Audit-ready detection governance, EU-first.
Immutable audit logs, separation of duties, and deployment options that never move your customer logs. Self-hosted, regional SaaS, or air-gapped, your choice.
Audit trail
Immutable change history
Every rule change, approval, deployment, and rollback is logged and exportable for auditors, no SIEM-by-SIEM digging.
Policy guardrails
Separation of duties baked in
Approvals, deployment guardrails, noise/cost caps, and scoped kill switches keep production safe and compliant.
EU-first
Data stays in your boundary
No customer telemetry ingested. Deploy self-hosted, regional SaaS, or air-gapped with optional AI fully disabled.
Compliance deep dive
Mapped to SOC2, NIS2, DORA, and GDPR
Show your DPO and auditors exactly how detections are governed: identity, approvals, audit exports, and processing scope are explicit.
Identity & access
OIDC + passkeys, per-tenant RBAC, delegated admin. No shared secrets.
Audit exports
Immutable logs; export to your SIEM or GRC in CSV/JSON. Evidence bundles for audits.
Data processing scope
We manage rules and metadata only; no customer logs ingested. Optional on-prem AI.
Approvals & Separation of Duties
Dual control on deploys, change windows, scoped kill switches, rollback SLAs.
Templates
DPIA, RoPA, and TOMs starter packs ready for your legal counsel/DPO.
Deployment options
Self-host, regional SaaS, or air-gapped. Agents are outbound-only; no inbound ports.
NIS2 & DORA evidence
Detection audit trails, incident-response records, and testing evidence you can export for NIS2 and DORA reporting.
Platforms
Works with Splunk, Sentinel, CrowdStrike, Rapid7.
One rule, portable translations with diffs so you can prove parity across environments.
- • Import 10–30 priority rules
- • Add positive/negative tests + noise expectations
- • Shadow-eval against test data; see projected alerts/cost
- • Monitoring deploy with rollback SLA
Not your role?
Detections as code, live SIEM testing, CLI-first workflow
SOC LeadersMITRE coverage, noise dashboards, ROI calculator
CISOs & ComplianceAudit trails, AI governance, SOC2/NIS2 alignment
In-House SOCGoverned deploys, noise budgets, multi-SIEM parity
MSSPs & MDRsMulti-tenant waves, delegated RBAC, fleet health
Ready to brief your DPO and CISO?
We’ll share the compliance pack (DPIA/RoPA/TOMs starter) and run a 30-minute governance review with your stakeholders.
GDPR-first design. No customer logs ingested. Optional AI disablement.