Inventor(s)

Abstract

A multi-tenant security operations platform maintains, for each customer tenant, a store of discrete environment facts that are compiled into a briefing consumed by an AI analysis pipeline for every security incident. Facts carry provenance classes, lifecycle states, evidence counters, validity windows, and stable natural keys. Facts learned automatically from closed incidents pass a two-stage verification: an adversarial language-model pass checks that every concrete identifier in a candidate fact appears verbatim in the incidents it cites, and a deterministic set check validates the citations themselves. Failing candidates carry a machine-readable quarantine annotation naming each unsupported identifier. Activation requires a minimum count of independent supporting incidents; confidence is derived from evidence cardinality rather than model self-report. The system structurally excludes its own output from its learning signal. Customers view every fact marked customer-visible and may confirm, dispute, or propose facts; a disputed fact is deterministically excluded from the next compiled briefing. Every briefing version is archived as a dated copy, making each automated decision auditable against the knowledge that produced it.

Creative Commons License

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 License.

Share

COinS