Chronolith · On-Premises AI SIEM
Your clients' data stays
on their hardware.
Threats resolved in minutes.
Security intelligence for the organizations that can't send their data to the cloud.
Law firms. Financial services. Healthcare. No SOC required.
< 3 minAlert to resolved
0 GBLeaves client site
1 clickInsurer-ready report
FlatAnnual licensing
Shipping early Q4 2026 — not a roadmap, not a beta
Building on enterprise HPE infrastructure now
Built by a working systems architect
Founding MSP partners — early Q4 2026
01 · BLUEPRINT
AI remediation, step by step
When an alert fires, Chronolith generates a plain-English numbered runbook with copy-paste commands. Your tier-1 tech resolves it without escalation. Average time to resolution: under 3 minutes.
Read the brief →
02 · SHUTTER VIEW
Ambient security status
A full-screen ambient display — green when clear, red when active. Non-security staff understand it immediately. Incident cards surface only when they're needed.
03 · COMPLIANCE REPORT
One-click insurer submission
Auto-generated monthly compliance reports with cyber insurance submission metadata, posture scoring, and a signatory block. Your clients hand this to their insurer. No log dumps.
Read the brief →
04 · AUTOMATED DISPOSITION
Closes noise automatically
When a brute-force fires, a short-term listener watches for account lockout or admin reset. If it resolves, the alert closes itself. Your techs only see what needs humans.
Read the brief →
05 · THREAT INTEL
CISA KEV, MITRE, OTX — live
Feodo C2, CISA KEV, AlienVault OTX, Abuse.ch URLhaus and MalwareBazaar, Spamhaus DROP — all refreshed automatically. IOC hits surface on every matching event.
Read the brief →
06 · POST-INCIDENT REPORT
CEO-ready incident summary
Every incident generates a lockable, exportable executive summary with MTTD/MTTR metrics, root cause analysis, and typed action items. A compliance artifact and a billable deliverable.
Read the brief →
Law Firms
Attorney-client privilege demands data residency. Sentinel and Splunk Cloud fail this test on day one.
Financial Services
Regulatory obligations and fiduciary duty require knowing exactly where client data lives at all times.
Healthcare
HIPAA BAA and PHI handling requirements make cloud-based log aggregation a liability.
Government Contractors
CMMC and CUI handling requirements demand on-premises processing and documented incident response.
Insurance-Mandated SMBs
Cyber insurers now require documented logging and incident response. Chronolith provides both, affordably.
Architecture
Runs on what
you already own
No cloud dependency. No vendor lock-in. Chronolith runs on any server capable of running PostgreSQL — including the HPE hardware your clients already have in the rack.
- WEF, Linux syslog, Syslog UDP/TCP, Batch API ingestion
- VMware, Hyper-V, Nutanix AHV, bare metal — OVA + VHDX
- LDAP/AD sync · BYOK API key · offline-first licensing
- 3,100-test suite · production hardened · no external data flows
aperlock-chronolith
✓ Ingest WEF · syslog · API
✓ Enrich GeoIP · IOC · baseline
✓ Correlate 104 detection rules
✓ Alert webhook · Slack · email
✓ Blueprint Claude AI runbook
✓ Disposition auto-close on evidence
✓ Report compliance · PIR · audit
Get started
Ready to see Chronolith
on your infrastructure?
Download is coming soon. Drop your email and you'll be first in line — or contact us directly to book a live demo.