Platform / SecOps
SecOps for the AI era: autonomous SOC agents and runtime AI security
Two halves of one discipline. AI that works your security operations under human approval, and security that governs the AI you already run.
Security teams now face AI twice. It is a new way to do the work, with autonomous SOC agents that triage, investigate and prepare response. And it is a new thing to protect, with agents, models and tools that hold real authority. The Sovereign Intelligence Platform treats both with the same controls: identity, permissions, policy evaluated at runtime, human approval where it matters and an evidence-grade audit trail.
Two halves, one control model
The same identity, permission, policy, approval and audit controls apply whether AI is doing the security work or being secured.
AI for security operations
Autonomous SOC agents that read the queue, build the investigation and prepare the response. Governed response means an agent acts only inside limits you set, and a named person approves anything above them.
AI SOC agentsSecurity for AI
Runtime AI security for the agents and models in your estate: defense against prompt injection, least-privilege permissions, tool and MCP controls, shadow AI discovery and testing against OWASP and MITRE ATLAS.
Agent runtime security
AI for security operations
Agents that work the alert queue, investigate and prepare response, with people approving what matters.
AI SOC agents
Autonomous SOC agents for triage, investigation and governed response, with a human approving what matters.
AI incident response
A runbook for incidents where an AI system is the cause, the target or the tool: contain, preserve, report.
Security for AI
Runtime guardrails, prompt-injection defense, agent permissions, tool security and discovery for the AI you already run.
Prompt injection defense
Design agents so a successful prompt injection cannot reach anything that matters.
Agent runtime security
Identity, permissions and policy enforced while the agent runs: zero-trust for agents.
MCP and tool security
Govern which tools an agent can call: registry, scoped tokens, audience validation, approvals and audit.
Shadow AI discovery
Find the unsanctioned models, agents and keys, then bring them under policy without stopping the work.
AI red teaming
Adversarial testing of models and agents against OWASP and MITRE ATLAS, in a sandbox, with findings you can retest.
Frameworks and evidence
The OWASP and MITRE vocabulary, and the audit trail that turns controls into proof.
OWASP LLM Top 10
The OWASP Top 10 for LLM Applications (2025) and the Agentic Top 10 (2026), mapped to platform controls.
AI audit trail
An evidence-grade record from data to model to agent to decision to action to outcome.
SecOps across the six platform layers
Security is not a seventh layer. It is how each of the six layers is run.
| Layer | What SecOps does here | Entry points |
|---|---|---|
| 01Sovereign Infrastructure | Run SOC agents and models where your telemetry is allowed to be. The platform is designed so security data and incident evidence can stay on infrastructure you control. | |
| 02Data & Context | Give agents your runbooks, asset context and past incidents as controlled knowledge, and connect the SIEM, EDR, identity and ticketing tools they need to read. | |
| 03Intelligence & Models | Decide which models may see which data. The gateway screens inputs and outputs, limits consumption and logs every model call. | |
| 04Governed Agents | Every SOC agent and every business agent gets an identity, an owner, scoped permissions and in-flight policy. Nexus governs; Studio builds. | |
| 05Governed Workflows | Triage, investigation and response run as workflows with approval gates between steps, so a person is in the loop exactly where risk is. | |
| 06AI Solutions | SOC triage, AI incident response, AI security posture and shadow AI governance, packaged as measurable outcomes rather than as tools. |
The Trust and Governance Fabric runs through all of it
Governance happens inside the AI. Thirteen facets apply across every layer, and traceability is the chain from data to model to agent to decision to action to outcome.
- Identity
- Access
- Data controls
- Policy
- Security
- Privacy
- Compliance
- Risk
- Human oversight
- Auditability
- Traceability
- Evidence
- Monitoring
See trust and governance and the Trust Profile.
Controlled autonomy for SecOps actions
Not manual to autonomous: five levels, set per action type and earned from the record. Destructive or hard-to-reverse actions can stay at an approval level permanently.
| Level | Definition | SecOps example | Guardrail |
|---|---|---|---|
| L1 Assist | The agent recommends. A person does the work and makes every decision. | Triage recommendation: severity, enrichment, linked cases and a drafted ticket. | Read-only access. Inputs and recommendations are recorded. |
| L2 Approve | The agent prepares the action. A human approves before anything happens. | A prepared containment step, such as isolating a host, queued for a named approver. | Every action approved. The approver and the evidence shown are recorded. |
| L3 Supervise | The agent acts within limits and is monitored. Exceptions above thresholds go to a person. | Contain within limits: a non-critical endpoint or a single standard user session. Critical assets escalate. | Explicit per-action limits, live monitoring and an easy undo. |
| L4 Autonomous | The agent acts independently within strict policy and risk bounds. | A narrow, reversible playbook for a well-understood alert class, with sampled human review. | Hard bounds enforced at runtime, anomaly detection on the agent itself. |
| L5 Adaptive | The agent improves within controlled boundaries. | Proposes detection or playbook tuning from past cases. Changes are tested, versioned and gated. | Boundaries cannot be self-modified. Behaviour changes are recorded. |
An agent cannot raise its own level. Changes are made by the accountable owner and recorded in the agent's Trust Profile. Full model: controlled autonomy.
Aligned to the frameworks security teams already use
Controls are mapped to published frameworks so coverage is visible and testable. Mapped means designed to address those risks. It does not mean the framework bodies have certified anything.
OWASP Top 10 for LLM Applications (2025)
Ten risks from Prompt Injection (LLM01) to Unbounded Consumption (LLM10).
OWASP Top 10 for Agentic Applications (2026)
Ten risks for agents that plan, remember and act, from Agent Goal Hijack (ASI01) to Rogue Agents (ASI10).
MITRE ATLAS
Adversary tactics and techniques against AI systems, built on the ATT&CK model and updated often.
Details: OWASP LLM Top 10 and MITRE ATLAS mapped to controls.
EU angle: evidence for NIS2, DORA, GDPR and the EU AI Act
Swfte supports evidence for these obligations. It does not make any use compliant by itself.
NIS2 (Directive (EU) 2022/2555)
Art. 21 risk-management measures and Art. 23 staged incident reporting. Supports evidence for incident handling, supply-chain security and access control.
DORA (Regulation (EU) 2022/2554)
ICT risk, incident reporting, resilience testing and third-party risk for financial entities. Supports a register of AI dependencies and a classified incident record.
GDPR
Art. 32 security of processing. Supports evidence of access control, minimisation and logging around personal data.
EU AI Act (Regulation (EU) 2024/1689)
Art. 12 record-keeping, Art. 14 human oversight, Art. 15 accuracy, robustness and cybersecurity. Supports evidence of logging, oversight points and resilience controls, where a use falls within scope.
Swfte is built compliance-by-design. It provides the technical controls, governance mechanisms and evidence required to deploy AI within an organisation's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration. Nothing on this page is legal advice. Swfte's own security attestations are listed on the trust page.
Related pages across the site
These cover adjacent topics in depth. The SecOps pages link to them rather than repeat them.
- SecOps Agents (product)
Beta status, roadmap and waitlist.
- AI security tools compared
Where each category of tool fits.
- Zero trust for AI agents
The principle and the toolset.
- MCP gateway
The control plane for tool calls.
- MCP security best practices
A hardening checklist.
- What is shadow AI?
The concept and the risks.
- AI agent governance
Inventory, policy and audit for agents.
- Claude Code security
The coding-agent case.
- OpenClaw security
Securing a popular open agent.
- Trust
Security attestations and the current security position.
From the blog
- AI SOC agents with human approval: what to automate first
Sequencing triage, investigation and response.
- Prompt injection defense in agentic systems
Layered controls beyond filtering.
- Securing MCP servers and tool access
Registry, scoped tokens and audit.
- OWASP LLM Top 10 explained for engineers
Each risk with a worked example and a control.
- AI incident response runbook
Six steps with evidence to preserve.
- Shadow AI: finding and governing unsanctioned model use
Discover, classify, decide, migrate, monitor.
What this section does not claim
- No detection rate, accuracy figure, response-time improvement, customer result or benchmark is stated, because none is published here.
- SecOps Agents is in beta. Where a page describes a capability, it describes what the platform is designed to let your team do. Nexus enforcement is deepest today for coding agents.
- Nothing here claims that your use of the platform is compliant with any regulation. Swfte's own security attestations are listed on the trust page.
Frequently asked questions
What does SecOps mean on the Swfte platform?
Both directions of AI in security. AI for security operations: autonomous SOC agents that triage, investigate and prepare response under human approval. And security for AI: runtime guardrails, prompt-injection defense, agent permissions, MCP and tool security, shadow AI discovery and audit for the AI you already run.
Is the autonomous SOC fully autonomous?
Only where you decide. Controlled autonomy runs from L1 (recommend) to L5 (adaptive) per action type. A typical start is L1 for triage and L2 for containment, with L3 for narrow, reversible actions once the record supports it. Many teams will keep destructive actions at an approval level permanently.
What is runtime AI security?
Security applied while an AI system runs: each agent has an identity and scoped permissions, policy is evaluated before every action, risky actions require human approval, limits and kill switches stop runaways and a record is kept of what happened. Governance happens inside the AI rather than in a document.
Which frameworks do you align to?
Controls are mapped to the OWASP Top 10 for LLM Applications (2025), the OWASP Top 10 for Agentic Applications (2026) and MITRE ATLAS. Mapped means designed to address those risks and testable against them. It does not mean certified or audited by those bodies.
Is the platform compliant with NIS2, DORA, GDPR or the EU AI Act?
Swfte is built compliance-by-design. It provides the technical controls, governance mechanisms and evidence required to deploy AI within an organisation's applicable regulatory, security and policy requirements. The exact posture depends on the customer's use case, jurisdiction, deployment and configuration. The trust page lists the current security position.
What is the status of SecOps Agents?
SecOps Agents is in beta. The pages in this section describe what the platform is designed to let your team do and which controls apply. The product page carries the current status and the waitlist. <general availability date - founder to fill>
Do you publish detection rates?
No. We do not publish detection or accuracy rates, and be wary of any vendor that promises to block all prompt injection. Our position is that a successful attack should have little to reach, and that you should be able to prove what happened.
Run SecOps on the Sovereign Intelligence Platform
Start with one agent and one policy, or talk to the team about your environment, your data and your regulators.