ClearSkies AI SOC Analyst logo
Privacy Security · Security Fraud

ClearSkies AI SOC Analyst

ClearSkies AI SOC Analyst is an agentic AI module inside the ClearSkies iISOC platform that triages alerts, runs investigations and drafts case narratives for security teams, using a private offline language model rather than a public cloud service.

Active GDPR compliant Subscription No public API Verified by Guidaio
Overview

What is ClearSkies AI SOC Analyst?

ClearSkies AI SOC Analyst is not a standalone product: it is a named module of the ClearSkies iISOC platform, listed in the main menu under native add-ons and appearing in the footer under its commercial name, AI SecOps Assistant. It enters the published price grid at the Pro tier. The host platform is a cloud-native Threat Detection, Investigation and Response platform-as-a-service, built around a single TDIR orchestration core through which every signal is correlated.

The module behaves as a virtual analyst. It triages alerts, prioritises them with adaptive scoring, proposes and carries out investigation steps, creates and assigns cases, and writes the case narrative — while the vendor insists the human keeps the decision. An analyst invokes it by right-clicking an alert in the console and receives AI-generated context, recommended investigation steps and incident-creation options.

Two claims set it apart from most agentic SOC assistants. The first is that it runs on a private, offline large language model trained in-house for cybersecurity, with no dependency on a public-cloud AI provider; the vendor states that prompts and telemetry are never exposed to a third-party model. The second is that its analysis is generated from the underlying log telemetry rather than from an already-compressed alert summary, so context is not lost. Every decision is presented as auditable and traceable, and an explicit autonomy ladder — assistive, semi-autonomous, approval-based, fully automated — can be selected per use case and per tenant.

Around the module, the same core carries DNS Shield, endpoint threat monitoring and response, identity threat protection, threat hunting, attack surface monitoring and SOAR, extended by a marketplace of third-party connectors. Telemetry reaches the platform through the iCollector, a physical or virtual appliance deployable on-premise, in cloud or in hybrid environments.

The publisher is Odyssey Consultants Ltd, a Cypriot managed security services provider claiming more than two decades of SOC operations across more than thirty countries, and reporting recognition as a Niche Player in Gartner's Magic Quadrant for SIEM.

What it does

  • Triage and prioritise incoming security alerts automatically, with adaptive scoring
  • Return enriched context, analysis and next investigation steps from a single right-click on an alert
  • Open, assign and track an incident case directly from the alert that triggered it
  • Draft the case narrative and keep every recommendation traceable to the underlying log telemetry
  • Cut alert noise by weighing relevance, severity and context — the vendor claims 95% fewer false positives
  • Adapt continuously to the customer's environment from incidents, analyst feedback and threat intelligence
  • Operate at a chosen level of autonomy, from assistive to fully automated, per use case and per tenant
Audience

When to use ClearSkies AI SOC Analyst / When not to

A quick filter to help you decide if ClearSkies AI SOC Analyst is the right fit.

When to use ClearSkies AI SOC Analyst

  • In-house SOC analysts drowning in alert volume — the vendor cites roughly 5,000 alerts a day, of which 67% go unaddressed
  • Managed security service providers that need a multi-tenant, white-label platform to serve many clients from one core
  • Security teams in the regulated sectors the vendor addresses directly: energy, financial services, government, healthcare and retail
  • Organisations under data-sovereignty constraints that refuse to send telemetry to a public-cloud AI provider
  • Detection engineers and threat hunters who want the AI's reasoning traceable back to the underlying log telemetry

When not to use ClearSkies AI SOC Analyst

  • Developers who need to drive the tool programmatically: no product API and no API documentation are published anywhere on the site
  • Small businesses without a security function — the cheapest published plan starts at €100 per month, and the AI module only appears at the €2,000 Pro tier
  • Anyone wanting to try before buying: there is no free plan, and no free trial is documented
  • Application security teams looking for source-code scanning — the platform watches infrastructure, identity and endpoints, not code
  • Buyers who need a signed data processing agreement or a published subprocessor list before purchase: neither exists on the site
Get started

How to use ClearSkies AI SOC Analyst

A typical end-to-end flow, from setup to results.

  1. Compare the four published tiers on the pricing page, checking the capacity specifications: daily ingestion, log retention, portal users and correlation rules
  2. Confirm the AI SOC Analyst is included in the tier you are considering — it appears from the Pro plan upwards
  3. Request a demo first if you would rather see the platform before committing
  4. Buy Lite, Plus or Pro online through their dedicated purchase pages, or contact sales for the Enterprise and MSSP editions
  5. Plan the collection layer: deploy the iCollector as a virtual appliance on VMware, Hyper-V, KVM or Proxmox, as a physical appliance, or from a cloud marketplace image
  6. Provision at least the published minimum for the virtual appliance: 8 vCPUs, 12 GB of RAM and 300 GB of disk
  7. Connect the log sources and let the platform correlate them on the TDIR core
  8. Take up the guided onboarding, role-based training and optimisation services if you need help reaching production
  9. Work from the Secure Web Portal, and right-click any alert to invoke the AI SOC Analyst
  10. Allow the four to six weeks the vendor publishes before expecting operational results
Quick read

Pros & Cons

Pros

  • A private, offline AI model with no dependency on an external provider — an uncommon position on this market
  • Explainability and auditability are structural to the pitch, with recommendations traceable to raw telemetry
  • Three of the four tiers carry a public price, which is rare in enterprise cybersecurity
  • Technical limits are published per tier: daily ingestion volume, retention, portal users, correlation rules
  • Support runs 24/7, with hotlines in five countries and a published support address
  • A multi-tenant, white-label edition for managed security service providers runs on the same core
  • The publisher operates security operations centres itself rather than only selling software

Cons

  • No product API and no API documentation exist anywhere on the site or in its sitemap
  • No data processing agreement is published or offered, and no subprocessor list exists — unusual for a vendor selling into regulated European sectors
  • There is no trust centre, no security page and no security.txt file, which is surprising from a cybersecurity publisher
  • The privacy notice and terms cover the website only; no service contract governing customer telemetry is published
  • No hosting country is ever named — only a Middle East data-centre option and an EU statement scoped to website data
  • No free plan and no documented free trial; entry starts at €100 per month, and the AI module only at €2,000
  • The privacy notice carries no effective date, and no opt-out from model learning is documented
Pricing

Pricing & Plans

There is no permanent free plan, and no free trial is documented. The lowest published entry point is €100 per month for the ClearSkies Lite tier, followed by €400 per month for Plus and €2,000 per month for Pro, which is the first tier to include the AI SOC Analyst. The Enterprise tier is quoted on request, as is the MSSP edition. Prospective buyers should note that the same pricing page states elsewhere that billing is currently quarterly and refers to an annual subscription cost, so the effective billing period is worth confirming with the vendor before committing.

ClearSkies Lite — Essential Security
  • from €100 per month
  • 5 to 10 GB ingested per day
  • 2 portal users
  • 1 to 3 months of log retention
ClearSkies Pro — AI-powered, proactive cybersecurity
  • from €2
  • 000 per month
  • 30 to 80 GB per day
  • 10 portal users
  • 12 to 36 months of retention
  • first tier to include the AI SecOps Assistant
  • SOAR
  • Enterprise ETMR
ClearSkies Enterprise
  • price on request
  • 100 GB to 2 TB per day
  • 15 portal users
  • 36 months of retention
ClearSkies for MSSPs
  • a separate multi-tenant
  • SLA-driven licensing model with no public price
Special offers — First month free on a platform plan subscription, advertised site-wide with a stated deadline of 31 August 2026 — a deadline already past at the review date of 2 September 2026, although the banner was still displayed · An older version of the same first-month-free promotion, carrying a stated deadline of 30 June 2026, was still visible on the ClearSkies Lite plan page
Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how ClearSkies AI SOC Analyst handles your data.

GDPR overview

GDPR alignment is claimed explicitly: the privacy notice states that Odyssey affirms its commitment to remain aligned with the General Data Protection Regulation. The concrete mentions are few but real — data received is stored within the geographical scope of the EU until deletion or an erasure request, personal information is not transferred beyond EU borders without consent, and rights of erasure, rectification and objection are exercised through the published data protection address or by telephone. Because the publisher is established in Cyprus, no Article 27 representative is required or named. What is missing matters: the notice carries no effective date, no data processing agreement is published or offered, no subprocessor list exists, and the notice covers website visitors rather than platform telemetry. The compliance frameworks shown elsewhere describe what the software helps customers evidence, not credentials held by the publisher.

Who owns the data?

The published terms and conditions govern use of the website only, not the SaaS service, so the site carries no contractual statement about who owns customer telemetry. The privacy notice addresses website visitors: Odyssey states that personal information supplied there is not shared with any other organisation without consent, is accessible only to authorised employees, and is not transferred beyond EU borders without consent. On the product side the vendor asserts that customer data stays inside the tenant boundary and is never exposed to a third-party model provider — but no customer contract, data processing agreement or service terms are published to support that assertion. Website text and images are stated to be the property of Odyssey Consultants Ltd.

Reuse rights

For the website, Odyssey states that personal data is used to answer messages, honour contractual obligations, send news and content, and process job applications, while technical visit data serves only to improve the site; cookies are set both by Odyssey and by third parties. Nothing in the published documents grants an end user any right to reuse content without permission: the site's text and images are declared the property of Odyssey Consultants Ltd, personal copies are allowed, and commercial reuse requires written permission. On the product side the vendor says its model learns continuously from the customer's incidents, analyst feedback and threat intelligence, and adapts to their network, while also asserting that no prompt or telemetry reaches an external or public model. Note that the same page places the private language model both on our infrastructure and inside the customer boundary, and that no opt-out from that learning is documented.

Data retention & training

Retention summary
Two separate retention rules apply, and they should not be confused. For personal data collected through the website, the privacy notice says only that data will be retained as long as is necessary, or as long as the law dictates, whichever is longer; no figure is given, and erasure or amendment can be requested from the data protection contact by email or telephone. For platform log data, retention is a contractual capacity sold by tier: one to three months on Lite, three to twelve months on Plus, twelve to thirty-six months on Pro and thirty-six months on Enterprise, with real-time analysis windows of one, two, four, and six to twelve weeks respectively. No retention policy for the service outside the pricing grid is published, and no anonymisation practice is described.
Trains on customer data
Unclear
GDPR contact

Hosting summary

Two hosting statements appear on the site, and their scopes differ. The privacy notice, which covers website visitors, says data received is stored within the geographical scope of the EU until it is deleted or erasure is requested, and that personal information is not transferred beyond EU borders without consent. Separately, the homepage says the platform offers hosting where the customer requires it, explicitly including a Middle East data-centre option. No hosting country is ever named, and no hosting provider or subprocessor is disclosed. The sovereignty argument is architectural rather than geographic: telemetry is described as collected and protected at the iCollector edge and as never leaving the customer's control, and the iCollector itself can run on-premise, in cloud or in hybrid environments, which puts part of the question back into the customer's hands. The website's public IP resolves to a content-delivery anycast node, which reflects how the marketing site is served and says nothing about where platform data resides.

Hosting regions
EUMiddle East
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting ClearSkies AI SOC Analyst.

  • Automation complacency: when an assistant triages the queue and writes the narrative, analysts can drift from reading the evidence to approving conclusions they have not checked
  • Skill erosion among junior analysts — the vendor's own pitch is that forty minutes of junior investigation collapses into seconds, and that is precisely the work through which juniors learn the craft
  • The autonomy ladder is a real risk surface: at its higher settings the system acts on production, so who is allowed to raise that setting matters more than the technology itself
  • A model that learns continuously from your environment with no documented opt-out means you cannot easily revoke what it has already absorbed
  • Ownership of telemetry rests on marketing statements rather than any published contract: there is no data processing agreement, no subprocessor list and no service terms
  • The frameworks named across the site — GDPR, NIS2, ISO 27001, PCI DSS, HIPAA — describe what the software helps you evidence; they are not credentials of the publisher and should never be read as such
  • Customer logos, partner networks and reseller listings say nothing about the publisher's own security posture, and the site's public IP is a content-delivery node that says nothing about where customer data lives
Setup

Setup & Integrations

Technical difficulty

Buying is easy; deploying is a project. Lite, Plus and Pro can be purchased online through dedicated pages, but collection requires an iCollector — a physical appliance, a virtual appliance on VMware, Hyper-V, KVM or Proxmox, or a cloud marketplace image — sized from 8 vCPUs, 12 GB of RAM and 300 GB of disk. The vendor publishes a four- to six-week window before operational results, and offers guided onboarding, role-based training and continuous optimisation. The intended audience is security and MSSP teams, so infrastructure skills are assumed.

Deployment

Web appMobile appIOS appAndroid app

Apps stores

Company

Behind ClearSkies AI SOC Analyst

Company name
Odyssey Consultants Ltd
Founded
INFORMATION_NOT_FOUND
Country of origin
🇨🇾 Cyprus
Headquarters
Vasili Michailidi 6, 2015 Strovolos, Nicosia, Cyprus
UBO
Eleftherios Antoniades and Christos Onoufriou
UBO country
🇨🇾 Cyprus
Domain registrar country
🇺🇸 United States
Support contact

Fundraising

23 May 2024 — DECA Investments AIFM, exclusive fund manager of Diorama Investments II RAIF S.C.A., acquired a significant minority stake in Odyssey Consultants Limited, the publisher of ClearSkies. The amount was not disclosed. The two founders retained a majority stake and continued to manage the company.

Social

Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

What exactly is the ClearSkies AI SOC Analyst?
It is a module of the ClearSkies iISOC platform rather than a standalone tool. It works as a virtual analyst that triages alerts, prioritises them, proposes and carries out investigation steps, and writes the case narrative, with the human analyst keeping the decision.
Which plan do I need in order to get it?
It appears from the Pro tier, published at €2,000 per month. The cheaper Lite and Plus tiers, at €100 and €400 per month, do not include it.
Where does the AI model actually run?
The vendor describes a private, offline language model developed in-house for cybersecurity. Be aware that the same page states both that the model is installed on the vendor's infrastructure and that it is deployed inside the customer boundary; the site does not reconcile the two.
Is my data used to train the model?
The vendor says the model learns continuously from the customer's incidents and analyst feedback, while asserting that no data feeds a third party's foundation model. No opt-out from that learning is documented, which is why the vendor's stance is recorded here as unclear.
Is there an API?
No. Neither the site nor its 98-URL sitemap documents a product API. What exists is a marketplace of third-party connectors, which is a different thing: it lets the platform read other tools, not the other way round.
Is there a free plan or a free trial?
No free plan is offered, and no free trial is documented. A demo can be requested, and the site has been advertising a promotion offering the first month free on a subscription.
Where is my data hosted?
No country is ever named. The site mentions a Middle East data-centre option and, for website data specifically, storage within the geographical scope of the EU. The iCollector can also be deployed on-premise, which keeps part of the collection under the customer's own control.
Is a data processing agreement available?
None is published, and the site never says one is available on request. The published privacy notice and terms and conditions cover the website rather than the SaaS service.
What support is included?
Support runs 24/7, with hotlines in Cyprus, Greece, the United Kingdom, the United States and Saudi Arabia, plus an email support address. Ticket volume is capped by tier: four for Lite and Plus, six for Pro, unlimited for Enterprise.
How long does deployment take?
The vendor publishes a window of four to six weeks, depending on the size and complexity of the environment. The collection layer needs an iCollector appliance, sized from 8 vCPUs, 12 GB of RAM and 300 GB of disk.
Conclusion

Should you pick ClearSkies AI SOC Analyst?

ClearSkies AI SOC Analyst is a credible, well-documented module rather than a product in its own right. Its differentiator is stated plainly and is genuinely uncommon: an AI that reasons over security telemetry without renting a model from a hyperscaler, with an autonomy level the customer sets and an audit trail leading back to the raw logs. The commercial side is unusually transparent for enterprise cybersecurity — three of the four tiers carry a public price, and every tier publishes its ingestion, retention and user limits.

The weakness is contractual rather than functional. The privacy notice and the terms and conditions cover the website, not the service; there is no published data processing agreement, no subprocessor list, no trust centre and no security.txt, and the privacy notice carries no effective date. For a vendor selling detection and compliance capability into regulated European sectors, that gap is the first thing a buyer should raise.

Two further points deserve care. The site does not agree with itself on billing: the grid and the plan page quote a monthly price, while the pricing FAQ says billing is currently quarterly and mentions an annual subscription cost. And the same product page places the private language model both on the vendor's infrastructure and inside the customer boundary — a distinction that matters enormously to anyone buying for sovereignty reasons.

Finally, read the compliance material for what it is. GDPR, NIS2, ISO 27001, PCI DSS and HIPAA appear across the site as frameworks the platform helps customers evidence; that is the product's purpose, not a list of the publisher's own credentials. The publisher does claim certifications of its own, in a single platform FAQ answer. That claim is the site's own, and worth verifying independently.