exceptions.
Yes. The architecture is natively multi-tenant, with tenant-level data separation and reporting, which is what lets a service provider run autonomous investigations for several customers without their data mixing.
In customer controlled hot, warm and archive storage, sized to the organisation's own retention, search and compliance requirements. Cases, entity history, model inputs and investigation outputs stay inside the customer environment.
It is built for regulated environments that require data sovereignty, restricted connectivity and auditable cyber operations. Every investigation step, evidence query and response action is traceable, which is what internal audit, regulatory review and customer governance ask for.
The cybersecurity model that runs locally in this deployment.
The agentic investigation engine that queries your local telemetry.
The governance layer that validates every autonomous action.
SaaS, private cloud, sovereign, hybrid or on-premises.
The OT and ICS side of the same investigation surface.
The platform this deployment runs.
A walkthrough on your own estate, in the deployment model your environment actually permits, rather than a canned demo on someone else's infrastructure.