You choose the AI model path
With the Claude API: the log excerpts an agent analyzes go to Anthropic. With a local model inside your environment (for example, Ollama): logs stay in your environment. You choose before we start. You can change later.
AI agents analyze alerts and gather evidence. People make the final decision. This page covers monthly operations, response targets, and data handling.
Every month
First assessment and build: once. Operating and reporting: every month after that.
We inventory your systems, read existing logs, and list the most important gaps first.
Collection, detection, and hardening, highest-risk systems first. The HITL approval table is agreed at this step.
AI agents triage every alert every day. An engineer reviews every week and approves risky actions.
A plain-language report and next month's tuning plan, every month.
These steps apply to the Detect and respond tier and above. For tier differences, see the tier table.
Where a person decides
Low-risk actions: the agent handles them directly. Actions that are hard to undo or affect production: run only after an engineer approves. The table below sets which is which.
| Action | Who decides |
|---|---|
| Read logs, group related events, explain why something looks wrong, draft a fix | The agent, without asking |
| Block a known attack source (for example, an IP repeating failed sign-ins) | The agent, automatically. The block is recorded and can be lifted |
| Delete data, change accounts or permissions, restart production, change firewall or SSH settings | An engineer approves first. The agent cannot run these alone |
| Widen the set of actions that run automatically | You. Widened only after written agreement |
| Every action above | Time, reason, and result recorded. Open to later audit |
For industry trends, see Industry and regulation.
Records are kept for the period set in the agreement. Available on request during that period. The monthly report includes the records for key decisions.
For an incident, send a technical support request. Choose "Security incident" and enter a phone number. You can also email support@themonthly.tech.
With the Claude API: the log excerpts an agent analyzes go to Anthropic. With a local model inside your environment (for example, Ollama): logs stay in your environment. You choose before we start. You can change later.
Where collected logs are stored, and for how long, is written into the agreement before collection starts.
We work only with the access you grant. You can revoke it when needed. We do not ask for passwords, private keys, or access tokens by form or email.
Personal information sent through this website is covered by our privacy policy.