Security professionals ask hard questions. They should. Here are the answers — including the ones most vendors would not give you.
These are the real objections we hear from CISOs, IT managers, and MSPs. Here are the honest answers.
This is the right question to ask. Here is how ARRAC is designed to answer it.
Every ARRAC deployment begins at Tier 1 — ARRAC observes and alerts but takes no action. It operates in your environment, learns what normal looks like, and builds a track record. Your team reviews every suggestion. You approve or reject. The AI learns.
Autonomy is earned through verified performance at each tier. Tier 4 requires a 30-day record at Tier 3 with zero false positives — and every false positive resets the clock. Even then, ARRAC does not switch itself on: your SOC administrator enables Tier 4 deliberately, and can step it back at any time.
By the time ARRAC reaches full autonomous response, it has 30 days of evidence that it understands your environment — including your CFO's travel patterns, your VPN exit nodes, and your scheduled automation scripts.
And when it does act, it acts surgically. ARRAC contains the single compromised identity or process — never the team, the office, or the device group. There is no blast radius from ARRAC's own containment actions.
Two distinct concerns here — both worth addressing directly.
On catastrophic errors: ARRAC operates on a strict principle of isolate and hold. It revokes sessions, blocks sign-ins, and isolates devices. It does not delete data, modify configurations permanently, or take actions that cannot be undone in seconds. The blast radius of any ARRAC error is a temporary disruption — not a data loss event.
On compromise: ARRAC is designed with the assumption that it could itself be attacked. Every agent connection is mutually authenticated via unique device certificates. The platform uses tamper-resistant architecture. An attacker who compromises the platform can cause ARRAC to stop acting — they cannot cause it to act maliciously against your environment. The worst case is that your autonomous response layer goes offline temporarily. Your existing tools continue to function.
You should be sceptical of any vendor performance claim. Here is exactly what 12.3 seconds means and where it comes from.
12.3 seconds is the measured average time from verified threat detection to completed containment actions — in ARRAC's production environment, on a real Microsoft 365 tenant. It covers the full sequence: signal received, AI investigation completed, threat confirmed, containment actions executed, and confirmation written back to Entra ID.
This is containment time — not detection time. Detection depends on how quickly Microsoft's signals fire. Containment is what ARRAC controls, and 12.3 seconds is what we have measured.
The best way to verify this claim is to see it on your own environment during a 14-day trial. ARRAC does not simulate threats — it monitors your real environment. If a real threat fires during your trial, you will see the exact timestamps from detection to containment in the incident record.
This is a sophisticated objection and it deserves a precise answer.
The Guarantee Score measures successful containment — not blocking activity. A false positive that disrupts a legitimate user is not a successful containment. It is a failed action that reduces the score, not increases it.
The incentive structure works correctly: true positive containment increases the score. False positive disruption decreases it. A missed real attack decreases it. The metric is aligned with your outcome, not our activity volume.
This is precisely why we moved away from alert-count metrics. Alert counts reward noise. The Guarantee Score rewards results. If our score is high, your environment is genuinely better protected.
Because we built something they have not built yet.
The major enterprise security platforms are excellent at what they do. They were designed for enterprise security operations teams with dedicated analysts, six-figure budgets, and months to implement and tune.
ARRAC's AI Autonomy Engine — the four-tier framework that earns the right to act before it acts — does not exist in any enterprise platform today. It resolves the fundamental commercial barrier to AI-driven security automation: the question of trust.
Enterprise platforms also do not serve the mid-market. A 200-person law firm cannot afford a six-figure security platform and cannot wait six months for implementation. ARRAC is live in under 5 minutes at a price that works for organisations that have been structurally excluded from enterprise-grade protection.
If you are evaluating enterprise platforms and ARRAC simultaneously — they serve different needs and are not mutually exclusive. ARRAC integrates with Microsoft Sentinel, which means if you already have enterprise tooling, ARRAC adds the autonomous response layer that your existing tools lack.
Four autonomy tiers. Each requires verified performance at the tier below before it becomes available.
Reaching Tier 4 does not mean ARRAC activates it automatically. Your SOC administrator enables it deliberately — and can step it back to any lower tier instantly, at any time, for any reason.
Autonomy is configured per client, not platform-wide. MSPs can run different clients at different tiers simultaneously. Regulated clients — financial services, healthcare, legal — can be permanently capped at Tier 2 or Tier 3 to meet compliance requirements. ARRAC never overrides a compliance cap.
The most common concern about AI in security is this: what if it gets it wrong?
It is a legitimate question. The more a single AI model is asked to hold at once, the higher the risk of confident errors.
ARRAC doesn't ask one model to do everything. Every security incident is worked through by the Multi-Agent Reasoning Board — eight specialised stages, each focused on a single narrow question.
Every assessment carries a confidence score. When confidence falls below the threshold you set, ARRAC does not act — it escalates to a human.
Every decision comes with a complete evidence chain: what ARRAC saw, what it concluded, and why. No black-box decisions.
Three layers between an AI assessment and a real-world action: the Reasoning Board, the Earned Autonomy tier, and your team.
Does this eliminate errors?
No system eliminates errors. What it eliminates is the conditions where errors go undetected and propagate into actions. Every ARRAC decision includes a confidence score, a full evidence chain, and an audit trail. When ARRAC is uncertain — it says so, and escalates to a human.
Every security platform sends notifications. Most of them wait to be read.
ARRAC calls.
When a critical or high-severity incident requires a human decision — because the autonomy tier requires approval, or because a protected account is involved — ARRAC does not file a ticket and wait for someone to check their inbox.
If no Teams or Slack channel is configured, the call is immediate. If Teams or Slack is active, the notification arrives first — and the call follows within 60 seconds for critical incidents (90 for high) if no action has been taken.
The call reads the incident aloud and presents three options:
Press 1 to approve containment. ARRAC acts immediately.
Press 2 to decline. The incident stays open for manual review.
Press 3 to escalate. Your secondary contact is called immediately.
If nobody answers — ARRAC does not go silent. An SMS fires immediately, along with a Teams alert where Teams is connected: incident open, no response received, manual action required. The incident is never silently dropped.
Every response is written to the audit trail with a timestamp — approved, declined, escalated, or timed out — against the incident it concerns. For DORA and NIS2 compliance, this is your documented evidence of human escalation.
When ARRAC identifies a threat, it acts on the single compromised identity — not the team, not the office, not the device group.
If a ransomware process is detected on a device, ARRAC isolates that process. The employee's Teams call continues. Their document stays open. Their colleagues are unaffected.
If a compromised account is detected in your finance team, ARRAC contains that one account. The rest of the finance team keeps working.
There is no blast radius from ARRAC's own containment actions. Only the confirmed threat is affected — nothing else.
It is the first question every security leader asks. It should be.
ARRAC does not block a CEO because they logged in from a New York hotel.
Before any containment action, ARRAC combines two signals: the cloud identity alert and the on-device agent confirmation.
If the agent also confirms the device is in New York — that is a different picture. That is a real threat. That is when ARRAC acts.
Two signals. Not one. Context. Not just rules.
Executive accounts can be configured with elevated thresholds that require human approval before any containment action — regardless of the platform autonomy tier. Your CEO will never be blocked by an algorithm working alone. The decision to contain a C-suite identity always includes a human signal, a device confirmation, or both.
We made deliberate decisions about what to build first. Here is an honest picture of where ARRAC is today and where it is going.
If your environment does not use Microsoft 365, ARRAC cannot help you today. If it does — even partially — we can protect that part of your environment while the rest of your stack catches up.
If a capability on the In Development list is a hard requirement for you today, we would rather tell you that than sell you something that does not fit. Contact us and we will tell you honestly when it will be ready →
The 44-minute gap between when ransomware begins encrypting and when a human team begins responding is not a technology failure. It is a physics problem. Human detection, triage, investigation, escalation, and response cannot happen in under 3 minutes. Autonomous response can.
That is the only claim ARRAC makes. Not that AI is better than humans. Not that your security team is inadequate. That machine-speed attacks require machine-speed responses — and that the response should be trusted, auditable, and reversible.
Connect your Microsoft 365 environment in under 5 minutes. ARRAC starts monitoring immediately. If a threat fires during your 14-day trial, it contains it. You see exactly what happened, why, and what was done — on your own environment, with your own data.
No simulations. No demos. No sales engineer required. Just ARRAC, your environment, and the evidence.
14-day free trial · No credit card required · All 10 modules included · Cancel anytime