FAQ

The five objections we hear before the discovery call — answered plainly.

Autonomy and guardrails. The audit log. The named-human handoff. Insurance notification triggers. The flat subscription. Each answer below is consistent with the same claims across the home page and /pricing— no new numbers, no new promises.

Objection 01

Autonomy without losing the loop.

What stops an autonomous agent from going further than you wanted?

Every enrolled endpoint runs four stations — Watch, Patch, Contain, Escalate — in sequence, with explicit guardrails between them. Suspicious processes are quarantined, identity tokens revoked, and network egress restricted the moment confidence drops below threshold. The agent never closes the loop alone: every action — patch, quarantine, token revocation — produces a row in the audit log before it produces a notification, and a reversal is its own row.

Out-of-window changes are held, summarised, and only applied after explicit sign-off. Patches only apply inside the maintenance windows you configure at enrolment — one window on Starter, two on Standard, three on Complete.

  • Watch

    EDR, identity, and SaaS signal stream into a triage agent that ranks and correlates in seconds.

  • Patch

    Routine OS and third-party patches apply inside the maintenance window you configured.

  • Contain

    Crossing the confidence threshold triggers quarantine, with a full actions trail attached.

  • Escalate

    A named technician is paged only for incidents that exceed agent confidence — never for noise.

Objection 02

An audit log a regulator will accept.

How do you prove what the agent actually did, after the fact?

Each action produces a row in the audit log BEFORE it produces a notification. Row contents are fixed: agent ID, evidence, and outcome. The log is Merkle-anchored, append-only, and readable by both the customer and the auditor from the same source of truth. The Merkle head is anchored off-platform so it cannot be quietly rewritten.

The export shape depends on your tier — same log, different reader. Starter exports CSV on demand, Standard groups rows by containment lineage and ships with a 15-minute acknowledgment SLA, Complete adds a weekly attestation pack for the underwriter.

  • Merkle-anchored

    Each row is hashed into the chain; the head is anchored off-platform.

  • Append-only

    A reversal is a new row, never an edit — the timeline stays provable.

  • Customer-read & auditor-read

    Same source of truth; the underwriter reads what your CISO reads.

Objection 03

A named human, only when it counts.

When does a real person actually get paged?

Escalations are reserved for incidents that exceed the agent confidence threshold. The rule is narrow: a human is paged only when (a) an incident crosses the confidence threshold, (b) a governance review requires sign-off, or (c) a cyber-insurance notification trigger fires. Routine triage, correlation, and patching never page an analyst.

The shape of the human handoff depends on the tier — the rule is the same, the depth is calibrated.

  • Starter

    A named operator above the confidence threshold. No published acknowledgment SLA.

  • Standard

    A named operator with a 15-minute SLA to acknowledge the handoff.

  • Complete

    A named technician on call during the maintenance windows you declare.

Objection 04

Cyber-insurance notification triggers.

Which events page the customer AND their underwriter?

A notification to the customer and their underwriter fires when the audit log records one of the trigger events below. The goal is a paper trail that matches the policy language — no surprise phone calls, no missing rows.

  • Confirmed containment lineage change

    When an alert crosses the confidence threshold and shifts into the containment lineage, the row fires the trigger.

  • Complete tier escalation

    A named-technician handoff on the Complete tier — the customer and underwriter both see it.

  • Audit anchor divergence

    If the anchored Merkle head fails to reconcile at the next anchor cycle, the divergence itself is a row and a trigger.

  • Identity-graph / token-graph mutation

    A revoke or rotate on the identity graph (Okta / Entra ID) writes a row that underwriters expect to see.

Objection 05

Flat subscription, not hourly surge.

Why per endpoint, and why no surge pricing when an incident lands?

Pricing is $10–$25 per endpoint per month across three tiers (Starter, Standard, Complete) — a flat subscription, not a meter you only notice after it ticks over.

The rationale is the same as the audit log itself: fees don't grow because an attacker probed harder. The flat model removes the perverse incentive against declaring an incident and aligns with the predictability a mid-market security budget needs to plan around. Onboarding the wider org does not re-license (no per-user fees). An incident does not change your invoice — that is by design.

Still curious

The smaller questions, in the same register.

Scope, onboarding, billing windows, export shapes — the follow-up details behind the five answers above. If yours isn’t on the list, write to us — a real person reads it.

curtainwall@polsia.app

Ready when you are

Answers covered, fleet next. Enrol one tier, watch the audit log fill in.

curtainwall@polsia.app