01
Investigate in context
Bring endpoint, cloud, identity, AI, email, and exposure signals into workflows where analysts can see what happened and what matters next.
CulperIQ security operations suite
Turn security signals into owned work.
Meridian connects detection, exposure, investigation, assessment, and remediation across the environment so operational context stays intact from first signal to final resolution.

Suite architecture
01Security monitoring
02Exposure management
03Assessment operations
Operational security, connected
Security programs rarely need another isolated stream of findings. Meridian connects what teams observe with the investigation, ownership, and remediation needed to change the environment.
01
Bring endpoint, cloud, identity, AI, email, and exposure signals into workflows where analysts can see what happened and what matters next.
02
Connect technical findings to affected systems, users, evidence, and ownership so teams can distinguish urgent risk from background volume.
03
Move from detection to accountable action without losing the investigation record, current status, or the decisions that shaped the response.
Meridian modules
Each module handles a focused area of security operations while sharing the CulperIQ platform context, permissions, and workflow that keep the broader program connected.
01 / SIEM and event investigation
Detect and respond to security incidents from Aegis endpoints, Microsoft 365, Azure, Google Cloud, AWS, and other external sources and integrations.
Explore Security Operations
02 / AI security and observability
Monitor organizational AI harness usage for sensitive prompt data, unsafe skills and MCP servers, usage, cost, and personal account activity.
Explore AI Atlas
03 / Continuous exposure management
Use Aegis-powered endpoint visibility, prioritization, and fleet-wide threat hunting to move vulnerability data into accountable work.
Explore Vulnerability Management
04 / Cloud security posture management
Benchmark AWS, Azure, Microsoft 365, and Google Cloud, score cloud security posture, and give teams actionable remediation for identified gaps.
Explore Kestrel Cloud Security
05 / Breach and dark web exposure
Continuously monitor organizational users and domains across breach data and dark web sources, then connect exposed accounts to response.
Explore Signals Intelligence
06 / Email infrastructure assurance
Validate SPF, DMARC, DKIM alignment, DNSSEC, transport security, and more than 100 blacklist sources while tracking meaningful configuration drift.
Explore MXSignet
07 / Assessment and remediation management
Replace static penetration test reports and remediation spreadsheets with a live record of assessment scope, findings, evidence, ownership, and progress.
Explore Assessments
The Meridian operating loop
Meridian is structured around the actual motion of security work. The record becomes richer as activity moves through the team instead of being rebuilt in every tool.
01
Continuously collect the activity, posture, and exposure data that defines the operating environment.
02
Correlate signals with endpoint, identity, cloud, and organizational context to understand impact.
03
Prioritize the response, document the reasoning, and assign clear ownership for the next action.
04
Track the work through resolution while preserving findings, evidence, and response history.
Built for active defense
Use one operating record across exposure, investigation, assessments, and remediation
Deploy the Aegis agent across Windows, macOS, and Linux endpoints
Add modules as the security program expands without rebuilding context
Bring secure, task-aware Cody assistance into active security workflows
Also in CulperIQ
Governance, risk, and compliance suite
Connect Meridian security operations to frameworks, controls, risks, technical evidence, vendors, and policy management across the CulperIQ platform.
Explore SafeguardSee Meridian in your environment
Show us where signals, investigations, and remediation separate today. We will map the Meridian modules to the operating outcomes your team needs.