Aria, an AI security analyst that has to earn its autonomy
Most AI security tools ask you to trust them on day one. Aria starts at zero. It investigates a threat, explains the evidence and blast radius, and proposes an action, but a human approves it. Every approval, override, and outcome is logged. Only after it's been verifiably right does it move up a tier. It cannot promote itself.
It runs on-prem on a local model, so nothing leaves the network. Source-available under BSL 1.1, so you can read exactly how the governance works instead of taking my word for it.

Axon ERP
Gestión inteligente: Facturación, Punto de Venta e IA en la nube
Comments (3)
Sary, does the Aria investigate a threat to a computer or an application running in my local area network or I can point to a remote URL and let it investigate a through coming to my website running on AWS? 🤔
Good question. Today Aria does two things: local network/endpoint discovery on your own machine, and AI-SPM on AWS, so if you connect your AWS account it inventories your Bedrock/SageMaker/IAM/Lambda footprint and flags misconfigured AI infrastructure (wildcard IAM roles, exposed secrets, that kind of thing). It also connects to Github, Azure, Snyk, Virus Total, Elastic Threat and and Okta too.
Live threat monitoring for a public website (watching incoming traffic to something like a site running on AWS) isn't in yet, it's on the roadmap next. Building toward "point Aria at your production stack and it watches inbound traffic" as the next milestone.
Sary, the tiered autonomy model is the part that stands out to me. Most tools ask for full trust immediately, and you are making Aria earn it through logged outcomes instead. That is a harder path to build but a more honest one. Curious how long it typically takes a deployment to move from Aria proposing an action to a human trusting it enough to approve quickly, is that measured in weeks of use or number of correct calls?
Sign in to comment or upvote.