Audit-ready detection governance, EU-first.
Immutable audit logs, separation of duties and deployment options that avoid moving raw customer log streams into CraftedSignal. Self-hosted, regional SaaS, or air-gapped, your choice.
Audit trail
Immutable change history
Every rule change, approval, deployment and rollback is logged and exportable for auditors, no SIEM-by-SIEM digging.
Policy guardrails
Separation of duties baked in
Approvals, deployment guardrails, noise/cost caps and scoped kill switches keep production changes controlled.
EU-first
Raw telemetry stays in your boundary
No raw customer telemetry lake inside CraftedSignal. Queries and derived statistics support testing, health and evidence. Deploy self-hosted, regional SaaS, or air-gapped with optional generation fully disabled.
Evidence deep dive
Evidence for NIS2, DORA, GDPR and internal audits
Show your DPO and auditors exactly how detections are governed: identity, approvals, audit exports and processing scope are explicit.
Identity & access
OIDC + passkeys, per-tenant RBAC, delegated admin. No shared secrets.
Audit exports
Immutable logs; export to your SIEM or GRC in CSV/JSON. Evidence bundles for audits.
Data processing scope
We manage rules, metadata and derived query statistics; no raw customer log ingestion. Optional on-prem models.
Approvals & Separation of Duties
Dual control on deploys, change windows, scoped kill switches, rollback SLAs.
Templates
DPIA, RoPA and TOMs starter packs ready for your legal counsel/DPO.
Deployment options
Self-host, regional SaaS, or air-gapped. Agents are outbound-only; no inbound ports.
NIS2 & DORA evidence
Detection audit trails, incident-response records and testing evidence you can export for NIS2 and DORA reporting.
Platforms
Works with Splunk, Sentinel, CrowdStrike, Rapid7.
One rule, portable translations with diffs so you can prove parity across environments.
- • Import 10–30 priority rules
- • Add positive/negative tests + noise expectations
- • Shadow-eval against test data; see projected alerts/cost
- • Monitoring deploy with rollback SLA
Not your role?
Detections as code, live SIEM testing, CLI-first workflow
SOC LeadersMITRE coverage, noise dashboards, ROI calculator
CISOs & ComplianceRuntime risk, audit trails, evidence exports
In-House SOCGoverned deploys, noise budgets, multi-SIEM parity
MSSPs & MDRsMulti-tenant waves, delegated RBAC, fleet health
Ready to brief your DPO and CISO?
We’ll share the compliance pack (DPIA/RoPA/TOMs starter) and run a 30-minute governance review with your stakeholders.
GDPR-first design. No raw log ingestion. Optional generation disablement.