The conversation your current vendor won't have

Your SIEM fires alerts.
It doesn't fix anything.

You're paying five or six figures a year for a product that tells you something happened. What happens next is still on your team. That's not a security tool. That's an expensive log viewer.

Typical enterprise SIEM spend
$60–80K
Per year. License + support + professional services to stand it up.
Return on that investment
$0
Alerts fired. Analysts investigated. Escalations happened. Bill came anyway.
Chronolith enterprise
$60–75K
Detection. Remediation. Compliance docs. On your hardware. Same price range.
On-premises — data never leaves your network
Alert to resolution in under 3 minutes
One-click insurer-ready compliance output

Why the category is broken

Detection without remediation
is just expensive noise

More alerts look like more security
Legacy SIEMs are optimized to detect. The more alerts they fire, the more they look like they're working. Your analysts spend their days triaging noise while actual threats wait their turn.
You pay more during your worst incidents
Per-GB and per-event pricing means the moment an attack generates maximum log volume is the moment your bill spikes highest. You're being charged for the incident on top of experiencing it.
Compliance docs are still manual
Your underwriter, your auditor, and your board all want documentation. Your SIEM exports logs. Someone on your team turns those logs into a document. That someone bills by the hour.
Your data left the building
Cloud-optional means cloud-default. If you're in legal, healthcare, financial services, defense contracting, or manufacturing — your security event data is subject to your compliance obligations, not your vendor's convenience.

What changes with Chronolith

The category stops at the alert.
Chronolith keeps going.

Capability
What you have now
Chronolith
After the alert fires
gapInvestigation is yours. Your analyst, your time, your escalation path.
fixedBlueprint generates immediately — plain-English numbered runbook with copy-paste PowerShell. Tier 1 closes it.
False positive rate
gapManual triage. No learning. Same sources fire the same FPs every week.
fixedBehavioral dedup profiler learns your environment over 21 days. Statistical anomaly detection — not rule matching.
Account lockout resolution
gapEventID 4740 fires. Go find the source. LockoutStatus.exe at 11pm. Three hours if you're lucky.
fixedSource host, logon type, and exact service identified in the same alert. Five minutes. Blueprint tells you which service to update.
Data residency
riskCloud-optional is cloud-default. Your event logs leave the building.
fixedOn-premises. Always. Your hardware. Data never leaves your network. Not negotiable.
AI pipeline ownership
riskVendor-managed AI. Your security events feed their model.
fixedBYOK — you provision your own AI key. Aperlock has zero access to your event data through the AI pipeline.
Compliance documentation
gapExport logs. Write the report yourself or hire a consultant, billed hourly.
fixedOne-click Insurance Renewal Pack. Underwriter-ready, chain-of-custody sealed. No consultant required.
Regulatory guidance
gapGeneric playbooks. No sector awareness. HIPAA looks the same as DFARS.
fixedSector-aware remediation built in — 10 sectors covered — HIPAA, DFARS, GLBA, NERC CIP and more. Notification clocks automatic.
Pricing during incidents
riskPer-GB or per-event. Worst incident = highest bill.
fixedFlat annual by source count. Worst day, same invoice.
A column of green ticks is easy to write. The capability briefs are how this actually works underneath, including where the product is blind — written to be checked rather than skimmed.

The return on investment

What Chronolith gives back
that your current SIEM doesn't

Mean time to resolution
3 hrs → 5 min
Account lockout incidents. Blueprint generates the runbook. Tier 1 closes it without escalation.
Alert volume, not just alert count
21-day learning window
Behavioral dedup profiler learns your environment automatically and locks out known false-positive sources. Fewer alerts your team has to look at twice.
Compliance consultant spend
$0
Insurance Renewal Pack in one click. The document your underwriter asks for — built in, not billed out.
Tier 1 escalation rate
Near zero
Guided remediation with risk classification and reversibility notes. Escalation becomes the exception, not the workflow.

How it works

From alert to closed

1
Alert fires on your hardware
Chronolith ingests from Windows Event Forwarding, FortiGate, M365, Entra ID, VMware, iLO, and more. Everything stays on-premises. Nothing leaves your network.
2
Blueprint generates in seconds
AI classifies the threat, identifies the affected systems, and generates a plain-English numbered runbook with copy-paste PowerShell. Risk level, reversibility notes, and regulatory implications included.
3
Tier 1 closes the incident
Your tech follows the Blueprint. No escalation. No consultant call. No 11pm phone tree. Mean time to resolution drops from hours to minutes.
4
Compliance documentation — one click
Post-Incident Report and Insurance Renewal Pack generate automatically. Underwriter-ready, chain-of-custody sealed. Hand it to your auditor, your insurer, or your board. No consultant required.

Pricing

Flat annual. No surprises.

Starter
$9,000
per year · up to 10 sources
On-premises deployment
BYOK AI pipeline
Full detection engine
Blueprint runbooks
Post-Incident Reports
Insurance Renewal Pack
Advanced
$36,000
per year · up to 150 sources
Everything in Professional
Direct sales engagement
Dedicated deployment support
SLA options available
Custom connector development
Enterprise — 150+ sources

Custom quote. If you're currently spending $60–80K/yr on a SIEM that generates alerts without outcomes, that is worth half an hour before your next renewal.

Talk before your renewal

One conversation before
you sign another year

Your renewal date is coming. Before you sign another year of alerts-without-outcomes, 30 minutes with us — no demo theater, no sales deck. Just an honest conversation about whether what you have is working and whether what we've built is the right replacement.

✓  Got it — you'll hear from us within one business day.

Or email directly: partners@aperlock.com