ClearSkies AI SOC Analyst
ClearSkies AI SOC Analyst is an agentic AI module inside the ClearSkies iISOC platform that triages alerts, runs investigations and drafts case narratives for security teams, using a private offline language model rather than a public cloud service.
What is ClearSkies AI SOC Analyst?
ClearSkies AI SOC Analyst is not a standalone product: it is a named module of the ClearSkies iISOC platform, listed in the main menu under native add-ons and appearing in the footer under its commercial name, AI SecOps Assistant. It enters the published price grid at the Pro tier. The host platform is a cloud-native Threat Detection, Investigation and Response platform-as-a-service, built around a single TDIR orchestration core through which every signal is correlated.
The module behaves as a virtual analyst. It triages alerts, prioritises them with adaptive scoring, proposes and carries out investigation steps, creates and assigns cases, and writes the case narrative — while the vendor insists the human keeps the decision. An analyst invokes it by right-clicking an alert in the console and receives AI-generated context, recommended investigation steps and incident-creation options.
Two claims set it apart from most agentic SOC assistants. The first is that it runs on a private, offline large language model trained in-house for cybersecurity, with no dependency on a public-cloud AI provider; the vendor states that prompts and telemetry are never exposed to a third-party model. The second is that its analysis is generated from the underlying log telemetry rather than from an already-compressed alert summary, so context is not lost. Every decision is presented as auditable and traceable, and an explicit autonomy ladder — assistive, semi-autonomous, approval-based, fully automated — can be selected per use case and per tenant.
Around the module, the same core carries DNS Shield, endpoint threat monitoring and response, identity threat protection, threat hunting, attack surface monitoring and SOAR, extended by a marketplace of third-party connectors. Telemetry reaches the platform through the iCollector, a physical or virtual appliance deployable on-premise, in cloud or in hybrid environments.
The publisher is Odyssey Consultants Ltd, a Cypriot managed security services provider claiming more than two decades of SOC operations across more than thirty countries, and reporting recognition as a Niche Player in Gartner's Magic Quadrant for SIEM.
What it does
- Triage and prioritise incoming security alerts automatically, with adaptive scoring
- Return enriched context, analysis and next investigation steps from a single right-click on an alert
- Open, assign and track an incident case directly from the alert that triggered it
- Draft the case narrative and keep every recommendation traceable to the underlying log telemetry
- Cut alert noise by weighing relevance, severity and context — the vendor claims 95% fewer false positives
- Adapt continuously to the customer's environment from incidents, analyst feedback and threat intelligence
- Operate at a chosen level of autonomy, from assistive to fully automated, per use case and per tenant
When to use ClearSkies AI SOC Analyst / When not to
A quick filter to help you decide if ClearSkies AI SOC Analyst is the right fit.
When to use ClearSkies AI SOC Analyst
- In-house SOC analysts drowning in alert volume — the vendor cites roughly 5,000 alerts a day, of which 67% go unaddressed
- Managed security service providers that need a multi-tenant, white-label platform to serve many clients from one core
- Security teams in the regulated sectors the vendor addresses directly: energy, financial services, government, healthcare and retail
- Organisations under data-sovereignty constraints that refuse to send telemetry to a public-cloud AI provider
- Detection engineers and threat hunters who want the AI's reasoning traceable back to the underlying log telemetry
When not to use ClearSkies AI SOC Analyst
- Developers who need to drive the tool programmatically: no product API and no API documentation are published anywhere on the site
- Small businesses without a security function — the cheapest published plan starts at €100 per month, and the AI module only appears at the €2,000 Pro tier
- Anyone wanting to try before buying: there is no free plan, and no free trial is documented
- Application security teams looking for source-code scanning — the platform watches infrastructure, identity and endpoints, not code
- Buyers who need a signed data processing agreement or a published subprocessor list before purchase: neither exists on the site
How to use ClearSkies AI SOC Analyst
A typical end-to-end flow, from setup to results.
- Compare the four published tiers on the pricing page, checking the capacity specifications: daily ingestion, log retention, portal users and correlation rules
- Confirm the AI SOC Analyst is included in the tier you are considering — it appears from the Pro plan upwards
- Request a demo first if you would rather see the platform before committing
- Buy Lite, Plus or Pro online through their dedicated purchase pages, or contact sales for the Enterprise and MSSP editions
- Plan the collection layer: deploy the iCollector as a virtual appliance on VMware, Hyper-V, KVM or Proxmox, as a physical appliance, or from a cloud marketplace image
- Provision at least the published minimum for the virtual appliance: 8 vCPUs, 12 GB of RAM and 300 GB of disk
- Connect the log sources and let the platform correlate them on the TDIR core
- Take up the guided onboarding, role-based training and optimisation services if you need help reaching production
- Work from the Secure Web Portal, and right-click any alert to invoke the AI SOC Analyst
- Allow the four to six weeks the vendor publishes before expecting operational results
Pros & Cons
Pros
- A private, offline AI model with no dependency on an external provider — an uncommon position on this market
- Explainability and auditability are structural to the pitch, with recommendations traceable to raw telemetry
- Three of the four tiers carry a public price, which is rare in enterprise cybersecurity
- Technical limits are published per tier: daily ingestion volume, retention, portal users, correlation rules
- Support runs 24/7, with hotlines in five countries and a published support address
- A multi-tenant, white-label edition for managed security service providers runs on the same core
- The publisher operates security operations centres itself rather than only selling software
Cons
- No product API and no API documentation exist anywhere on the site or in its sitemap
- No data processing agreement is published or offered, and no subprocessor list exists — unusual for a vendor selling into regulated European sectors
- There is no trust centre, no security page and no security.txt file, which is surprising from a cybersecurity publisher
- The privacy notice and terms cover the website only; no service contract governing customer telemetry is published
- No hosting country is ever named — only a Middle East data-centre option and an EU statement scoped to website data
- No free plan and no documented free trial; entry starts at €100 per month, and the AI module only at €2,000
- The privacy notice carries no effective date, and no opt-out from model learning is documented
Pricing & Plans
There is no permanent free plan, and no free trial is documented. The lowest published entry point is €100 per month for the ClearSkies Lite tier, followed by €400 per month for Plus and €2,000 per month for Pro, which is the first tier to include the AI SOC Analyst. The Enterprise tier is quoted on request, as is the MSSP edition. Prospective buyers should note that the same pricing page states elsewhere that billing is currently quarterly and refers to an annual subscription cost, so the effective billing period is worth confirming with the vendor before committing.
- from €100 per month
- 5 to 10 GB ingested per day
- 2 portal users
- 1 to 3 months of log retention
- from €400 per month
- 20 to 30 GB per day
- 5 portal users
- 3 to 12 months of retention
- adds UEBA and vulnerability management
- from €2
- 000 per month
- 30 to 80 GB per day
- 10 portal users
- 12 to 36 months of retention
- first tier to include the AI SecOps Assistant
- SOAR
- Enterprise ETMR
- price on request
- 100 GB to 2 TB per day
- 15 portal users
- 36 months of retention
- a separate multi-tenant
- SLA-driven licensing model with no public price
Data, GDPR & hosting
A consolidated view of how ClearSkies AI SOC Analyst handles your data.
GDPR overview
GDPR alignment is claimed explicitly: the privacy notice states that Odyssey affirms its commitment to remain aligned with the General Data Protection Regulation. The concrete mentions are few but real — data received is stored within the geographical scope of the EU until deletion or an erasure request, personal information is not transferred beyond EU borders without consent, and rights of erasure, rectification and objection are exercised through the published data protection address or by telephone. Because the publisher is established in Cyprus, no Article 27 representative is required or named. What is missing matters: the notice carries no effective date, no data processing agreement is published or offered, no subprocessor list exists, and the notice covers website visitors rather than platform telemetry. The compliance frameworks shown elsewhere describe what the software helps customers evidence, not credentials held by the publisher.
Who owns the data?
The published terms and conditions govern use of the website only, not the SaaS service, so the site carries no contractual statement about who owns customer telemetry. The privacy notice addresses website visitors: Odyssey states that personal information supplied there is not shared with any other organisation without consent, is accessible only to authorised employees, and is not transferred beyond EU borders without consent. On the product side the vendor asserts that customer data stays inside the tenant boundary and is never exposed to a third-party model provider — but no customer contract, data processing agreement or service terms are published to support that assertion. Website text and images are stated to be the property of Odyssey Consultants Ltd.
Reuse rights
For the website, Odyssey states that personal data is used to answer messages, honour contractual obligations, send news and content, and process job applications, while technical visit data serves only to improve the site; cookies are set both by Odyssey and by third parties. Nothing in the published documents grants an end user any right to reuse content without permission: the site's text and images are declared the property of Odyssey Consultants Ltd, personal copies are allowed, and commercial reuse requires written permission. On the product side the vendor says its model learns continuously from the customer's incidents, analyst feedback and threat intelligence, and adapts to their network, while also asserting that no prompt or telemetry reaches an external or public model. Note that the same page places the private language model both on our infrastructure and inside the customer boundary, and that no opt-out from that learning is documented.
Data retention & training
Hosting summary
Two hosting statements appear on the site, and their scopes differ. The privacy notice, which covers website visitors, says data received is stored within the geographical scope of the EU until it is deleted or erasure is requested, and that personal information is not transferred beyond EU borders without consent. Separately, the homepage says the platform offers hosting where the customer requires it, explicitly including a Middle East data-centre option. No hosting country is ever named, and no hosting provider or subprocessor is disclosed. The sovereignty argument is architectural rather than geographic: telemetry is described as collected and protected at the iCollector edge and as never leaving the customer's control, and the iCollector itself can run on-premise, in cloud or in hybrid environments, which puts part of the question back into the customer's hands. The website's public IP resolves to a content-delivery anycast node, which reflects how the marketing site is served and says nothing about where platform data resides.
Things to keep in mind
Risks and trade-offs to weigh before adopting ClearSkies AI SOC Analyst.
- Automation complacency: when an assistant triages the queue and writes the narrative, analysts can drift from reading the evidence to approving conclusions they have not checked
- Skill erosion among junior analysts — the vendor's own pitch is that forty minutes of junior investigation collapses into seconds, and that is precisely the work through which juniors learn the craft
- The autonomy ladder is a real risk surface: at its higher settings the system acts on production, so who is allowed to raise that setting matters more than the technology itself
- A model that learns continuously from your environment with no documented opt-out means you cannot easily revoke what it has already absorbed
- Ownership of telemetry rests on marketing statements rather than any published contract: there is no data processing agreement, no subprocessor list and no service terms
- The frameworks named across the site — GDPR, NIS2, ISO 27001, PCI DSS, HIPAA — describe what the software helps you evidence; they are not credentials of the publisher and should never be read as such
- Customer logos, partner networks and reseller listings say nothing about the publisher's own security posture, and the site's public IP is a content-delivery node that says nothing about where customer data lives
Setup & Integrations
Technical difficulty
Buying is easy; deploying is a project. Lite, Plus and Pro can be purchased online through dedicated pages, but collection requires an iCollector — a physical appliance, a virtual appliance on VMware, Hyper-V, KVM or Proxmox, or a cloud marketplace image — sized from 8 vCPUs, 12 GB of RAM and 300 GB of disk. The vendor publishes a four- to six-week window before operational results, and offers guided onboarding, role-based training and continuous optimisation. The intended audience is security and MSSP teams, so infrastructure skills are assumed.
Deployment
Apps stores
Behind ClearSkies AI SOC Analyst
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What exactly is the ClearSkies AI SOC Analyst?
Which plan do I need in order to get it?
Where does the AI model actually run?
Is my data used to train the model?
Is there an API?
Is there a free plan or a free trial?
Where is my data hosted?
Is a data processing agreement available?
What support is included?
How long does deployment take?
Should you pick ClearSkies AI SOC Analyst?
ClearSkies AI SOC Analyst is a credible, well-documented module rather than a product in its own right. Its differentiator is stated plainly and is genuinely uncommon: an AI that reasons over security telemetry without renting a model from a hyperscaler, with an autonomy level the customer sets and an audit trail leading back to the raw logs. The commercial side is unusually transparent for enterprise cybersecurity — three of the four tiers carry a public price, and every tier publishes its ingestion, retention and user limits.
The weakness is contractual rather than functional. The privacy notice and the terms and conditions cover the website, not the service; there is no published data processing agreement, no subprocessor list, no trust centre and no security.txt, and the privacy notice carries no effective date. For a vendor selling detection and compliance capability into regulated European sectors, that gap is the first thing a buyer should raise.
Two further points deserve care. The site does not agree with itself on billing: the grid and the plan page quote a monthly price, while the pricing FAQ says billing is currently quarterly and mentions an annual subscription cost. And the same product page places the private language model both on the vendor's infrastructure and inside the customer boundary — a distinction that matters enormously to anyone buying for sovereignty reasons.
Finally, read the compliance material for what it is. GDPR, NIS2, ISO 27001, PCI DSS and HIPAA appear across the site as frameworks the platform helps customers evidence; that is the product's purpose, not a list of the publisher's own credentials. The publisher does claim certifications of its own, in a single platform FAQ answer. That claim is the site's own, and worth verifying independently.
- Choosing a selection results in a full page refresh.
- Opens in a new window.