Compare
The four platforms overlap less than their descriptions suggest. Each one was built for a different question, and the fastest way to tell them apart is what happens to your data and where the software sits when it runs.
Scroll sideways to see all four.
| Question | ALPACA Governance beside your SIEM | IBEX Sealed, on-premises appliance | Meerkat Sovereign AI with a gate | ALF Answers with their sources |
|---|---|---|---|---|
| The problem it solves | Log sources with no named owner, no retention, and assets that report nothing at all. | Attack surface and undeclared AI in networks the cloud can never reach. | People need a capable assistant, but the documents cannot go to a cloud model. | Knowledge that already exists in writing, scattered across manuals, tickets and knowledge bases. |
| Where it runs | Beside your existing SIEM, not in place of it. | A sealed appliance on its own hardware, inside your perimeter, with no data egress. | Two machines on your premises. The one holding the documents has no route out. | On-premises, in a private cloud, or fully isolated. |
| It connects to | QRadar, Splunk, Sentinel and Elastic, plus your CMDB, Active Directory or Entra ID, and Jira. | An internal Git host, a locally held vulnerability database and your asset baseline. Nothing external. | Your existing document repositories and a local model, with cloud models reachable only through the gate. | ERP, ITSM, document management and data lakes, with access governed through AD or SSO. |
| Pick it when | You cannot say who owns a log source, or which assets are escaping coverage. | Nothing may leave the network, and you still have to see everything inside it. | Some questions deserve a frontier model and others must never leave the building. | The answer exists somewhere in your own material and nobody can find it. |
Still not obvious? Tell us the constraint you are working under, not the product you think you need, and we will say which of these applies and which does not. Talk it through


Meerkat