Solutions · CyberSec · Respond

Containment that earns the right to act.

Governed Containment gives the enforcement points you already run the knowledge of what an access could lead to. Blocking earns its authority through measured accuracy, and every change to your estate is previewed, approved by a person and written to a tamper-evident audit trail.

Attacks contained sooner, with every change approved and on the record.

  • Containment in effect sooner. Measured by MTTC, Mean Time to Contain.
  • More blocking rules that have earned enforcement. Measured by rules that earned enforcement.
  • Fewer blocks overridden or reverted. Measured by denial override rate.
MTTC · Mean Time to Containdwell-time averagesdown against your baseline · a human approval on every change

Supporting KPIs

Time from verdict to approved containment ↓

From an evidenced verdict to a human-approved action

audit trail

Rules that earned enforcement ↑

Share of blocking rules that moved from shadow to enforce on a measured override rate

audit trail

Denial override rate ↓

Denials overridden or reverted, per rule

audit trail

Actions with rollback armed ↑

Share of executed actions that were reversible with a rollback armed

audit trail

Actions without a recorded approval ↓

Executed actions with no recorded human approval. Must stay at none

audit trail

Baselines are set in the 30-day diagnostic. Targets are committed in the 90-day scorecard. A KPI we cannot measure is reported as UNMEASURED.

Too slow by hand. Too dangerous on autopilot.

Manual containment moves at the speed of the approval chain, and attackers move in minutes.

Read why

Automated remediation fails the other way. Detect a problem, ask a model, act: a wrong detection, a wrong decision and an irreversible action are three survivable failures that combine into one catastrophic one.

And every enforcement point decides half-blind. The WAF sees the request and finds nothing malicious in it. The identity provider sees a known service account in an expected location. Neither knows what that access could reach once it is allowed.

What it costs

  • Containment that waits while approvals are assembled.
  • Automation switched off after its first false positive.
  • A block that causes the outage it was meant to prevent.

Four proposals. One crossed the boundary.

  • narrow sg-0f3a41 · close tcp/8080 → applied · change C-4117 · rollback armed · by: a human
  • delete unused role hl-legacy-admin → refused · blast radius UNMEASURED · a guess may not act
  • quarantine 10.0.4.17 → refused · oldest fact stale · 9 days · freshness is a gate
  • let the model apply its own fix → refused · no write path exists in the AI process

Change C-4117 crossed the boundary because a human pressed Approve. Nothing else did.

illustrative console output · the categories and the final line are the contract

Two lanes, split by reversibility and nothing else.

Governed Containment runs on SecSemantic's twin, so every decision is made with what the access or the change could lead to.

Fast lane · blockingSlow lane · acting
The questionShould this request proceed?Should we change this infrastructure?
Speedmicrosecondsminutes
Human approvalno · policy decided in advancealways
Undone bythe next requesta rollback, if one exists
Earned byobserve → shadow → soft → enforcetrust rung 1 → 2 → 3

Access decisions at your identity provider, API gateway, WAF and service mesh are made with knowledge of what the access could reach, served in microseconds from a precomputed set. Nothing calls the appliance on the request path.

What you get

  • An enforcement policy set for your estate, each rule with its earned rung and override record
  • Containment actions as named, reversibility-classed changes with approval routes
  • A tamper-evident audit trail of every proposal, approval, rejection and outcome
  • Change records, freeze windows and regulated-system exclusions honoured on every action

Industry lens

Containment that honours change freezes and excludes SOX-scoped systems where your policy says so.

What it is not

Not an autonomous remediation engine. It is banned outright in the architecture, and an automated test proves the ban holds.

FAQ

Will it block legitimate traffic?

A rule cannot deny anything until it has earned it: it runs in observe and shadow first, and moves to enforce only on a measured override rate. The blast radius of each denial is computed before it happens, and a circuit breaker stops enforcement from turning into an outage.

Does our traffic flow through the appliance?

No. Decisions are precomputed and served to the enforcement points you already run. Nothing on the request path calls the appliance.

What happens if the appliance goes down?

Your enforcement points keep their last decision set and the degradation is shown on screen. Your traffic never stops because of it.

Can the AI take an action?

No. AI proposes, deterministic code decides, and a human approves anything that touches production. The AI process has no write path, and a test proves it on every build.

What credentials does it use to make changes?

A short-lived credential your own systems mint for a single action, valid for minutes. The appliance holds no standing write access.

Can we stop everything at once?

Yes. All action can be halted through your own identity system within one credential lifetime.

Which enforcement points does it work with?

Your identity provider, API gateway, WAF and service mesh for blocking. Infrastructure changes in your clouds for the slow lane.

What does tamper-evident mean here?

Every proposal, approval, rejection and outcome is recorded before the action runs, in a form where any later alteration is detectable.

How Governed Containment is delivered

A capability, the people who run it with you, and numbers you can check.

  • Diagnostic · days 0 to 30, at no cost.

    The twin is launched and nothing can act. Your enforcement points, change process, freeze windows and regulated-system exclusions are mapped into policy, and your current time to contain is measured from your incident records where they exist. Where they do not, it is UNMEASURED.

  • Outcome · days 30 to 90.

    Blocking rules run in observe and shadow mode and move to enforce only on a measured override rate. Every infrastructure change runs with a human approval.

  • The Semantic Loop · from day 90.

    Every approval, rejection and outcome is fed back into policy and into the twin. Actions without a recorded approval stay at none.

The pod

two senior engineers and a fractional CISO advisor

  • Forward-deployed security engineer.

    Integrates your enforcement points and change process, writes the policy with you, owns the KPI baseline.

  • Incident analyst.

    Works containment decisions with your security operations team and reviews every rule's shadow record before it is promoted.

  • Fractional CISO advisor.

    Owns the 90-day scorecard with your leadership and chairs the day-90 review.

What runs underneath

SecSemantic's Command, the only component that may change the estate: the fast lane for blocking and the slow lane for acting. It is fed by Shield's verdicts and Sentinel's blast radius, and Insights presents the audit trail, read-only.

Let containment earn its authority.

We start in shadow, measure every decision a rule would have made, and let it act only when the record says it should. Every change still ends at a person.

  • SOC 2Type 2
  • HIPAACompliant
  • GDPRCompliant
  • ISO 270012013
  • ISO 90012015
  • ISO 200002018
  • ISO 134852016