# Triage

*/Startups/Triage*

## Startup Overview

Security operations centers face an endless volume of low-fidelity alerts, forcing analysts to manually sift through false positives and repetitive threats. This engine ingests the daily flood of security events and automatically resolves the noise. By applying historical SOC resolution data, it executes the exact investigative steps a human analyst takes to close routine tickets.

Traditional orchestration tools like Splunk SOAR and Cortex XSOAR demand extensive playbook engineering and continuous maintenance to automate basic tasks. Outsourced MSSPs shift the manual labor to an external team with high monthly retainers. In contrast, this system operates fully autonomously out of the box, deploying models that immediately recognize and close familiar alert patterns without custom rule configuration.

Organizations pay exclusively for outcomes rather than software licenses or hourly labor. The service charges solely per successfully resolved security incident. This structure aligns cost directly with the reduction of analyst workload, ensuring security teams spend budget only when the system actively closes cases and reduces the alert queue.

## Startup Founding Hypothesis

**Approach**: that auto-resolves low-fidelity alerts using historical SOC resolution data
**Competitors**:
- [Splunk SOAR](/Competitors/Splunk_SOAR)
- [Cortex XSOAR](/Competitors/Cortex_XSOAR)
- [Outsourced MSSPs](/Competitors/Outsourced_MSSPs)
**Differentiator2x2**: fully autonomous out-of-the-box and priced per successfully resolved security incident

## Startup Solution Coordinate

**Solution**: [Triage Autonomous Analyst](/Agents/Triage_Autonomous_Analyst)

## Startup Position2x2

```mermaid
quadrantChart
    title Security Alert Resolution Market
    x-axis "Requires Playbook Engineering" --> "Out-of-the-Box Autonomy"
    y-axis "Fixed or Volume Licensing" --> "Outcomes-Based Pricing"
    quadrant-1 "Outcome-Driven Automation"
    quadrant-2 "Service-Wrapped Outcomes"
    quadrant-3 "Legacy SOAR Platforms"
    quadrant-4 "Usage-Billed Engines"
    Splunk SOAR: [0.15, 0.15]
    Cortex XSOAR: [0.25, 0.20]
    Outsourced MSSPs: [0.10, 0.45]
    Triage: [0.85, 0.85]
```

## Startup Offer

**Proof**:
- Aim to auto-resolve up to 70% of routine brute-force and impossible-travel alerts for mid-sized enterprise SOCs.
- Targeting zero false-negative closures during the standard 14-day shadow-mode deployment phase.
- Designed to eliminate 20+ hours per week of manual L1 triage work, allowing analysts to focus strictly on escalated threats.
**Tiers**:
- Name: On-Demand Resolution · Price: ~$4–$8 per resolved incident · Inclusions: Unlimited ingestion of low-fidelity alerts, standard historical matching engine, and billing triggered only when an alert is definitively closed without human intervention.
- Name: Committed Volume · Price: ~$2–$5 per resolved incident · Inclusions: Intended for teams processing over 5,000 monthly alerts, including custom runbook parsing and priority API rate limits for faster processing.
- Name: Enterprise Dedicated · Price: ~$60k–$90k/yr flat rate · Inclusions: Unmetered alert resolution for a single global SOC, including intended connectors for custom data lakes and a dedicated, isolated model tuning instance.
**Guarantee**: If an auto-resolved alert is later reopened by an analyst or flagged as a missed true-positive, the incident fee is immediately refunded and the specific resolution path is quarantined pending human review.
**Business Function**: ProvideService
**Objection Handlers**:
- Objection: AI will incorrectly dismiss a critical true-positive threat. Response: The system is designed to default to human escalation immediately if the historical match confidence score falls below your strictly defined threshold.
- Objection: Connecting this to our existing SIEM will require a massive security review. Response: Intended to operate via read-only API access during the training phase, requiring explicit write-permissions only when you are ready to enable active resolution.
- Objection: We already have a SOAR platform that we spent years configuring. Response: Designed to function as an upstream filter for your SOAR, handling repetitive L1 alerts so your expensive SOAR playbooks only trigger for complex, multi-stage threats.
**Pricing Architecture**: UsageMeter
**Agent Checkout Support**:
- agentic-commerce-protocol

## Startup Brand

**Voice**: Clinical and authoritative, prioritizing factual incident reporting and direct action.
**Tagline**: Resolves low-fidelity security alerts autonomously using historical data.
**Icon Concept**: pager
**Palette Intent**: electric-signal
**Visual Identity**: Deep charcoal backgrounds anchor high-contrast neon green typography that evokes command-line interfaces for immediate incident visibility.
**Archetype Reference**: the-sage

## Startup Buyer Chain

**Chain**: B2B (Startup → CISO / SOC Manager → Tier 1 Security Analyst)
**Gtm Motion**: Acquisition relies on a shadow-mode proof of concept that ingests historical SIEM alerts to demonstrate autonomous resolution accuracy without impacting the live environment. Expansion occurs directly through the usage-based, per-resolved-incident pricing model as SOC teams gain trust and route additional alert categories to the system.
**Agent Channel**: Designed for registration in AI agent tool registries (such as the LangChain tools ecosystem) as a callable triage API that overarching autonomous security agents can query to offload the deterministic verification of low-fidelity alerts.
**Primary Channel**: Inbound discovery driven by intended listings in major SIEM ecosystem directories (such as Splunkbase or the Microsoft Sentinel Content Hub) where SOC engineers actively search for alert reduction and SOAR augmentation tools.

## Startup Customer Journey

```mermaid
flowchart LR; A[SIEM Ecosystem Directory] --> B[Shadow-Mode POC]; B --> C[Auto-Resolved Incident]; C --> D[L1 Triage Workflow]; D --> E[Usage-Metered Contract]; E --> F[Custom Runbook Parser]; F --> G[Agent Tool Registry];
```

## Startup Proof Points

_Illustrative — target and order-of-magnitude estimate figures, not an achieved track record (this Thing is concept-stage)._

**Pilot Goals**:
- 14-day shadow-mode deployment using read-only API access. Target result: Validate the historical matching engine against human decisions to prove zero false-negative closures before enabling write-permissions.
- 30-day active resolution pilot focused on a single high-volume alert category. Target result: Automatically resolve at least 50% of the targeted alert type without triggering a single human reopening, validating the per-incident ROI.
**Target Metrics**:
- Target: 70% auto-resolution rate for routine brute-force and impossible-travel alerts
- Target: Zero false-negative closures during a 14-day shadow-mode phase
- Target: 20 manual L1 triage hours eliminated per week per 5,000 alerts processed
- Aim: 100% automated refund and quarantine trigger for any system-closed alert reopened by a human analyst
**Target Case Studies**:
- Target: A mid-sized enterprise SOC Director. Transformation: Reduces analyst fatigue by automatically resolving brute-force and impossible-travel alerts, clearing the queue for analysts to investigate advanced persistent threats.
- Target: An MSSP Operations Manager. Transformation: Scales alert handling across multiple client environments without adding L1 headcount by using the triage engine as an upstream filter for their existing SOAR playbooks.
- Target: A Head of Security Engineering at a high-growth tech company. Transformation: Safely deploys read-only shadow-mode triage, smoothly transitioning to active usage-metered resolution after proving zero false-negatives.
**Testimonial Targets**:
- Role: Enterprise SOC Manager. Sentiment: Relief that the system effectively filters out L1 noise and immediately defaults to human escalation whenever the historical match confidence drops.
- Role: L1/L2 Security Analyst. Sentiment: Excitement that they no longer spend shifts closing repetitive location-based alerts and now strictly investigate escalated, multi-stage threats.
- Role: Chief Information Security Officer. Sentiment: Confidence in the risk-free adoption model, specifically praising the initial read-only API deployment and the immediate financial SLA on missed true-positives.

## Startup Top Risks

**Risks**:
- Severity: existential · Description: The autonomous engine incorrectly resolves a critical true-positive alert, resulting in a severe customer data breach and destroying market trust. · Mitigation Status: in-progress
- Severity: high · Description: Customer historical SOC data is too fragmented or poorly labeled to train reliable out-of-the-box resolution models for new deployments. · Mitigation Status: unmitigated
- Severity: high · Description: Incumbent SOAR vendors like Splunk and Palo Alto bundle native LLM-driven auto-resolution features into existing enterprise contracts at no extra cost. · Mitigation Status: unmitigated
- Severity: moderate · Description: SOC managers refuse to delegate resolution authority to a fully autonomous system due to strict compliance mandates or internal risk policies. · Mitigation Status: in-progress
- Severity: low · Description: Customers dispute billing invoices due to disagreements over the technical definition of a successfully resolved incident. · Mitigation Status: unmitigated

## Startup Competitors

- [Splunk SOAR](/Competitors/Splunk_SOAR) — Legacy SOAR
- [Cortex XSOAR](/Competitors/Cortex_XSOAR) — Legacy SOAR
- [Outsourced MSSPs](/Competitors/Outsourced_MSSPs) — Status Quo
- [Torq](/Competitors/Torq) — Modern Security Automation
- [Tines](/Competitors/Tines) — No-Code Workflow
- [Dropzone AI](/Competitors/Dropzone_AI) — Autonomous SOC Analyst

## Startup Solution Stack

- [Incident Resolution Service](/Services/Incident_Resolution_Service) — Service-as-Software
- [Autonomous Triage Agent](/Agents/Autonomous_Triage_Agent) — Agent
- [Historical Context Worker](/Agents/Historical_Context_Worker) — Agent
- [Alert Ingestion API](/Software/Alert_Ingestion_API) — Software
- [SOC Telemetry Engine](/Software/SOC_Telemetry_Engine) — Software

## Startup Story Brand

**Hero**:
- **Need**: to be the defender who detects sophisticated breaches, not an alert-clearing clerk
- **Want**: to clear the daily backlog of repetitive security alerts without analyst burnout
- **Identity**: the L1 SOC Manager at a mid-market enterprise
**Plan**:
- Step: Select alerts · Detail: Choose the specific low-fidelity alert types you want Triage to handle autonomously.
- Step: Verify logic · Detail: Run the system in shadow-mode to confirm every resolution matches your existing security standards.
- Step: Enable resolution · Detail: Grant write-permissions to allow the system to definitively close incidents without human intervention.
**Guide**:
- **Empathy**: Does your alert queue still overflow with the same low-fidelity noise every morning?
**Problem**:
- **Villain**: Alert Fatigue
- **External**: Analysts spend 20+ hours per week manually dismissing brute-force and impossible-travel alerts in Splunk or Cortex XSOAR.
- **Internal**: You feel like your skilled team is drowning in noise while missing the real threats.
- **Philosophical**: Cybersecurity expertise belongs in threat hunting, not in repetitive data entry.
**Success**: Your SOC queue remains at zero for routine events, leaving analysts free to focus exclusively on complex, multi-stage threats.
**One Liner**: Instead of burying analysts in low-fidelity noise, Triage resolves routine security alerts autonomously — freeing your team for actual threat hunting.
**Positioning**:
- **So That**: 70% of routine alerts resolve without human intervention
- **Unlike**: manual triage in Cortex XSOAR
- **For Whom**: the L1 SOC Manager
- **Category**: Autonomous SOC Resolution
**Call To Action**:
- **Direct**: Resolve first incident
- **Transitional**: Download resolution schema
**Failure Stakes**:
- Critical breaches missed due to noise
- High analyst turnover from burnout
- Rising MSSP costs for L1 triage
**Transformation**:
- **To**: the domain's elite threat hunter
- **From**: the SIEM-bound clerk dismissing brute-force logs
**Controlling Idea**: Security expertise should be spent on hunting threats, not dismissing alerts.

## Startup Token Hero

**Genre**: founding-hypothesis
**Rendered**: Instead of burying analysts in low-fidelity noise, Triage resolves routine security alerts autonomously — freeing your team for actual threat hunting.
**Mechanism**: spine-derived-v1
**Template Id**: spine-founding-hypothesis
**Vocab Fingerprint**: ffdd9c2662eedb65

## Startup Token Positioning

**Genre**: moore-positioning
**Rendered**: Autonomous SOC Resolution for the L1 SOC Manager. Unlike manual triage in Cortex XSOAR — 70% of routine alerts resolve without human intervention.
**Mechanism**: spine-derived-v1
**Template Id**: spine-moore-positioning
**Vocab Fingerprint**: e017ce46d5624234

## Startup Token Pitch Deck

**Genre**: pitch-deck
**Rendered**: Problem: Analysts spend 20+ hours per week manually dismissing brute-force and impossible-travel alerts in Splunk or Cortex XSOAR.
Solution: Instead of burying analysts in low-fidelity noise, Triage resolves routine security alerts autonomously — freeing your team for actual threat hunting.
Customer: the L1 SOC Manager
Unlike: manual triage in Cortex XSOAR
**Mechanism**: spine-derived-v1
**Template Id**: spine-pitch-deck
**Vocab Fingerprint**: 01612d58fb79bb9f

## Startup Token M E D D P I C C

**Pain**: Analysts spend 20+ hours per week manually dismissing brute-force and impossible-travel alerts in Splunk or Cortex XSOAR.
**Metrics**: Target: Your SOC queue remains at zero for routine events, leaving analysts free to focus exclusively on complex, multi-stage threats.
**Rendered**: Pain: Analysts spend 20+ hours per week manually dismissing brute-force and impossible-travel alerts in Splunk or Cortex XSOAR.
Economic buyer: CISO / SOC Manager
Metrics: Target: Your SOC queue remains at zero for routine events, leaving analysts free to focus exclusively on complex, multi-stage threats.
Competition: manual triage in Cortex XSOAR
**Mechanism**: spine-derived-v1
**Competition**: manual triage in Cortex XSOAR
**Economic Buyer**: CISO / SOC Manager
**Vocab Fingerprint**: 1e85109b9258a289

## Startup Token Cold Email

**Genre**: cold-email
**Rendered**: Subject: Autonomous SOC Resolution for the L1 SOC Manager

the L1 SOC Manager — Analysts spend 20+ hours per week manually dismissing brute-force and impossible-travel alerts in Splunk or Cortex XSOAR. Instead of burying analysts in low-fidelity noise, Triage resolves routine security alerts autonomously — freeing your team for actual threat hunting.
**Mechanism**: spine-derived-v1
**Template Id**: spine-cold-email
**Vocab Fingerprint**: 9b21ac9c9a54de45

## Startup Token Agent Spec

**Genre**: ai-agent-spec
**Rendered**: Autonomous SOC Resolution. Instead of burying analysts in low-fidelity noise, Triage resolves routine security alerts autonomously — freeing your team for actual threat hunting. Serves the L1 SOC Manager.
**Mechanism**: spine-derived-v1
**Template Id**: spine-ai-agent-spec
**Vocab Fingerprint**: 90d6cd45d5877bce

## Neighborhood

### Candidate solutions

- [Triage Duplicate Defect Reports](/Problems/Triage_Duplicate_Defect_Reports) — candidate solution for · Problems
- [Inbound Document Routing Bottlenecks](/Problems/Inbound_Document_Routing_Bottlenecks) — candidate solution for · Problems
- [Complex Infusion Scheduling](/Problems/Complex_Infusion_Scheduling) — candidate solution for · Problems
- [Exception Routing](/Problems/Exception_Routing) — candidate solution for · Problems
- [resubmitting denied claims because the CPT code was one digit off](/Problems/resubmitting_denied_claims_because_the_CPT_code_was_one_digit_off) — candidate solution for · Problems
- [Cross-Functional Resource Allocation](/Problems/Cross-Functional_Resource_Allocation) — candidate solution for · Problems

### Entrant startups

- [EHR Normalization Engine](/Opportunities/EHR_Normalization_Engine) — is entrant in · Opportunities

### Competitors

- [Tines](/Competitors/Tines) — competes with · Competitors
- [Dropzone AI](/Competitors/Dropzone_AI) — competes with · Competitors
- [Splunk SOAR](/Competitors/Splunk_SOAR) — competes with · Competitors
- [Cortex XSOAR](/Competitors/Cortex_XSOAR) — competes with · Competitors
- [Outsourced MSSPs](/Competitors/Outsourced_MSSPs) — competes with · Competitors
- [Torq](/Competitors/Torq) — competes with · Competitors

### What it offers

- [Triage Autonomous Analyst](/Agents/Triage_Autonomous_Analyst) — offers · Agents

### Embodies

- [Agent](/Theses/Agent) — embodies · Theses

### Composed of

- [Incident Resolution Service](/Services/Incident_Resolution_Service) — composes · Services
- [Autonomous Triage Agent](/Agents/Autonomous_Triage_Agent) — composes · Agents
- [Historical Context Worker](/Agents/Historical_Context_Worker) — composes · Agents
- [Alert Ingestion API](/Software/Alert_Ingestion_API) — composes · Software
- [SOC Telemetry Engine](/Software/SOC_Telemetry_Engine) — composes · Software

### Similar Startups

- [Problemgate](/Startups/Problemgate) — similar · Startups
- [Sepsoph](/Startups/Sepsoph) — similar · Startups
- [Triagestar](/Startups/Triagestar) — similar · Startups
- [Detectionyard](/Startups/Detectionyard) — similar · Startups
- [Security](/Startups/Security) — similar · Startups
- [Probluard](/Startups/Probluard) — similar · Startups
- [Triageridge](/Startups/Triageridge) — similar · Startups
- [Gatherstar](/Startups/Gatherstar) — similar · Startups
- [Dropzone Security](/Startups/Dropzone_Security) — similar · Startups
- [Autoreman](/Startups/Autoreman) — similar · Startups
- [Sentus](/Startups/Sentus) — similar · Startups
- [Flarestorm](/Startups/Flarestorm) — similar · Startups
- [Sen](/Startups/Sen) — similar · Startups
- [Triagehaven](/Startups/Triagehaven) — similar · Startups
- [Almepair](/Startups/Almepair) — similar · Startups
- [Autagent](/Startups/Autagent) — similar · Startups
- [Problequency](/Startups/Problequency) — similar · Startups
- [Anomalyload](/Startups/Anomalyload) — similar · Startups
- [Outagyard](/Startups/Outagyard) — similar · Startups
- [Action](/Startups/Action) — similar · Startups
