Technology

    Three layers: reason, act, and stay inside the line

    Autonomy in security fails in one of three ways. The model does not understand the domain, the agents cannot act on what it concluded, or nothing constrains what they do. SAGE™, AuraXP™ and AirWatch™ are the answers to those three, in that order.

    Why a general-purpose model is the wrong tool

    The obvious way to build an AI security product is to send telemetry to a large general-purpose model and ask it what it thinks. It demonstrates well and it fails in production for two reasons that have nothing to do with model quality.

    The first is boundary. Security telemetry is among the most sensitive data an organisation holds: it describes the internal topology, the identities, the access patterns and the weaknesses. In regulated sectors it frequently cannot leave the jurisdiction, let alone the organisation. A platform whose reasoning happens at somebody else's API is a platform that cannot reason about the data that matters most, and no amount of contractual assurance changes what the network path is.

    The second is fit. A general model has read a great deal about security and has practised very little of it. It knows what a Kerberos ticket is in the sense that an encyclopaedia knows; it has not developed the judgement about which sequence of authentication events in this environment is worth waking someone for. That judgement is what a security operation actually needs, and it comes from training on the domain rather than from scale alone.

    SAGE™ is Spharaka's answer: a cybersecurity-specific small language model rather than a general-purpose large one. Small is the point. A model sized for the domain can run inside your own data centre, which means the reasoning happens where the data already is, including on networks with no outbound connectivity at all.

    Reasoning is not enough on its own

    A model that reaches a correct conclusion and then presents it to a human for action has automated the thinking and left the bottleneck exactly where it was. The gap between knowing what happened and having done something about it is where most of the mean time to respond actually sits.

    AuraXP™ closes that gap. It is a multi-agent fabric, forty or more agents that collect, correlate, investigate, decide and act, working on one shared case rather than as isolated automations each holding a fragment. The distinction from conventional automation is that the sequence is not fixed in advance. A hand-built playbook encodes the steps someone anticipated; an agent works from the case in front of it, which is why novel incidents do not simply fall through to the manual queue.

    This is also what separates agentic AI from SOAR automation, a comparison worth reading in full if you are evaluating the category. SOAR executes a decision tree a person wrote. An agent fabric reaches the decision.

    Autonomy needs a line drawn around it

    An agent that can disable an account, isolate a host or block a route can also disable the wrong account, isolate a production database or block a route the business depends on. Any platform that claims autonomy and has no answer to that is asking you to accept a new class of incident in exchange for closing an old one.

    AirWatch™ is that answer. It is the governance layer, and it defines three categories of action: what the platform may do on its own, what requires human approval before execution, and what is prohibited outright. Every action in every category is recorded with the evidence chain that led to it, which is what turns an autonomous decision into something reviewable after the fact rather than something to be taken on trust.

    The practical consequence is that change control operates on the policy rather than on individual actions. A CISO office, a legal function and an audit function review the envelope once and revisit it on a schedule, instead of being asked to approve machine-speed decisions one at a time, which they cannot do at machine speed and should not be asked to.

    • Reasoning runs wherever the platform runs, including fully air-gapped
    • Agents work one shared case rather than passing fragments between automations
    • Every autonomous action carries the evidence chain that produced it
    • The permitted envelope is explicit, reviewable and versioned as policy
    • Prohibited actions stay prohibited regardless of model confidence
    Questions

    Frequently asked questions

    What is SAGE and how is it different from a general-purpose LLM?

    SAGE is a cybersecurity-specific small language model, trained on the domain rather than adapted to it. Two things follow. It is sized to run inside a customer's own environment, so reasoning happens where the telemetry already sits instead of at an external API, which is what makes air-gapped deployment possible. And its judgement about what matters in a sequence of security events comes from the domain rather than from general knowledge about security.

    What does AuraXP actually do?

    AuraXP is the multi-agent fabric that turns a conclusion into an action. Forty or more agents collect, correlate, investigate, decide and act on one shared case. Unlike a playbook, the sequence is not fixed in advance, so an incident nobody anticipated does not fall straight through to the manual queue. It is the layer that closes the gap between knowing what happened and having done something about it.

    How does AirWatch prevent an autonomous action causing an incident?

    AirWatch defines three categories: actions permitted autonomously, actions requiring human approval before execution, and actions prohibited outright. Prohibited stays prohibited regardless of how confident the model is. Every action in any category is recorded with its evidence chain, and because the policy is the unit of change control, governance functions review the envelope rather than individual machine-speed decisions.

    Is this the same as agentic AI applied to SOAR?

    No, and the difference is where the decision is made. SOAR executes a decision tree a person wrote in advance, so its coverage is limited to what was anticipated. An agent fabric reaches the decision itself from the case in front of it. A SOAR playbook can be made faster; it cannot be made to handle a case its author did not foresee.

    Can these run without sending data outside our environment?

    Yes. All three layers run wherever the platform runs, including on-premises and fully air-gapped with no outbound connectivity. This is the specific reason the model is small and cybersecurity-specific rather than large and general: a model that only runs at a public API cannot reason about data that is not permitted to go there.

    Experience the Future

    See Spharaka Sphere™ in action

    Discover how Spharaka's AI-native, autonomous cyber defence platform modernises your security operations.