Messaging Enablement
Internal · Not for external distribution
v3 and the Foundational Story

What changed, and how we talk about it

TLDR; security operations was never one problem, so we stopped building it as one product. We became the foundation a security team grows on. Investigations are still the front door. Foundational AI Security is the whole building.

START HERE
The short version
Others add an "AI Analyst" on top of your SIEM and tell you to fire your people. 7AI is the foundation that runs investigation, detection, response, and hunting on one engine and your data wherever it lives, with humans on the loop.
GO A LEVEL DEEPER
The shift
Faster investigations is now a commodity. The real value is a system teams keep expanding into, adapted to their environment instead of changing how they work because of a tool they bought.
FULL DETAIL
The architecture
A rebuilt engine, a native data layer, and a build surface. This is the part that earns the word foundational, and the part prospects should feel, not sit through.
The one rule that comes first

"v3" is our word, and it stays our word. It answers Allen's real question, which was never "what is it" so much as "how do we talk about it."

Say this

Externally, always: the 7AI platform, Foundational AI Security, the foundation you grow on.

For the capabilities: Investigation, Detection, Response, Threat Hunting.

"We started with investigations. From there teams grow into detection, response, and hunting on the same foundation."

Never say this externally

Never say "v3" to a prospect, customer, partner, or analyst. It means nothing to them and invites "so what was wrong with v2?"

Keep "Engine V3" / "EV3" for internal and deep technical conversations only.

"v3" is our internal name for the step change. The market only ever hears the foundational story.

01 · The simple version

What is v3?

v3 is two changes that arrived together. Internally we bundle them under one label. Externally we only ever tell the second one.

Change one · backstage

A rebuilt engine

We rebuilt the investigation core from the ground up (internally, Engine V3). It reasons more flexibly, adapts to each environment, and is built to improve as the underlying models improve, without a re-engineering project each time.

Who hears about this: engineers, technical evaluators, and analysts who ask. Nobody else. It is proof the platform is smarter, not a headline.

Change two · the headline

We became a foundation

The platform grew from doing investigations into a foundation a security team keeps building on: investigation first, then detection, response, and threat hunting, on one engine and one connected view of the environment.

Who hears about this: everyone. This is the story. Investigations is where a customer starts. Foundational is what they are actually buying into.

The platform today
PLAID ELITE
Chat Bot
Analyst Console
Mobile App
7AI Dynamic Agent Architecture
Incident Response
Detection Optimization
Threat Hunting
Agent
Wave Planner Think Skill Selection Execute
Knowledge & Memory
Data Model provider Model provider
Strategy Skills
Enterprise Insights
Knowledge Graph
Connector Skills
7AI Agentic SOAR
Case Management
Response Actions
Workflow Engine
Agentic Workflow Editor
7AI Federated SIEM · emerging
Detection Engine
Federated Query
Ingestion
On Prem Connector
Connectors
Data Exploration Agent
Data Presence
On Prem 7AI Data Lake Data Lake SIEM Cloud Identity EDR

Yonatan's marketecture, from the managed tier at the top down through the agent architecture and Agentic SOAR to the Federated SIEM reaching your data wherever it lives. The breadth is the point. This is still being locked, so treat labels as directional.

The trap to avoid

Do not sell v3 as "our engine got smarter." Smarter engines are what every vendor in this category claims this year. If the headline is the engine, we sound like everyone else. The headline is the foundation. The engine is the receipt.

01.5 · Why the shift, in plain terms

Faster is table stakes. Foundational is the position.

Everyone started with investigations, because the math never worked with people alone and AI is obviously faster and more consistent. That is exactly why speed and false-positive reduction are now a commodity. A whole category says the same words we do: no playbooks, go to the data, show your work, multiple agents. Winning on those is winning a race everyone is already running.

Here is what we noticed and they did not build for. Once a team proves AI can reach data where it lives and do the execution work, they immediately want to move in three directions:

But these are not three separate products bolted together. Run on one foundation and one shared data layer, they become a single loop, and each turn of it makes the next one sharper.

Continuous Security

The Agentic Flywheel

Threat intelligence drives hunting. Hunting expands detection. Detection triggers investigation. Investigation informs response. Response feeds optimization. A self-reinforcing loop that gets smarter with every cycle.

Automated Governed Easy
Powered by a shared federated data layer.
7AI Agentic SIEM
Federated Data Layer query · store · correlate Threat Intel Hunt Detect Investigate Respond Optimize
One-size-fits-all is excellent for no one. We have all lived that with the last generation of tooling.

The two enemies we stand against are fragmentation (a SOC stitched from disconnected point tools) and sameness (generic AI that treats every environment identically). Fragmentation is the sharper one, because our architecture genuinely answers it.

Adaptive, not "customizable"

The virtue is not that you can configure us. The last generation made you author and babysit endless playbooks, and everyone remembers. The virtue is that the platform adapts to your environment on its own, and is extensible if you ever want to reach in. Bespoke behavior without the burden. That pairing is the thing our sharpest competitors cannot claim: the pure-automation camp gives you no way to reach in, and the pure-DIY camp makes you do the work to get value at all.

02 · Audiences

What it means for each audience

Same story, different entry point. The rule of thumb: the closer someone is to our current platform, the more you talk about growth and continuity. The further away, the more you talk about approach and outcome, never internal history.

Direct audiences
Customers · they know today's platform

Same platform, now doing more for you

Frame everything as continuous improvement. Never imply what they have today was lacking.

  • The engine got smarter and more adaptive under the hood. Same platform, better results.
  • The directions you asked about (detection, response, hunting) now run on the same foundation you are already connected to.
  • Growing into a new capability is a decision, not a new integration project.
Prospects · never saw the architecture

Sell the approach, not the history

They do not know v1 or v2, so never mention them. Differentiate on approach and outcome.

  • Start with investigations. Prove it on your own environment.
  • When it works, grow into detection, response, and hunting without stacking on another tool for each.
  • A foundation shaped to you, with humans on the loop. Not a black box, and not a headcount-replacement claim.
Partners
Channel

A platform to grow an account on

The foundational story is a channel gift: land on investigations, expand across detection, response, hunting, and the managed tier over time. More surface to sell into one account, less rip-and-replace friction on the way in.

Lead with: expansion motion and attach, not architecture.

Tech alliances

We reach your data, we do not fight it

Because we go to data where it lives and speak the native language of the tools, integrations are a strength, not a threat. Position alliances as the platform reaching into their surface, making both more valuable.

Handle with care: the data-layer story can read as "we replace things." Frame it as reach and consolidation choice, on the customer's timeline.

AWS and others

Built on the platform, scaled with the partner

Keep the AWS narrative on speed and scale: built on AWS, running production at scale, to market through Marketplace and the co-sell motion. AWS is infrastructure and a go-to-market lever, not a place to expose architecture internals.

Lead with: proof of scale and the joint motion.

03 · Two registers

How we talk about what's changing

There are two registers, and most of the field lives in the first one. Value and benefit is the default. Technical and architecture is on request, for the people who can act on it.

Register A · value and benefits (default)

The discipline here is simple: translate every architecture fact into what the customer gets. "We own the data layer" is a fact about us and means nothing to a buyer. Here is the same set of facts, said as benefits.

Architecture fact

We go to data where it lives

What the customer gets

Nothing to centralize, no translation into the language of a SIEM. We speak your tools' native languages, so you keep control of your own data architecture and avoid lock-in.

Architecture fact

One engine and one data layer across the lifecycle

What the customer gets

Detection, investigation, response, and hunting run off one consistent picture of your environment. Context carries end to end instead of dying in the handoff between five disconnected products. Nothing falls between the seams.

Architecture fact

Capabilities built on one foundation

What the customer gets

Growing into detection, response, or hunting does not mean standing up another tool or re-integrating your environment. It runs on the foundation you are already connected to. Add capability, not complexity.

Architecture fact

People on the loop by design

What the customer gets

Accountable humans on the loop, all the way up to a fully managed tier in PLAID ELITE. A force multiplier for your team, not a replacement, and not an unattended black box.

The one line that will get us in trouble

We promise no new plumbing, never no new purchase. Adding a capability means no new integration and no re-architecture. Whether it is an add-on or already inside a package depends entirely on how the customer buys, from investigations as a starting point up through PLAID ELITE. Keep all external language on the technical benefit and stay silent on packaging mechanics. If a prospect pushes on cost, that is a discovery move and a human conversation, not a number on a slide: "That depends on how you use us and which way you buy. The point is the capability is already built to run on what you have connected, so adding it is a decision, not a project."

Register B · technical and architecture (on request)

For engineers, technical evaluators, and analysts. This is where "v3" and "Engine V3" are allowed, and where the data layer detail earns its keep.

03.5 · Say less of this

Claims to retire as headlines

These were real wedges a year ago. The whole category says them now, word for word. Keep them as reasons to believe once someone is interested. Never build the opening on them.

Now table stakes
  • No playbooks to write or maintain
  • Go to the data, no ingestion required
  • Show your work, verify don't trust
  • Multiple agents instead of one
  • Minutes not hours, fewer false positives
Lead with this instead
  • A foundation you grow on, not a tool you bolt on
  • Investigation, then detection, response, hunting, on one engine
  • Adapted to your environment, not configured by you
  • Humans on the loop by design, up to fully managed
  • Consolidate the stack over time instead of adding to it
04 · Black Hat

The story we tell at Black Hat

Booth #1839, Mandalay Bay. One story, told at three depths, so a passer-by, a serious buyer, and an analyst each get the right version without us switching scripts.

The 10-second version

The banner and the walk-up

Foundational AI Security. The foundation a security team grows on, from investigation to detection, response, and hunting. No engine talk, no v3.

The 3-minute version

The demo

Open on a live investigation as the proof, then widen to the loop on one foundation. Show the smarter engine as evidence of quality, on stable, curated paths only.

The deep version

The analyst and engineer chat

Register B. The engine, the data layer, the build surface, the commitments. This is where "v3" and the architecture live, and nowhere else on the floor.

What to stress at the booth
Handle Federated SIEM with care

The Federated SIEM and the data-layer story are the most differentiated thing we have, and also the least mature. Treat them as an emerging capability and a direction, not a shipped, sell-hard product, in any external material and on the floor. Show the reach and the consolidation choice as where the platform is going. Keep unified chat and the mobile app demo-only, as UI and direction with representative data. Confirm the live status of anything data-layer before it goes on a slide.

05 · Cheat sheet

The line for each moment

Prospect cold open

"Others add an 'AI Analyst' on top of your SIEM and tell you to fire your people. 7AI is the foundation that runs investigation, detection, response, and hunting on one engine and your data wherever it lives, with humans on the loop. Start with investigations, then grow into the rest without stacking on another tool."

Customer expansion

"Same platform, now doing more for you. The directions you asked about run on the foundation you are already connected to, so adding one is a decision, not another integration project."

"How is this different from the AI SOC tools?"

"They investigate alerts on top of your stack, and stop there. We are the foundation underneath: one engine across detect, investigate, respond, and hunt, shaped to your environment, with humans on the loop. They add to the pile. We help you collapse it over time."

"Why is the engine better?" (technical)

"It is the most adaptable and extensible engine in the category: bounded specialist skills over a planner, shared memory, and built to take stronger models over time without a rebuild. Approach, not a spec war."