For regulated entities
The agentic SOC your regulator can read.
Morpheus is the agentic SOC platform built for EU-regulated entities. It investigates every alert to L2 depth, grades every verdict by its evidence, keeps a human in oversight of every AI decision as EU AI Act Article 14 expects, and produces one regulator-readable record per incident that serves the NIS2, DORA and KRITIS reporting clocks. Deployed in EU regions or on your premises. Built by a Canadian company.
Trusted by regulated financial institutions, operators of essential services and their MSSPs across Europe.


Your organisation answers to a regulator.
NIS2 wants an early warning inside 24 hours. DORA wants a major-incident notification inside four. The BSI wants to hear from KRITIS operators in 24. And since August 2026 the EU AI Act asks a new question of anyone who lets software make security decisions: who was overseeing it, and can you show me?
Most SOCs can’t answer the last one, and increasingly can’t meet the first three, because the clock starts at detection and the investigation that decides whether an incident is reportable takes longer than the window. Morpheus is built so the investigation is done, graded and on the record before anyone has to draft a notification.
Is autonomous AI in the SOC a compliance risk or a compliance control?
A control, if three things are true: every verdict shows its evidence, every AI action runs inside oversight a human set, and every incident leaves one record an examiner can read end to end. Morpheus is built on those three.
Every verdict graded by its evidence
Confirmed, with the source telemetry attached. Inferred, with the reasoning shown and the evidence circumstantial. Gap, where Morpheus looked, found nothing and says so. The examiner’s question “on what basis was this closed?” has an answer on every alert.
Oversight you configure, not a checkbox
Four autonomy modes, set per case type or per tenant. Deterministic invokes no AI at all. Autonomous runs inside approval gates set at design time. Every mode change, override and pause is logged with the analyst’s identity. That is Article 14 human oversight as a control, not a policy.
One record per incident
Detection, investigation, evidence, findings, actions, approvals and autonomy mode on one continuous, signed, exportable trail, in the same format whether a playbook or the AI acted. The artifact your SOC, your risk officer and your counsel draft the notification from.
A human-only SOC cannot show an examiner what it didn’t investigate. An accountable agentic SOC can show what it investigated, how it graded it, and who was watching. That is a stronger position, not a weaker one.
Which regulation, which clock?
The same three mechanisms serve all four regimes. What differs is the article and the deadline. Each card links to the detailed page.
NIS2
Articles 21 and 23 · 24 hours, 72 hours, one month
Risk-management measures for essential and important entities, and a three-stage clock for significant incidents. Morpheus produces the investigated, graded record the 24-hour early warning is drafted from.
DORA
Articles 5, 6, 19 and 28 · 4 hours, 72 hours, one month
ICT risk governance for financial entities and a four-hour initial notification once an incident is classified as major. Article 28 pulls your ICT providers, including your MSSP, into scope.
KRITIS-Dachgesetz and BSIG
Ten sectors · 24-hour BSI notification
Germany’s critical-infrastructure regime, with the BSI’s 24-hour window and two reporting paths. Morpheus delivers L2 investigation on every alert inside the window and one trail mapped to both obligations.
EU AI Act
Articles 9, 12, 14 and 26 · high-risk obligations from 2 August 2026
Bounded reasoning, automatic logging and human oversight for high-risk AI, and a provider-deployer split that puts obligations on your organisation as the deployer. Morpheus is built to the high-risk standard regardless of classification.
What does the examiner actually see?
One record. Not a SIEM export, a SOAR log, a case ticket and a folder of screenshots stitched together by an engineer three weeks later.
A DORA major incident, from detection to notification
At 03:10 a payments platform’s EDR flags credential use from an unexpected host. Morpheus correlates the endpoint, identity and transaction telemetry, traces the path to two further hosts, grades the lateral movement Confirmed with the session logs attached, and pages the on-call lead with containment drafted. The lead approves isolation of the three hosts inside the gate set at onboarding. By 04:00 the ICT risk officer has the record open: what fired, what was investigated, what was found and at what grade, what was done, who approved it, and that the case ran in AI-Led mode. The four-hour notification is drafted from that record, not reconstructed from it.

Record signed · exportable · readable by non-engineers
Does the AI decide, or do we?
You do, at the level you choose, per case type. Morpheus investigates and drafts; response runs on deterministic playbooks with hard guardrails; the autonomy mode decides how much of that happens before a human signs.
Deterministic
Rule-based playbooks run end to end. No AI in the chain, no inference invoked.
AI-Assisted
Morpheus investigates and recommends. Your analyst approves every step.
AI-Led
Morpheus investigates and drafts the response. You sign off; response runs.
Autonomous
Investigation and response at AI speed. Gates set at design time. Roll back any action.
A regulated payments workflow can stay Deterministic indefinitely while commodity phishing runs Autonomous, on the same platform with the same trail. Adaptive Tasking pulls any case back to a lower mode mid-investigation. When Morpheus cannot confirm a finding, it grades it Gap and defers to a human. It never guesses and it never bluffs. For the compliance officer, this is the oversight dial Article 14 describes, and the log of who turned it.
Where does the data live, and who is the vendor?
In the EU if you need it to. Morpheus deploys on Azure regions including Ireland for EU residency, on your premises, or fully air-gapped. D3 Security is a 100% Canadian company with Canadian hosting, not a US hyperscaler’s security division.
Customer telemetry, investigation artifacts and audit trails stay in the jurisdiction you choose. The deployment model and controller arrangement support GDPR-grade DPA terms. For air-gapped deployments, everything including AI inference stays inside your own infrastructure. Autonomy settings and the record format are identical across every deployment model, so the examiner sees the same artifact whether you run in Dublin or in your own data centre in Frankfurt.
For MSSPs serving regulated clients
Under DORA Article 28 and NIS2’s supply-chain provisions you inherit your clients’ obligations. Morpheus sets autonomy and residency per tenant and produces the same record per client incident, so the evidence your client’s examiner asks for is the record you already hold. Morpheus for security service providers
Outside the EU
The same record serves Canadian federal requirements (ITSG-33 and designated-operator obligations under federal critical-cyber-systems legislation), UK FCA and PRA operational resilience, Swiss FINMA, and US frameworks including SEC Form 8-K Item 1.05, NYDFS Part 500, HIPAA and NERC CIP. Morpheus for the Canadian public sector
The document to forward.
Most Heads of Security won’t buy an agentic SOC alone. They’ll bring the SOC manager, the risk officer and the MSSP. This is the paper written for that meeting: what an examiner will ask about AI in the SOC, and how an accountable agentic SOC answers each question.

Whitepaper
Who Watches the AI? Governance for the Autonomous SOC Human oversight, evidence grading and the one-record standard, mapped to NIS2, DORA, KRITIS and the EU AI Act. Read the whitepaper
faqs
Questions regulated SOC teams and their risk officers ask us
Is an agentic SOC platform a high-risk AI system under the EU AI Act?
It depends on deployment. Morpheus can be high-risk when deployed by critical-infrastructure operators (Annex III §2); typical enterprise SOC triage often falls under the Article 6(3) carve-out for preparatory tasks that feed a human decision. D3 builds Morpheus to the high-risk standard regardless: bounded reasoning (Article 9), automatic logging (Article 12) and configurable human oversight (Article 14). D3 is the provider under Article 16; your organisation is the deployer under Article 26.
How does Morpheus help meet the NIS2 24-hour and DORA 4-hour clocks?
By finishing the investigation before the clock matters. Every alert is investigated to L2 depth and graded, up to 95% in under two minutes per customer-reported production data, July 2026, so when a finding indicates a significant or major incident the evidence, classification basis and actions are already on one record. The notification is drafted from that record rather than reconstructed under deadline.
Can we run some workflows with no AI at all?
Yes. Deterministic mode runs rule-based playbooks end to end with no AI in the chain and no inference invoked. It is set per case type or per tenant, so a regulated payments workflow can stay Deterministic indefinitely while other alert types run at higher autonomy on the same platform, with the same record format.
What exactly is in the audit record?
Detection, every investigation step and its evidence, each finding with its grade (Confirmed, Inferred or Gap), the drafted and executed response, every approval with the analyst’s identity, and the autonomy mode the case ran in, including any mid-case change. One continuous, signed, exportable trail per incident in the same format across all four modes, readable by a non-engineer.
Where is our data processed and stored?
Morpheus deploys on Azure regions including Ireland for EU data residency, with US, Canada and Japan regions also available, on-premises, hybrid, or fully air-gapped. Telemetry, investigation artifacts and audit trails remain in the jurisdiction you choose. D3 Security is a 100% Canadian company with Canadian hosting.
Our MSSP runs our SOC. Does this still apply to us?
Yes. Under DORA Article 28 and NIS2 supply-chain provisions your provider inherits your obligations. If your MSSP runs Morpheus, autonomy and residency are set for your tenant specifically and every incident on your tenant produces the same record, which your MSSP can hand to you and you can hand to your examiner.
How is human oversight evidenced, not just claimed?
The autonomy mode is a logged setting. Every override, dismissal, pause and approval carries the analyst’s identity and timestamp on the incident record. Adaptive Tasking, which pulls a case back to a lower mode mid-investigation, is logged the same way. An examiner can see not only that oversight existed but who exercised it and when.
How is Morpheus priced?
Annual subscription, sized by your alert volume envelope. The AI is included: no token costs, no usage meter. Above the envelope, additional alerts are priced per alert, published in advance. Deployment model does not change which capabilities you have.
D3 Security builds Morpheus, the agentic SOC platform. Vancouver, Canada. 100% Canadian company and hosting. Regulatory references are provided for information and do not constitute legal advice.