WITHSTAND
Thesis

The critical layer was never going to the cloud.

For over a decade the security industry assumed its future was in the cloud. In 2026 that assumption reversed. Capital is now being raised at scale to build on-premises security platforms for sovereign and air-gapped environments, before a product has shipped. The category being funded is the one the most sensitive networks never left.

1. Security infrastructure comes home

Security markets move in roughly ten-year shifts: mobile, SaaS, cloud, now AI. Each one re-draws where budgets are captured. Unlike the previous three, the AI shift is pulling critical security infrastructure back on-premises.

Three forces drive this. Cloud economics: platforms built on hyperscale storage inherit usage-based pricing, and when costs rise, vendors quietly reduce retention and functionality. Exposure: running the system that watches everything on infrastructure the customer neither owns nor controls widens the attack surface of the one system that must not be compromised. Data gravity: effective machine learning over security telemetry needs all of the raw data, in one place, close to the compute that reasons over it. The cloud makes that expensive; sovereignty makes it impossible.

2. The data puddle problem

Traditional security platforms operate on fragmented stores. Endpoint data lives in one product, network telemetry in another, identity events in a third, and the SIEM receives a filtered, normalised summary of each. Every store is a puddle; none is a lake. Analysis across puddles is slow and lossy, and machine learning trained on any one of them inherits its blind spots.

The sharper critique is aimed at legacy SIEM: it ingests only post-processed data. Parsers decide at collection time what is kept, and what they discard is gone. Any AI layered on top is reasoning about the parser's opinion of events, not the events. That critique is correct, and it sets the first requirement of any modern platform: keep every event raw, discard nothing at collection, and hold the whole environment in one record.

3. What sovereignty actually requires

'Sovereign' has become the most abused word in security. Every vendor now claims it. For the buyers who need it, it is a threshold with four tests: operational, jurisdictional, supply chain and AI data governance. Most offerings clear the first. Almost none clear all four.

A foreign-domiciled vendor with foreign capital can deliver operational sovereignty, because you run the software, but cannot deliver jurisdictional sovereignty, and its assurances on AI data governance rest on trust rather than law. Withstand is independently owned, carries no intelligence-community capital, is delivered and hardened in your jurisdiction, and runs inference inside your accreditation boundary. Clearing all four tests is the basis on which it competes.

4. Machine learning detects, generative AI investigates and explains

Generative models are the wrong tool for real-time detection. Token cost and context limits mean a language model can reason over tens of thousands of events; enterprise environments generate millions per second. Behavioural detection at that scale is the domain of classical machine learning running against complete raw data.

Generative AI earns its place in four constrained roles: taking every alert to a verdict with its reasoning recorded, natural-language interaction with the platform, translating incident timelines into narrative for executives and boards, and drafting response workflows that run automatically where policy allows and wait for a human where it does not. Withstand will never lead with an 'AI-powered detection' claim. Its detection credibility comes from proven content, with classical machine learning on top.

5. Trusted to act

Detection is the easier half. Every alert is taken to a verdict with its reasoning recorded, and the first two tiers of the SOC run without a human queue. The reason point tools were never trusted to act is that nobody could say in advance which actions were safe. Withstand decides that in the core. Every proposed action is evaluated against the environment profile, the action class and the verdict's confidence, and the outcome is automatic execution, human approval, or prohibited. Operational-technology and classified profiles default to human approval, and an action on a control network is never automated, whichever engine proposed it.

Every action is recorded against the evidence that justified it, in a tier an intruder cannot rewrite. The same telemetry measures whether each control fired, continuously, mapped to the obligations that named executives are accountable for. GRC platforms document that controls exist. Withstand measures whether they work.

6. Coexist, do not replace

Withstand is for networks that cannot leave: classified and protected government estates, OT and industrial networks, and the crown-jewel enclaves inside regulated firms. It is not a replacement for the cloud security platform that runs the rest of a large enterprise.

On that estate Withstand consumes the cloud platforms' telemetry as sources and correlates it with what only Withstand can see. Specialist OT monitoring tools feed it their asset inventories and alerts. A buyer who reads Withstand as a rip-and-replace will not buy it; a buyer who reads it as the sovereign layer beside what they already run will.

7. Built to withstand

The name is a design claim. A security platform that cannot withstand attack is a liability: an attacker who reaches the monitoring layer can blind the organisation, alter evidence and hide. Withstand assumes it is a target. The operating system is a signed image with measured boot; evidence is written to immutable storage with cryptographic chaining; the platform monitors itself; recovery to a known-good state needs no external service.

That posture is delivered as software on hardware you control, in your jurisdiction, with an accredited foundation already in production. The next generation is being built with design partners whose constraints are the specification. If you cannot send a single byte to a vendor, you are who this is for.

If this reads like your constraints, talk to us.

The next-generation Withstand platform is being built with design partners whose constraints are the specification. If your networks cannot leave, you are who this is for.

Become a design partner