Edge observation
Local agents normalize telemetry, retain raw events, run deterministic detectors, score findings, and deliver selected evidence through a durable pipeline.
Sigvid · A Norvid platform
Sigvid combines deterministic edge detection, persistent evidence, AI-led investigation, independent challenge, and human-governed response in one supervised security operations architecture.
Core distinction
Instead of treating every alert as an isolated ticket, Sigvid relates activity to assets and risk, then builds persistent hypotheses that can gain support, lose confidence, decay, or be contradicted as new evidence arrives.
Local agents normalize telemetry, retain raw events, run deterministic detectors, score findings, and deliver selected evidence through a durable pipeline.
The platform connects hosts, identities, services, incidents, relationships, source health, prior decisions, and coverage gaps.
Threat, exposure, asset importance, evidence quality, and potential impact guide which findings receive deeper analysis.
A supervised AI analyst requests narrow evidence, develops provisional verdicts, and produces concise incident briefs with explicit reasoning.
Evidence contributes to persistent hypotheses. Separate challenge processes can weaken conclusions, preserve contradictions, and expose missing support.
Policies and approvals bound actions, while execution state, rollback, verification, overrides, and evidence histories remain inspectable.
Operating model
AI is used for contextual analysis and security judgment—not as a substitute for deterministic collection, enforcement, authentication, or safety controls.
Raw security events can remain local while structured findings support central analysis.
AI effort scales with meaningful findings rather than total log volume.
Confidence can change as supporting, contradictory, or missing evidence is evaluated.
Humans govern policies and consequential actions; deterministic systems enforce limits.
Current stage
Sigvid is being developed and evaluated as a private-beta AI security analyst. Norvid does not present it as a proven replacement for a mature security operations team. Validation across diverse environments is part of the work.
Evaluate the platform
Private pilots are designed around evidence selection, investigation quality, governance boundaries, and operational fit.