WHY ARRAC

Every question answered.
Honestly.

Security professionals ask hard questions. They should. Here are the answers — including the ones most vendors would not give you.

THE MOST COMMON QUESTIONS

Why not just use what you already have?

COMPLEMENTARY
Defender detects. ARRAC contains.
Microsoft Defender is one of the most capable threat detection tools available. ARRAC is not a replacement for it — it is what happens after Defender fires an alert.

Defender tells you there is a fire. ARRAC closes the doors, isolates the room, and calls the fire brigade — in under 3 seconds, automatically, while Defender's alert is still sitting in your queue.

ARRAC ingests Defender alerts directly. Every containment action ARRAC takes is written back to Defender as evidence. Your security stack gets stronger, not replaced.
ARRAC + DEFENDER = STRONGER TOGETHER
FASTER
MSSPs respond in minutes. Ransomware encrypts in 3.
Managed security providers are staffed by skilled people working hard. The problem is not their capability — it is physics.

The best MSSP SLAs promise a 15-30 minute response. Modern ransomware begins encrypting files within 3 minutes of execution. That gap is not a people problem. It is a speed problem that no human team can solve.

ARRAC contains in 12.3 seconds — measured in production. That is not faster than your MSSP. It is a different category of response entirely.

ARRAC and your MSSP work together. ARRAC closes the immediate threat autonomously. Your MSSP handles the investigation, recovery, and strategic response. Both are better for having the other.
ARRAC CLOSES THE GAP BEFORE YOUR MSSP PICKS UP THE PHONE
DIFFERENT MARKET
Enterprise platforms are built for enterprise teams.
The leading enterprise security platforms are excellent tools. They are also built for organisations with dedicated security operations teams, six-figure annual budgets, and months available for implementation and tuning.

If that describes your organisation — those platforms are worth evaluating, and ARRAC will integrate with them.

If you have 50 to 2,000 Microsoft 365 users, an IT manager responsible for security alongside six other priorities, and you need to be protected by Thursday — ARRAC was built specifically for you.

Deployment takes under 5 minutes. No professional services engagement. No six-month implementation project. No dedicated security team required to operate it.
LIVE IN UNDER 5 MINUTES. NO IMPLEMENTATION PROJECT.
OBJECTIONS WE HEAR

The questions every serious buyer asks.

These are the real objections we hear from CISOs, IT managers, and MSPs. Here are the honest answers.

"What if the AI makes a mistake and blocks a legitimate user?"

This is the right question to ask. Here is how ARRAC is designed to answer it.

Every ARRAC deployment begins at Tier 1 — ARRAC observes and alerts but takes no action. It operates in your environment, learns what normal looks like, and builds a track record. Your team reviews every suggestion. You approve or reject. The AI learns.

Autonomy is earned through verified performance at each tier. Tier 4 requires a 30-day record at Tier 3 with zero false positives — and every false positive resets the clock. Even then, ARRAC does not switch itself on: your SOC administrator enables Tier 4 deliberately, and can step it back at any time.

By the time ARRAC reaches full autonomous response, it has 30 days of evidence that it understands your environment — including your CFO's travel patterns, your VPN exit nodes, and your scheduled automation scripts.

And when it does act, it acts surgically. ARRAC contains the single compromised identity or process — never the team, the office, or the device group. There is no blast radius from ARRAC's own containment actions.

Autonomy is earned, then enabled by your team — not configured on day one. Containment is surgical: one account, never a department.
"I am handing control of my environment to an AI. What if it is compromised or makes a catastrophic error?"

Two distinct concerns here — both worth addressing directly.

On catastrophic errors: ARRAC operates on a strict principle of isolate and hold. It revokes sessions, blocks sign-ins, and isolates devices. It does not delete data, modify configurations permanently, or take actions that cannot be undone in seconds. The blast radius of any ARRAC error is a temporary disruption — not a data loss event.

On compromise: ARRAC is designed with the assumption that it could itself be attacked. Every agent connection is mutually authenticated via unique device certificates. The platform uses tamper-resistant architecture. An attacker who compromises the platform can cause ARRAC to stop acting — they cannot cause it to act maliciously against your environment. The worst case is that your autonomous response layer goes offline temporarily. Your existing tools continue to function.

ARRAC cannot cause data loss. It isolates and holds — one account, one process, never a department.
"How do I know the 12.3-second containment claim is real?"

You should be sceptical of any vendor performance claim. Here is exactly what 12.3 seconds means and where it comes from.

12.3 seconds is the measured average time from verified threat detection to completed containment actions — in ARRAC's production environment, on a real Microsoft 365 tenant. It covers the full sequence: signal received, AI investigation completed, threat confirmed, containment actions executed, and confirmation written back to Entra ID.

This is containment time — not detection time. Detection depends on how quickly Microsoft's signals fire. Containment is what ARRAC controls, and 12.3 seconds is what we have measured.

The best way to verify this claim is to see it on your own environment during a 14-day trial. ARRAC does not simulate threats — it monitors your real environment. If a real threat fires during your trial, you will see the exact timestamps from detection to containment in the incident record.

12.3 seconds is measured containment time in production — not a marketing claim. Verify it on your own environment during the trial.
"The AI Autonomy Score — are you optimising for your own metrics rather than my security?"

This is a sophisticated objection and it deserves a precise answer.

The Guarantee Score measures successful containment — not blocking activity. A false positive that disrupts a legitimate user is not a successful containment. It is a failed action that reduces the score, not increases it.

The incentive structure works correctly: true positive containment increases the score. False positive disruption decreases it. A missed real attack decreases it. The metric is aligned with your outcome, not our activity volume.

This is precisely why we moved away from alert-count metrics. Alert counts reward noise. The Guarantee Score rewards results. If our score is high, your environment is genuinely better protected.

False positives reduce the Guarantee Score — not increase it. The metric is aligned with your outcome.
"We are evaluating enterprise security platforms. Why would we choose a newer company?"

Because we built something they have not built yet.

The major enterprise security platforms are excellent at what they do. They were designed for enterprise security operations teams with dedicated analysts, six-figure budgets, and months to implement and tune.

ARRAC's AI Autonomy Engine — the four-tier framework that earns the right to act before it acts — does not exist in any enterprise platform today. It resolves the fundamental commercial barrier to AI-driven security automation: the question of trust.

Enterprise platforms also do not serve the mid-market. A 200-person law firm cannot afford a six-figure security platform and cannot wait six months for implementation. ARRAC is live in under 5 minutes at a price that works for organisations that have been structurally excluded from enterprise-grade protection.

If you are evaluating enterprise platforms and ARRAC simultaneously — they serve different needs and are not mutually exclusive. ARRAC integrates with Microsoft Sentinel, which means if you already have enterprise tooling, ARRAC adds the autonomous response layer that your existing tools lack.

The AI Autonomy Engine does not exist in any other platform. Autonomous response that earns trust before it acts is a genuinely new capability.
HOW IT ACTUALLY WORKS

ARRAC earns the right to act. Your team decides when to use it.

Four autonomy tiers. Each requires verified performance at the tier below before it becomes available.

TIER 1
Observe and alert
ARRAC monitors and flags. No autonomous actions. Every decision goes to your team.
WHERE EVERY DEPLOYMENT STARTS
→
TIER 2
Recommend and wait
ARRAC investigates and recommends a containment action. Your team approves before anything executes.
→
TIER 3
Contain and notify
ARRAC acts on confirmed high-severity threats, then immediately notifies your team. Every action is logged. Your SOC reviews and validates each one.
→
EARNED · TIER 4
Full autonomous response
Available only after a verified 30-day record at Tier 3 with zero false positives. Every false positive resets the clock. Your SOC team manually reviews the complete Tier 3 log before Tier 4 becomes available.
EARNED — ENABLED BY YOUR SOC

Reaching Tier 4 does not mean ARRAC activates it automatically. Your SOC administrator enables it deliberately — and can step it back to any lower tier instantly, at any time, for any reason.

Autonomy is configured per client, not platform-wide. MSPs can run different clients at different tiers simultaneously. Regulated clients — financial services, healthcare, legal — can be permanently capped at Tier 2 or Tier 3 to meet compliance requirements. ARRAC never overrides a compliance cap.

AI ACCURACY

Why ARRAC's AI doesn't guess

The most common concern about AI in security is this: what if it gets it wrong?

It is a legitimate question. The more a single AI model is asked to hold at once, the higher the risk of confident errors.

ARRAC doesn't ask one model to do everything. Every security incident is worked through by the Multi-Agent Reasoning Board — eight specialised stages, each focused on a single narrow question.

Every assessment carries a confidence score. When confidence falls below the threshold you set, ARRAC does not act — it escalates to a human.

Every decision comes with a complete evidence chain: what ARRAC saw, what it concluded, and why. No black-box decisions.

Three layers between an AI assessment and a real-world action: the Reasoning Board, the Earned Autonomy tier, and your team.

Does this eliminate errors?

No system eliminates errors. What it eliminates is the conditions where errors go undetected and propagate into actions. Every ARRAC decision includes a confidence score, a full evidence chain, and an audit trail. When ARRAC is uncertain — it says so, and escalates to a human.

HUMAN ESCALATION

When ARRAC cannot act — it calls.

Every security platform sends notifications. Most of them wait to be read.

ARRAC calls.

When a critical or high-severity incident requires a human decision — because the autonomy tier requires approval, or because a protected account is involved — ARRAC does not file a ticket and wait for someone to check their inbox.

If no Teams or Slack channel is configured, the call is immediate. If Teams or Slack is active, the notification arrives first — and the call follows within 60 seconds for critical incidents (90 for high) if no action has been taken.

The call reads the incident aloud and presents three options:

Press 1 to approve containment. ARRAC acts immediately.

Press 2 to decline. The incident stays open for manual review.

Press 3 to escalate. Your secondary contact is called immediately.

If nobody answers — ARRAC does not go silent. An SMS fires immediately, along with a Teams alert where Teams is connected: incident open, no response received, manual action required. The incident is never silently dropped.

Every response is written to the audit trail with a timestamp — approved, declined, escalated, or timed out — against the incident it concerns. For DORA and NIS2 compliance, this is your documented evidence of human escalation.

SURGICAL CONTAINMENT

Surgical containment. One account. Never a department.

When ARRAC identifies a threat, it acts on the single compromised identity — not the team, not the office, not the device group.

If a ransomware process is detected on a device, ARRAC isolates that process. The employee's Teams call continues. Their document stays open. Their colleagues are unaffected.

If a compromised account is detected in your finance team, ARRAC contains that one account. The rest of the finance team keeps working.

There is no blast radius from ARRAC's own containment actions. Only the confirmed threat is affected — nothing else.

C-SUITE PROTECTION

What about our executives?

It is the first question every security leader asks. It should be.

ARRAC does not block a CEO because they logged in from a New York hotel.

Before any containment action, ARRAC combines two signals: the cloud identity alert and the on-device agent confirmation.

THE CLOUD SEES
Impossible travel.
London to New York in three hours.
THE AGENT SEES
Device in London.
The device is physically in London, a corporate VPN is active, the connection is normal.
COMBINED VERDICT
VPN exit node. No threat.
Logged only. CEO unaffected.

If the agent also confirms the device is in New York — that is a different picture. That is a real threat. That is when ARRAC acts.

Two signals. Not one. Context. Not just rules.

Executive accounts can be configured with elevated thresholds that require human approval before any containment action — regardless of the platform autonomy tier. Your CEO will never be blocked by an algorithm working alone. The decision to contain a C-suite identity always includes a human signal, a device confirmation, or both.

HONEST ABOUT OUR FOCUS

Built for this. Growing into that.

We made deliberate decisions about what to build first. Here is an honest picture of where ARRAC is today and where it is going.

FULLY LIVE TODAY
✓ Microsoft 365 environments (identity, email, cloud, devices)
✓ Windows endpoint protection (EDR agent, behavioural detection, ransomware prevention)
✓ Azure infrastructure monitoring and containment
✓ Microsoft Sentinel integration (ingestion + evidence pushback)
✓ MSP multi-tenant management (verified tenant isolation)
✓ DORA, NIS2, CRA compliance documentation (automated)
✓ 50 to 2,000 Microsoft 365 users
✓ Deployment in under 5 minutes
IN DEVELOPMENT
→ Google Workspace integration
→ AWS security coverage
→ GCP security coverage
→ macOS endpoint agent
→ Linux endpoint agent
→ Splunk and non-Microsoft SIEM
→ Okta identity provider
→ Enterprise scale (2,000+ users) — contact us to discuss

If your environment does not use Microsoft 365, ARRAC cannot help you today. If it does — even partially — we can protect that part of your environment while the rest of your stack catches up.

If a capability on the In Development list is a hard requirement for you today, we would rather tell you that than sell you something that does not fit. Contact us and we will tell you honestly when it will be ready →

WHERE THE NUMBERS COME FROM

12.3 seconds. 47 minutes. What these mean.

12.3s MEASURED CONTAINMENT
Average time from verified threat detection to completed containment actions. Measured in ARRAC's production environment on a real Microsoft 365 tenant. This is containment time — not detection time.
47 min INDUSTRY AVERAGE RESPONSE
Average time for a human security team to begin responding to a confirmed threat. Source: IBM Cost of a Data Breach Report 2024 and multiple industry benchmarks. This figure has not materially improved in five years.
3 min RANSOMWARE ENCRYPTION START
Time from initial execution to the beginning of file encryption for modern ransomware variants including LockBit and BlackCat. The gap between 3 minutes and 47 minutes is where organisations lose data.

The 44-minute gap between when ransomware begins encrypting and when a human team begins responding is not a technology failure. It is a physics problem. Human detection, triage, investigation, escalation, and response cannot happen in under 3 minutes. Autonomous response can.

That is the only claim ARRAC makes. Not that AI is better than humans. Not that your security team is inadequate. That machine-speed attacks require machine-speed responses — and that the response should be trusted, auditable, and reversible.

See real containment scenarios →

The only way to know if it works is to see it work.

Connect your Microsoft 365 environment in under 5 minutes. ARRAC starts monitoring immediately. If a threat fires during your 14-day trial, it contains it. You see exactly what happened, why, and what was done — on your own environment, with your own data.

No simulations. No demos. No sales engineer required. Just ARRAC, your environment, and the evidence.

14-day free trial · No credit card required · All 10 modules included · Cancel anytime