Integration Category
AI & LLM Integrations
OpenAI, AWS Bedrock, Azure OpenAI, Vertex AI — ManySignal uses large language models to generate investigation narratives, assist analyst triage, and explain AI-driven severity decisions in plain language.
AI and language model integrations
OpenAI
GPT-4o for investigation narrative generation, triage summaries, and analyst chat
AWS Bedrock
Claude and Titan models for on-AWS inference with data residency controls
Azure OpenAI Service
GPT-4 via Azure with tenant isolation, private endpoint, and compliance controls
Google Vertex AI
Gemini models for GCP-native AI inference and multimodal log analysis
Anthropic Claude
Long-context reasoning for complex multi-step investigation analysis
AI integration FAQs
How does ManySignal use AI in security operations?
ManySignal uses AI across four areas: (1) alert triage — scoring and prioritising incoming alerts based on entity context and historical patterns; (2) investigation narrative — generating human-readable summaries of what happened, why it matters, and what to do; (3) analyst assist — answering ad hoc analyst questions about detections in natural language; (4) hunt generation — suggesting hunting queries based on MITRE ATT&CK coverage gaps.
Which AI model does ManySignal use by default?
ManySignal ships with a built-in AI inference layer using OpenAI GPT-4o for investigation narrative and triage reasoning. Customers can configure alternative model providers (AWS Bedrock, Azure OpenAI, Vertex AI) for data residency or compliance requirements.
Can I use AWS Bedrock instead of OpenAI for data residency?
Yes. ManySignal's AI inference layer supports AWS Bedrock as a drop-in alternative, routing all LLM calls through your own AWS account. This keeps investigation data within your cloud environment and satisfies data residency requirements that prohibit sending data to third-party AI providers.
Does ManySignal send raw security logs to AI models?
No. ManySignal extracts structured evidence fragments (entity names, event summaries, alert metadata) from the investigation graph and sends only those normalised facts to the AI inference layer. Raw log payloads, PII fields, and credential values are never sent to external AI providers.
How does ManySignal's AI explain its triage decisions?
Every AI-assisted triage decision includes an evidence chain: the specific signals that contributed to the severity score, the threat categories matched, and the entity risk factors applied. Analysts can inspect and override any AI decision, and overrides are used to improve future model behaviour.
Can ManySignal's AI assist analysts with natural language questions?
Yes. The ManySignal analyst chat interface accepts natural language questions about active investigations: 'What is the risk score for this user?', 'Show me all lateral movement events in the last 24 hours', 'Generate a CISO-ready incident summary'. Answers are grounded in ManySignal's investigation data, not generic AI training data.
How does ManySignal prevent AI hallucinations in security investigations?
ManySignal's AI narrative generation is strictly grounded: it only references entities, events, and timestamps present in the ManySignal investigation graph. The system prompt prohibits the model from inferring facts not present in the evidence, and all narrative statements are linked to specific evidence items that analysts can verify.
Does ManySignal use AI for detection rule generation?
Yes. ManySignal can suggest detection rules based on analyst-confirmed investigation patterns. After an analyst closes a True Positive investigation, ManySignal offers to generate a Sigma rule capturing the detection pattern, ready for review and deployment to the connected SIEM.
What data is shared with AI providers when using OpenAI integration?
Only structured investigation context is sent: alert type, normalised event fields (no raw logs), entity identifiers (anonymised by default), severity scores, and analyst annotations. ManySignal uses OpenAI's API with data processing agreement terms that prohibit training on customer data.
Can ManySignal's AI be fine-tuned on our environment's alert history?
ManySignal's triage scoring model is continuously adapted to your environment through analyst feedback (True Positive / False Positive verdicts). This in-product learning does not require external fine-tuning. Custom fine-tuning of the underlying LLM is available in the Enterprise tier for large SOC deployments.
Add AI-assisted investigation to your SOC
See ManySignal's AI narrative and triage scoring in a 30-minute demo.