Icertis supports customers in regulated industries and needed to scale security without adding headcount. This customer story shows how the contract intelligence company deployed Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Purview, and Microsoft Entra to protect generative AI applications and enforce compliance, cutting alert triage time by 80%. Read the story to learn from Icertis's experience.
How did Icertis improve SOC efficiency and reduce security incidents?
Icertis reshaped its SOC operations by standardizing on the Microsoft security stack, especially Microsoft Defender for Cloud and Security Copilot.
Key outcomes:
- 50% drop in SOC incident volume
- Mean time to resolution reduced from 40 minutes to 25 minutes
- Alert triage time cut by up to 80% (from about 60 minutes to 15 minutes for high-priority alerts)
How they achieved this:
- Used Security Copilot agents to summarize and prioritize high-risk alerts, compressing manual investigation workflows.
- Correlated signals across Microsoft security and compliance tools to present a unified incident timeline with recommended actions.
- Automated common response steps (for example, in a phishing case: identifying malicious domains, revoking sessions, enforcing multifactor authentication, and resetting passwords within minutes).
- Enabled developers to generate KQL queries from natural language, which sped up onboarding and helped engineers investigate threats independently.
The net effect is a more scalable SOC that can support rapid AI adoption and frequent audits without adding headcount, while giving analysts more time to focus on higher-value engineering and long-term security priorities.
How does Icertis secure sensitive contract data and generative AI workloads?
Icertis works with customers in regulated industries, so securing contract data and AI workloads is central to its operating model. The company uses a combination of Microsoft cloud security and compliance services to create layered protection.
Core elements of the approach:
- Defender for Cloud (CNAPP) for AI workload protection:
- Monitors Azure OpenAI deployments used in Icertis generative AI and Vera applications.
- Detects malicious prompts and potential prompt injection or jailbreak attempts.
- Provides AI posture visibility, risk reduction recommendations, and attack path analysis.
- Compliance at scale across more than 300 Azure subscriptions:
- Built-in regulatory frameworks such as ISO 27001, SOC 2, and NIST 800-53 help maintain continuous compliance.
- Azure policies block public endpoints and correct policy drift.
- Multicloud connectors extend visibility into AWS environments.
- Data governance with Microsoft Purview:
- Automatically classifies and encrypts files containing sensitive contract information.
- Applies conditional access and blocks unauthorized activity from unmanaged devices.
- Threat detection with Microsoft Sentinel:
- Correlates insights from Defender for Cloud Apps and other sources to provide a unified view of threats across SaaS and AI environments.
- Delivers high-fidelity alerts and actionable insights for faster response.
- Identity and access control with Microsoft Entra:
- Implements a Zero Trust model—no default access; roles must be explicitly requested, justified, and approved.
- Risk-based identity monitoring flags anomalies such as impossible travel or token misuse and triggers automated remediation.
By combining these capabilities, Icertis can support AI-driven contract intelligence while maintaining strong data security, audit readiness, and customer trust.
How does Icertis govern AI and embed security into its product lifecycle?
Icertis treats security as a core product feature and has reimagined its development and governance practices to keep pace with generative AI.
AI and SaaS governance
- Uses Defender for Cloud Apps to discover, classify, and control web and GenAI applications.
- Assigns security scores to apps, blocks low-scoring ones, and integrates with Microsoft Sentinel and Defender Threat Intelligence for better detection and response.
- Combines Defender for Cloud Apps with Microsoft Purview and Microsoft Entra to gain granular control over data movement and user behavior, including evaluation of shadow IT GenAI tools.
Secure-by-design product development
- Embeds Secure by Design principles into the product lifecycle, including early threat modeling, risk assessments, and architectural reviews.
- Uses Microsoft Defender for Containers in CI/CD workflows so developers can scan Python-based container images for vulnerabilities before deployment, reducing run-time exploit risk.
- Leverages Defender for Cloud to proactively identify attack paths and harden workloads before they are exploited.
Policies and training
- Runs internal training and AI literacy programs to help employees use generative AI tools more securely.
- Applies an Icertis AI Policy grounded in the company’s FORTE values, with a governance process to ensure responsible AI design and deployment.
Looking ahead, Icertis plans to extend Defender for Cloud capabilities across its Vera suite and is exploring malware scanning as a service to detect threats in uploaded documents before they reach production. This continuous evolution supports a more secure, trusted approach to AI-powered contract intelligence.