The AI-powered security workspace

The space to shape security

Labs provides the enterprise foundation. You run, customize and build the production-ready security apps your team needs, in natural language.

14-day free trialNo credit cardStart straight away
How Labs works

From prompt to production in four moves

No shelfware, no waiting on the dev team, no security work left to do at the end.

01

Connect your stack

Anything you can reach through an API pulls into one consolidated data layer.

02

Describe the app

Describe what you need in plain language and get a working interface, built on your live data.

03

Ship to production

Auth, audit, and permissions are pre-built. You hit deploy, not a three-month hardening sprint.

04

Automate with approvals

Wire in actions that request sign-off, respect permissions, and write the audit trail for you.

Click on a use case to see the demo
Labs

What would you like to build?

Describe your application and Labs will build it for you.

"Build an incident response dashboard"
"Create a compliance tracking tool"
"Monitor endpoint security status"
"Track user access reviews"
"Analyze security logs and events"
"Manage vulnerability reports"
"Track threat intelligence feeds"

AI Composer

Describe what you need

Start a conversation or click a prompt below
The problems that Labs solves

Every security team needs something no vendor sells

The gap is always in the same place: between the tools you've bought and the way your organization actually works.

You're paying for tools you barely use

Every new challenge brings another product, but not every one becomes part of the day-to-day.

Building it is only the beginning

AI writes a working script in minutes. Permissions, auditability and ownership are where the idea dies.

Innovation doesn't wait for roadmaps

Your team is already writing the workarounds. The question is whether anyone else can see them.

One size rarely fits

Software built for every organization fits none of them, and you're the one expected to adapt.

Visibility without action only gets you so far

Knowing where the problems are is only part of the job. Fixing them means switching tools and running manual processes.

Manual work has a hidden cost

One-off scripts and knowledge held by a handful of people work until they don't.

So until now, the options were another rigid subscription you'll use a fraction of, an unmanaged AI script that stops at security review, or a dashboard that can spot the problem but not fix it. Or nothing, and hope the person holding it together doesn't change role.

The Labs Platform

One workspace. Data, Actions, Studio.

Connect the systems you already run, build on what they tell you, then act, with a human in the loop and a record of everything.

Data

Ground truth for everything you build

Labs connects to the systems your organization already relies on, from cloud platforms and identity providers to security tools and HR systems, through simple API connections. The result is one live, consolidated data layer that every app queries directly. No CSV exports, no stale mirrors.

Data stays read-only, so teams can explore, build and report without touching production.

Data layer — connected sources, matched
  • Entra ID128,410
  • AWS96,882
  • CrowdStrike84,117
  • Intune71,204
  • Workday HR32,193
412,806
records · matched · deduplicated
one live data layer · read-only
Illustrative preview

Actions

Automation with a paper trail

Update a cloud configuration, trigger a device policy, revoke access, raise a ticket. Actions reach across your stack.

Every outbound action requests human approval before it runs. Your existing permissions stay in place, every action lands in the audit log, and you keep complete oversight of every change.

Actions — human approval gate
Queued action

Revoke 3 stale admin entitlements in Entra ID

requested by
coverage-gaps
scope
directory.write
rollback
available
Approval required

This action changes a live system. Your permissions apply; everything is logged.

  • 14:02:11approved — s.patel
  • 14:02:12revoke 3/3 complete
  • 14:02:12written to audit log
Illustrative preview

Studio

Describe the app. Ship it to production.

Studio is a secure, sandboxed workspace where apps take shape in natural language. Describe what you need and AI Composer builds it: data connections, logic and a working interface, on your real data and behind your real authentication and permissions.

No backend infrastructure to manage. No development resource to wait for. Experiment freely, then move to production when you're ready.

Studio — prompt in, working app out
Prompt

Show every endpoint missing EDR, grouped by business unit, with an owner column.

Done — 214 uncovered devices across 6 units. Want a weekly digest?

Add a remediation deadline…
Coverage GapsSandbox
  • Finance61 gaps
  • Retail ops44 gaps
  • Engineering12 gaps
Illustrative preview
Works where you work

Build and ship your apps without leaving Claude Code

Labs ships with a full MCP server, so the whole platform is available from inside Claude Code, or whichever assistant you already work in. Describe an app, refine it, ship it to production and keep editing it later, all without switching to a browser. It's the same Studio underneath: your live data, your permissions, approval gates on every action, everything audited.

claude mcp add labs

Studio connected

build, edit, ship — from your editor

Enterprise foundation

The hard 80% is already built

AI coding tools write the code and leave you to make it safe for production. Labs provides and maintains the production environment, so the parts that take months are done before you type a prompt.

SSO and RBAC

Every app ships behind your identity provider with role-based access, on every plan, never an upsell.

Audit fabric

Every view, change and action lands in an immutable audit log your assessors can query directly.

Data scale

Seven years of platform architecture handling enterprise estates, millions of assets, matched and deduplicated.

Hosting and tenancy

Dedicated tenancy, regional residency and uptime SLAs. Your apps run where compliance says they must.

Safe by design

Live data stays read-only so teams build with zero risk to production, and live systems are only altered with human sign-off.

Action approvals

Automated actions request sign-off, respect permission boundaries, and roll back cleanly when you say so.

We never train models on your data.

App library

No need to start from a blank canvas

Ready-to-run security apps. Some built by us, others published by security teams around the world.

Three ways to use Labs
01Run

Take a ready-made app from the App Library and point it at your data.

02Customize

Take an app that's close and reshape it in natural language until it fits.

03Build

Describe the app that doesn't exist yet and ship it to production.

Inside the App Library

A sample of what's in there. The library keeps growing, with new apps built and shared every day by the Labs community. Anything that isn't there yet, you build in Studio. Open one to see what it does.

A sample of the librarySelect an app to open it

SOC Dashboard

Security Operations

Live incident volume, trends and threat mix on one screen for the whole shift.

Apps /SOC DashboardPreview

Security Operations Dashboard

Updated 2s ago

Open Incidents

51

+12%

Threats Blocked

204

+8%

Resolved

235

+15%

Avg Response

12m

-15%

Incident trends · last 24 hours

Threat Distribution

463
Total

Response Metrics

Avg Response
15%
12m
MTTD
22%
8m
MTTR
8%
44m
System Health
CPU
23%
Memory
45%
Agents
2.4k
Uptime
99.9%

Recent Critical Events

Using AI Composer in Labs let us build and customize security apps on our real data using natural language without any backend infrastructure to manage.
Martyn Styles
CISO, Bird & Bird
Bird & Bird
Pricing

Start small. Scale when it ships.

Build and run your first security app without a sales call, a proof-of-concept budget or a procurement cycle.

Every plan includes your first 10,000 records and SSO.

10,000
10,000 included, then $20 per month per 10,000

Build & ship

Starter

$49/mo

Billed monthly

Users
Unlimited
Data records
10,000 included
AI credits
1,000 /mo
Feeds, actions, apps
10 each
Action invocations
500 /mo
Workspaces
3

Includes

  • SSO
  • Enterprise-grade foundation
  • Isolated tenant infrastructure
Most popular

Collaborate & audit

Team

$189/mo

Billed monthly

Users
Unlimited
Data records
10,000 included
AI credits
10,000 /mo
Feeds, actions, apps
50 each
Action invocations
10,000 /mo
Workspaces
50

Everything in Starter, plus

  • Workspace permissions
  • Auditing
  • Standard SLAs

Control & govern

Business

$1,500/mo

Billed monthly

Users
Unlimited
Data records
10,000 included
AI credits
20,000 /mo
Feeds, actions, apps
200 each
Action invocations
100,000 /mo
Workspaces
100

Everything in Team, plus

  • Priority support
  • SCIM provisioning
  • On-prem connectorSoon
  • Fine-grained RBACSoon
  • Change approvalsSoon
  • Global data layerSoon

Scale & assure

Enterprise

Let's talk

Volume, seats and rates per deal

Users
Unlimited
Data records
10,000 included
AI credits
Negotiated
Feeds, actions, apps
On request
Action invocations
High-volume
Workspaces
Unlimited

Everything in Business, plus

  • Dedicated CSM
  • Forward deployed engineer
  • Priority SLAs
  • Security questionnaire support
Frequently asked questions

The things people ask first

No. Apps are built in natural language, by the people who understand the problem. There's no backend to manage and no code to review before something reaches production.