Skip to content
crafted signal
For CISOs & Compliance

Runtime risk, control and audit evidence.

A live view of detection risk, evidence and work in progress. Exportable audit trails, controlled approvals, and deployment choices for SaaS, private cloud or air-gapped environments.

Risk Posture

Know what is exposed before the board asks

Detection coverage mapped to business services, current threats, findings, telemetry and MITRE techniques you actually face. Every blind spot has an owner, risk score and next action.

Exposure, quantified

Runtime risk score across threats, assets, telemetry and detection coverage. One number, drillable to the specific items driving it.

Silently broken rules

Industry data says only 5% of deployed detections actually work. We flag the dead ones in real time, so a rule count never gives false comfort again.

Board-ready metrics

MTTD, MTTR, noise rate and MITRE coverage trending over time. Exportable. No spreadsheet archaeology the night before the meeting.

Sovereignty-ready

Secured SaaS, customer-governed KMS paths, on-premises and private-cloud deployment options for teams with data residency or infrastructure-control requirements.

Cloud Sovereignty

Keep the control boundary where policy needs it

Choose SaaS with hardened GCP controls, add customer-governed key access for sovereign cloud requirements, or run CraftedSignal in your own private cloud or air-gapped environment.

Secured SaaS

Private GKE and Cloud SQL, regional KMS/CMEK, Cloud Armor, signed releases, manual deployment approval and Binary Authorization attestations. Your logs stay in your SIEM.

Application-level encryption

Tenant data-encryption keys are wrapped by a KEK. Sovereign deployments can place that KEK under customer governance and release it through an attested key-broker path.

Confidential computing

Confidential Space can gate key access to stable attested workloads. Supported Confidential GKE Nodes or Confidential VMs add encrypted memory for data in use.

Private deployment

Run the same control plane on-premises, in a private cloud, or fully air-gapped with local models, internal feed mirrors and customer-operated network boundaries.

Independent penetration testing

Third-party penetration testing and major-change security reviews are part of the assurance program. Findings are triaged, remediated and tracked through closure.

Automation Governance

Assistance that never acts alone

Generated changes stay under human control. CraftedSignal can draft, test and suggest fixes, but your team reviews and approves. Nothing deploys without explicit authorization.

  • Generated suggestions require human approval before deployment
  • Self-host models via Ollama so your data never leaves your infrastructure
  • Disable generation entirely if your policy requires it
  • Full audit trail of every generated suggestion and decision
Suggestion Review Example
Pending Approval

Suggested: Add process lineage check to webshell detection

Reduces false positives by 40% based on analysis of last 30 days

Approve Reject Modify

Deployment

Deploy on your terms

SaaS

Managed by CraftedSignal on hardened GCP infrastructure with private networking, KMS/CMEK, signed releases and Binary Authorization attestations. Raw log storage stays in your SIEM.

Private cloud

Customer-operated infrastructure with the same detection workflow, optional customer KMS/HSM control, private ingress and internal release approval gates.

Air-gapped

No public outbound access, internal IP endpoints only, local models, internal feed mirrors and manual bundle import. You control upgrades, backups and availability.

Ready to take control of your detection program?