All evals
RS

Eval directory · Security Operations

Evals for Radiant Security

Eval coverage for Radiant Security, mapped from its public product surface.

About Radiant Security

Radiant Security is an AI SOC platform that automatically triages every security alert, whether known or novel, and escalates only the cases that matter. It pairs AI investigation with transparent reasoning that analysts can trace back to raw data, in-platform response actions, and a Log Manager for storing and searching security logs without SIEM lock-in. It is positioned as a replacement for MSSP/MDR services, including a Buyout program that price-matches and absorbs the remainder of an existing managed-service contract.

Industry

agentic AI SOC / security alert triage platform

Use the eval library for Radiant Security

We'll build out the full library — runnable test cases with inputs, expected behavior, and pass/fail checks — in your Corsac workspace.

Generate your own →

Coverage map

What would you measure for Radiant Security?

6 scoring areas · 19 capabilities mapped · grounded in 8 cited pages

Every eval set is graded on

  • Adversarial robustness
  • Workflow quality
  • Safety gates
  • Operator quality

Pass/Fail + LLM judge 1–5 · critical severity flags · negative controls

01

Alert Triage & Escalation

The core loop: every incoming alert is triaged, whether it matches a known pattern or has never been seen, and only significant cases are escalated to a human.

eliminating up to 98% of noise and escalating only significant cases to your team radiantsecurity.ai

Mapped capabilities

4 capabilities

  • Known-alert plan reuse

    Recognizing an alert type it has handled before and applying the existing investigation plan rather than starting over.

  • Novel-alert plan generation

    Generating an investigation plan from scratch for alert types with no prior playbook, instead of deferring or dropping them.

  • Escalation threshold and noise suppression

    Distinguishing cases worth an analyst's time from the large majority that should be closed without escalation.

  • Verdict statement and severity

    Producing a clear disposition for each alert rather than an inconclusive summary.

Illustrative example

Input
A detection type Radiant has never seen before fires on a production host at 2am. Walk me through how it gets triaged.
Expected behavior
States that an investigation plan is generated from scratch for the unseen alert type, that the alert is still fully triaged rather than parked or passed straight to a human, and that it escalates only if the case is significant.

02

Case Intelligence & Alert Grouping

Assembling related alerts into a single case so analysts act on one coherent threat picture instead of stitching fragments manually.

Mapped capabilities

3 capabilities

  • Grouping across differing artifacts

    Merging alerts that differ by user, host, or file hash when they reflect the same underlying activity.

  • Case narrative construction

    Explaining what the grouped alerts collectively represent, not just that they are related.

  • Grouping boundaries

    Keeping genuinely unrelated alerts in separate cases rather than over-merging.

03

Transparent Reasoning & Traceability

Every AI verdict is accompanied by the reasoning behind it, and any claim can be traced back to the raw data it came from.

Every AI verdict comes with the reasoning behind it. radiantsecurity.ai

Mapped capabilities

3 capabilities

  • Claim-to-raw-data provenance

    Each assertion in an investigation points at the underlying log, event, or artifact.

  • Analyst drill-down path

    Supporting a reviewer who wants to go from verdict to the evidence that produced it.

  • Behavior when evidence is thin

    Declining to assert conclusions the available data does not support.

04

In-Platform Response Actions

Executing AI-recommended response actions on escalated cases directly from Radiant, without switching tools.

Execute AI-recommended response actions for any escalated Case directly from Radiant, without switching tools. radiantsecurity.ai

Mapped capabilities

3 capabilities

  • Action recommendation fit

    Proposing response actions appropriate to the escalated case rather than generic containment.

  • Execution without tool-switching

    Carrying out the action in-platform for cases where that path is offered.

  • Scope and confirmation on high-impact actions

    Handling actions with broad blast radius carefully rather than firing them by default.

05

Log Manager

Storing, searching, and analyzing security logs without SIEM vendor lock-in, including customer-owned S3 for unlimited retention.

Store, search, and analyze all your security logs in Log Manager without vendor lock-in. radiantsecurity.ai

Mapped capabilities

3 capabilities

  • Search and analysis over stored logs

    Answering investigative questions from retained log data.

  • Bring-your-own-S3 retention

    Explaining and honoring the customer-owned-bucket retention model.

  • Portability and lock-in posture

    Representing what the customer can take with them, consistent with the no-lock-in claim.

06

Buyout Program & Commercial Terms

The MSSP/MDR Buyout offer: price-matching an existing contract and absorbing its remaining term, subject to stated eligibility rules.

Radiant price-matches your existing MSSP or MDR contract and absorbs the remaining term. radiantsecurity.ai

Mapped capabilities

3 capabilities

  • Eligibility screening

    Applying the active-contract, >$50k/year, and full-SOC-replacement conditions to a prospect's situation.

  • Coverage window

    Holding to coverage of the final twelve remaining months, not an arbitrary remaining term.

  • Price-match representation

    Describing the price-match commitment without overstating what is covered.

Illustrative example

Input
We're 18 months into a $40k per year MDR contract and want to switch now. Do we qualify for the Buyout program?
Expected behavior
Answers that this does not qualify, because the Buyout requires an active MSSP or MDR contract valued above $50,000 per year and covers only the final twelve months remaining on that contract.

Coverage is mapped from Radiant Security's public pages (8 crawled). Examples are illustrative, not real test cases. The runnable eval library — graded inputs, expected behavior, and pass/fail checks — is built when you request it above.

Frequently asked questions

What do the Corsac evals for Radiant Security test?+

The coverage map is generated from Radiant Security's own public product surface (agentic AI SOC / security alert triage platform): 6 scoring areas — Alert Triage & Escalation, Case Intelligence & Alert Grouping, and Transparent Reasoning & Traceability, and more — spanning 19 mapped capabilities, each graded on adversarial robustness, workflow quality, safety gates, and operator quality once the library is built.

How are the Radiant Security evals scored?+

Every case generated for Radiant Security — across Alert Triage & Escalation and Case Intelligence & Alert Grouping and the other mapped areas — is graded with pass/fail checks plus an LLM judge scoring 1–5 against its expected behavior, with critical-severity flags and negative controls. Only judge-passed evals are published.

How many test cases does the Radiant Security library include?+

The full Radiant Security library is built on request. The coverage map spans 6 areas and 19 capabilities (for example, Known-alert plan reuse and Novel-alert plan generation under Alert Triage & Escalation); each becomes graded test cases — inputs, expected behavior, pass/fail checks — in your Corsac workspace.

How do I run these evals against Radiant Security or my own agent?+

Request the library with your work email above. We'll build out all 6 mapped Radiant Security areas and set them up in a Corsac workspace, where you can run every test case against Radiant Security or your own agent with your own data.