Home / About us

Giving every SOC analyst their time back

CyberSentinal builds the agentic SOC for multi-tenant Microsoft Sentinel. Our agents handle the repetitive work across every tenant, so analysts can focus on the decisions that need a person.

Our mission

Security operations that scale on judgment, not headcount.

Most SOC hours go to the same checks repeated across alerts and tenants. We combine hands-on Sentinel operations experience with agents that investigate, explain their evidence and act only within the limits each customer sets.

Protecting the people who protect others

MSSP and SOC teams carry the security of many organisations. We make their work lighter and their response faster, without asking them to give up control.

Trust is earned, not assumed

Every agent action is visible, approved or pre-authorised, and logged. Autonomy grows one alert class at a time, based on measured accuracy.

Our team

One team. One mission. Two cities.

Engineering, research and operations in Kathmandu. Go-to-market and partnerships in San Francisco. Between the two, we cover most of the clock.

27.7208° N, 85.3159° E

Kathmandu

Engineering, research and operations

Lainchaur, Kathmandu, Nepal

--:--
NPT
37.7749° N, 122.4194° W

San Francisco

Go-to-market and partnerships

San Francisco, California, USA

--:--
PT
Our philosophy

How we think about the SOC

01

Evidence first

Every verdict comes with the queries and results behind it. If an analyst can't check the work in seconds, it isn't finished.

02

Earn autonomy

Agents start by recommending. They take on more only when their accuracy on your own incidents proves they're ready.

03

Humans decide

Risky actions wait for approval. A single switch returns any tenant to recommend-only mode.

04

Learn from every incident

Closed incidents feed back into rule tuning, runbooks and agent behaviour, so each week is quieter than the last.

Our story

Built from the analyst's chair

CyberSentinal started inside day-to-day Sentinel operations: assigning incidents, running the same KQL, closing benign alerts, drafting client notifications and doing it all again in the next tenant.

We built agents to take that work on, with the approval gates and audit trail a SOC needs before it trusts automation. That remains our test for every feature: would an analyst running ten tenants on a night shift want it?

Want to see CyberSentinal in action?

Run a 30-day read-only pilot on your own Sentinel tenants, or come build it with us.