EDG3 by SIEMonster

The Security Lakehouse, with AI built in.

EDG3 is SIEMonster's edge-resident Security Lakehouse. A deterministic agent detects and isolates ransomware at the endpoint, a columnar Parquet lakehouse in your own cloud tenant holds every event for years, and an AI analyst triages what matters with cited evidence. Detection, reasoning and response that continue when the cloud link drops.

0
Per-GB ingestion fees
7+ yrs
Retention on Enterprise Plus
3
Agent platforms: Linux, Windows, macOS
100%
Of your data in your own tenant
Why a lakehouse

Cloud-only SIEM is breaking. Severing the telemetry link is an attacker's first move.

If every detection depends on a round trip to someone else's cloud, cutting that link blinds you at the worst possible moment. EDG3 moves detection to where the data is created and keeps the full history in open Parquet you own.

Edge: deterministic detection

The agent runs Detection-as-Code rules locally, forkable, diffable and auditable in git, with MITRE ATT&CK context where mapped. It keeps detecting with no cloud round-trip and no lag.

Edge: autonomous ransomware isolation

Ransomware behaviour triggers local network isolation immediately. A safety deadman restores connectivity if the control channel stays unavailable, and every other response action is approval-gated.

Cloud: the columnar lakehouse

Events land in a per-tenant Parquet lakehouse with an NVMe hot tier and object-storage sync. Per-tenant storage and keys, regional deployment choices, and retention measured in years, not days.

AI that shows its work

Security-focused reasoning produces verdicts, techniques, evidence chains and confidence scores. An append-only investigation history records the evidence and every analyst decision.

Cross-source correlation

Logs, endpoint, network and cloud telemetry correlated together: AWS CloudTrail, Microsoft 365, Entra, Okta, GitHub, Slack, 1Password, Active Directory and OCSF-normalised inputs.

Compliance mapped

Controls mapped to CIS Benchmarks, NIST 800-53, SOC 2 TSC, HIPAA 164.312 and PCI DSS, with cloud security posture, enterprise SSO and RBAC built in.

Capabilities

Ten capabilities, one lakehouse.

SIEM and log management. Detection-as-Code. Agentic triage. Autonomous response. Forensics and evidence. Threat intelligence. Segmented estates. Cloud security posture. Enterprise SSO and RBAC. Cloud integrations. All of it running on the same open Parquet data, so there is no second copy to pay for and no vendor format to escape later.

EDG3 is built on the SIEMonster V5 engine and a decade of Red Team expertise. Enterprises that need a cloud SIEM at scale run SIEMonster V5; teams that need detection and containment to survive a cut link, with data that never leaves their estate, run EDG3. MSSPs get a multi-tenant control plane with isolated customer data paths, available by invitation through the SIEMonster partnership program.

Pricing

Priced by endpoint tier, not by the gigabyte.

Ingestion-based SIEM pricing punishes you for collecting the data you need. EDG3 charges by endpoint tier so you can keep everything.

EditionEndpointsRetentionEffective monthly (annual)
StarterUp to 1506 monthsUS$479
ProfessionalUp to 5001 yearUS$949
EnterpriseUp to 1,5003 yearsUS$1,899
Enterprise PlusUnlimited7+ yearsCustom

Month-to-month rates and current pricing are published on edg3.io.

FAQs

EDG3, answered.

A security lakehouse stores security telemetry in open columnar formats (Parquet) on cheap object storage, with a hot tier for fast queries, and runs detection, search and AI analysis directly on top of it. You get data-lake economics and retention with the query speed and alerting of a SIEM, and your data stays in your own tenant in a format any tool can read.
A cloud SIEM needs the link to the cloud to detect anything. EDG3 runs deterministic detection and autonomous ransomware isolation inside the endpoint agent, so detection and containment continue when the cloud path is cut. The cloud side adds contextual investigation, cross-source correlation and long-term retention on the lakehouse.
No. EDG3 is a Security Lakehouse with AI built in. The AI analyst triages alerts with cited evidence, ATT&CK context and a confidence score, and records an append-only investigation history, but every response action other than ransomware containment is approval-gated. Your team stays in control.
By endpoint tier, not by gigabytes ingested. Starter covers up to 150 endpoints with 6 months retention, Professional up to 500 endpoints with 1 year, Enterprise up to 1,500 endpoints with 3 years, and Enterprise Plus is custom with 7+ years retention. Current pricing is on edg3.io.
Linux x64, Windows x64 and macOS arm64, with native Windows event collection, Linux eBPF process telemetry and macOS endpoint telemetry.
A fully self-hosted, air-gapped platform is on the roadmap for Q4 2026. Today EDG3 runs as an edge agent backed by an isolated cloud tenant with per-tenant storage and keys.

See the Security Lakehouse in action.

Start on edg3.io, or talk to the SIEMonster team about EDG3 for your estate or your MSSP.