AI that explains threats.
Not just flags them.

Vimy's AI engine triages every detection, generates plain-English incident narratives, and answers natural language questions about your environment — all powered by AI engine on Canadian GPUs. Your data never leaves Canada for AI processing.

AI engine Canadian GPUs Zero data sent to US AI providers
Vimy AI investigation dashboard
The Problem

Alerts without context waste your team's time.

01

Alert says what. Not why.

Traditional security tools fire an alert: "Suspicious login detected." Your analyst spends 45 minutes gathering context — who is this user, what do they have access to, is this normal for them, what happened before and after? The alert told them something happened. It didn't tell them what it means.

02

Investigation is manual archaeology

To understand an incident, analysts dig through log files across multiple tools, correlate timestamps manually, build timelines in spreadsheets, and piece together the story. It's slow, error-prone, and doesn't scale.

03

AI that phones home

Many AI-powered security tools send your data to US-based LLM providers. For Canadian organizations handling sensitive data, this creates a data sovereignty problem. Your security tool shouldn't be a compliance risk.

Capabilities

Three ways AI accelerates your security team.

Every Detection

AI Triage

Every detection that fires is immediately triaged by AI. The triage engine scores severity, estimates blast radius, assesses false positive probability, identifies affected entities, maps to MITRE ATT&CK techniques, and recommends response actions — in seconds, not hours.

What it produces
  • Severity score with confidence level
  • Blast radius estimate — which entities are affected
  • False positive probability
  • MITRE ATT&CK technique mapping
  • Recommended response actions
  • Related historical TROs

Your analyst opens a TRO and the investigation is already half done.

Every TRO

Narrative Generation

Every Threat Response Operation gets a plain-English narrative — a human-readable account of what happened, which systems and users were involved, what the impact is, and what was done about it. Vimy generates three narrative types for three audiences.

Three Narrative Types
Technical Timeline
For your security team. Chronological event sequence, detection rules that fired, entity relationships, response actions executed. The forensic record.
Business Impact Summary
For leadership. What happened, what's at risk, what was the business impact, and what are we doing about it. No jargon.
Compliance Artifact
For auditors. Structured incident documentation mapped to framework controls — PIPEDA breach records, SOC 2 incident response evidence, ISO 27001 Annex A.16.

One incident. Three narratives. Three audiences. Zero manual writing.

On Demand

Natural Language Investigation

Ask questions about your environment in plain English. Vimy translates your question into queries against your live telemetry, ontology graph, and event store — and returns answers grounded in your actual data.

You
Show me all failed logins from outside Canada in the last 24 hours
Vimy
Found 14 failed login attempts from 6 unique IPs across 3 countries (DE, BR, SG). 3 attempts targeted the same account within 4 minutes — possible credential stuffing.
Example Queries
  • "Which users accessed the finance server after midnight?"
  • "What changed on web-01 in the last 48 hours?"
  • "How many OAuth apps have write access to Google Drive?"

Answers come from your data, not the model's training data. The model structures the query — your telemetry provides the facts.

Under the Hood

From raw signal to actionable intelligence.

Six steps, under five minutes. Every detection Vimy fires follows this path — from raw telemetry to a fully contextualized, AI-triaged TRO with response recommendations.

Event detected
A detection specification fires on normalized telemetry. A raw signal becomes a candidate threat.
Context gathered
The ontology graph provides entity context — user identity, access scope, behavioral baseline, asset criticality.
AI triage
The AI engine evaluates the detection with full context. Severity scored, blast radius estimated, false positive probability assessed.
TRO created
A Threat Response Operation is created with AI triage results, evidence chain, and affected entities already attached.
Response recommended
AI recommends proportional response actions based on severity, affected entities, and your rules of engagement configuration.
Narrative generated
Technical, business, and compliance narratives are generated automatically. The TRO is ready for human review or autonomous execution.
End-to-end time: under 5 minutes from detection to fully contextualized TRO with response recommendation.
Data Sovereignty

Canadian AI. No exceptions.

Many AI-powered security tools create a sovereignty gap: your data leaves Canada every time the AI runs. Vimy closes that gap. Completely.

AI engine

Open-weight model running on dedicated infrastructure. Not a black-box API. Not a hosted service controlled by a US company. A model we deploy, control, and operate on Canadian hardware.

Canadian GPUs — Toronto

AI inference runs on Canadian GPU infrastructure in Toronto. Every prompt, every response, every token generated stays on Canadian soil. No data crosses the border for AI processing.

Your data is never used for training

Vimy's AI is inference-only. Your security telemetry is never used to train, fine-tune, or improve the model. Processing is stateless — no data is retained after inference completes.

Other AI Security ToolsVimy
AI ProviderUS-hosted LLM APIsSelf-hosted AI engine
Processing LocationUS data centersToronto, Canada
Data RetentionVaries, often retained for improvementZero retention, stateless
Training on Your DataOften yes, opt-out requiredNever. No opt-out needed.
Model TransparencyClosed-weight, black boxOpen-weight, inspectable

Ask your environment a question.

30-minute demo. We'll run a natural language investigation on your live data and show you what Vimy's AI surfaces — context your current tools don't provide.

AI engine Canadian GPUs Zero data sent to US