Welcome, Christian
Choose a console.
Each console is an isolated Meridian workspace bound to one detection source. The demo console below runs against a live pipeline — no mock data.
7,810 artifacts·3 investigations·7,336 writes / 24h
03Architecture
Five layers — integration, protocol, persistence, compute, surface — each decoupled from the others.
Read more →
04ContextSync Protocol
Versioned, content-addressed artifacts with default-deny ACLs and immutable provenance.
Read more →
05USC
Seven-field spatiotemporal coordinate. Cross-tier match formula links events across noisy sources.
Read more →
06Agent loop
Seven-step investigate() procedure plus agentic-loop meta-tools for free-form questions.
Read more →
Add a console
Roadmap — additional detection sources Meridian will support in production.SplunkComing soon
Connect Splunk Cloud
Stream detections and saved searches from your tenant. Inherits ContextSync versioning automatically.
SentinelComing soon
Connect Microsoft Sentinel
Ingest analytic rule fires, incident records, and entity behavior from a Log Analytics workspace.
Org-wideComing soon
Production console
Promote the agent against your live SOC. RBAC, audit export, and SOC2-grade retention.