Zaun is an AI‑native, decentralized security platform that connects to over 100 identity, cloud, endpoint and SaaS sources via API/OAuth and pulls only the small fraction of telemetry needed for compliance and investigations. It delivers 1,000+ MITRE‑aligned detections and editable plain‑English runbooks, automatically enriches alerts to cut false positives by more than 95% and executes deterministic response actions in under a minute, while keeping data where it resides.
Funding
Funding not disclosed
Founders
Product
Problem
Organizations must collect and analyze security telemetry from dozens of disparate sources, often requiring costly data ingestion pipelines and centralized storage that introduce latency and expense. This fragmentation leads to incomplete visibility, high alert noise, and slow response to emerging threats.
Solution
Zaun provides a decentralized, AI‑native security platform that connects to over 100 identity, cloud, endpoint, and SaaS systems via API or OAuth without installing collectors. The platform pulls only the 1 % of events needed for compliance and investigations, storing them in the Zaun Lake for fast, query‑by‑plain‑English access. Built on MITRE ATT&CK and D3FEND, Zaun delivers more than 1,000 detections and automated runbooks authored in plain English, which can be edited by security teams. When a detection fires, AI enriches the alert, reduces noise by over 95 %, and executes deterministic response actions in under a minute, while keeping human experts in the loop for sensitive decisions. The result is continuous, low‑latency coverage across the entire stack with minimal ingest cost and faster mean‑time‑to‑respond.
Target Audience
Zaun targets security operations centers, SOC analysts, and enterprise security teams that need comprehensive, low‑latency threat detection and response across multi‑cloud and SaaS environments.
Features
- On‑demand API/OAuth integration with 100+ IdP, cloud, EDR, SaaS and custom sources, no log forwarders or collectors required
- Selective data retention (≈1.4 % of logs) in Zaul Lake, enabling sub‑second queries across months of history via plain‑English prompts
- Library of 1,000+ AI‑generated detections and runbooks mapped to MITRE ATT&CK techniques and D3FEND countermeasures, editable in plain English
- Automated SOAR workflow that enriches alerts, correlates evidence, and executes deterministic actions with sub‑1‑minute MTTR while reducing false positives by >95 %
- Transparent, version‑controlled rule and runbook artifacts with audit trails for compliance reporting (NIST, SOC 2, HIPAA, PCI, etc.)
- Real‑time investigation view that aggregates evidence from all connected sources and generates compliance‑ready reports without SQL coding