How it works

A day in the loop for an enrolled endpoint — and what the audit trail proves.

A long-form look at how the AI-native MDR model runs in practice, written for a buyer who's never heard of Curtainwall and wants to read the mechanism before booking a discovery call. Every claim below is consistent with /faq and /pricing — no numbers invented here, no new tiers.

The loop

Four stations, run in sequence, every minute of every day.

The agent never closes the loop alone. Every action — patch, quarantine, token revocation — produces a row in the audit log before it produces a notification, and a reversal is its own row.

  1. Station 01
    Watch
    EDR, identity, and SaaS signal stream into a triage agent that ranks, correlates, and either acts below threshold or files in seconds. The L1 queue never pages your team.
  2. Station 02
    Patch
    Routine OS and third-party patches apply autonomously, on the cadence you configured at enrollment. Out-of-window changes are held, summarised, and applied only after explicit sign-off.
  3. Station 03
    Contain
    Suspicious processes are quarantined, identity tokens revoked, and network egress restricted the moment confidence drops below threshold. Every action produces an audit row first.
  4. Station 04
    Escalate
    A named technician is paged only when an incident crosses the agent confidence threshold, a governance review demands sign-off, or an insurance notification trigger fires — never on noise.

The agent never closes the loop alone.

Every action — patch, quarantine, token revocation — produces a row in the audit log before it produces a notification. If the action is reversed, the reversal is also a row. The customer reads the same log the auditor does.

The split

When a named human actually steps in.

The rule is narrow. A real person is paged only when (a) an incident crosses the confidence threshold, (b) a governance review demands sign-off, or (c) a cyber-insurance notification trigger fires. Routine triage, correlation, and patching never page an analyst. The shape of the human handoff is calibrated by tier — the rule is the same.

Tier
Starter
A named operator is paged above the confidence threshold. No published acknowledgment SLA.
Tier
Standard
A named operator is paged above the confidence threshold, with a 15-minute SLA to acknowledge the handoff.
Tier
Complete
A named technician is on call during the maintenance windows you declare at enrollment.
The audit trail

What the auditor actually reads.

Each action produces a row in the audit log BEFORE it produces a notification. Row contents are fixed: agent ID, evidence, and outcome. The log is Merkle-anchored, append-only, and readable by both the customer and the auditor from the same source of truth. The Merkle head is anchored off-platform so it cannot be quietly rewritten — a reversal is a new row, never an edit.

Merkle-anchored
Append-only
Customer-read
Auditor-read
Audit trail
live · last 5
  • 14:02:11Ztriageprocess quarantined · wininit.exe clone · mb=57%agent/sigma-3 · 0x9c4a…b217
  • 13:58:47Zpatchapplied · CVE-2026-3191 · 412 endpointsagent/rho-12 · 0x9c4a…b204
  • 13:55:02Zidentitytoken revoked · session 9b31…a204agent/theta-7 · 0x9c4a…b1f1
  • 13:50:36Ztriageclosed · lowercase-noise · false-positiveagent/iota-1 · 0x9c4a…b1d8
  • 13:42:19Zescalatehandoff · analyst: l.chen · ct-confidence 0.94agent/lambda-4 · 0x9c4a…b1c2
Cadence

The maintenance window, untangled.

Patching is not "as fast as possible." It runs on the cadence you defined at enrollment, inside the windows you configured. The plan-adjust / no-adjust split is deliberate: most patches need no decision, a few do, and the agent knows which is which.

Inside the window · apply
Routine OS and third-party patches apply autonomously during your declared window. Each one lands with an agent ID and a single row confirming the version delta.
Outside the window · hold
Out-of-window changes are held and summarised. On Standard and Complete they can be staged for human sign-off; on Starter they apply at the start of the next window.
Trust

Why trust a vendor you just heard of.

Five transparency pillars — the things a vendor either does or does not do when nobody is watching. None of these are marketing slides; they are commitments that show up in the log, the contract, and the contact surface.

  • One log, two readers

    The auditor reads the same log the customer reads. There is no separate "vendor view" — what your underwriter sees is what your CISO sees, with the same row IDs and the same Merkle head.

  • A named human per handoff

    Every agent→human escalation names the technician on the receiving end. No anonymous ticketing, no rotating queues — a human is on the hook per handoff, by name, in the row.

  • Narrow escalation gates

    Escalations fire on three triggers, nothing else. The rule is published in /faq in plain English, so a stranger can audit the threshold without signing a contract first.

  • Flat subscription cannot grow

    Pricing is a flat monthly subscription per endpoint, inside the established $10–$25 band (see /pricing). An incident does not change your invoice — by design — so there is no penalty for declaring one.

  • A real address, not a chat widget

    No chat widget, no captcha farm, no third-party marketing tracker. The contact surface is one address: a real person reads what lands there.

Cross-references: /faq — the objection ledger. /pricing — the flat-subscription detail. The home page — the short version of the same loops above.

Follow-ups

The four follow-ups we hear most.

Short questions, short answers — written for a stranger who has read this far and wants the last few details before they book the call.

curtainwall@curtainwallsecurity.com

Ready when you are

Read the loop, then enroll the fleet. We’ll confirm scope on the discovery call.

curtainwall@curtainwallsecurity.com