SQUDO AI® Documentation — Deployment & API Reference
Get SQUDO AI® running on your stack in under a day.
Sections: Getting started (Overview, Quickstart, Sovereign tenant setup, Concepts). Deployment (Architecture, Region selection, Identity & SSO, Network requirements). Connectors (SIEM, EDR/XDR, Identity providers, Cloud providers, Email security, OT/ICS). Workflows (Investigation, Containment, Hunt with Sovereign GPT, Reporting). API reference (Authentication, Incidents, Telemetry, Webhooks, Rate limits). Security & compliance (Data residency, Encryption, Audit logs, Sub-processors, Vulnerability disclosure).
Overview: this quickstart walks through provisioning a sovereign tenant, connecting your SIEM and EDR, and triggering the first SQUDO AI® investigation. Estimated time: 30–60 minutes. A SQUDO AI® tenant is provisioned in the region you select. You receive an admin invite, set SSO, and connect your first telemetry source, typically your SIEM. SQUDO immediately starts triaging incoming alerts; you stay in the loop via the console.
Prerequisites: admin access to your SIEM (Splunk, Sentinel, QRadar, Elastic, Google SecOps, etc.) and EDR (CrowdStrike, SentinelOne, Defender). A team identity provider (Okta, Entra ID, Ping). One technical contact for the provisioning call.
1. Request a sovereign tenant — email hello@nexulis.com or use the Get a demo flow. You will be asked for your region (SG, MY, ID, CH), your IdP, and your primary SIEM. A tenant is provisioned within one business day.
2. Connect identity (SSO) via SAML/OIDC.
3. Connect your SIEM via a config-only connector.
4. Trigger the first investigation — from the console, pick any open alert and click Investigate. SQUDO AI® triages the alert end-to-end, cites the MITRE ATT&CK technique, and writes an audit-ready report. Median time: 4–10 minutes per alert.
Get a demo · Visit NEXULIS