AI-native cybersecurity intelligence

The AI runs inside your walls. Not ours.

Every other AI security tool sends your telemetry somewhere else to be analysed. Odin runs the detection, the reasoning and the language model itself inside your own environment. We hold no data and have no access path — enforced by architecture, not promised in a contract.

AI-native cybersecurity intelligence for customer-controlled security operations
// The problem

Volume outran human triage. Twice.

Security teams are not short on data. They are short on the time to decide what any of it means.

48,185
Vulnerabilities published in 2025 — roughly 131 every day
~59,000
Forecast for 2026, with upside scenarios reaching 100,000
40–63%
Of security alerts are never investigated at all
46%
Of alerts turn out to be false positives
April 2026

The public vulnerability database stopped keeping up.

Enrichment is now limited to vulnerabilities in the known-exploited catalogue, federal software, or software designated critical by executive order — an estimated 15–20% of volume. Even before the change, only 28% received full enrichment. The gap between vulnerabilities published and vulnerabilities understood is now permanent, and widening.

Sources: FIRST 2026 Vulnerability Forecast · NIST NVD operations update, April 2026 · Microsoft SOC report 2026

// Sovereignty

Everyone says your data is safe. We arranged it so we never see it.

The usual model

Your telemetry goes to their cloud.

Logs, alerts, mailbox content and dependency data are sent out to be analysed. Your protection is a data-processing agreement and a promise. The honest answer to "what can your vendor see?" is: quite a lot.

Odin

Nothing leaves. Including the AI.

Detection, reasoning and the language model all run inside your environment, under your keys. The answer to the same question is nothing.

Faster security review

There is little to assess when the vendor holds no data and has no access path.

Works where others cannot

Healthcare, financial services, legal, government suppliers, defence contractors.

Single-tenant by design

One deployment per customer. No pooled data lake, no shared analysis layer.

Machine learning at speed

GPU-accelerated models score events in real time, inside your own environment.

// The platform

Detection, investigation and decision — in your cloud.

ODIN turns the events you already collect into alerts worth a person's time. Detection models flag what looks wrong; Huginn investigates every alert and explains it; your policy decides what may happen next; and when someone confirms a real threat, they declare an incident — the moment the regulatory clock starts. Everything below runs inside your own environment.

Platform · included
Huginn, the AI Security Analyst

Investigates every alert on a self-hosted model: what happened, why it matters, the evidence it used, an ATT&CK mapping and recommended next steps — each recommendation passed through your policy before anyone acts. It can query your SIEM read-only, and it can recommend that a person declare an incident. It never executes anything and never declares an incident itself.

Available now

Email

Phishing Detection

Scores inbound email for phishing and credential harvesting after delivery. Your mail routing is never touched.

Data

Data Leak Prevention & Detection

Finds sensitive data — credentials, private keys, API secrets and personal data — in email and application traffic, continuously.

Identity & users

User Behaviour Analytics & Baselines

Learns each user's normal behaviour from your own history and flags departures from it, stating how mature each baseline is.

Your SIEM

SIEM integration

Your SIEM's alerts become ODIN alerts that Huginn investigates; ODIN can forward alerts and its audit trail back to your SIEM.

Software supply chain

Vulnerability Triage

Triages scanner findings by whether the vulnerable component is actually used in your build, and writes standard VEX output. A platform capability, not a separate product.

Governance

Change control

Every admin change is staged, justified and committed after a fresh sign-in, with versions you can roll back.

Evidence

Tamper-evident audit trail

Every decision is written to a hash-chained, signed audit log you can verify offline and forward to your SIEM.

Performance

GPU-accelerated detection

Detection models score events on your own GPU, in real time, inside your environment.

On the roadmap

Ransomware detection

Behavioural detection of encryption, staging and preparation activity.

Network behaviour

Anomaly detection across east-west and egress traffic.

AI system protection

Detection of attacks on your own AI agents: prompt injection, tool abuse, data poisoning.

Fraud detection

Graph-based analysis of transaction and relationship patterns.

Adaptive log parsing

Machine-learned parsing of unfamiliar log formats.

Root-cause analysis

Tracing an incident back to its originating cause.

Available now to design partners Roadmap — not available yet Installs into your Kubernetes in your cloud. Google Cloud is validated; AWS and Azure are in progress.
// How Odin works

Detect. Reason. Decide.
Only then act.

Four responsibilities, kept deliberately separate. Machine learning models score what happens. The AI analyst investigates and explains. A policy engine decides what is permitted. Only an authorised decision is ever executed.

Your cloud · single tenant
SOURCES

Identity
Endpoint
Network
Cloud
Email

01

Collect & Normalize

Any source in, one schema out

02

Detection

GPU ACCELERATED

Streaming inference on your hardware

03

Huginn investigates

Self-hosted AI investigates every alert. Evidence, ATT&CK, recommendation

05

You act

Approved actions run in your own tools

04

Policy Engine decides

Your rules gate every action. AI advises, never executes

No arrow leaves this box. No vendor cloud. No external AI API. Ever.

That separation is what makes automated response safe to offer at all — and it is why every action carries an audit record showing which policy allowed it, on what evidence.

The customer keeps the keys

No shared vendor data lake. No telemetry tunnelled out of your environment.

AI recommends; humans decide

Recommendations are advisory and reviewable. No autonomous destructive action.

Evidence over claims

Odin produces structured artifacts. You and your auditors determine compliance.

No lock-in by stealth

We connect to telemetry you already collect. Portability is part of the design.

// Data sources

Vendor agnostic.
If it sends syslog or JSON, ODIN can ingest it.

Keep the security stack you own. Sources are normalised into one schema on arrival, so adding a new one never changes how detection works. Every ingest channel is encrypted and authenticated.

Syslog over TLS, or JSON over HTTPS. Your SIEM's alerts by pull or webhook.

Systems & perimeter

Linux / Unix syslog Firewalls (syslog) Applications (JSON)

Identity & email

Microsoft Entra ID Microsoft 365 mail Postfix

Your SIEM

Microsoft Sentinel Splunk Enterprise Security Elastic Security

Product names indicate data-source compatibility only. They do not imply partnership, affiliation or endorsement. All trademarks are the property of their respective owners.

// Design partners

Build it with us, on your own data.

We are working with a small number of design partners before general availability.

What you get
50% off year one
  • ODIN installed in your cloud, with hands-on support from the founding team
  • 50% off the first year of your subscription
  • Direct influence on the roadmap
  • Training for your team through the OSI Academy
What we ask
8–10 weeks
  • A named champion and about two hours a week of your team's time
  • A cloud account with the capacity in our sizing guide
  • Two or three log sources, or your SIEM, connected
  • Honest feedback every two weeks, and a wrap-up review
// Company

Too much sight. Not enough seeing.

Odin was built out of a stubborn observation from years inside security consulting: teams paid for dashboards they had no time to read, telemetry left their environment and never quite came home, and AI features arrived as black boxes asking for trust they had not earned.

Odin
the watcher

In the old stories Odin sent his ravens out each day to watch the world and bring back what mattered.

Huginn
thought

One of those ravens gives our AI Security Analyst its name: it investigates what the detection models find and reasons about what it means.

The signal
not the noise

Not everything, and not the noise — the few things that deserve a person's attention, with the evidence to act on them.

// Get in touch

Let's compare notes.

Tell us what you're running and what's drowning your team. If Odin is a fit we'll say so; if it isn't, we'll say that too.

Or email contact@odinsecurity.ai directly.
ODIN is pre-launch and working with design partners. We will tell you exactly what is available before you start.