AI investigates first. Automation executes second.
The Familiar investigates every alert end to end, pulling context across your stack and recommending what to do next. Anything consequential stops at the Seal, a deterministic policy gate outside the model, before automation executes it. Autonomous where the risk is low, sealed where it matters.
It plans before it acts
State the outcome in plain English. The Familiar returns a visible plan: the steps, the tools it will use, and its assumptions. Nothing runs until you approve.
It casts the Spell
On your approval, it builds and runs the Spell across the tools you already run: enrich, correlate, contain, restore. Every step carries its evidence on one trail.
Consequential steps halt
Anything destructive or high-blast-radius stops at the Seal with a rationale and a reversible plan. A human approves, and the receipt records who and why.
A plan you can read, not a flowchart you maintain
Legacy SOAR makes you draw the investigation by hand and rebuild it every time a tool changes. The Familiar does the legwork instead: it reads what you asked, correlates the signals mapped to MITRE ATT&CK, and lays out the plan the way a senior analyst would, opening and building the case as it goes. You see the plan before anything runs.
- Context across endpoints, identity, email, cloud, and tickets, in one case.
- Indicators enriched automatically, with the evidence kept attached.
- No prebuilt flowchart to maintain when your tools change.
Decisions you can replay and defend
Investigation is creative. The record should not be. The case documents itself as it unfolds: explicit, repeatable decision logic renders the call, with the evidence and a confidence value attached, all on one receipt. The approvals it collects and your ticketing stay in sync.
- The same inputs reach the same call, every time.
- Every conclusion carries its evidence, never a bare verdict.
- One trail end to end, ready to review, replay, or defend.

Actual product. Demo data.
Spells, dialed to the trust you have
A Spell is the response the Familiar builds and casts, mapped to MITRE D3FEND. You set the autonomy per use case: full speed where the risk is low and the call is clean, the Seal where the blast radius is real. Spells are reversible, so a confident automated cast never becomes a one-way door. What works is saved to your Spellbook to run again, and the Bazaar lets you adopt prebuilt Spells for common outcomes.
- Block, isolate, reset, or escalate across the tools you already run.
- A per-use-case autonomy dial, with the Seal on every consequential cast.
- Reversible Spells, saved to your Spellbook, never a one-way door.
Your Spellbook. The Bazaar.
Automation you can keep. A Spell does not evaporate when the case closes: it is saved, versioned, and ready to run again, with its plan-first, Seal-gated behavior intact.
Your Spellbook
Every Spell you build and approve is saved and versioned. Run it again on demand, and it behaves exactly as approved: plan shown first, consequential steps still held at the Seal.
The Bazaar
Adopt a prebuilt Spell for a common outcome instead of starting from a blank prompt. Read its plan, tune it to your stack, and it lands in your Spellbook, ready to run.
The Seal: a policy gate outside the model.
Not a prompt, not a vibe. The Seal is a deterministic policy gate that sits outside the model and decides what the Familiar may do on its own and what must wait for a human. It is the reason a plan can be ambitious and the system can still be safe.
Low blast radius runs
Reading, enriching, correlating, and drafting happen on their own, within the bounds you set. Speed where the risk is small.
Consequential steps halt
Anything destructive or high-blast-radius stops with its rationale and a reversible plan. A human approves or rejects, explicitly.
Everything is on the record
Every decision carries a receipt: the evidence, the confidence, the approver, and a full exportable audit for review or replay.
Hostile input cannot talk its way past the Seal: see how we treat untrusted content.
One verdict hides the truth. A spread shows it.
Most tools collapse a threat into a single score and move on. Soarcery checks every artifact on every case against a native multi-engine verdict spread, and keeps the full picture of where the engines agree and disagree intact instead of averaging it into one number.
Disagreement is signal. Instead of averaging the engines into one number and losing the nuance, Soarcery keeps the spread intact: when the engines split beyond agreement, the verdict is marked contested, and the Familiar treats that as a reason to dig deeper and bring in an analyst.
Engines agree, high confidence
A tight spread means the engines line up: high agreement, high confidence, a clear call rather than a contested one.
Engines split, contested
A wide spread means the engines disagree. The call is contested, so Soarcery escalates instead of guessing.
Kept on the record
The full spread is kept with the case as part of its evidence record, not collapsed into a single score, so the reasoning behind a contested call stays preserved instead of lost to an average.
Works with the tools you already run.
If it has an API, Soarcery works with it. Bring the stack you have, no rip-and-replace.
Start asking the Familiar.
A 30-minute walkthrough on your real triage flow. Watch it plan, cast a Spell, and stop at the Seal, on your own alerts.