Every other AI security tool sends your telemetry somewhere else to be analysed. Odin runs the detection, the reasoning and the language model itself inside your own environment. We hold no data and have no access path — enforced by architecture, not promised in a contract.
Security teams are not short on data. They are short on the time to decide what any of it means.
Enrichment is now limited to vulnerabilities in the known-exploited catalogue, federal software, or software designated critical by executive order — an estimated 15–20% of volume. Even before the change, only 28% received full enrichment. The gap between vulnerabilities published and vulnerabilities understood is now permanent, and widening.
Sources: FIRST 2026 Vulnerability Forecast · NIST NVD operations update, April 2026 · Microsoft SOC report 2026
Your telemetry goes to their cloud.
Logs, alerts, mailbox content and dependency data are sent out to be analysed. Your protection is a data-processing agreement and a promise. The honest answer to "what can your vendor see?" is: quite a lot.
Nothing leaves. Including the AI.
Detection, reasoning and the language model all run inside your environment, under your keys. The answer to the same question is nothing.
There is little to assess when the vendor holds no data and has no access path.
Healthcare, financial services, legal, government suppliers, defence contractors.
One deployment per customer. No pooled data lake, no shared analysis layer.
GPU-accelerated models score events in real time, inside your own environment.
ODIN turns the events you already collect into alerts worth a person's time. Detection models flag what looks wrong; Huginn investigates every alert and explains it; your policy decides what may happen next; and when someone confirms a real threat, they declare an incident — the moment the regulatory clock starts. Everything below runs inside your own environment.
Investigates every alert on a self-hosted model: what happened, why it matters, the evidence it used, an ATT&CK mapping and recommended next steps — each recommendation passed through your policy before anyone acts. It can query your SIEM read-only, and it can recommend that a person declare an incident. It never executes anything and never declares an incident itself.
Scores inbound email for phishing and credential harvesting after delivery. Your mail routing is never touched.
Finds sensitive data — credentials, private keys, API secrets and personal data — in email and application traffic, continuously.
Learns each user's normal behaviour from your own history and flags departures from it, stating how mature each baseline is.
Your SIEM's alerts become ODIN alerts that Huginn investigates; ODIN can forward alerts and its audit trail back to your SIEM.
Triages scanner findings by whether the vulnerable component is actually used in your build, and writes standard VEX output. A platform capability, not a separate product.
Every admin change is staged, justified and committed after a fresh sign-in, with versions you can roll back.
Every decision is written to a hash-chained, signed audit log you can verify offline and forward to your SIEM.
Detection models score events on your own GPU, in real time, inside your environment.
Behavioural detection of encryption, staging and preparation activity.
Anomaly detection across east-west and egress traffic.
Detection of attacks on your own AI agents: prompt injection, tool abuse, data poisoning.
Graph-based analysis of transaction and relationship patterns.
Machine-learned parsing of unfamiliar log formats.
Tracing an incident back to its originating cause.
Four responsibilities, kept deliberately separate. Machine learning models score what happens. The AI analyst investigates and explains. A policy engine decides what is permitted. Only an authorised decision is ever executed.
Identity
Endpoint
Network
Cloud
Email
Any source in, one schema out
Streaming inference on your hardware
Self-hosted AI investigates every alert. Evidence, ATT&CK, recommendation
Approved actions run in your own tools
Your rules gate every action. AI advises, never executes
No arrow leaves this box. No vendor cloud. No external AI API. Ever.
That separation is what makes automated response safe to offer at all — and it is why every action carries an audit record showing which policy allowed it, on what evidence.
No shared vendor data lake. No telemetry tunnelled out of your environment.
Recommendations are advisory and reviewable. No autonomous destructive action.
Odin produces structured artifacts. You and your auditors determine compliance.
We connect to telemetry you already collect. Portability is part of the design.
Keep the security stack you own. Sources are normalised into one schema on arrival, so adding a new one never changes how detection works. Every ingest channel is encrypted and authenticated.
Syslog over TLS, or JSON over HTTPS. Your SIEM's alerts by pull or webhook.
Product names indicate data-source compatibility only. They do not imply partnership, affiliation or endorsement. All trademarks are the property of their respective owners.
We are working with a small number of design partners before general availability.
Odin was built out of a stubborn observation from years inside security consulting: teams paid for dashboards they had no time to read, telemetry left their environment and never quite came home, and AI features arrived as black boxes asking for trust they had not earned.
In the old stories Odin sent his ravens out each day to watch the world and bring back what mattered.
One of those ravens gives our AI Security Analyst its name: it investigates what the detection models find and reasons about what it means.
Not everything, and not the noise — the few things that deserve a person's attention, with the evidence to act on them.
Tell us what you're running and what's drowning your team. If Odin is a fit we'll say so; if it isn't, we'll say that too.
Or email contact@odinsecurity.ai directly.
ODIN is pre-launch and working with design partners. We will tell you exactly what
is available before you start.