For security operations

Route security alerts to the right analyst without sending them to a model.

Security is the largest source category in the catalogue, and a detection finding is the alert where “our AI reads it to triage it” is the least acceptable answer. That is a platform choice CallHeim can back with code.

The sources

25 security sources — the largest category here.

Each alert source has a payload mapping for that tool’s webhook format and its own setup page, built and tested against sample payloads.

All 25 security sources →

The objection you actually have

Nothing here is scored by an external model.

No incident data is sent to any external LLM. CallHeim’s AI features are rule-based code running in our own AWS account, and CallHeim does not train any model on your incidents. An optional Amazon Bedrock path exists in the code and is switched off.

A finding contains hostnames, usernames, file paths and often the indicator itself. Sending that to a hosted model is a disclosure decision, not a triage feature. CallHeim does not ask you to make it.

How CallHeim’s incident intelligence works →

Triage

A severity suggestion you can put in a runbook

Detection engineering already lives on rules you can read. A triage layer that scores your alerts with something opaque is a step backwards from the SIEM content you spent a year tuning.

How the incident record works →

What a suggestion looks like

CallHeim suggests a severity from a fixed keyword ruleset plus your own resolved incidents, shows the matched terms, and a person applies it. Suggestions never change severity or page anyone.

The incident itself carries the severity your source sent, mapped to P1 through P5. A local ruleset also suggests a severity with the matched terms shown; a person decides whether to apply it.

Noise

Dedup within five minutes — and it says so.

A scanner that reports the same finding once an hour is outside that window: it pages again, and CallHeim does not claim otherwise.

  • Repeats of the same alert collapse onto one incident while they keep arriving within five minutes of each other.
  • A repeat that arrives after a longer quiet gap opens a new incident.
  • The thresholds behind the noise handling are published: a 300-second dedup window, a flap threshold of 4 state changes in 600 seconds, and title-similarity grouping at a default of 0.6.

The full noise-reduction pipeline →

Controls

For the team that will review this.

  • Reads and writes are scoped by the API authorization rule to the caller’s tenant, or to the caller’s own user for personal records, and custom operations enforce the tenant in server-side code. CallHeim is multi-tenant on a shared database.
  • E-mail and password sign-in with optional authenticator-app (TOTP) two-factor authentication.
  • The audit log is append-only: no client can modify or delete an entry.
  • Audit records are copied daily to an S3 Object Lock archive (governance mode) with a 7-year retention lock, held by CallHeim.

The full security page →

CallHeim

Put a rule you can read between your alerts and your on-call.

CallHeim helps teams stay in control when critical systems are not. Explore the platform, connect one source, and send yourself a page.

Early access · every workspace starts with a 14-day trial for up to 5 seats, no card required