Security Packs
Investigate incidents and secure the agent supply chain
Security operations and application security teams are overwhelmed by alerts and findings they cannot validate fast enough.
The problem
What Security Packs resolves
Alert overload
Tier-1 and Tier-2 analysts cannot investigate every alert in time.
Unvalidated findings
Scanners report issues faster than engineers can confirm exploitability.
Unsafe automation
Automated remediation without approval can cause outages or lockouts.
Where it acts
Where Cydra controls an agent action
Security Packs are agents themselves: each investigative or remediation step goes through CydraGateway policy and approval.
Capabilities
Security Packs capability tour
Discover
CydraDevSec outcome
RoadmapValidate findings and determine exploitability across development pipelines and security tooling.
Decide
Provided by the core platform.
Enforce
CydraSOC remediation
RoadmapRecommend remediation and execute high-impact steps, such as disabling accounts, after explicit human approval.
CydraDevSec fixes
RoadmapPropose remediation, open pull requests, test fixes and create tickets with human oversight.
Investigate
CydraSOC outcome
RoadmapInvestigate alerts, correlate evidence across security tools and build attack timelines.
Prove
Evidence for every step
AvailableEach investigative and remediation action is recorded in the evidence chain.
Prerequisites
Security Packs build on the core platform.
- CydraGateway for policy and approval of every pack action
- CydraShield inventory and Security Graph for context
- Access to your SIEM, EDR or development tooling
Workflow examples
Planned workflows, to be validated with design partners.
- Investigate a suspicious sign-in alert, build a timeline and request approval to disable the account
- Validate a dependency vulnerability, confirm exploitability and open a pull request with a tested fix
- Detect an unreviewed MCP server added to a repository and open a review task
Available today
Incident responders can already use blast-radius analysis, the action timeline, the kill switch and verifiable evidence from the core platform.
Agent incident responseCoverage
Integrations and deployment
Every item carries its current status.
Integrations
- Roadmap
Microsoft Sentinel, Splunk, Google Security Operations
CydraSOC
- Roadmap
CrowdStrike and Microsoft Defender
CydraSOC
- Roadmap
GitHub, GitLab, Jenkins
CydraDevSec
- Roadmap
Checkmarx, Snyk, SonarQube, Jira
CydraDevSec
Deployment
- Pilot programme
CydraLabs-managed SaaS
Hosted and operated by CydraLabs.
- Pilot programme
Customer cloud or private VPC
Deployed into your own cloud account with the CydraLabs reference deployment.
- Roadmap
On-premises or sovereign deployment
Planned for environments that cannot use cloud services.
Full capability list with status
- Roadmap
Autonomous Tier-1/Tier-2 alert investigation
Investigate alerts, correlate evidence and build attack timelines.
- Roadmap
Finding validation and fix proposals
Validate exploitability, propose remediation and open pull requests with human oversight.
- Available
- Implemented, tested and demonstrable in the current proof-of-concept build.
- Beta
- Implemented and demonstrable, with documented limitations.
- Preview
- Interface or mock implementation behind a real contract; live integration not yet enabled.
- Roadmap
- Not built in this phase. Shared platform foundations are in place.
Trust
Security, privacy and trust
- Every pack action is subject to the same identity, policy, approval and evidence controls as any other agent.
- Tenant isolation with PostgreSQL row-level security for the application role.
- Payloads stored as hashes plus redacted previews by default; no secrets in logs.
- TLS in transit; encrypted storage in the AWS reference deployment.
- No third-party certifications or attestations yet. See the Trust Centre for current assurance status.
Proof
What we can show today
Roadmap status
CydraSOC and CydraDevSec are on the 2026–2030 roadmap as a primary focus in 2028. They are not built in the current phase.
Design-partner outcomes
Pilot outcomes and case studies will be published when design partners agree. We do not publish customer names, logos or results before then.
Help shape the Security Packs
Register for the pilot to work with us on CydraSOC and CydraDevSec workflows as they are built.