Curtainwall: AI agents that watch, patch, and contain.
AI agents that watch, patch, and contain — your techs only when it counts. Curtainwall is the AI-native managed security service for endpoints.Built for mid-market orgs that can't staff a 24/7 SOC — agents run the L1 triage queue, apply routine patches inside the maintenance windows you define, and quarantine suspicious processes before they spread. Your named technician only gets paged when an incident actually needs them.
Escalations reserved for incidents that exceed the agent confidence threshold.
- Endpoints reporting412 / 412
- Patches due this window7
- Containments · last 24h3
- Escalations · last 30d1
- Audit rows · today2,948
The SOC loop, on autopilot — with a human hand on the lever.
Agents run the full L1 loop autonomously — routine triage, routine patching, and below-threshold containments never page your team. A named technician steps in only when an incident crosses the confidence threshold, and only then.
- Station 01WatchEDR, identity, and SaaS signal stream into a triage agent that ranks and correlates in seconds.
- Station 02PatchRoutine OS and third-party patches apply inside the maintenance window you configured.
- Station 03ContainWhen a process crosses the confidence threshold, it’s quarantined and the log gets a new row.
- Station 04EscalateA named technician is paged only for incidents that exceed agent confidence — never for noise.
The agent never closes the loop alone.
Every action — patch, quarantine, token revocation — produces a row in the audit log before it produces a notification. If the action is reversed, the reversal is also a row. The customer reads the same log the auditor does.
What agents handle. What humans handle.
The agent owns the parts that don't need a judgement call. The named technician owns the rest.
- L1 triage and correlation across EDR, identity, and SaaS signal.
- Routine OS and third-party patching inside configured maintenance windows.
- Below-threshold containment — quarantine, identity-token revocation, egress restriction.
- Append-only audit-log row on every action, with agent ID and evidence.
- Incidents that exceed the agent's confidence threshold.
- Governance and change reviews outside the maintenance window.
- Cyber-insurance notification trigger and post-event reporting.
- Customer-facing incident communications and executive briefings.
What the fleet is doing, end to end.
Each capability is a station that runs continuously on every enrolled endpoint, with a shared evidence model tying them together.
The pricing model, in one line.
$10–$25 per endpoint, per month.
Inside the band used by adjacent MDR vendors, by design. No per-user fees, no surge pricing when an incident lands, no invoice that punishes you for growing.
Flat monthly subscription
Predictable; scales with endpoints, not incidents.
No per-user fees
Onboard the whole org without re-licensing.
No surge pricing
An incident does not change your invoice.
Every action, before any notification.
Underwriters and auditors do not want a story — they want a receipt. Curtainwall produces one row per action, with agent ID, evidence, and outcome, and anchors the chain off-platform so it cannot be quietly rewritten.
- 14:02:11Ztriageprocess quarantined · wininit.exe clone · mb=57%agent/sigma-3
- 13:58:47Zpatchapplied · CVE-2026-3191 · 412 endpointsagent/rho-12
- 13:55:02Zidentitytoken revoked · session 9b31…a204agent/theta-7
- 13:50:36Ztriageclosed · lowercase-noise · false-positiveagent/iota-1
- 13:42:19Zescalatehandoff · analyst: l.chen · ct-confidence 0.94agent/lambda-4
The ones we get most.
If yours isn’t on the list, write to us — a real person reads it.
Bring the SOC loop home. Mid-market coverage, autonomous by default, audited end-to-end.
curtainwall@polsia.app