During a cyber incident, you'll have questions.
The answers are already
in your own systems.
CICADA IR helps you find them. It connects to the security tools you already have — on your network and in your cloud — works out what the attacker is doing or has done, and produces the report your board, your insurer and the regulator will want. The investigating happens on a single machine you run yourself. Nothing is sent to us. It all stays under your control.
One machine · OVA · QCOW2 · VHDX · running in 30 minutes · nothing to install on staff computers

Most organisations can't say how bad it is for weeks.
The evidence exists. It's spread across the security tools you already pay for, and getting a clear account out of them means someone with the right skills opening five consoles, copying details between them and rebuilding a timeline by hand. That's why the honest answer to the first question a board asks is usually that the investigation is ongoing.
- ×Five consoles open. Five sets of credentials. Five filters.
- ×Copying suspicious files and addresses between vendors by hand to check them.
- ×Reconstructing the timeline in a spreadsheet.
- ×AI tools that send your evidence to someone else's cloud.
- ✓One machine. One screen. One timeline.
- ✓Suspicious files, addresses and domains checked automatically against six threat databases.
- ✓Related events grouped into one account of what the attacker did, step by step.
- ✓The AI runs on your machine. Evidence stays under your control.
It doesn't wait for someone to notice.
CICADA is connected to your security tools, so it's already reading what they see. When something looks wrong it works out what should happen next and puts it in front of your team with the evidence attached.
Gathering more evidence it does on its own — searching for a file across your machines, pulling logs off a server, listing what's sitting on a file share. None of that changes anything, and waiting on it only costs you time.
Anything that would disrupt someone's work waits for a person. Disabling an account, cutting a machine off the network, blocking an address, forcing a password reset — each one goes to a named approver and is recorded against them. An action CICADA doesn't recognise is treated as needing approval too. That list is enforced by the software, not decided by the AI.
Built to run on a machine you own.
We're a new vendor. We don't expect blind trust. We earn it the same way good IR works: by being explicit about every artefact we publish.
Nothing leaves your control
One machine you run yourself. There is no service to sign up to, and it works even on a network with no internet connection.
It only reads
CICADA cannot change or delete anything in your systems. Anything that would disrupt someone's work goes to a named approver first.
Everything is accounted for
Every piece of evidence is tracked and signed, so it holds up later. Every release publishes a full list of the software inside it.
Four things it does.
Every screenshot below is the actual product — no mockups.

The AI runs on your machine, not someone else's.
Ollama, LM Studio, llama.cpp or any OpenAI-compatible local model runs end to end on the same machine as everything else, so your evidence is never sent to a model provider. Cloud models are available if you want them — switched on one provider at a time, with personal data and credentials blocked, and an audited setting you have to turn on deliberately.
Local LLM setup guide
It notices what a person reading logs would walk past.
Known-bad patterns are caught outright. Beyond that, CICADA looks for sequences of events that only mean something together, learns what normal looks like for each account and flags what isn't, and takes your analysts' own judgement into account. Related events are grouped into one account of what the attacker did, even when several accounts or machines are involved.

From the first sign of trouble to a finished report, in one place.
CICADA collects the evidence, analyses it, connects related events and brings them together for your team to review — each step following on from the last, over whatever time period you choose. Connecting it to Entra ID, Defender, Active Directory, CrowdStrike and Microsoft 365 is done through a setup wizard, and every connection is read-only.

The report your board asks for, written from your own evidence.
Fifteen report types covering the investigation itself, your legal and compliance obligations, and the summary your executives and insurer will want. Available as PDF, Word, HTML, JSON or Markdown. Includes notifiable data breach assessment, legal hold, how far the attacker actually got, and how their steps map to the industry-standard MITRE ATT&CK framework.
Connects to what you already have.
On your network and in your cloud. Every connection is read-only, and there is nothing to install on your staff's computers.
Frequently asked questions
Where does my investigation data go?
How is CICADA IR priced?
How long does deployment take?
What support do you offer?
Can I upgrade from Community to Professional later?
Deploy in under 30 minutes.
One machine, three formats (OVA · QCOW2 · VHDX), and nothing to install on your staff's computers. Free Community Edition — full step-by-step in the Getting Started guide.