Agent Architecture

The model asks the questions, and software holds the keys.

AI Investigation, early access · Updated Sep 24, 2026

How can a model investigate without authority?

Cyberdroid AI Investigation separates judgment from authority. The model decides what to ask, software decides what it may read, and a person accepts the result.

See the method

Method

Each case starts from Detection findings and SIEM alerts. The model chooses to investigate or monitor, and names the evidence that would disprove it.

The model states an intent. Software turns it into read-only queries, checks every field, fixes the scope and enforces row, time and cost budgets.

Each result carries into later reasoning, with truncation disclosed. When the budget runs out, the case is parked incomplete.

A separate critic tests whether the evidence earns the conclusion. Objections it cannot resolve stay attached to the case.

Verdict, confidence, rationale and evidence references, with disagreement recorded. The case ends in review, for a person to accept.

Measures

Correct and incorrect conclusions, unsupported assertions, cases parked incomplete and reviewer effort, on a labelled set agreed before the first case. We publish the method, not a score.

Limits

AI Investigation is in early access and never remediates. Critique without new evidence can repeat an error, so a person accepts every case.

Sources

Related

Evaluations and Benchmarks

Method

Local Inference

Method
Contact

Products

Takes a Detection finding or SIEM alert through read-only queries and challenges its own verdict before writing the case.

Early access

Cross-source behavioral detection on your SIEM: identity, network, DNS, process and firewall telemetry, baselined against each entity’s own history.

Available now
ARRTECH

© 2026 ARRTECH Corporation. All rights reserved.