TierX will be released as an open-source project. Get notified at the repo launch →
TierX · Open Source · On-Premise

SOC automation that never leaves your network.

Drop-in alert triage with local AI. Open source. TierX turns the alert flood from your SIEM and EDR tools into analyst-ready incidents — on-premise, fully air-gapped if you choose. Built for KRITIS, NIS2 and BSI IT-Grundschutz.

Available for pilot deployments · In production within a day
tierx · incident INC-2041
incident  INC-2041  HIGH
alerts    14 correlated → 1 incident (host, user, technique)
kill-chain Initial Access → Credential Access → Lateral Movement
mitre     T1078 · T1021.002 · T1550
next steps Disable account, isolate host, forensic snapshot
// nothing left your network
alert_type: lateral_movement
model: security-analysis # security model for alert analysis
report_model: gpt-oss
steps:
  - gather_context: hosts, users, processes
  - threat_intel: your own MISP instance
  - assessment: kill chain + recommendation
version: 3 # versioned, auditable
$ docker compose up -d
sources   splunk · cortex-xdr · qradar · wazuh · sentinel
intel     misp (self-hosted) · mitre att&ck
handoff   jira · xsoar · thehive
llm       ollama · model of your choice
status    running · on-premise · air-gapped
Connects the tools you already run
SplunkCortex XDRQRadar WazuhMicrosoft SentinelMISP MITRE ATT&CKJiraXSOAR TheHiveOllama
The new standard

Sovereign SOC automation

100 %
On-premise

Alert data, threat intelligence and AI inference run entirely inside your infrastructure — fully air-gapped if you choose.

0 Byte
Cloud transfer

No data leaving the building, no data processing agreements, no cross-border transfer assessments. Locality by architecture, not by contract.

1 day
to production

A single Docker Compose stack on one server or VM. Offline release bundles via USB/SFTP for air-gapped sites.

Built for analysts who want proof — not promises

Deterministic pre-processing before the AI, every step recorded, every model your choice.

Efficiency

Noise out before the AI runs

Exact-duplicate suppression via fingerprinting and entity-based correlation deterministically condense the alert flood into incidents — reproducible and predictable. Critical alerts escalate instantly.

Traceability

Playbooks, not a black box

The AI investigates by shipped, versioned YAML playbooks — with enough context for open-source models to master the analysis reliably. Full audit trail: every step recorded and replayable.

Control

Your models, your hardware

The best local model per task — e.g. GPT-OSS for reports, a security model for alert analysis. If context is missing, TierX asks departments by email. Analysts search everything via chat.

How it works

From alert flood to finished incident

01

Filter & consolidate

TierX receives alerts from your existing tools via REST API, suppresses duplicates and links related alerts into one incident.

02

AI investigation — local

A locally hosted LLM investigates the incident by playbook and gathers missing information by email on its own.

03

Analyst-ready hand-off

What happened, evidence, kill chain, next steps — in the dashboard or directly in Jira, XSOAR or TheHive.

Sovereignty guarantee

Built for critical infrastructure. Designed for control.

TierX is the invisible intelligence behind your SOC: it analyzes every alert in full enterprise context — with access to internal data, knowledge base and SOC processes. That context is exactly what makes the analysis precise. And exactly why it must never leave the building.

Sovereign

Air-gap capable, threat intel from your own MISP instance, not a byte leaves the network. Open source: every line inspectable, no lock-in, no license kill-switch.

Portable

One Docker Compose stack on your server or VM. Offline bundles via USB/SFTP. Multi-tenant with hard data isolation for group structures and MSSPs.

Auditable

Every alert, every processing step, every AI decision: recorded and replayable. Forensic-grade traceability — nothing disappears silently.

Air-gap capableNIS2-aligned data localityBSI IT-Grundschutz-alignedOpen source (repo public soon)
Positioning

Cloud-AI-SOC vs. TierX

Cloud AI-SOC vendorsTierX
Alert data leaves the networkNothing leaves the network — air-gap capable
AI reasoning is a black boxPlaybook-driven: your team writes the AI’s investigation steps
Pricing anxiety: per seat, per GB, per cloud callRuns on your own hardware
Compliance assessment per data flowLocality by architecture, not by contract
Closed, proprietary codeOpen source — inspectable, auditable, no lock-in
Honest framing: TierX is analysis and triage automation — it investigates and recommends, but does not execute autonomous containment actions (automated response is on the roadmap). For critical-infrastructure operators that is a feature: no AI gets the keys to your production infrastructure.
Feature set

Everything in the current release

PIPELINEMulti-stage alert pipeline with full audit trail — every step recorded and replayable
DEDUPExact-duplicate suppression via fingerprinting
CLUSTERINGEntity-based incident clustering with severity-aware timing
LLMPlaybook-driven local AI analysis (Ollama, model of your choice)
MODEL ROUTINGThe best model per task — e.g. GPT-OSS for reports, a security model for analysis
SCHEMASCustomer-managed alert schemas as YAML — self-service in the dashboard
PLAYBOOKSReady-made playbooks included — versioned, adaptable, LLM-optimized
CONTEXTAnalysis in full enterprise context — internal data and SOC processes
FOLLOW-UPSAutomated email communication with business departments
KNOWLEDGEKnowledge base with semantic search — your own reference documents
THREAT INTELYour own MISP instance + MITRE ATT&CK context
DASHBOARDAnalyst dashboard incl. quarantine management and platform health
SOC CHATNatural-language search across customer data, alerts and knowledge base
CASE MANAGEMENTSimple integration with Jira, XSOAR or TheHive
MULTI-TENANTStructurally isolated data per tenant — for groups and MSSPs
DEPLOYMENTSingle-command Docker deployment · offline/air-gapped delivery
Free resource

NIS2/BSI checklist: evaluating on-premise AI in the SOC

The key criteria for assessing AI-powered alert triage under NIS2, BSI IT-Grundschutz and critical-infrastructure requirements — compact, as a PDF. Not ready for a demo yet? Start here.

Give your SOC sovereignty.

Available for pilot deployments. We show TierX where it will run later: in your network, behind your firewall.