FAQ

Frequently Asked Questions

Everything you need to know about Aether SOC AI.

What is Aether SOC AI?

Aether SOC AI is an AI-powered SOC platform that triages, enriches, and investigates every security alert in seconds — with a human analyst approving every response action.

How does Aether handle security alerts?

Every alert enters an AI pipeline: exception rule matching, false-positive whitelisting, a first-pass AI triage, and an optional senior AI verification pass for uncertain cases. Each layer is cheaper than the next, so most alerts are closed before the more expensive analysis runs.

Is Aether fully autonomous?

No. Aether's AI agents triage, enrich, and investigate alerts, but every response action requires explicit analyst approval. We believe in human-in-the-loop security operations — AI recommends, humans decide.

What integrations does Aether support?

Aether currently has live integrations with AWS GuardDuty, Microsoft Azure Sentinel, Google Cloud Security Command Center, Wazuh SIEM, Slack, Jira Service Management, Okta, and Discord. More integrations are on the roadmap.

What is the pricing model?

Aether uses simple, volume-based pricing on monthly alert volume. No seat limits, no feature gates, no integration restrictions. Every client gets the full platform regardless of plan. Plans start at $149/month for 30,000 alerts.

Is there a free trial?

Contact our sales team at cynoculist.com/contact to discuss trial options and pilot programs tailored to your environment.

Does Aether work with my existing SIEM?

Yes. Aether connects to your existing security stack — AWS GuardDuty, Azure Sentinel, Wazuh SIEM, and more. No rip-and-replace required. Native connectors and webhooks mean no custom scripts.

How fast is alert triage?

Aether triages most alerts in under 15 seconds. The AI pipeline processes alerts through exception rules, false-positive whitelisting, and L1/L2 agent analysis in a cost-optimised decision tree.

What about data privacy?

Aether provides per-org data isolation, optional Privacy Mode that redacts IPs, email addresses, AWS ARNs, and account IDs before any data reaches an LLM, and BYOK (bring your own LLM API key) so inference costs and data stay with you.

Does Aether use my data to train AI models?

No. Customer data is never used to train AI models. With BYOK, you bring your own LLM API key — your data stays under your control.

What is Privacy Mode?

Privacy Mode is an optional per-org data redaction feature. When enabled, IPs, email addresses, AWS ARNs, and account IDs are replaced with tokens before reaching any LLM, providing full analysis capability with zero raw data exposure.

Can Aether handle high alert volumes?

Yes. Aether is designed to scale to thousands of simultaneous alert streams. The cost-optimised pipeline ensures predictable AI spending even at high volume — most alerts are closed by pattern matching before any LLM call.

What is the difference between the first-pass and senior AI review?

The first-pass triage handles routine work: IOC extraction, enrichment against threat intel sources, and an initial verdict. The senior verification pass only fires on uncertain cases — most alerts never reach it.

Does Aether support MSSP multi-tenant environments?

Yes. Aether scales from small security teams to multi-tenant MSSP deployments. Each organization is fully isolated with separate data, users, and integrations.

What compliance standards does Aether support?

Aether provides MITRE ATT&CK technique tagging, investigation timelines, and one-click report templates aligned to SOC 2 and ISO 27001 requirements, to help your team build audit evidence faster.

How does Aether reduce alert fatigue?

Aether's AI pipeline automatically triages and filters noise, delivering only high-confidence true positives with full context to analysts. The exception rule engine and false-positive whitelist close known noise instantly before any AI processing.

Can I bring my own LLM API key?

Yes. Aether supports BYOK (bring your own LLM API key). LLM inference costs stay with you, not us. This gives you full control over your AI spending and data.

What happens when alerts exceed my plan limit?

Overage alerts are queued, never dropped. Overage pricing is $0.001 per alert over your plan cap. Your service continues without interruption.

How does Aether handle false positives?

Aether's false-positive whitelist uses semantic similarity matching against past false positives to automatically close known noise. The exception rule engine pattern-matches on IP, keyword, and title regex to close noise instantly.

Does Aether generate compliance reports?

Yes. Aether provides one-click compliance-ready reports with MITRE ATT&CK technique tagging, investigation timelines, and full audit trails for SOC2 and ISO 27001.

Still have questions? We'd love to hear from you.

Contact Us →