The problem: detection is solved, response isn't. Alerts pile up, a human triages, and the attacker is gone. Dwell time is hours; an automated attack finishes in seconds.
Parry closes the loop. It sits inline as a reverse proxy; every request becomes a row in ClickHouse, and an AI blue-team agent runs a continuous loop: DETECT, TRIAGE, GROUND, RESPOND.
How we use each partner: ClickHouse Cloud — the brain. Detection IS SQL: 8 rules over live telemetry every 2s, with materialized views pre-aggregating at ingest. Add a detector in one SELECT. Akash — triage runs on a rented NVIDIA A100 via the new Console API (managed wallet, auto-funding, runtime cap). One model scores alerts, writes the code patch, and the incident report. Semgrep — pins the exact vulnerable line on every high-severity alert; the Akash LLM then writes a secure patch. Senso — grounds every call in verified playbooks, citing the doc ids used. Guild — a hosted commander agent adjudicates critical detections as a tamper-evident audit trail.
What makes it smart: when an exploit succeeds once, Parry distills it into a brand-new, validated ClickHouse rule and arms it instantly. And the moment exfiltration is seen, it rotates every touched secret for real — the stolen key is already dead.
The result: launch an attacker from the dashboard, watch it caught, blocked, and patched live; run it again and the whole attack returns 403. Autonomous defense, with receipts.