Audit-ready detection governance, EU-first.
Immutable audit logs, separation of duties, and deployment options that never move your customer logs. Self-hosted, regional SaaS, or air-gapped—your choice.
Audit trail
Immutable change history
Every rule change, approval, deployment, and rollback is logged and exportable for auditors—no SIEM-by-SIEM digging.
Policy guardrails
Separation of duties baked in
Approvals, deployment guardrails, noise/cost caps, and scoped kill switches keep production safe and compliant.
EU-first
Data stays in your boundary
No customer telemetry ingested. Deploy self-hosted, regional SaaS, or air-gapped with optional AI fully disabled.
Compliance deep dive
Mapped to SOC2, NIS2, and GDPR
Show your DPO and auditors exactly how detections are governed: identity, approvals, audit exports, and processing scope are explicit.
Identity & access
OIDC + passkeys, per-tenant RBAC, delegated admin. No shared secrets.
Audit exports
Immutable logs; export to your SIEM or GRC in CSV/JSON. Evidence bundles for audits.
Data processing scope
We manage rules and metadata only; no customer logs ingested. Optional on-prem AI.
Approvals & Separation of Duties
Dual control on deploys, change windows, scoped kill switches, rollback SLAs.
Templates
DPIA, RoPA, and TOMs starter packs ready for your legal counsel/DPO.
Deployment options
Self-host, regional SaaS, or air-gapped. Agents are outbound-only; no inbound ports.
Platforms
Works with Splunk, Sentinel, CrowdStrike, Rapid7.
One rule, portable translations with diffs so you can prove parity across environments.
- • Import 10–30 priority rules
- • Add positive/negative tests + noise expectations
- • Shadow-eval against test data; see projected alerts/cost
- • Monitoring deploy with rollback SLA
Not your role?
Detections as code, live SIEM testing, CLI-first workflow
SOC LeadersMITRE coverage, noise dashboards, ROI calculator
CISOs & ComplianceAudit trails, AI governance, SOC2/NIS2 alignment
In-House SOCGoverned deploys, noise budgets, multi-SIEM parity
MSSPs & MDRsMulti-tenant waves, delegated RBAC, fleet health
Ready to brief your DPO and CISO?
We’ll share the compliance pack (DPIA/RoPA/TOMs starter) and run a 30-minute governance review with your stakeholders.
GDPR-first design. No customer logs ingested. Optional AI disablement.