Drop-in alert triage with local AI. Open source. TierX turns the alert flood from your SIEM and EDR tools into analyst-ready incidents — on-premise, fully air-gapped if you choose. Built for KRITIS, NIS2 and BSI IT-Grundschutz.
Alert data, threat intelligence and AI inference run entirely inside your infrastructure — fully air-gapped if you choose.
No data leaving the building, no data processing agreements, no cross-border transfer assessments. Locality by architecture, not by contract.
A single Docker Compose stack on one server or VM. Offline release bundles via USB/SFTP for air-gapped sites.
Deterministic pre-processing before the AI, every step recorded, every model your choice.
Exact-duplicate suppression via fingerprinting and entity-based correlation deterministically condense the alert flood into incidents — reproducible and predictable. Critical alerts escalate instantly.
The AI investigates by shipped, versioned YAML playbooks — with enough context for open-source models to master the analysis reliably. Full audit trail: every step recorded and replayable.
The best local model per task — e.g. GPT-OSS for reports, a security model for alert analysis. If context is missing, TierX asks departments by email. Analysts search everything via chat.
TierX receives alerts from your existing tools via REST API, suppresses duplicates and links related alerts into one incident.
A locally hosted LLM investigates the incident by playbook and gathers missing information by email on its own.
What happened, evidence, kill chain, next steps — in the dashboard or directly in Jira, XSOAR or TheHive.
TierX is the invisible intelligence behind your SOC: it analyzes every alert in full enterprise context — with access to internal data, knowledge base and SOC processes. That context is exactly what makes the analysis precise. And exactly why it must never leave the building.
Air-gap capable, threat intel from your own MISP instance, not a byte leaves the network. Open source: every line inspectable, no lock-in, no license kill-switch.
One Docker Compose stack on your server or VM. Offline bundles via USB/SFTP. Multi-tenant with hard data isolation for group structures and MSSPs.
Every alert, every processing step, every AI decision: recorded and replayable. Forensic-grade traceability — nothing disappears silently.
| Cloud AI-SOC vendors | TierX |
|---|---|
| Alert data leaves the network | Nothing leaves the network — air-gap capable |
| AI reasoning is a black box | Playbook-driven: your team writes the AI’s investigation steps |
| Pricing anxiety: per seat, per GB, per cloud call | Runs on your own hardware |
| Compliance assessment per data flow | Locality by architecture, not by contract |
| Closed, proprietary code | Open source — inspectable, auditable, no lock-in |
The key criteria for assessing AI-powered alert triage under NIS2, BSI IT-Grundschutz and critical-infrastructure requirements — compact, as a PDF. Not ready for a demo yet? Start here.
Available for pilot deployments. We show TierX where it will run later: in your network, behind your firewall.
The TierX repository will be published shortly. Sign up and we will notify you at launch.