The AI-powered security workspace
Labs provides the enterprise foundation. You run, customize and build the production-ready security apps your team needs, in natural language.
No shelfware, no waiting on the dev team, no security work left to do at the end.
Anything you can reach through an API pulls into one consolidated data layer.
Describe what you need in plain language and get a working interface, built on your live data.
Auth, audit, and permissions are pre-built. You hit deploy, not a three-month hardening sprint.
Wire in actions that request sign-off, respect permissions, and write the audit trail for you.
The gap is always in the same place: between the tools you've bought and the way your organization actually works.
Every new challenge brings another product, but not every one becomes part of the day-to-day.
AI writes a working script in minutes. Permissions, auditability and ownership are where the idea dies.
Your team is already writing the workarounds. The question is whether anyone else can see them.
Software built for every organization fits none of them, and you're the one expected to adapt.
Knowing where the problems are is only part of the job. Fixing them means switching tools and running manual processes.
One-off scripts and knowledge held by a handful of people work until they don't.
So until now, the options were another rigid subscription you'll use a fraction of, an unmanaged AI script that stops at security review, or a dashboard that can spot the problem but not fix it. Or nothing, and hope the person holding it together doesn't change role.
Connect the systems you already run, build on what they tell you, then act, with a human in the loop and a record of everything.
Ground truth for everything you build
Labs connects to the systems your organization already relies on, from cloud platforms and identity providers to security tools and HR systems, through simple API connections. The result is one live, consolidated data layer that every app queries directly. No CSV exports, no stale mirrors.
Data stays read-only, so teams can explore, build and report without touching production.
Automation with a paper trail
Update a cloud configuration, trigger a device policy, revoke access, raise a ticket. Actions reach across your stack.
Every outbound action requests human approval before it runs. Your existing permissions stay in place, every action lands in the audit log, and you keep complete oversight of every change.
Revoke 3 stale admin entitlements in Entra ID
This action changes a live system. Your permissions apply; everything is logged.
Describe the app. Ship it to production.
Studio is a secure, sandboxed workspace where apps take shape in natural language. Describe what you need and AI Composer builds it: data connections, logic and a working interface, on your real data and behind your real authentication and permissions.
No backend infrastructure to manage. No development resource to wait for. Experiment freely, then move to production when you're ready.
Show every endpoint missing EDR, grouped by business unit, with an owner column.
Done — 214 uncovered devices across 6 units. Want a weekly digest?
Labs ships with a full MCP server, so the whole platform is available from inside Claude Code, or whichever assistant you already work in. Describe an app, refine it, ship it to production and keep editing it later, all without switching to a browser. It's the same Studio underneath: your live data, your permissions, approval gates on every action, everything audited.
claude mcp add labs
Studio connected
build, edit, ship — from your editor
AI coding tools write the code and leave you to make it safe for production. Labs provides and maintains the production environment, so the parts that take months are done before you type a prompt.
Every app ships behind your identity provider with role-based access, on every plan, never an upsell.
Every view, change and action lands in an immutable audit log your assessors can query directly.
Seven years of platform architecture handling enterprise estates, millions of assets, matched and deduplicated.
Dedicated tenancy, regional residency and uptime SLAs. Your apps run where compliance says they must.
Live data stays read-only so teams build with zero risk to production, and live systems are only altered with human sign-off.
Automated actions request sign-off, respect permission boundaries, and roll back cleanly when you say so.
We never train models on your data.
Ready-to-run security apps. Some built by us, others published by security teams around the world.
Take a ready-made app from the App Library and point it at your data.
Take an app that's close and reshape it in natural language until it fits.
Describe the app that doesn't exist yet and ship it to production.
A sample of what's in there. The library keeps growing, with new apps built and shared every day by the Labs community. Anything that isn't there yet, you build in Studio. Open one to see what it does.
Live incident volume, trends and threat mix on one screen for the whole shift.
Open Incidents
Threats Blocked
Resolved
Avg Response
Using AI Composer in Labs let us build and customize security apps on our real data using natural language without any backend infrastructure to manage.

Build and run your first security app without a sales call, a proof-of-concept budget or a procurement cycle.
Every plan includes your first 10,000 records and SSO.
Build & ship
Billed monthly
Includes
Collaborate & audit
Billed monthly
Everything in Starter, plus
Control & govern
Billed monthly
Everything in Team, plus
Scale & assure
Volume, seats and rates per deal
Everything in Business, plus