All AI inference stays inside your network

See every AI interaction. Investigate 30× faster.

Anjung Sentinel is the local AI SecOps console for LogRhythm SIEM. It monitors enterprise AI use and Claude Enterprise agents, and lets EvolveX AI investigate with models that run on your own hardware.

Bytes sent to external AI0
AI interactions, last 24h48,212
Prompts with sensitive data214
Rogue Claude agents1 suspended
Mean time to triage10 min
Active local modelLlama 3.3 70B
30×
faster average case triage, as measured by our own SOC
0 B
of prompts, logs or answers sent to external AI
10 min
to a cited first triage summary for 90% of cases
1 year
hash-chained audit trail of every model interaction

One console for AI-era security operations

Built on the LogRhythm data you already collect. Ten modules cover shadow AI, rogue agents, investigation, detection, local inference and proof for auditors.

Enterprise AI activity

Every prompt to ChatGPT, Copilot, DeepSeek, browser extensions and internal LLMs, parsed from the LogRhythm sources you already collect, scored for risk.

Claude Enterprise agents

Each agent gets a 30-day behavioural baseline. Drift is scored every 15 minutes, and a rogue agent can be suspended from the console.

EvolveX AI investigator

A persistent investigator that gathers context, runs follow-up searches and posts a cited triage summary within about 10 minutes.

Related Cases

Cases sharing a key, host, IP or agent are linked with a confidence score and a plain-language reason, then merged in one click.

Agentic SOC plugin

Triage alerts, prioritise your shift and investigate cases in natural language from Claude Code or OpenAI Codex.

AI detection rules

Seven rules for AI-era threats mapped to MITRE ATLAS and ATT&CK, plus plain-language rule drafting with backtest and two-person approval.

Local models and guardrails

Run Llama, Qwen or Mistral on your own GPUs. Secrets are masked, context follows analyst permissions and actions need a human.

Outcomes and Executive Digest

A 250-word digest for leadership and an Outcomes Navigator that ties SOC work to the business priorities that matter.

Tamper-evident audit trail

Every model request and AI-driven action is SHA-256 hash-chained, forwarded to LogRhythm and exportable for SOC 2 and ISO 27001.

How it works

From raw log record to a contained incident, without a single prompt leaving your network.

Collect

Proxy, firewall, endpoint, CASB, DLP, SaaS and AI gateway logs flow through LogRhythm as they do today.

Classify and score

AI interactions are recognised, secrets are masked at ingest, and each event gets a High, Medium or Low risk.

Investigate

EvolveX AI opens the case, gathers context, links related cases and answers questions with citations.

Prove

Every request and action is hash-chained in the audit trail and summarised for leadership in the digest.

Faster investigation with EvolveX AI

EvolveX AI works across the New-Scale Security Operations Platform as a persistent investigator: it gathers context when a case opens and keeps searching as the incident unfolds.

  • Every answer cites its log sources and record counts
  • Says "I can't tell from the evidence" instead of guessing
  • Suggests containment; a person always approves it

Average case triage time

EvolveX AI
~10 min
Human analyst
~5 hours

As measured by our own security operations team.

Security you can prove

Guardrails that are locked on, not promised.

Block all external model calls

Network policy denies egress from inference and app pods. An egress counter watches firewall logs every 10 seconds.

Locked on

Mask secrets and personal data

Keys, passwords, tokens, national IDs and card numbers are replaced with reversible tokens before inference.

Locked on

Limit context to permissions

The model only sees log sources the analyst can already search in LogRhythm.

Locked on

Require human approval

Any model output that maps to an action becomes a proposal. Only a person can run it.

Locked on

Bring AI under control in your SOC

Request access to the Anjung Sentinel Console. An administrator reviews every request.