THIRD-PARTY VALIDATION

Anthropic built CLUE for themselves. We build it for the other 99%.

Their own Detection team cut false positives from 33% to 7% and saved 1,870 hours in a single month with Claude. What their engineers built in-house, we ship as a finished product — EU-hosted, audit-grade, affordable for SMBs.

WHAT THEY PUBLISHED

I can finally build the tools I always wished I had. Our CLUE stack (Claude Looks Up Evidence) reduced the false-positive rate from ~33% to 7%, ran 12,000 automated queries and 27,000 tool calls in 30 days, and saved an estimated 1,870 hours — 234 person-days.

The story is public because Anthropic wants to demonstrate AI-driven SOC works. That's good for us — we deliver exactly the same workflow as a production-ready platform, without you having to build your own Detection Engineering team.

THE NUMBERS FROM THEIR BLOG

What an AI-driven SOC delivers

Numbers from the Anthropic Detection team over 30 days running their CLUE stack. Not a marketing claim from us — a published result from their own team.

33% → 7%
false-positive rate on alert triage
1.870h
manual work saved in 30 days (≈ 234 person-days)
12.000
automated queries · 27,000 tool calls
3-4 min
average investigation time (vs hours manually)
COMPARE

What they built internally vs what we sell

Anthropic has the people to build CLUE in-house. Most Belgian SMBs don't. We have the same workflow, plus what an EU company needs on top.

AxisAnthropic CLUE (internal)monsys.ai (production-ready)
Build effortCustom build on Claude Code + internal logsAgent + hub + dashboard, day-1 deployable
Data residencyUS-hosted Claude APIEU-hosted (GoTrust BV, Belgium)
Team requirementOwn Detection Engineering team5 servers free · €3/agent from #6
Output shapeWorkflow tool for internal analystsWorkflow + auditor evidence pack in one
ComplianceNo GDPR/NIS2/CyFun outputCompliance engine + Ed25519 evidence packs
InstallationSoup-to-nuts engineering projectiwr | iex / curl | bash
WHAT WE ADD

Three things their blueprint doesn't cover

Anthropic's CLUE is internal tooling for one company. We sell to EU SMBs with different obligations.

EU residency by default

Everything runs on EU infrastructure. No Claude API call routing through US jurisdiction. Critical for healthcare, legal, government, or anyone under NIS2.

Audit-grade evidence pack

Per month or per incident, an Ed25519-signed tarball with the full trail. Your auditor verifies offline with our open-source Python script — no account, no network call.

GDPR/NIS2/CyFun native

Our compliance engine automatically maps your infra to ISO27001, NIS2, BE-CyFun and CIS controls. Your auditor gets a complete file, not a dashboard screenshot.

BEING HONEST

What we DON'T claim

Anthropic's numbers (33%→7%, 1,870 hours) are Anthropic's, not ours. They show an AI-driven SOC works — not that every monsys.ai tenant gets the same reduction. Your numbers depend on alert volume, log quality, and configuration.

We also deliberately don't run unbounded LLM autonomy the way they describe. Our AI Explain runs locally on the host (Ollama, opt-in), and our compliance + alert flow is rule-based. AI is a layer on top of our deterministic core, not a replacement. That's a feature, not a limitation — auditors want repeatable rules, not stochastic output.

Ready to start?

5 servers free forever. No credit card. EU-hosted.

Create an account →Read the long-form