Managed endpoint security

Curtainwall: AI agents that watch, patch, and contain.

AI agents that watch, patch, and contain — your techs only when it counts. Curtainwall is the AI-native managed security service for endpoints.Built for mid-market orgs that can't staff a 24/7 SOC — agents run the L1 triage queue, apply routine patches inside the maintenance windows you define, and quarantine suspicious processes before they spread. Your named technician only gets paged when an incident actually needs them.

Escalations reserved for incidents that exceed the agent confidence threshold.

Fleet status
enrolled cohort
  • Endpoints reporting412 / 412
  • Patches due this window7
  • Containments · last 24h3
  • Escalations · last 30d1
  • Audit rows · today2,948
How it works

The SOC loop, on autopilot — with a human hand on the lever.

Agents run the full L1 loop autonomously — routine triage, routine patching, and below-threshold containments never page your team. A named technician steps in only when an incident crosses the confidence threshold, and only then.

  1. Station 01
    Watch
    EDR, identity, and SaaS signal stream into a triage agent that ranks and correlates in seconds.
  2. Station 02
    Patch
    Routine OS and third-party patches apply inside the maintenance window you configured.
  3. Station 03
    Contain
    When a process crosses the confidence threshold, it’s quarantined and the log gets a new row.
  4. Station 04
    Escalate
    A named technician is paged only for incidents that exceed agent confidence — never for noise.

The agent never closes the loop alone.

Every action — patch, quarantine, token revocation — produces a row in the audit log before it produces a notification. If the action is reversed, the reversal is also a row. The customer reads the same log the auditor does.

The split

What agents handle. What humans handle.

The agent owns the parts that don't need a judgement call. The named technician owns the rest.

Agents
Handled autonomously
  • L1 triage and correlation across EDR, identity, and SaaS signal.
  • Routine OS and third-party patching inside configured maintenance windows.
  • Below-threshold containment — quarantine, identity-token revocation, egress restriction.
  • Append-only audit-log row on every action, with agent ID and evidence.
Humans
Named, on threshold
  • Incidents that exceed the agent's confidence threshold.
  • Governance and change reviews outside the maintenance window.
  • Cyber-insurance notification trigger and post-event reporting.
  • Customer-facing incident communications and executive briefings.
Capabilities

What the fleet is doing, end to end.

Each capability is a station that runs continuously on every enrolled endpoint, with a shared evidence model tying them together.

Continuous triage, no analyst on the line
Every endpoint alert — EDR, identity, and SaaS telemetry — fans into a triage agent that ranks, correlates, and either acts or files in seconds. The L1 queue never pages your team.
Patching inside defined maintenance windows
Routine OS and third-party patches run autonomously on the cadence you set. Out-of-window changes are held, summarised, and only applied after explicit sign-off.
Containment that stops lateral movement
Suspicious processes are quarantined, identity tokens revoked, and network egress restricted the moment confidence drops below threshold — with a full actions trail attached.
Immutable audit log, audited end-to-end
Every triage decision, patch, and containment action is appended to a tamper-evident log with agent ID, evidence, and outcome. Underwriters, auditors, and your CISO read from the same source of truth.
Pricing
Flat per endpoint

The pricing model, in one line.

$10–$25 per endpoint, per month.

Inside the band used by adjacent MDR vendors, by design. No per-user fees, no surge pricing when an incident lands, no invoice that punishes you for growing.

  • Flat monthly subscription

    Predictable; scales with endpoints, not incidents.

  • No per-user fees

    Onboard the whole org without re-licensing.

  • No surge pricing

    An incident does not change your invoice.

The audit log

Every action, before any notification.

Underwriters and auditors do not want a story — they want a receipt. Curtainwall produces one row per action, with agent ID, evidence, and outcome, and anchors the chain off-platform so it cannot be quietly rewritten.

Merkle-anchored
Append-only
Customer-read
Auditor-read
Activity log
live · last 5
  • 14:02:11Ztriageprocess quarantined · wininit.exe clone · mb=57%agent/sigma-3
  • 13:58:47Zpatchapplied · CVE-2026-3191 · 412 endpointsagent/rho-12
  • 13:55:02Zidentitytoken revoked · session 9b31…a204agent/theta-7
  • 13:50:36Ztriageclosed · lowercase-noise · false-positiveagent/iota-1
  • 13:42:19Zescalatehandoff · analyst: l.chen · ct-confidence 0.94agent/lambda-4
Questions

The ones we get most.

If yours isn’t on the list, write to us — a real person reads it.

Get in touch

Bring the SOC loop home. Mid-market coverage, autonomous by default, audited end-to-end.

curtainwall@polsia.app