Skip to main content
These are the questions users ask most often about how I work, what I can do, and how to get the most out of working together.

Getting started

I’m your AI security teammate. I’m built to act like a real member of your security team. I can chat with people, reply to emails, raise PRs, file tickets, answer questions, and follow through on issues until they’re fully resolved.The more I’m treated like a teammate, the more useful I become. My job is to make security clear, focused, and genuinely helpful - not just another source of alerts and dashboards.
I can help with everything from quick security questions to complex investigations:
  • Answer security questions instantly in Slack, email, Chrome, or Firefox
  • Run assessments and deep investigations on demand
  • Fix vulnerabilities and misconfigurations by raising PRs and tickets
  • Monitor compliance and close gaps before they become problems
  • Automate repetitive security tasks
  • Investigate incidents and provide detailed analysis
  • Create documentation, reports, and presentations
  • Collaborate with teammates to get security issues resolved
In short, I can produce nearly anything a human security professional can - from code and charts to documents and reports.
Not at all. I’m built to work with teams of all experience levels. Whether someone is a seasoned security engineer or just starting to learn about compliance, I’ll adapt to their level.I break down complex topics in plain language, explain why they matter, and give clear, actionable steps. Think of me as that teammate who always explains things without judgment.
Getting started is easy. Just follow these steps:
  1. Connect me to Slack so I can join conversations where the work happens.
  2. Install the Chrome or Firefox extension so I can help directly in tools like AWS, GitHub, and Jira.
  3. Give me something to do - ask a question, run an assessment, or forward me an email.
That’s it! Once connected, I can be treated like a team member. The more tools I have access to, the more I can help across the entire security workflow.
I work with the tools teams already use every day:Cloud: Plerion, AWS, Azure, GCP
Code: GitHub, GitLab, Bitbucket
Compliance: Vanta, Drata
Communication: Slack, Microsoft Teams, Email
Ticketing: Jira
Browser: Chrome, Firefox
And much more: See all tools

Working together effectively

Here are a few examples of how to communicate with me:
  • Share the goal, not just a command (“Help me understand why this control failed” works better than “Check Vanta”)
  • Give me context about what’s being worked on
  • Ask follow-ups if something’s unclear
  • Reach me wherever you work - Slack, email, Chrome, Firefox
  • Start small and expand as we work together
Don’t stress about perfect wording - I’ll ask questions if I need more detail.
I can work in different ways depending on what’s needed:Don’t limit me to just answering questions, I can actually do the work.
I don’t flood teams with alerts. Instead, I focus on what truly matters. Using the Plerion platform’s deep visibility, I:
  • Assess actual impact in the specific environment
  • Connect issues across cloud and code to find root causes
  • Weigh business context to determine real priorities
  • Surface only actionable items, not theoretical risks
When I flag something, it’s because it genuinely needs attention.
If something doesn’t work or I can’t help directly:
  1. Rephrase the request with a bit more context
  2. Ask me to investigate the specific issue
  3. Share feedback on what could be done better
Feedback helps me continuously improve and become more useful to the team.

Security and compliance capabilities

Using the Plerion platform, I give teams deep visibility into cloud environments and help with:
  • Risk prioritization - focus on the issues that matter
  • Clear explanations - plain-language breakdowns of complex risks
  • Root cause analysis - link cloud issues back to code changes
  • Automated remediation - fix misconfigurations and raise PRs automatically
  • Follow-through - track issues until they’re fully resolved
I don’t just flag problems, I help teams understand and fix them.
Definitely. I scan repositories for IaC issues, secrets, and vulnerabilities, and then take action:
  • Prioritize issues by risk
  • Raise PRs with recommended fixes
  • Handle Dependabot alerts intelligently
  • Connect code to cloud when a risky commit creates exposure
  • Follow up with reviewers to keep things moving
I see beyond the code itself, connecting changes in code to their impact in the cloud.
I integrate with platforms like Vanta and Drata to:
  • Explain failed controls clearly, with context and next steps
  • Answer compliance questions about frameworks and evidence
  • Trace root causes in cloud or code configurations
  • Automate evidence collection and documentation
  • Track remediation until everything passes
I help teams stay ahead of compliance work instead of rushing before audits.
Yes, I can help investigate and respond to security incidents:
  • Analyze suspicious activities
  • Correlate events from multiple tools
  • Provide recommendations for containment and remediation
  • Document findings and coordinate responses
  • Follow up to ensure issues are closed
I complement existing incident response processes, adding analysis and coordination.
I support major frameworks including:
  • SOC 2 (Type I & II)
  • ISO 27001
  • PCI DSS
  • HIPAA
  • GDPR
  • FedRAMP
  • And many others
I can help teams understand requirements, collect evidence, fix failing controls, and maintain continuous compliance.

Technical details and integrations

I connect securely through API integrations and browser extensions:I only access what’s explicitly allowed, following the principle of least privilege.
Setup is quick:
  • Slack integration: ~2-3 minutes
  • Browser extensions (Chrome, Firefox): ~30 seconds
  • Tool integrations: ~2-5 minutes each
  • First task: Ready to use immediately
Teams can start with just Slack or a browser extension and expand from there.
Absolutely. Teams can:
  • Set up recurring tasks with specific schedules
  • Customize notifications for alerts and updates
  • Adjust integrations to fit the workflow
  • Share feedback to shape future improvements
I’m designed to adapt to each team’s unique needs.
Teams stay in control at all times:
  • Revoke API tokens in any connected platform
  • Uninstall browser extensions from browsers
  • Disable integrations directly in Plerion
Access can be revoked instantly without disrupting tools or data.

Data security and privacy

Data protection is at the core of how I’m built:
  • Amazon Bedrock integration ensures all AI processing happens securely within AWS
  • No training on data - ever
  • Encryption for data at rest and in transit
  • Strong tenant isolation for each customer
  • ISO 27001 and SOC 2 certified infrastructure
For details on security and compliance practices, visit the Trust Center.
No - absolutely not.
Data is never used to train or fine-tune AI models. Foundation models process requests securely and don’t retain information afterward.
Data stays private and confidential at all times.
All AI processing occurs within AWS using Amazon Bedrock’s secure infrastructure.
No external model providers ever access data.
Regional hosting is available in:
  • Australia
  • India
  • Singapore
  • United States
Data never leaves the chosen region.
I’m designed with multiple layers of human oversight:
  • All changes require approval before merging
  • Admin controls for configuring or disabling features
  • Comprehensive audit trails for every action
  • Rollback mechanisms for easy reversion
  • Transparent operations so everything I do is explainable
I enhance human decision-making, not replace it.

Getting help and support

Teams have several options:
  • Email me at [email protected] for questions or issues
  • Ask me directly in Slack or via browser extensions (Chrome, Firefox)
  • Reach Plerion support through the platform for account or billing questions
  • Share feedback - I’ll make sure it reaches the product team
Most common questions can be solved directly through me.
Absolutely. I’m designed for teams:
  • Each member can install browser extensions (Chrome, Firefox)
  • Shared Slack channels allow me to help multiple people at once
  • Collaborative workflows for team coordination
  • Role-based access for proper visibility and control
The more teammates I work with, the more effective I become.
I have safeguards in place, but if something goes wrong:
  • Human approval required for important changes
  • Audit logs for everything I do
  • Feedback loops to help me improve
I’m always learning and improving from real-world use.
Yes - I’m always on:
  • Responsive via email, Slack, and browser extensions
  • Continuous monitoring for background and reactive tasks
  • Global coverage across time zones
  • No downtime for updates or maintenance
Security doesn’t sleep, and neither do I.