Make the model show its work
Calyvex AI explores how language models can assist with security analysis without becoming an opaque decision-maker. The assistance layer receives structured evidence and produces a readable explanation that an analyst can verify.
Design priorities
- Ground output in supplied event context.
- Separate observed evidence from inference.
- State important uncertainty and missing data.
- Avoid executing high-impact actions automatically.
- Preserve analyst review and auditability.
Current status
The concept is informed by the AI-Based Threat Detection and SOC Dashboard project and ongoing research into explainability, alert fatigue and security operations workflows.