Foresite Catalyst is a fully managed Extended Detection and Response (MXDR) solution built natively for Google Cloud. It integrates with Google SecOps and Gemini Enterprise to deliver autonomous threat detection, investigation, and response at machine speed, while maintaining human oversight and auditability. Catalyst unifies SIEM, SOAR, and XDR capabilities into a modular platform, providing continuous visibility, automated workflows, and 24/7 managed security. Key features include agentic AI that accelerates TDIR cycles (reducing MTTR by up to 90%), a 'Glass Box' model ensuring every action is transparent and defensible, and seamless integration with Google Security Command Center and Mandiant threat intelligence. Foresite's Catalyst is delivered as a service, making enterprise-grade security accessible without the need for proportional headcount growth. AiDOOS enhances deployment by providing a structured environment for rapid integration, expert-led configuration, and continuous optimization, ensuring that organizations can maximize their security posture while minimizing operational burden.
Challenges It Solves
Manual threat detection and response are too slow for modern attacks, leading to extended dwell times and increased risk.
Security teams are overwhelmed by alert fatigue from low-fidelity alerts and fragmented security tools.
Siloed security tools operate in isolation, preventing unified defense and timely response.
Scaling security operations requires hiring proportional headcount, which is costly and unsustainable.
Screenshots
Use Cases
Cloud Security Operations
Provides continuous monitoring and response for cloud environments, ensuring threats are detected and neutralized promptly.
Incident Response
Automates and accelerates incident investigation, containment, and remediation with human expert oversight.
Threat Hunting
Uses AI and threat intelligence to proactively hunt for advanced persistent threats and unusual activity.
Compliance and Audit Support
Provides continuous compliance monitoring and audit-ready reporting for frameworks like NIST, ISO, and PCI.
Pricing
Custom pricing — built for your team
Foresite Catalyst pricing is tailored to your organisation's size, integrations, and requirements. AiDOOS generates your proposal instantly — scoped & ready in seconds.
💡 Pricing insight from reviewers: Pricing is custom quote-based; no public pricing is listed.
Key Features
Agentic AI Investigation
Autonomous threat investigation at machine speed using multi-agent reasoning.
Glass Box Transparency
Every autonomous action is logged and visible, ensuring full auditability and defensibility.
24/7 Managed SOC
Named Foresite analysts provide round-the-clock monitoring and response.
Google SecOps Integration
Seamless integration with Google SecOps, Chronicle, and Security Command Center.
Automated Response
SOAR playbooks auto-contain threats and trigger remediation actions.
Threat Intelligence
Mandiant and Google Threat Intelligence operationalized within workflows.
What Reviewers Say
What works well
Built specifically for Google Cloud, offering deep integration with Google SecOps and Gemini Enterprise.
Agentic AI reduces MTTR by up to 90% by automating investigation tasks.
Full transparency and auditability with the Glass Box model.
Common concerns
Requires Google Cloud environment; may not suit organizations outside GCP.
Pricing not publicly disclosed, potentially costly for smaller businesses.
Reviews
None
★★★☆☆
out of 5
By segment
Mid-Market100%
T
Technology Consultant
"Foresite Provision Assessment"
Foresite has lived up to the expectations set by our client. They resolve complex issues effortlessly and swiftly. There's always a significant risk of external security threats, but they are the preferred partner for meeting our security and compliance objectives.
A
Associate Manager
"Evaluation of Foresite Provision"
Their expertise spans the entire security landscape impressively. There is nothing like it at present; everything operates flawlessly. The ProVision Platform represents a state-of-the-art cloud-native SecOps solution that enables comprehensive cybersecurity and compliance oversight to counter modern threats.
Reviewer Demographics
Top Industries
No data available
Enterprise Readiness
SOC 2
ISO 27001
PCI DSS
NIST CSF
Identity & Access
SSO✓ Google Cloud Identity, Okta, Microsoft Entra ID
RBAC✓ Role-based access controls with granular permissions
Audit Logs✓ 365-day retention
Data Security
At restAES-256
In transitTLS 1.2+
Key mgmtVendor-managed
SLA & Availability
Uptime SLA99.9%
RPO4h
RTO2h
Pen test—
Compliance & Portability
Data residencyUS, EU
Data export✓ JSON, CSV
Right to erasure✓ Supported
Integrations
GS
Google SecOps
Cloud-native SIEM and SOAR platform for detection, investigation, and response. Catalyst integrates with Google SecOps for AI-driven security operations.
Native2-4 hours⇄ Bi-directional
CH
Chronicle
Google's cloud-native SIEM that enables log ingestion, threat correlation, and historical search. Catalyst leverages Chronicle for telemetry correlation.
Native2-4 hours⇄ Bi-directional
MT
Mandiant Threat Intelligence
Global threat intelligence and adversary research from Mandiant. Catalyst operationalizes Mandiant intel within Google SecOps workflows.
Third_Party2-4 hours
SC
Google Security Command Center
Cloud security posture management and risk visibility. Catalyst integrates with SCC for scanning findings and compliance mapping.
Native< 1 hour
CS
CrowdStrike Falcon
Cloud-delivered endpoint protection. Catalyst automates alert triage and response for CrowdStrike-detected threats.
Third_Party2-4 hours
TN
Tanium
Endpoint management and patching. Catalyst integrates with Tanium for vulnerability closure and configuration enforcement.
Third_Party2-4 hours
IV
Ivanti
IT asset management and patching. Used by Catalyst for automated patching workflows.
Third_Party2-4 hours
GE
Google Gemini Enterprise
Google's enterprise AI platform. Catalyst uses Gemini for autonomous investigation and reasoning chains.
AiDOOS handles setup, CRM integration, SSO config, and user provisioning. Your team goes live — not your IT department.
12
Deployments
94%
Adoption rate
4.8/5
Post-deploy sat.
4-8 weeks
Time to value
Prerequisites
Active Google Cloud Platform account
Google SecOps instance or willingness to migrate
Security team involvement for policy configuration
Data sources connected (logs, endpoints)
Configuration Options
Custom detection rules
Integration with existing security tools (EDR, SIEM)
Tailored incident response playbooks
Role-based access controls configuration
How Foresite Catalyst Compares
Product
AI & Analytics
Ease of Use
Enterprise Features
Pricing
Integrations
Mobile Experience
Quick Setup
Customer Support
Rating
Price/mo
F
Foresite Catalyst This product
Excellent
Good
Excellent
Fair
Good
Poor
Fair
Good
—
$Custom/user
CS
CrowdStrike Falcon
Good
Good
Excellent
Fair
Good
Good
Good
Good
—
$Custom/user
PA
Palo Alto Networks Cortex XDR
Good
Fair
Good
Fair
Good
Poor
Fair
Good
—
$Custom/user
SI
SentinelOne Singularity
Good
Good
Good
Fair
Good
Good
Good
Good
—
$Custom/user
Virtual Delivery Center · A new delivery category
A Virtual Delivery Center for
Foresite Catalyst
Pre-vetted experts and AI agents in the loop, assembled as a delivery
pod. Pay in Delivery Units — universal pricing across roles,
seniority, and tech stacks. No hiring, no contracting, no procurement
cycle.
Plans from $2,000 — Starter Pack, 10 Delivery Units, 90 days
Refundable on unused Delivery Units, anytime — no questions asked
Re-delivery guarantee on acceptance miss
Pre-flight delivery sizing — you see the plan before you commit
Foresite Catalyst is an Agentic SOC platform that provides MXDR for Google Cloud, combining AI-driven detection and response with human oversight. It integrates with Google SecOps and Gemini Enterprise to deliver autonomous investigations and a fully managed security operations outcome.
What integrations does Catalyst support?
Catalyst natively integrates with Google SecOps, Chronicle, Security Command Center, and Gemini Enterprise. It also supports third-party integrations with CrowdStrike, Tanium, Ivanti, and Mandiant Threat Intelligence for endpoint detection, patching, and threat intelligence.
How does Catalyst ensure human oversight?
Catalyst maintains human-in-the-loop through a 'Glass Box' model. Every autonomous action is visible and logged, and critical responses require authorization from authorized personnel. It generates traceable reasoning chains for every investigation.
What is the deployment process for Catalyst?
Deployment through AiDOOS typically takes about 72 hours, with a typical time-to-value of 4-8 weeks. It requires an active Google Cloud account and a Google SecOps instance. AiDOOS handles integration and configuration.
What security certifications does Foresite hold?
Foresite is SOC 2, ISO 27001, and PCI DSS compliant, and aligns with NIST CSF. They provide detailed compliance documentation upon request.
Is Catalyst suitable for small businesses?
Catalyst is designed for enterprise-level security operations, particularly for organizations using Google Cloud. It is best suited for medium to large enterprises with complex security needs.