Hearth by Blumira

    Your whole workspace. One command center.

    Consolidate the solutions you trust without compromise. Forge the tools your team needs, but doesn't have time to build.

    Hearth is an AI security analyst that works across the security tools you already run without locking you into one vendor's ecosystem. Ask it a question in plain language and it investigates your logs, reaches into your connected stack for context, and hands back a finding with the evidence attached and a next step you can act on. It is built for IT teams and MSPs who need analyst-grade answers on limited headcount.

    The same investigations produce your compliance evidence — SOC 2, NIST 800-171, CMMC, HIPAA, PCI DSS, FERPA, GLBA, ISO 27001 and CIS — with the query that produced it attached.

    Blumira is our security operations platform. Hearth is an independent command center that natively integrates with Blumira, but isn't tied to it.

    Works with the stack you already run

    What can Hearth see across my stack?

    Most AI security tools reason over their own vendor's telemetry. They are very good at explaining what happened inside the platform that sold them to you, while often charging a premium for, or limiting functionality with, third-party sources.

    Hearth reasons across three sources at once:

    1Your live stack

    Hearth connects directly to the tools in your environment and reads them live — whoever makes them. Each one connects in minutes, and new integrations land continuously:

    • SIEM: CrowdStrike Falcon, Huntress, Microsoft Sentinel, SentinelOne, Splunk Cloud, Trend Micro Vision One, Wazuh
    • Identity and Access: Duo Security, Google Workspace, JumpCloud, Microsoft 365, Microsoft 365 (OAuth), Okta
    • Endpoint: Bitdefender GravityZone, Blumira Agents, CrowdStrike Falcon, Harmony Endpoint, Huntress, SentinelOne, Trend Micro Vision One, Wazuh
    • Cloud: AWS, Azure, Google Cloud, Cisco Meraki, Oracle Cloud (OCI)
    • Vulnerability Management: Intruder.io, Qualys VMDR, Rapid7 InsightVM, Tenable.io
    • Network: Cloudflare, FortiGate (FortiCloud), Cisco Meraki, Palo Alto Networks (Strata), runZero, SonicWall (NSM), Ubiquiti UniFi, WatchGuard (Firebox)
    • Ticketing: Autotask PSA, ConnectWise PSA, HaloPSA, Syncro
    • Messaging: Harmony Email & Collaboration, Incoming Webhook
    • Code & Source Control: GitHub
    • Password & Secrets: Bitwarden, LastPass, 1Password
    • RMM: NinjaOne, Splashtop
    • Backup & Recovery: Datto BCDR, Veeam (VSPC)
    • Other: Box, Dropbox Business, HubSpot, Salesforce, VirusTotal

    No integration for that one odd tool you still run? Export it and ask anyway! Hearth reads spreadsheets, PDFs and JSON alongside everything else.

    2Your public attack surface

    What an attacker can see from the outside: exposed services, credentials surfaced in breach data, infrastructure you may not know is yours.

    3Your Blumira logs, if you're a Blumira customer

    Blumira platform subscription isn't required to use Hearth, but customers will natively get every log the platform has already parsed and normalized, connected automatically. Hearth also inherits Blumira's own integration coverage, broader still on the log-source side, and its one-year log retention.

    Vendor-agnostic, right down to whether you use Blumira for your own organization or your clients'.

    Managing client environments? Ask one question across every organization you manage, from one place — no switching logins to find out which clients are affected.

    It shows its work — and you can watch it live

    How do you know the answer is right?

    Before Hearth investigates, it tells you what it is about to do.

    Ask it for your top security risks and it lays out the plan first: find the internal hosts nothing is monitoring, trace where your internal systems are talking to on the outside and enrich the top destinations against public exposure data, check authentication patterns for anomalies and brute-force attempts across the last week, then correlate all of it into a ranked register.

    Then it runs that plan, and every finding it returns carries the query that produced it. Hearth never makes black box decisions or requires you to trust a verdict. You are shown the work, and you get to make the call.

    Live product · the plan before the run
    Hearth taking a saved CISO risk-register briefing and stating its numbered investigation plan before executing it

    Hearth states its investigation plan — tools named, sources named — before it executes.

    Hearth stays informed, so you can focus on what matters

    Hearth checks with you before approving actions or automations, but quietly works in the background to score security headlines, tailored to what's relevant to your actual workspace and tells you which affect it.

    Live product · headline scoring
    Hearth scoring cybersecurity headlines against the tenant stack
    Headline scoring, filtered to your workspace.
    Live product · briefings on a schedule
    Hearth briefing library grouped by the person each report is built for

    Zero homework for you, no RSS feeds to set up. Hearth provides a filtered list of what is relevant to the systems you actually run, with a one-click path from "this is in the news" to "here is whether it affects us."

    It runs briefings on a schedule and files them: coverage scorecards, risk registers, cloud exposure reviews, vulnerability posture reviews. They land in a queue and in your inbox, built for the person reading them.

    How teams are using Hearth

    Use Case 1

    Automated compliance evidence collection

    Ask where you're exposed and get an answer built from your own environment, not a checklist. Hearth pulls risk signal from your parsed logs, your live stack and your public attack surface, runs scheduled checks against all three, and returns a ranked register — each item carrying the evidence behind it and a remediation step you can action right away.

    Compliance reporting maps to the control language of SOC 2, NIST 800-171, CMMC, HIPAA, PCI DSS, ISO 27001 and more on the way, with the underlying evidence query attached. "How do you know?" always has an answer — and so does the auditor's follow-up.

    Use Case 2

    Keep everyone informed, not just your analysts

    The person triaging needs the queue. The one reporting upward needs the trend. The one answering the auditor needs the register. Hearth runs the posture review once and builds the report for the person reading it, so nobody hand-builds three versions of the same thing. Coverage scorecards track metrics over time with direction, so "are we getting better?" stops being a matter of opinion. And it keeps leadership informed, translating what's important accessibly even for a board that doesn't speak security.

    Use Case 3

    Full-scope investigation, while you grab a coffee

    No query language, no console-hopping. Describe what looks wrong, and Hearth goes to work — querying logs, pulling enrichment from your connected stack, and coming back with a structured verdict: severity, MITRE ATT&CK mapping, affected entities, the evidence query, and recommended actions.

    Every claim is cited back to the data that produced it, so an analyst can check the answer instead of re-deriving it. Work that took 30 to 60 minutes takes minutes, and you can just ask for what you want to know without complex query language calls or manual report building.

    Live product · the investigation
    Hearth investigation showing severity, MITRE ATT&CK mapping and affected entities
    Live product · the evidence
    Hearth evidence rows cited back to the query that produced them

    Use Case 4

    Detection to granular action, without a separate SOAR

    A risky sign-in fires. The same motion that surfaced it can propose the response: lock the account, revoke the sessions, contain the host... all through the tools you already use.

    Hearth proposes. A person approves. Then it executes, files the receipt, and lets you decide whether you want to automate the response next time.

    Response actions run across your identity provider, endpoint agent, cloud platforms and your collaboration tools today, with more integrations on the way. Every one is admin-gated and auditable.

    Live product · rules and schedules
    Hearth automations list showing every rule and schedule and whether it is on
    Live product · the automation builder
    Hearth automation builder listing the response actions it can propose, each labelled with its risk level and the platform it runs on
    Live product · the action plan
    Hearth action plan for a tenant-wide OAuth consent finding, with its steps pending and a run-for-me control on each

    Use Case 5

    Tabletop exercises built from your environment

    Skip generic templates. Hearth builds your tabletop exercise from your integrations, your entities, your risk profile. It produces the whole thing: roles, injects with facilitator notes, comms templates, success criteria, and an after-action template for the debrief. Run it once before an audit, or make it a standing readiness check.

    Live product · the scenario
    Hearth tabletop scenario built from the connected environment, with the facilitator's guide, ground rules and logistics
    Live product · roles at the table
    Hearth tabletop roles at the table, each with its responsibilities and a pre-read brief, under the scenario background and learning objectives
    Live product · the injects
    Hearth tabletop inject timeline with facilitator notes, discussion questions, expected actions and success criteria
    Live product · comms templates
    Hearth tabletop communication templates, drafted for staff notice and for an executive and board briefing

    The answer outlives the incident

    What do you keep when the incident is over?

    An incident closes, and the answer that resolved it usually gets logged or reported and closes with it. But why should the next responder have to start over from scratch?

    Hearth's output forges durable tools that your team can use long after the incident where they were created. The investigation you ran becomes a saved artifact you can re-run, schedule, hand to someone else, or promote into a standing check. The hunt that found a new threat becomes a detection. The risk register becomes the starting point for the investigation it triggered.

    Your team ends up with tooling built from your own environment, for your own environment... and it's yours to keep, not an outcome rented from someone else's SOC.

    Live product · register to investigation
    A saved Hearth risk register with an entity menu open, offering to seed a 24-hour investigation from a finding

    A risk register hands off directly into the investigation it triggered.

    Where Hearth fits

    How is this different from what we already have?

    What it doesWhat you're left with
    Managed detection serviceSomeone else's analysts work your alerts and send you the outcomeThe outcome. The expertise stays with the vendor.
    AI layer on one vendor's platformReasons expertly over that vendor's own telemetryGreat answers about one part of your workspace. Consolidate onto them to get more.
    AI overlay on your SIEMReads what your SIEM already surfacedFaster triage of the signal you already had. No new sources.
    SOAR platformExecutes playbooks you author and maintainAutomation, and a playbook-authoring job nobody has time for.
    HearthReasons across your live stack, your public attack surface, and your logs, with or without BlumiraAnswers, plus durable tooling built from your environment that your team keeps.

    Approval and AI governance

    Can it act on its own?

    No. Every response action is admin-gated: Hearth surfaces the specific action, with the risk it carries spelled out, and a person decides.

    Hearth drafts. Deterministic checks validate the draft against the evidence, because an investigation can't name an entity it can't cite. Then the decision is yours, and it can carry forward: once an admin has ruled on how a particular action should be handled, Hearth gives you the option to apply that same decision to matching cases.

    This graduated approach is by design, to guarantee that convenience isn't gained at the cost of security. Hearth is engineered to follow AI governance frameworks and best practices, including OWASP LLM09 and the Least-Agency principle.

    Hearth proposes. A person approves.

    FAQ

    Do I need Blumira to use Hearth?

    No. Hearth works directly with your stack, whether or not Blumira is your SIEM. If you are a Blumira customer, it also reads everything the platform has already parsed, with no extra setup, and you get Blumira's integration coverage on top of Hearth's own.

    What can't it do yet?

    Used entirely on its own, without Blumira, Hearth investigates and reports, but it doesn't run live detection rulesets. Continuous detection and automated response run on the Blumira platform. But the use cases shared here are just the jumping off point, as Hearth helps you craft new tools for the use cases you need as you work.

    Is this a chatbot?

    Our conversational interface is the easiest way to work with Hearth, but the real work happens outside the chat window. Hearth runs scheduled briefings, files artifacts you can re-run, maintains a work queue, scores security news against your workspace, and proposes response actions. Most of what it does happens without anyone typing a question.

    How do I know it isn't making things up?

    Every finding carries the logic behind what it identified. Investigations are validated against the evidence before they're returned, and when Hearth has to sample or truncate data to stay inside its limits, it says so rather than presenting a partial answer as a complete one.

    Who is it for?

    IT teams, MSPs, security teams without dedicated DFIR members, CISOs and GRC professionals looking for an easier way to cover compliance and security with limited security staff resources.

    How fast can I get it running?

    Minutes per integration. If you're already a Blumira customer, your logs are connected automatically and there's nothing to set up at all.

    How long is my data kept?

    One year of log retention, the same as the Blumira platform.

    What does it cost?

    You won't be billed per gigabyte ingested or per log source connected. Usage is metered by what Hearth does: the investigations and actions you run, and when creating an automation your credits are not used until that automation runs. Blumira customers get an included allowance rather than paying for everything as they go.

    Join the pilot

    Hearth is in public pilot now. Reach out to our team, tell us about your workspace, and we'll get you on the list.

    Loading the form...