Start with where a startup is exposed
A startup's risk sits in a handful of systems: the cloud account that runs the product, the identity provider everyone signs in with, the code host, and the machines people work on. A leaked credential, a risky permission change, a secret pushed to a repository, or a compromised laptop each shows up in one of them.
The practical starting point is visibility. Collect the security events those systems already produce, have something watching them at all hours, and decide who approves a response.
- Cloud: who changed IAM, which APIs were called, and what happened to resources.
- Identity: who signed in, and what administrators changed.
- Code: leaked secrets, vulnerable dependencies, and changes to branch protection or membership.
- Endpoints: security and system events from the machines your team uses.
What you can connect today
Jutsu monitors the sources you connect, and nothing else. Each connection in the table below has a step-by-step setup guide in the docs.
Alerts from Wazuh and syslog can also be sent in, and custom events can be posted to the Ingest API. Connectors for Splunk, Microsoft Sentinel, CrowdStrike, and Elastic are on the roadmap, not available today.
What happens to an alert
Every event that enters Jutsu passes through the same pipeline, run by AI agents.
- Triage: each alert gets a category, severity, risk score, and verdict.
- Enrich: indicators are checked against threat intelligence such as VirusTotal, AbuseIPDB, AlienVault OTX, GreyNoise, MalwareBazaar, Kaspersky OpenTIP, MISP, CISA KEV, and IP-API geolocation.
- Correlate: related alerts become incidents, including multi-hop attack chains such as lateral movement.
- Respond: AgentSOAR runs response actions against connected cloud, email, and identity providers.
- Report: incident reports and SOC activity reports are written for you.
No security team needed to start, and you stay in charge
No dedicated SOC team is required. The agents take the repetitive work: normalizing, enriching, triaging, and correlating alerts. Decisions that need judgment stay with your team. On a small team, the person approving a response can be the CTO or the engineer on call.
- Escalation: alerts the agents can't resolve with confidence go to a person.
- Approval-based response: from the Startup plan, a person approves an action before it runs.
- Policy-guided automation: from the Growth plan, actions your policies allow can run on their own.
- Audit and revert: every AgentSOAR execution is recorded with its status, and actions such as blocking an IP, isolating a host, or disabling a user can be reverted.
Security work that doubles as SOC 2 evidence
Larger customers ask startups how they monitor and respond to security events, and a SOC 2 audit asks for proof. Jutsu keeps an audit trail of alerts, investigations, and response actions, writes incident and SOC activity reports, and provides SOC 2 evidence exports from the Startup plan.
Where Jutsu fits, and where it doesn't
Jutsu fits a startup that runs on the systems above and wants monitoring, investigation, and response in one place, with pricing it can read before a sales call.
It does not replace the basics every team still has to do: turning on multi-factor authentication, limiting admin access, patching, and keeping backups. It also sees only what you connect to it.
