THE AUTONOMOUS RESPONSE LAYER FOR MICROSOFT 365

Your security team
is not fast enough.
ARRAC is.

AI detects, investigates and contains Microsoft 365 threats in seconds. Automatically. Without human intervention.

≤5s KNOWN THREATS
≤30s NOVEL THREATS
12.3s MEASURED CONTAINMENT

14-day free trial · No credit card required · All 10 modules included

THE PROBLEM

The gap between attack and containment costs everything.

ATTACKER
00:00 Initial access
00:30 Reconnaissance
01:30 Privilege escalation
03:00 Encryption begins
05:00 Data exfiltration
HUMAN SOC
45:00 Alert reviewed
60:00 Investigation begins
90:00 Ticket escalated
120:00 Containment attempt
Industry average: 47 minutes to first response
ARRAC
00:00 Threat detected
00:01 AI investigates
00:12 Threat confirmed
00:13 Containment executed
12.3s CONTAINED

"ARRAC exists to close the gap between compromise and containment."

ARRAC IN ACTION

This is what happens when ARRAC finds an attack.

A real incident type. Contained automatically. No human required.

ARRAC RESPONSE ENGINE · Meridian Legal Group ● LIVE
09:14:22 ● THREAT SIGNAL RECEIVED Suspicious sign-in · [email protected] · Lagos, Nigeria → London UK · Impossible travel: 2.3h
09:14:23 ● AI INVESTIGATION Identity · Email · M365 · Endpoint · Permissions · Blast radius: 847 files
09:14:24 ● THREAT CONFIRMED Account takeover · Confidence: 97% · Severity: CRITICAL
09:14:25 ⚡ CONTAINMENT EXECUTED ✓ Session revoked ✓ Sign-in blocked ✓ Risk confirmed in Entra ID ✓ Incident INC-0042 created ✓ Team notified via Teams
09:14:25 ✓ THREAT CONTAINED Total time: 3 seconds · Actions taken: 5 · Data accessed: 0 files
✓ THREAT CONTAINED · 3 seconds · 0 files accessed · 5 autonomous actions

Every action logged. Every action reversible. Human override available at every tier.

THE CORE INNOVATION

ARRAC earns the right to act.
Your team decides when to use it.

Four autonomy tiers. Each requires verified performance at the tier below before it becomes available.

TIER 1
Observe and alert

ARRAC monitors and flags. No autonomous actions. Every decision goes to your team.

DEFAULT START
TIER 2
Recommend and wait

ARRAC investigates and recommends a containment action. Your team approves before anything executes.

TIER 3
Contain and notify

ARRAC acts on confirmed high-severity threats, then immediately notifies your team. Every action is logged. Your SOC reviews and validates each one.

TIER 4
Full autonomous response

Available only after a verified 30-day record at Tier 3 with zero false positives. Every false positive resets the clock. Your SOC team manually reviews the complete Tier 3 log before Tier 4 becomes available.

EARNED — ENABLED BY YOUR SOC

Reaching Tier 4 does not mean ARRAC activates it automatically. Your SOC administrator enables it deliberately — and can step it back to any lower tier instantly, at any time, for any reason.

Autonomy is configured per client, not platform-wide. MSPs can run different clients at different tiers simultaneously. Regulated clients — financial services, healthcare, legal — can be permanently capped at Tier 2 or Tier 3 to meet compliance requirements. ARRAC never overrides a compliance cap.

✓
Every action logged

Immutable record of every AI decision — what it saw, concluded, and did.

✓
One account. Never a department.

Containment targets the single compromised identity or process. Nothing else is affected.

✓
You define the scope

Configure autonomy per client, cap regulated clients at Tier 2 or Tier 3, and require human approval for executive accounts.

✓
Human override always available

At any tier. At any time. Step back to any lower tier instantly.

Multi-Agent Reasoning Board

Eight specialised stages work on every security incident — each focused on a single question.

Every assessment carries a confidence score. Below your threshold, ARRAC doesn't act — it escalates to a human.

Every decision comes with a complete evidence chain. No black-box decisions.

SURGICAL CONTAINMENT

Surgical containment.
One account. Never a department.

When ARRAC identifies a threat, it acts on the single compromised identity — not the team, not the office, not the device group.

→
Ransomware on a device

ARRAC isolates that process. The employee's Teams call continues. Their document stays open. Their colleagues are unaffected.

→
Compromised account in finance

ARRAC contains that one account. The rest of the finance team keeps working.

There is no blast radius from ARRAC's own containment actions. Only the confirmed threat is affected — nothing else.

What about our executives? ARRAC combines cloud identity signals with on-device agent confirmation before acting. A CEO logging in via VPN from a hotel is never blocked — the agent confirms the device is in London. Context, not just rules. Executive accounts can be configured to always require human approval before containment, regardless of autonomy tier.

ARRAC doesn't notify. It calls.

When a human decision is needed, ARRAC places a voice call. Immediately — if no Teams or Slack channel is configured. Within 60 seconds for critical incidents (90 for high) — if Teams or Slack is active and no action has been taken.

Press 1 to approve. Press 2 to decline. Press 3 to escalate to your secondary contact.

If nobody answers — an SMS, plus a Teams alert where Teams is connected, fires immediately. The incident is never silently dropped.

Every response is written to the audit trail — evidence for DORA and NIS2.

WHAT DO YOU NEED ARRAC TO DO?

Choose your problem. ARRAC stops it.

ONE RESPONSE ENGINE

Ten security capabilities. One autonomous decision.

Every module feeds the AI engine. The AI engine acts.

LAYER 1 — AUTONOMOUS CONTAINMENT
Cloud Security

M365 threat detection and autonomous containment

Infrastructure

Azure resource monitoring and containment

AI Security

Shadow AI detection and policy enforcement

Endpoint Protection

Windows EDR — ransomware, behavioural detection, DLP

Endpoint DLP

Sensitive data protection at the device level

↓ Every containment action writes to the strategic oversight layer ↓
LAYER 2 — STRATEGIC OVERSIGHT
Analyst

Deep investigation, forensics, threat hunting

WarRoom

Incident coordination and evidence management

Audit

Posture, compliance benchmarking, attack surface

Virtual CISO

Board reporting and regulatory compliance evidence

Security Architect

Long-term architecture and risk prioritisation

All 10 modules included on every plan. No module gates. No add-ons. Explore all modules →

THE COMMERCIAL DIFFERENCE

Don't buy more alerts.
Buy a response outcome.

≤5s KNOWN THREATS
≤30s NOVEL THREATS
95–100 GUARANTEE SCORE

Measured from verified threat discovery to successful containment.

ARRAC's Guarantee as a Service model holds us accountable to measurable security outcomes — not activity metrics, not alert counts. Response time. Containment rate. Guarantee Score.

The guarantee applies when your Microsoft 365 environment maintains basic configuration hygiene: MFA enabled, patching current, Conditional Access configured. We show you exactly what green looks like. You maintain it. We take full responsibility for everything else.

14-day free trial · No credit card required

Learn about Guarantee as a Service →