Pondurance Announced the Launch of Pondurance Kanati™
Cyber Security / Threat Intelligence & Incident Response | 5 min read
Pondurance, the leading provider of next-generation managed detection and response (MDR) services engineered to eliminate breach risk for mid-market organisations, has announced the general availability of Pondurance Kanati™ — an innovative Agentic AI that now powers the core of Pondurance's award-winning MDR Security Operations Center (SOC) service. Kanati establishes a new operational standard: a Managed SOC capable of autonomous operation, where human analysts supervise rather than first-respond, enabling machine-speed defence as the new baseline.
SOC Operations at Machine Speed
"Cyber adversaries operate at machine speed, using AI with no rules of use. Security operations must match that pace or fall behind, while protecting and not negatively impacting each customer's environment. With our new Pondurance Kanati Agentic AI SOC, we've reimagined from the ground up how the SOC operates in the next-generation MDR, fusing at peak more than 60TB of daily event, alert, and threat intelligence data with contextual AI to achieve containment for high-confidence threats."
— Doug Howard, CEO, Pondurance
The design of Kanati does not layer automation onto legacy workflows. It uses an AI-native operating model where machine-speed defence is the default, and human expertise is focused precisely where it matters most — on complex or low-confidence situations that require human judgement. By autonomously acting on high-confidence threats instantly, Kanati frees human SOC analysts to take a more proactive advisory role, recommending improvements to customers' defensive posture, exposure closure, and broader IT hygiene.
Headline Performance Numbers
Initial performance measurements of Kanati demonstrate significant gains across every critical SOC metric:
- • 90% faster threat analysis with AI-powered confidence rating and containment
- • <2 minute average investigation time for all alerts, regardless of priority
- • 80% reduction in false positive tickets
- • 10x improvement in contextual enrichment and correlation of threats
- • 100% alert coverage — every alert investigated with full analytical rigour
How Kanati Works: Reimagining the Managed SOC
Traditional SOCs depend on human analysts to triage alerts, correlate data, and execute response playbooks — creating bottlenecks that extend dwell time, increase costs, and introduce human error. Kanati replaces these alert-driven, error-prone workflows with a coordinated system of AI agents that operate continuously across the full threat lifecycle, while preserving essential human oversight and 24/7 SOC availability.
Kanati's core capabilities include real-time ingestion and normalisation of telemetry across endpoint, network, cloud, operating systems, and identity platforms; multi-step, cross-system autonomous investigation using historical and behavioural baselines; autonomous execution of verified containment actions for high-confidence threats including endpoint isolation and identity control measures; generation of detailed, audit-ready investigation documentation for every alert; and escalation of lower-confidence or novel threats to experienced human analysts. At peak, Kanati processes more than 60TB of daily operational data at machine speed.
Kanati categorises threats using a confidence-band model that assesses both the accuracy of threat determination and the appropriateness of response actions. Only the highest-confidence incidents are autonomously resolved — lower-confidence threats are escalated for human review, ensuring automation never outpaces accountability.
Built for Trust, Governance, and Transparency
Recognising that autonomy in cybersecurity demands accountability, Pondurance engineered Kanati with security-by-design principles for Agentic AI. Key governance commitments include:
- • Data Isolation — the AI operates in a tightly controlled, tenant-isolated environment with all data access locked to a single tenant
- • Data Protection — all customer data remains within Pondurance's infrastructure via Amazon Bedrock; customer data is never used to train external foundation models
- • Accountability — every automated decision is logged, policy-bound, and auditable with Explainable AI investigation trails and immutable audit logs
- • Opt-Out Availability — customers subject to regulatory constraints may opt out of Kanati at any time
Pricing and Availability
Kanati is included across all configurations of the Pondurance MDR service at no additional cost — delivering faster, more accurate threat analysis and autonomous containment of high-confidence threats as a standard capability. The platform is available immediately to qualified enterprise and mid-market customers in North America. For more information or to request a demonstration, visit pondurance.com.
Key Takeaways
- • Pondurance Kanati™ is an AI-native Agentic AI SOC that autonomously investigates and contains high-confidence threats, shifting human analysts into supervisory roles.
- • Initial measurements show 90% faster threat analysis, sub-2-minute average alert investigation, 80% fewer false positive tickets, and 100% alert coverage.
- • Kanati processes over 60TB of daily operational data at machine speed, with a confidence-band model ensuring only the highest-confidence threats are autonomously resolved.
- • Built with enterprise-grade governance: tenant-isolated data, Amazon Bedrock implementation, immutable audit logs, Explainable AI trails, and a regulatory opt-out option.
- • Kanati is included in all Pondurance MDR configurations at no extra cost and is available immediately for North American enterprise and mid-market customers.
