For security operations
Route security alerts to the right analyst without sending them to a model.
Security is the largest source category in the catalogue, and a detection finding is the alert where “our AI reads it to triage it” is the least acceptable answer. That is a platform choice CallHeim can back with code.
The sources
25 security sources — the largest category here.
Each alert source has a payload mapping for that tool’s webhook format and its own setup page, built and tested against sample payloads.
Noise
Dedup within five minutes — and it says so.
A scanner that reports the same finding once an hour is outside that window: it pages again, and CallHeim does not claim otherwise.
- Repeats of the same alert collapse onto one incident while they keep arriving within five minutes of each other.
- A repeat that arrives after a longer quiet gap opens a new incident.
- The thresholds behind the noise handling are published: a 300-second dedup window, a flap threshold of 4 state changes in 600 seconds, and title-similarity grouping at a default of 0.6.
Controls
For the team that will review this.
- Reads and writes are scoped by the API authorization rule to the caller’s tenant, or to the caller’s own user for personal records, and custom operations enforce the tenant in server-side code. CallHeim is multi-tenant on a shared database.
- E-mail and password sign-in with optional authenticator-app (TOTP) two-factor authentication.
- The audit log is append-only: no client can modify or delete an entry.
- Audit records are copied daily to an S3 Object Lock archive (governance mode) with a 7-year retention lock, held by CallHeim.
Put a rule you can read between your alerts and your on-call.
CallHeim helps teams stay in control when critical systems are not. Explore the platform, connect one source, and send yourself a page.
Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required