Investigation / Governed response

Respond with authority, not autopilot.

SOAR is the governed response layer for typed evidence, investigation, scenario rehearsal, approval gates, rollback, and operator-controlled action.

SOAR console · soar.bwtr.ai. Console access may require authentication.

SOAR product identity artwork.
SOAR

01 / PRODUCT POSITION

SOAR in the ASOC system.

Agents can reason over claims and propose response paths, but action stays tied to evidence class, scope, health checks, and a named decision owner.

Evidence-class lattice and claim meet Injection isolation and typed-only outputs Attack-path ranking and blast-radius context AMBER proposal / GREEN actuation separation Approvals, breakers, rollback, and audit trail

02 / FEATURE FILMS

6 product films with the console on screen.

Source-product films reused from the original marketing sites. They are useful marketing proof, not production certification.

0:20

01 / Evidence ceilings

Typed claim system

Represent every answer as a bounded claim so no summary outruns the evidence class that produced it.

  • Measured, simulated, and inferred states stay distinct
  • LLM text cannot upgrade the verdict
  • Abstention is a valid outcome
0:14

02 / Detection without overreach

Live SIEM detection

Run detection rules over logs and packet metadata while preserving provenance and avoiding raw payload retention.

  • Real log and packet paths
  • Metadata-only network analysis
  • Raw payloads are not retained
0:19

03 / Hypothesis-driven investigation

Threat hunting workspace

Hunt across logs, the estate graph, and grounded threat intelligence with visible source citations.

  • Grounded facts are cited
  • Injected instructions are treated as data
  • Analyst remains in control
0:12

04 / Response before production

Digital twin rehearsal

Replay incidents and test response paths in a twin so proposed action carries blast radius and rollback context.

  • Twin evidence is labelled simulated
  • Attack paths are ranked, not asserted
  • Rollback remains part of the proposal
0:18

05 / AMBER to GREEN

Governed SOAR action

Separate proposal from actuation. GREEN execution requires policy bounds, health checks, and recoverable plans.

  • Policy gates checked first
  • Every action logged
  • Failed rollback stops the line
0:17

06 / Close the loop

Remediation verifier

Re-run original checks and retain fresh evidence before calling a fix complete.

  • Original condition is retested
  • Fresh evidence is recorded
  • Success does not erase history

SOAR is operator-gated. Active response requires separate authorization, local execution boundaries, and recoverable plans.

03 / CAPABILITY MAP

Typed investigation

Represent every answer as a claim with provenance and a bounded evidence class.

Scenario rehearsal

Use twin/range context to test response paths before acting on production systems.

Governed actuation

Keep containment and remediation behind explicit authority, safety cases, and executor parity checks.

Council review

Compare analyst, skeptic, and response-engineer viewpoints without upgrading weak evidence.

Local operation

Preserve air-gapped and zero-egress modes for sensitive investigation contexts.

Audit memory

Record who asked what, what tools were used, and what evidence supported the response.