See everything. Control everything. No black-box AI.
Immutable audit trails. Full visibility into AI suggestions. Every feature toggleable. Deploy on your terms: SaaS or a single binary.
Compliance & Governance
Built for audit-ready security programs
SOC2 aligned
Change management controls, access logging, and separation of duties built in.
NIS2 ready
Detection governance framework meets critical infrastructure requirements.
Immutable audit logs
Every change, every approval, every deployment. Exportable for auditors.
Feature toggles
Control every capability from the company admin page — AI assist, auto-deploy, Sigma compilation, notifications. Override per-rule when teams need flexibility. SSO, Passkey MFA, and RBAC included.
AI Governance
AI that assists, never acts
Unlike black-box platforms that automatically tune your detections, CraftedSignal keeps humans in control. AI suggests improvements. Your team reviews and approves. Nothing deploys without explicit authorization.
- All AI suggestions require human approval before deployment
- Self-host AI via Ollama—your data never leaves your infrastructure
- Disable AI entirely if your policy requires it
- Full audit trail of every AI interaction and decision
Suggested: Add process lineage check to webshell detection
Reduces false positives by 40% based on analysis of last 30 days
Governance Resources
Deep-dive into the security model
Security & Compliance
Data boundaries, encryption, audit logging, SSO, and compliance posture (SOC2, NIS2, GDPR).
Secure Workflows
Validation, testing, approval gates, monitoring mode, and rollback at every stage of the detection lifecycle.
Roles & Permissions
RBAC matrix with Admin, User, and Viewer roles. Separation of duties enforced by the platform.
Deployment Guide
SaaS, self-hosted, and air-gapped options. Single binary, outbound-only agents, local AI.
Deployment
Deploy on your terms
SaaS
Managed by CraftedSignal. Automatic updates, zero infrastructure overhead. Your logs never leave your SIEM — we manage rules and metadata only.
Self-hosted
Single binary, no external dependencies. SQLite built in, optional PostgreSQL. Run AI locally via Ollama. You control upgrades, backups, and availability.
Air-gapped
Full functionality with no internet access. AI via local Ollama, all features offline. Agents are outbound-only — no inbound ports required.
Not your role?
Detections as code, live SIEM testing, CLI-first workflow
SOC LeadersMITRE coverage, noise dashboards, ROI calculator
In-House SOCGoverned deploys, noise budgets, multi-SIEM parity
MSSPs & MDRsMulti-tenant waves, delegated RBAC, fleet health
Regulated EUGDPR/NIS2 mapping, EU-first deployment, compliance packs