The Security Lakehouse, with AI built in.
EDG3 is SIEMonster's edge-resident Security Lakehouse. A deterministic agent detects and isolates ransomware at the endpoint, a columnar Parquet lakehouse in your own cloud tenant holds every event for years, and an AI analyst triages what matters with cited evidence. Detection, reasoning and response that continue when the cloud link drops.
Cloud-only SIEM is breaking. Severing the telemetry link is an attacker's first move.
If every detection depends on a round trip to someone else's cloud, cutting that link blinds you at the worst possible moment. EDG3 moves detection to where the data is created and keeps the full history in open Parquet you own.
Edge: deterministic detection
The agent runs Detection-as-Code rules locally, forkable, diffable and auditable in git, with MITRE ATT&CK context where mapped. It keeps detecting with no cloud round-trip and no lag.
Edge: autonomous ransomware isolation
Ransomware behaviour triggers local network isolation immediately. A safety deadman restores connectivity if the control channel stays unavailable, and every other response action is approval-gated.
Cloud: the columnar lakehouse
Events land in a per-tenant Parquet lakehouse with an NVMe hot tier and object-storage sync. Per-tenant storage and keys, regional deployment choices, and retention measured in years, not days.
AI that shows its work
Security-focused reasoning produces verdicts, techniques, evidence chains and confidence scores. An append-only investigation history records the evidence and every analyst decision.
Cross-source correlation
Logs, endpoint, network and cloud telemetry correlated together: AWS CloudTrail, Microsoft 365, Entra, Okta, GitHub, Slack, 1Password, Active Directory and OCSF-normalised inputs.
Compliance mapped
Controls mapped to CIS Benchmarks, NIST 800-53, SOC 2 TSC, HIPAA 164.312 and PCI DSS, with cloud security posture, enterprise SSO and RBAC built in.
Ten capabilities, one lakehouse.
SIEM and log management. Detection-as-Code. Agentic triage. Autonomous response. Forensics and evidence. Threat intelligence. Segmented estates. Cloud security posture. Enterprise SSO and RBAC. Cloud integrations. All of it running on the same open Parquet data, so there is no second copy to pay for and no vendor format to escape later.
EDG3 is built on the SIEMonster V5 engine and a decade of Red Team expertise. Enterprises that need a cloud SIEM at scale run SIEMonster V5; teams that need detection and containment to survive a cut link, with data that never leaves their estate, run EDG3. MSSPs get a multi-tenant control plane with isolated customer data paths, available by invitation through the SIEMonster partnership program.
Priced by endpoint tier, not by the gigabyte.
Ingestion-based SIEM pricing punishes you for collecting the data you need. EDG3 charges by endpoint tier so you can keep everything.
| Edition | Endpoints | Retention | Effective monthly (annual) |
|---|---|---|---|
| Starter | Up to 150 | 6 months | US$479 |
| Professional | Up to 500 | 1 year | US$949 |
| Enterprise | Up to 1,500 | 3 years | US$1,899 |
| Enterprise Plus | Unlimited | 7+ years | Custom |
Month-to-month rates and current pricing are published on edg3.io.
EDG3, answered.
See the Security Lakehouse in action.
Start on edg3.io, or talk to the SIEMonster team about EDG3 for your estate or your MSSP.