Context Lake

As Simbian AI works to defend you, it automatically learns valuable information about your environment and continuously self improves adding new memories and context - privileged users, critical assets, not-patched applications, network structure, rate limits of your SIEM, and so on. And, worry not - humans stay in control with approval flow. You get the best defense curated with great detail for your business.

In production across 300+ enterprise environments

eBook

Security for Winners

Webinar

Why LLMs Fail in the SOC

Research

Simbian Research: The Cyber Defense Benchmark

Organization-wide persistent memory

One entry, not a thousand

Most tools need a new exception per IP, per hash, per rule. One Simbian entry covers the whole pattern, scoped to what you observed.

Consulted mid-investigation

Not a fixed bundle chosen up front, and not a rule applied at the end. Your context steers the investigation while it is still running.

One memory, every writer

Alerts, tickets, pentest reports and runbooks land in one place. Your Agents write what they learn; your team writes and reviews alongside them.

The AI SOC and AI Threat Hunt Agents share it today, across 100+ integrations.

PER-INSTANCEone per IP, per hash, per rule10.20.4.7 → dismisssha256:a91f… → ignorerule_4471 → suppress+ every new variantIt only growsGENERALISEDfact + scope + reasonPort scans from 10.20.0.0/16 are expected —it is our Qualys scanner subnet.One entry10.20.4.710.20.9.1not seen yetEvery other alert type is still investigated in full.
A FIXED SCRIPTsame path every time, whatever it findsEnrichQueryScoreVerdictSTEERED BY CONTEXTthe next step depends on the last oneAlertChild processVPN logsIdentityVerdictContext Lake consulted at each step
WHAT GOES INSIEM & EDR alertsTicketsPentest reportsRunbooks & PDFsCode & configContext Lakeorganization-wide persistent memorySimbian's AI Agentswrite what they learnread it back next timeYour teamwrites to it directlyreviews every changeNothing is applied until a human approves it.

Four layers of knowledge, built from your real data

THE ALERTEncoded PowerShell on BUILD-04702:14 UTC · endpoint EDR · High severityWITHOUT CONTEXTEscalated to a humanNothing in the telemetry says whetherthis is normal here.CONTEXT LAKE ATTACHESASSETSBUILD-047 is a disposable CI runnerIDENTITIESsvc-backup is your backup accountPROCESSESnightly job, 02:00 UTC windowDECISIONSsame alert closed benign in MarchWHAT IT KNOWSSuspicious — needs a humanExpected behavior — closedNo escalation needed.

Assets

Same alert, different asset, different wake-up call.


Identities

Knows the account. Knows the owner. Knows who to call.


Processes

Turn SOPs and escalation procedures into investigation steps Agents can follow.


Decisions

Past verdicts and corrections become institutional memory that outlives the analyst who made them.

Your Agents write their own skills and memories

Skills

Structured playbooks and lookups, private to you.

  • Enrichment skills owner sheets, internal IP ranges, and escalation matrices as queryable reference data
  • Scenario skills your investigation steps, evidence priorities, and severity guidance per alert type
  • Reference files large documents and SOPs attached to the skill that uses them

Memories

Small facts every one of your Agents can recall.

  • Environmental truths “svc-backup runs encoded PowerShell nightly on BUILD-* hosts — expected behavior”
  • Distilled feedback verdict and severity corrections your analysts made during triage
  • Time-scoped facts so a fact you added for one quarter expires instead of steering next year's verdicts

Three writers. One approval queue.

HUMANANALYST FEEDBACKSELF-EVOLUTIONONE REQUESTwho asked · whatchanged · beforeand after diffAPPROVALHumanapproves or rejectsAPPLIEDIn use on thenext investigationUntil a request is applied, it is not used in investigations.Same request object, same preview, same diffs, same audit trail — whatever raised it

You control what your Agents learn

Teach

Submit a description and attach the sheet. The Agent works out where it belongs.

  • Tribal knowledge
  • Internal IP ranges
  • Scanner subnets
  • Account owners
  • Escalation contacts

Track

Every update is a tracked request, and applied context stays visible in its own tab.

  • Who asked
  • What changed
  • Before/after diff

Control

A conflicted request is never applied.

  • Approvals
  • Side-by-side conflict resolution
  • Review notes
  • Routes to a reviewer

Your defense files its own change requests

Self-Improving DefenseRUNS MULTIPLE TIMES A DAYLearns inside your tenant only1Reviews closed casesgrouped by alert type2Finds the gapa pattern across cases3Writes the fixas a scenario skill4Human in controlset threshold for approval or auto-apply5Takes effecton the next matching alert

Defense Across Your Entire Security Stack

100+ integrations. No agent install. Federated reasoning across your entire stack.

Frequently asked questions

A Context Lake is organization-wide persistent memory for AI security Agents — the shared map of your assets, identities, processes, and every past verdict that they reason from. Simbian's Context Lake holds four layers: assets and what each is worth, identities and who they belong to, processes and your runbooks, and the decisions you've already made. Alerts, tickets, pentest reports and runbooks all land in it; your Agents and your team both write to it and read from it. The AI SOC and AI Threat Hunt Agents share it today.
A data lake stores your telemetry. A Context Lake stores what that telemetry means in your environment — which asset carries revenue, which behavior is expected on which hosts, which past call was right and why. Storage isn't understanding. You can query a data lake for what happened; the Context Lake is what lets an Agent judge whether it mattered.
Three architectural differences. Context here is generalised rather than per-instance, so one entry reshapes every investigation touching that pattern instead of needing a new exception per IP or hash, while every other alert type from that scope is still investigated in full. It's consulted mid-investigation, steering where the Agent looks next, not applied as a filter before or a verdict override after. And it's one memory rather than one per product: the SOC and Threat Hunt Agents already read and write the same Context Lake, so a hunt finding becomes a detection the SOC acts on without an integration in between.
You do. Every piece of knowledge that enters the platform becomes a tracked context update request with a full audit trail (who asked, what changed, and a before/after diff for every change), plus an approval gate wherever the submitter lacks write permission, and always for anything the Agent proposes itself. Nothing reaches the Agents without a human's say-so, and until a request is applied it isn't used in investigations.
No. Your telemetry never trains a shared model and never enters the war lab where the reasoning engine is hardened. Your Context Lake is tenant-scoped: it lives in your tenant's skills and memories only, is never pooled with another customer's, and global platform behavior is never edited on your behalf.

Sign up for Simbian's Newsletter

By submitting this form, you agree to our Privacy Policy.

Ask AI about Simbian