Overview
Arcanna-AI - Trustworthy AI for Modern SOC
Discover how Arcanna.ai is transforming mission critical operations with Decision Intelligence, an AI-powered approach that enhances human decision-making in mission critical operations.
Arcanna.ai is a decision-intelligence platform built for security operations teams and MSSPs that need to scale alert triage without sacrificing control or trust.
Arcanna applies analyst-trained decision models to incoming SIEM and SOAR alerts, reproducing each team's historical decision patterns at machine speed. This enables SOCs to safely auto-close 80-95% of false-positive alerts while preserving evidence, consistency, and accountability.
The platform includes policy-gated automation, explainable outcomes, and continuous feedback loops that detect drift and pause autonomy when risk increases. Every automated action is fully traceable and audit-ready, supporting compliance, investigations, and analyst review.
Deployed via BYOL in the customer's AWS environment, Arcanna integrates with existing security stacks to reduce alert backlog, improve MTTR and SLA performance, and increase analyst capacity without adding headcount.
Highlights
- Automated alert triage at scale: Arcanna safely auto-closes 80-95% of false-positive alerts in seconds by applying analyst-trained decision models to every SIEM and SOAR alert.
- Trustworthy automation by design: Policy-gated autonomy, explainable decisions, rollback controls, and full evidence trails ensure every automated action is transparent, reviewable, and audit-ready.
- Built for enterprise environments: Deploy via BYOL in your AWS account and integrate with existing SIEM, SOAR, and security workflows to scale analyst capacity without changing tools or processes.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
No refund
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
v1.86
v1.86.1
July 20, 2026
Features & improvements
- Improvement: "AI Assistant" now supports HITL tools (Human-in-the-Loop).
Bug fixes
- Fixed some UI issues regarding "Agentic Workflows" diagrams tab.
v1.86.0
July 16, 2026
Features & improvements
- New: Arcanna now provides Code block templates.
- New: "Agentic Workflows" now have a history for all changes made to the agentic workflow to which users can revert or go to.
- New: REST API support for Google ADK evaluations of agentic workflows.
- Improvement: "MCP Tools" now also display parameters information along side their descriptions.
- Improvement: "Arcanna Roles" can now be managed from the "Exposer Management API".
Bug fixes
- Fixed an issue where "Buckets Updater" component was using more RAM than it should have.
- Fixed an edge case where reprocessing a document would overwrite the "original_index" field from said document.
- Fixed an issue where the pipelines Overview metrics were incorrectly calculated.
- Fixed an edge case where users were able to create two "Agentic Workflows" with the same name.
Additional details
Usage instructions
After deploying the AMI, you can login to the web interface by using "admin" as the username, and your <instance-ID> as the password. The web interface is available on the IP address of your instance, on the default port (tcp/443) or (tcp/80). To access it, point your browser to http://ip.add.re.ss (where ip.add.re.ss is the IP address of your instance). Please make sure to configure your security groups so that they only allowed traffic from the desired IP addresses (the default security groups will allow from anywhere).
This Arcanna instance includes a basic license that supports up to two use cases, allowing you to explore its features. To upgrade to a full license, please contact our sales team at https://www.arcanna.ai/contact .
If you want to connect by SSH, you can use the key pair selected when the instance is created. The ssh default username is "ubuntu".
Resources
Vendor resources
Support
Vendor support
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.