
Aria-sec
AI security that earns your trust before it acts

What is Aria-sec?
I’m building ARIA, an AI security analyst that investigates threats and can take action within controls set by the customer. Today, companies either overwhelm analysts with alerts or ask them to trust automation. ARIA starts by requesting approval, verifies every outcome, and earns narrowly scoped autonomy over time - it cannot promote itself. Source code and BSL 1.1 License available https://github.com/sidevworks/aria-sec
- SOC analysts drown in alerts and lose hours reconstructing what an attack touched
- AI security tools demand trust they never earned and keep no record of being right
- Regulated and sovereign buyers cannot ship security telemetry to a US SaaS cloud
- Closed AI vendors can't be inspected, so buyers can't verify how autonomy is governed
- Voice-native 3D cockpit: ask a question, Aria investigates and explains the evidence
- Trust Ladder: autonomy is earned tier by tier from verified outcomes, never self-granted
- Runs fully on-prem on a local model, so telemetry never leaves the customer network
- Open source and model-agnostic: every action, approval and override is logged for audit
Key Features
AI security analyst
Threat investigation
Threat investigation with evidence Blast radius analysis
rust Ladder governed autonomy
Trust Ladder governed autonomy
Human approval queue
Voice-native hands-free operation
3D galaxy navigation
Network asset discovery
AI-SPM posture scoring
Full audit trail of every action
On-prem / air-gapped deployment
Model-agnostic LLM backend
Local speech-to-text
Integrations

TriageAI
Automate your Inbox Triage.
Questions & Answers
Have a question?
This is actually a pretty interesting approach to AI security. I like that Aria doesn’t just give an AI access and say “good luck” 😂 The approval-first approach and the fact that it can run on-prem make a lot of sense, especially for companies dealing with sensitive security data. The part I’d be most curious about is distribution. There are already so many security teams talking about alert fatigue, AI security and keeping their data in-house. That’s actually what we’re building with EarlyCustomers.com - finding people who are already having these conversations across Reddit, X and LinkedIn instead of guessing who might need the product. Feels like Aria-sec could find some really relevant conversations there.