CydraLabs

Security Packs

Investigate incidents and secure the agent supply chain

Security operations and application security teams are overwhelmed by alerts and findings they cannot validate fast enough.

Roadmap · 2028Join the pilot

The problem

What Security Packs resolves

  • Alert overload

    Tier-1 and Tier-2 analysts cannot investigate every alert in time.

  • Unvalidated findings

    Scanners report issues faster than engineers can confirm exploitability.

  • Unsafe automation

    Automated remediation without approval can cause outages or lockouts.

Where it acts

Where Cydra controls an agent action

Security Packs are agents themselves: each investigative or remediation step goes through CydraGateway policy and approval.

Action-control workflow: receive, authenticate, resolve, context, policy, inspect, decide, approve, execute with scoped credentials, evidence.1Receive2Authenticate3Resolve4Context5Policy6Inspect7Decide8Approve9Execute10EvidencePolicy errors fail closed · Deny outranks approval outranks allow · Every outcome produces an evidence record
The ten-step action-control workflow shared by every product.
Step-by-step explanation

Capabilities

Security Packs capability tour

  1. Discover

    • CydraDevSec outcome

      Roadmap

      Validate findings and determine exploitability across development pipelines and security tooling.

  2. Decide

    Provided by the core platform.

  3. Enforce

    • CydraSOC remediation

      Roadmap

      Recommend remediation and execute high-impact steps, such as disabling accounts, after explicit human approval.

    • CydraDevSec fixes

      Roadmap

      Propose remediation, open pull requests, test fixes and create tickets with human oversight.

  4. Investigate

    • CydraSOC outcome

      Roadmap

      Investigate alerts, correlate evidence across security tools and build attack timelines.

  5. Prove

    • Evidence for every step

      Available

      Each investigative and remediation action is recorded in the evidence chain.

Prerequisites

Security Packs build on the core platform.

  • CydraGateway for policy and approval of every pack action
  • CydraShield inventory and Security Graph for context
  • Access to your SIEM, EDR or development tooling

Workflow examples

Planned workflows, to be validated with design partners.

  • Investigate a suspicious sign-in alert, build a timeline and request approval to disable the account
  • Validate a dependency vulnerability, confirm exploitability and open a pull request with a tested fix
  • Detect an unreviewed MCP server added to a repository and open a review task

Available today

Incident responders can already use blast-radius analysis, the action timeline, the kill switch and verifiable evidence from the core platform.

Agent incident response

Coverage

Integrations and deployment

Every item carries its current status.

Integrations

  • Microsoft Sentinel, Splunk, Google Security Operations

    CydraSOC

    Roadmap
  • CrowdStrike and Microsoft Defender

    CydraSOC

    Roadmap
  • GitHub, GitLab, Jenkins

    CydraDevSec

    Roadmap
  • Checkmarx, Snyk, SonarQube, Jira

    CydraDevSec

    Roadmap

Deployment

  • CydraLabs-managed SaaS

    Hosted and operated by CydraLabs.

    Pilot programme
  • Customer cloud or private VPC

    Deployed into your own cloud account with the CydraLabs reference deployment.

    Pilot programme
  • On-premises or sovereign deployment

    Planned for environments that cannot use cloud services.

    Roadmap
Full capability list with status
  • Autonomous Tier-1/Tier-2 alert investigation

    Investigate alerts, correlate evidence and build attack timelines.

    Roadmap
  • Finding validation and fix proposals

    Validate exploitability, propose remediation and open pull requests with human oversight.

    Roadmap
Available
Implemented, tested and demonstrable in the current proof-of-concept build.
Beta
Implemented and demonstrable, with documented limitations.
Preview
Interface or mock implementation behind a real contract; live integration not yet enabled.
Roadmap
Not built in this phase. Shared platform foundations are in place.

Trust

Security, privacy and trust

  • Every pack action is subject to the same identity, policy, approval and evidence controls as any other agent.
  • Tenant isolation with PostgreSQL row-level security for the application role.
  • Payloads stored as hashes plus redacted previews by default; no secrets in logs.
  • TLS in transit; encrypted storage in the AWS reference deployment.
  • No third-party certifications or attestations yet. See the Trust Centre for current assurance status.
Visit the Trust Centre

Proof

What we can show today

  • Roadmap status

    CydraSOC and CydraDevSec are on the 2026–2030 roadmap as a primary focus in 2028. They are not built in the current phase.

  • Design-partner outcomes

    Pilot outcomes and case studies will be published when design partners agree. We do not publish customer names, logos or results before then.

Help shape the Security Packs

Register for the pilot to work with us on CydraSOC and CydraDevSec workflows as they are built.