Business owners, operators, and customers
Learn
Ready for review
Public
Supported

Product overview

What Sotiras AI is building, who it serves, and where this product fits. Start here if you already know the procedure, or go back to the support docs index if you need a different topic.

I want this article

Read the current support note if you are already in the right procedure.

I want the docs index

Go back to the section list when you need a different article or category.

I want support context

Jump to support docs home when the question is broader than one article.

Markdown article

Source: content/support-docs/getting-started/product-overview.md

What Sotiras AI is

Sotiras AI is practical security operations for small and medium businesses. It helps lean teams answer three everyday questions:

  • What are we responsible for protecting?
  • What changed or needs attention?
  • What should happen next, and who owns it?

The product is built around an authenticated workspace for assets, risks, controls, evidence, incidents, integrations, and AI-assisted analysis. The goal is not to create another dashboard that only specialists can understand. The goal is an operating rhythm that a business owner, IT generalist, MSP, or incident responder can actually use.

Core promise

Sotiras turns security noise into prioritized work:

  • See important assets and exposure in one place.
  • Convert findings and telemetry into a ranked action queue.
  • Keep evidence attached to risks and incidents.
  • Use AI to summarize, explain, draft, and recommend.
  • Require human approval and audit history for high-impact changes.

Who it serves

Sotiras is designed for organizations that need stronger security operations but do not have a large internal security team.

Primary users include:

  • Business owners and operators
  • IT generalists
  • Outsourced IT partners
  • MSP collaborators
  • Incident responders
  • Auditors and read-only stakeholders

Product surfaces

Sotiras can support several security paths as the product matures:

SurfaceWhat it helps with
PortalTenant workspace, assets, risks, controls, incidents, users, and evidence.
IntegrationsSaaS, identity, monitoring, endpoint, backup, ticketing, and cloud signals.
CollectorsServer, container, syslog, firewall, web server, and application telemetry.
Hosted observabilityManaged Grafana workspaces for Enterprise tenants that need dashboards, logs, metrics, alerts, and investigation views.
Proxy protectionBaseline protection, logging, and threat signals for selected applications.
AI assistancePlain-language summaries, triage support, remediation drafts, and incident notes.
BillingPlan visibility, usage, protected surge, invoices, and packaging boundaries.
Support docsProduct workflow guidance for owners, operators, IT partners, and responders.

Runtime is an implementation option, not the product category. When Sotiras runs a workload, collector, scan, or on-demand container, the reason is to make security easier to implement through built-in controls, telemetry, evidence capture, and response workflows.

What belongs elsewhere

The public marketing website, subscription checkout, payment operations, and broad demand-generation systems belong in the separate Sotiras website and commerce project. This portal focuses on the operational security experience.

Product posture

Sotiras should feel like an operator console for a lean business, not a security lab. Product guidance should be clear enough for a non-specialist to understand, but precise enough for an IT partner or responder to trust.

Trust boundaries

Sotiras should not claim perfect prevention or automatic security. Recommendations should be tied to evidence, tenant policy, confidence, and review. AI should help people move faster, while the product keeps high-impact decisions visible and auditable.