// AI security operations · Amazon Bedrock

An autonomous SOC analyst that never sleeps — with a human on every trigger.

NyxAI is a multi-agent platform that triages alerts, investigates threats, and executes response across your security stack. It does the repetitive work at machine speed; a human approves every real action.

2
agents · read / write
24/7
scheduled coverage
100%
actions human-approved
Bedrock
runtime + Claude
The platform

Five components, one governed pipeline.

NyxAI separates analysis from action at the architecture level — the analysis agents structurally cannot take destructive steps. Every component runs on AWS managed services with its own least-privilege role.

NyxOrchestrator

Routing brain

Directs each request to the right agent, applies input guardrails, and enforces the read/write boundary.

NyxRead

Analysis & reporting

Reads logs, queries threat intel, reviews GuardDuty / Security Hub, audits IAM escalation. No write access.

NyxRespond

Response engine

Blocks IPs, adds IOCs, updates & closes incidents — only after a human approves.

NyxFlow

SOAR automation

Scheduled pipeline: pull detections → enrich indicators → propose response → act on approval.

NyxConsole

Analyst portal

Web app with SSO + MFA where analysts query the system and read incident reports.

NyxGuard

Approval gate

Human-in-the-loop over Telegram: evidence in, Approve / Reject out. Authority lives outside the AI prompt.

The security fabric

From signal to action, through a control gate.

AnalystNyxConsole SchedulerNyxFlow · SOAR Auth gateCognito · JWT · MFA NyxOrchestratorrouting + guardrail NyxReadanalyze · report NyxRespondblock · close Threat intelCortex · TrendWAF · Cloudflare ⚑ NyxGuard · human approves
The read path runs freely. The write path is held at NyxGuard — a human approves before anything touches a live system.
AI proposes

Machine speed on the grind

Triage, IOC lookups, enrichment, report drafting, blocklist reconciliation — the repetitive load, done in seconds.

Humans decide

No free button

Blocking an IP or closing an incident always waits for an explicit human Approve. Not a "do-anything" agent.

Deployment

Runs in your AWS, your way.

Managed

On Amazon Bedrock

Default. Agents on Bedrock AgentCore + Claude, microVM-isolated, per-agent least-privilege IAM.

Isolated

Dedicated VPC

Infra runs in an isolated VPC; account can stay air-gapped. Secrets in AWS Secrets Manager.

Roadmap

Self-host open models

Route routine tasks to open-weight models on SageMaker for in-account inference — no data leaves your account.

// built entirely on AWS

Every workload runs on AWS managed services.

Agents, web app, SOAR automation, and email — all on AWS. The largest and fastest-growing cost is Amazon Bedrock inference, scaling with alert volume, integrations, and analyst seats.

Amazon Bedrock · AgentCore Claude models Lambda EC2 CloudFront API Gateway DynamoDB Cognito S3 Route 53 SES Secrets Manager CloudFormation · CDK
Securing the AI itself

Assessed against AI & agent security frameworks.

OWASP LLM Top 10 OWASP Agentic ASI MITRE ATLAS STRIDE

Structural privilege split

Read and write are separate agents with separate IAM roles — one compromised part can't act.

Human gatekeeper

Destructive actions require approval; authority is enforced outside the model prompt.

Auth & isolation

JWT + MFA, input guardrails, no-open-internet account, dedicated isolated VPC.

Integrates the tools you already run: Cortex XDR · Trend Vision One · AWS WAF · Cloudflare · GuardDuty · Security Hub.

FAQ

Questions, answered.

Does NyxAI act on its own?

No. It analyzes and proposes freely, but any real action — blocking an IP, closing an incident, adding an IOC — is held at a human-approval gate (NyxGuard) and only runs after an explicit Approve.

Which models does it use?

Anthropic Claude via Amazon Bedrock today, with a model-router roadmap: cheap open-weight models for routine tasks, higher-tier Claude for complex reasoning and write decisions.

Where does our data run?

Entirely inside your AWS account — Bedrock, Lambda, EC2, S3, DynamoDB. The roadmap adds self-hosted open models so inference can stay fully in-account.

What does it integrate with?

Cortex XDR, Trend Vision One, AWS WAF, Cloudflare, GuardDuty, Security Hub — reading findings and, on approval, pushing blocks and IOCs.

How is cost structured?

Mostly Amazon Bedrock inference, scaling with alert volume, integrations, and analyst seats. Routine work can be routed to cheaper models to control spend.

Move faster. Stay in control.

NyxAI takes the repetitive load off your SOC while keeping a human on every trigger. Built on Amazon Bedrock, running in your account today.