A reader for the war room that will not flinch at the artefact
During an incident the artefacts are ugly on purpose. Encoded commands, ransom notes, dumped LSASS strings. A model that refuses those inputs is a model you cannot put in the war room.
IR retainers, in-house DFIR, and anyone writing the first timeline at 2am.
Why the mainstream APIs fail here
The interesting strings are the ones the filter catches. You paste a command, the API returns a sermon, and the clock is still running. You already have the evidence. You need it ordered.
How Redline is used for this
A key that lives for the incident, capped, named, revoked when the report goes out. Timeline, cluster, next question. The receipt stays with the case file if counsel wants to know what left the building.
A working loop
- Stand up a key when the incident is declared.
- Paste artefacts, not whole disks.
- Revoke the key in the post-incident checklist.
Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.