AI detects, investigates and contains Microsoft 365 threats in seconds. Automatically. Without human intervention.
14-day free trial · No credit card required · All 10 modules included
"ARRAC exists to close the gap between compromise and containment."
A real incident type. Contained automatically. No human required.
Every action logged. Every action reversible. Human override available at every tier.
Four autonomy tiers. Each requires verified performance at the tier below before it becomes available.
ARRAC monitors and flags. No autonomous actions. Every decision goes to your team.
DEFAULT STARTARRAC investigates and recommends a containment action. Your team approves before anything executes.
ARRAC acts on confirmed high-severity threats, then immediately notifies your team. Every action is logged. Your SOC reviews and validates each one.
Available only after a verified 30-day record at Tier 3 with zero false positives. Every false positive resets the clock. Your SOC team manually reviews the complete Tier 3 log before Tier 4 becomes available.
EARNED — ENABLED BY YOUR SOCReaching Tier 4 does not mean ARRAC activates it automatically. Your SOC administrator enables it deliberately — and can step it back to any lower tier instantly, at any time, for any reason.
Autonomy is configured per client, not platform-wide. MSPs can run different clients at different tiers simultaneously. Regulated clients — financial services, healthcare, legal — can be permanently capped at Tier 2 or Tier 3 to meet compliance requirements. ARRAC never overrides a compliance cap.
Immutable record of every AI decision — what it saw, concluded, and did.
Containment targets the single compromised identity or process. Nothing else is affected.
Configure autonomy per client, cap regulated clients at Tier 2 or Tier 3, and require human approval for executive accounts.
At any tier. At any time. Step back to any lower tier instantly.
Multi-Agent Reasoning Board
Eight specialised stages work on every security incident — each focused on a single question.
Every assessment carries a confidence score. Below your threshold, ARRAC doesn't act — it escalates to a human.
Every decision comes with a complete evidence chain. No black-box decisions.
When ARRAC identifies a threat, it acts on the single compromised identity — not the team, not the office, not the device group.
ARRAC isolates that process. The employee's Teams call continues. Their document stays open. Their colleagues are unaffected.
ARRAC contains that one account. The rest of the finance team keeps working.
There is no blast radius from ARRAC's own containment actions. Only the confirmed threat is affected — nothing else.
What about our executives? ARRAC combines cloud identity signals with on-device agent confirmation before acting. A CEO logging in via VPN from a hotel is never blocked — the agent confirms the device is in London. Context, not just rules. Executive accounts can be configured to always require human approval before containment, regardless of autonomy tier.
ARRAC doesn't notify. It calls.
When a human decision is needed, ARRAC places a voice call. Immediately — if no Teams or Slack channel is configured. Within 60 seconds for critical incidents (90 for high) — if Teams or Slack is active and no action has been taken.
Press 1 to approve. Press 2 to decline. Press 3 to escalate to your secondary contact.
If nobody answers — an SMS, plus a Teams alert where Teams is connected, fires immediately. The incident is never silently dropped.
Every response is written to the audit trail — evidence for DORA and NIS2.
Stolen credentials and session tokens cannot be used in your M365 environment. Autonomous identity containment in seconds.
Learn more →Detect ransomware precursor activity before encryption spreads. Process terminated. Device isolated. Automatically.
Learn more →Detect and block unapproved AI tools across every endpoint. Prevent sensitive data leaving your organisation via AI apps.
Learn more →MSP multi-tenant security operations. One console. Every client. Per-tenant autonomy control.
Learn more →Immutable audit trail. AI-generated incident reports. DORA, NIS2, and CRA compliance evidence — generated automatically.
Learn more →Every module feeds the AI engine. The AI engine acts.
LAYER 1 — AUTONOMOUS CONTAINMENTM365 threat detection and autonomous containment
Azure resource monitoring and containment
Shadow AI detection and policy enforcement
Windows EDR — ransomware, behavioural detection, DLP
Sensitive data protection at the device level
Deep investigation, forensics, threat hunting
Incident coordination and evidence management
Posture, compliance benchmarking, attack surface
Board reporting and regulatory compliance evidence
Long-term architecture and risk prioritisation
All 10 modules included on every plan. No module gates. No add-ons. Explore all modules →
Measured from verified threat discovery to successful containment.
ARRAC's Guarantee as a Service model holds us accountable to measurable security outcomes — not activity metrics, not alert counts. Response time. Containment rate. Guarantee Score.
The guarantee applies when your Microsoft 365 environment maintains basic configuration hygiene: MFA enabled, patching current, Conditional Access configured. We show you exactly what green looks like. You maintain it. We take full responsibility for everything else.
14-day free trial · No credit card required
Learn about Guarantee as a Service →