the monthly 한국어

How we work

AI agents analyze alerts and gather evidence. People make the final decision. This page covers monthly operations, response targets, and data handling.

Every month

The engagement

First assessment and build: once. Operating and reporting: every month after that.

  1. Assess

    We inventory your systems, read existing logs, and list the most important gaps first.

  2. Build

    Collection, detection, and hardening, highest-risk systems first. The HITL approval table is agreed at this step.

  3. Operate

    AI agents triage every alert every day. An engineer reviews every week and approves risky actions.

  4. Report

    A plain-language report and next month's tuning plan, every month.

These steps apply to the Detect and respond tier and above. For tier differences, see the tier table.

Where a person decides

HITL (Human In The Loop): agent actions and human decisions

Low-risk actions: the agent handles them directly. Actions that are hard to undo or affect production: run only after an engineer approves. The table below sets which is which.

ActionWho decides
Read logs, group related events, explain why something looks wrong, draft a fixThe agent, without asking
Block a known attack source (for example, an IP repeating failed sign-ins)The agent, automatically. The block is recorded and can be lifted
Delete data, change accounts or permissions, restart production, change firewall or SSH settingsAn engineer approves first. The agent cannot run these alone
Widen the set of actions that run automaticallyYou. Widened only after written agreement
Every action aboveTime, reason, and result recorded. Open to later audit

For industry trends, see Industry and regulation.

Evidence-based analysis: the record kept for each decision

  • The alert received, and when
  • The logs the agent queried, and the query conditions
  • Related events grouped with it
  • The decision, and the reason for it
  • The action taken or proposed, and who approved it

Records are kept for the period set in the agreement. Available on request during that period. The monthly report includes the records for key decisions.

Monthly report contents

  • What we watched: systems and log sources covered
  • What happened: alerts, incidents, and blocked attempts
  • What changed, and why
  • Open risks and recommendations
  • Next month's tuning plan

Response targets

  • Urgent security incident: a reply within 4 hours, any day of the week
  • Other requests: a reply within 1 business day

For an incident, send a technical support request. Choose "Security incident" and enter a phone number. You can also email support@themonthly.tech.

Security and data

You choose the AI model path

With the Claude API: the log excerpts an agent analyzes go to Anthropic. With a local model inside your environment (for example, Ollama): logs stay in your environment. You choose before we start. You can change later.

Storage agreed in writing

Where collected logs are stored, and for how long, is written into the agreement before collection starts.

Access stays yours

We work only with the access you grant. You can revoke it when needed. We do not ask for passwords, private keys, or access tokens by form or email.

Personal information sent through this website is covered by our privacy policy.

Questions

Write to contact@themonthly.tech. Answers in plain language.

See our services