DFIR investigation intelligence

From raw evidence to defensible answers.

SURAGX is designed to help investigators reconstruct what happened, connect evidence into an attack story, test investigative questions, inspect supporting proof and produce reviewable findings—while keeping AI subordinate to evidence.

Evidence provenanceProof-linked claimsHuman confirmationPrivate/on-prem architecture
EVIDENCE → CONTEXT → INVESTIGATION → PROOF
EvidenceProof
Raw sourceReviewable finding
Ask this case

“How did the attacker enter, and which records support the conclusion?”

EVIDENCE REQUIRED
⌁
Attack StoryConnected, evidence-backed sequence
◎
Investigative AIAllowlisted tools; gaps surfaced
✓
Proof & ReportHuman-reviewed, reproducible output
Why SURAGX exists

Detection is not the same as explanation.

Security teams may have alerts, logs and forensic outputs across different tools. The investigation problem is turning that fragmented material into a coherent, reviewable account of what happened—without losing provenance or confusing AI interpretation with fact.

01

Evidence is fragmented

Events and forensic outputs arrive in different formats. Investigation needs normalization without losing the original source record.

02

Sequence matters

Investigators need a timeline and attack story across initial access, execution, persistence, lateral movement and impact.

03

Proof matters

A persuasive paragraph is not enough. Findings need supporting records, contradictions, gaps and reproducible provenance.

04

Human judgment remains central

AI can assist analysis, but authoritative conclusions are designed to require investigator review and confirmation.

North-star workflow

One path from evidence to a reviewable conclusion.

The approved architecture baseline defines a deliberately simple investigator journey. Open-source forensic engines stay behind adapters; the customer experience remains case-centric.

01Create CaseCustomer, scope, severity, analysts, time context
02Upload EvidenceResumable ingest and server-side hashing
03Process & NormalizeDerived artifacts, OCSF + provenance envelope
04Attack StoryConnected entities, events and evidence-backed edges
05Ask & Inspect ProofControlled AI tools, evidence gaps, proof references
06Confirm & ReportHuman decision and professional output
Security & forensic integrity

Evidence is authoritative. AI is assistive. Security is enforced by design.

SURAGX’s architecture baseline treats evidence, parser output and model input as untrusted. Security boundaries exist around identity, tenant access, evidence storage, forensic processing, AI tools, proof and operational telemetry.

Six security pillars

Customer-facing security language is intentionally conservative until each control is verified against a release.

✓
Tenant isolationAPI scope + PostgreSQL RLS + storage/search/AI boundaries
✓
Evidence integrityServer-side SHA-256, no overwrite, derived-artifact linkage
✓
Sandboxed processingNon-root workers, read-only evidence, resource/network limits
✓
AI guardrailsNo shell, arbitrary SQL, unrestricted files or autonomous remediation
✓
AuditabilitySecurity audit records + tamper-evident proof-ledger design
✓
Secure release lifecycleSAST, secret/SCA/container scan, SBOM and security review

“Every answer should lead back to evidence.”

Product principle for SURAGX investigation intelligence