Chronolith  ·  On-Premises AI SIEM

Your clients' data stays
on their hardware.
Threats resolved in minutes.

Security intelligence for the organizations that can't send their data to the cloud. Law firms. Financial services. Healthcare. No SOC required.

< 3 minAlert to resolved
0 GBLeaves client site
1 clickInsurer-ready report
FlatAnnual licensing
Shipping early Q4 2026 — not a roadmap, not a beta
Building on enterprise HPE infrastructure now
Built by a working systems architect
Founding MSP partners — early Q4 2026
What Chronolith does

Security intelligence that
runs where your data lives

Cloud SIEMs push your clients' privileged data off-site. Chronolith runs on the hardware you already manage — and uses AI to close incidents before they become incidents.

01 · BLUEPRINT
AI remediation, step by step
When an alert fires, Chronolith generates a plain-English numbered runbook with copy-paste commands. Your tier-1 tech resolves it without escalation. Average time to resolution: under 3 minutes.
Read the brief →
02 · SHUTTER VIEW
Ambient security status
A full-screen ambient display — green when clear, red when active. Non-security staff understand it immediately. Incident cards surface only when they're needed.
03 · COMPLIANCE REPORT
One-click insurer submission
Auto-generated monthly compliance reports with cyber insurance submission metadata, posture scoring, and a signatory block. Your clients hand this to their insurer. No log dumps.
Read the brief →
04 · AUTOMATED DISPOSITION
Closes noise automatically
When a brute-force fires, a short-term listener watches for account lockout or admin reset. If it resolves, the alert closes itself. Your techs only see what needs humans.
Read the brief →
05 · THREAT INTEL
CISA KEV, MITRE, OTX — live
Feodo C2, CISA KEV, AlienVault OTX, Abuse.ch URLhaus and MalwareBazaar, Spamhaus DROP — all refreshed automatically. IOC hits surface on every matching event.
Read the brief →
06 · POST-INCIDENT REPORT
CEO-ready incident summary
Every incident generates a lockable, exportable executive summary with MTTD/MTTR metrics, root cause analysis, and typed action items. A compliance artifact and a billable deliverable.
Read the brief →
Built for

The organizations cloud SIEMs
can't serve

Law Firms
Attorney-client privilege demands data residency. Sentinel and Splunk Cloud fail this test on day one.
Financial Services
Regulatory obligations and fiduciary duty require knowing exactly where client data lives at all times.
Healthcare
HIPAA BAA and PHI handling requirements make cloud-based log aggregation a liability.
Government Contractors
CMMC and CUI handling requirements demand on-premises processing and documented incident response.
Insurance-Mandated SMBs
Cyber insurers now require documented logging and incident response. Chronolith provides both, affordably.
Architecture

Runs on what
you already own

No cloud dependency. No vendor lock-in. Chronolith runs on any server capable of running PostgreSQL — including the HPE hardware your clients already have in the rack.

  • WEF, Linux syslog, Syslog UDP/TCP, Batch API ingestion
  • VMware, Hyper-V, Nutanix AHV, bare metal — OVA + VHDX
  • LDAP/AD sync · BYOK API key · offline-first licensing
  • 3,100-test suite · production hardened · no external data flows
aperlock-chronolith # your hardware
 
Ingest WEF · syslog · API
Enrich GeoIP · IOC · baseline
Correlate 104 detection rules
Alert webhook · Slack · email
Blueprint Claude AI runbook
Disposition auto-close on evidence
Report compliance · PIR · audit
 
→ 0 bytes leave your network
→ No cloud dependency
→ No per-GB billing
Get started

Ready to see Chronolith
on your infrastructure?

Download is coming soon. Drop your email and you'll be first in line — or contact us directly to book a live demo.

Or: book a demo · hello@aperlock.com