Skip to content
crafted signal
Trust

Your data stays yours.
Every control stays visible.

CraftedSignal is a control plane for detections, not a data lake. Your logs never leave your SIEM, every credential is encrypted with per-tenant keys, and every action is logged. Run it as SaaS, self-hosted, or fully air-gapped.

Data boundaries

We manage rules, not your logs

CraftedSignal stores detection rules, tests, approvals, and metadata. Your telemetry stays in the SIEM you already run.

Your logs stay in your SIEM

We store rules, tests, approvals, and metadata, never your log data or telemetry. Health metrics are derived from SIEM APIs, not raw logs.

Outbound-only agents

Agents initiate connections from your network to your SIEM. No inbound ports to open, nothing listening on your perimeter.

Never trained on your data

AI assists and suggests, it never auto-deploys and never trains on your data. Disable it entirely, or run it locally via Ollama.

Security architecture

Secure by default

Encryption everywhere

AES-256-GCM at rest with per-company keys, TLS 1.2+ in transit. One tenant's key cannot decrypt another's.

Immutable audit trail

Every rule change, approval, deployment, and rollback is logged and exportable to your SIEM or GRC system.

SSO + passkey MFA

OIDC providers (Okta, Azure AD, Google Workspace) with WebAuthn/FIDO2 passkeys or IdP-managed MFA. No shared secrets.

RBAC + separation of duties

Admin, User, and Viewer roles. Authoring and approval are separated and enforced by the platform.

Standards

Built to recognized standards

SOC 2 Type II

Designed with SOC 2 controls built in: change management, access control, and monitoring across the detection lifecycle.

EU Cyber Resilience Act

The self-hosted and air-gapped builds are products with digital elements, so the CRA applies. We are building for CRA readiness, SBOM, signed artifacts, secure defaults, ahead of the 2026 reporting and 2027 secure-by-design deadlines.

How it's built

Engineered to be trusted

Single binary

One self-contained binary with no external runtime dependencies. A small attack surface that is simple to audit, deploy, and air-gap.

Memory-safe by design

Built in a memory-safe language, eliminating whole classes of vulnerabilities such as buffer overflows and use-after-free.

Security tested every release

Static analysis (SAST), dynamic analysis (DAST), and AI-assisted security review run in CI on every change before it ships.

Hardened CI/CD supply chain

Signed binaries and container images, an SBOM published per release, and automated dependency and vulnerability scanning enforced in the pipeline.

Regular updates, included

Continuous security and feature updates at no extra cost, across the supported lifetime, on SaaS and self-hosted alike.

No phone-home telemetry

CraftedSignal does not send usage telemetry off your network. It runs fully offline, including fully air-gapped.

Hardened by default

CSRF protection, a strict Content-Security-Policy, per-IP rate limiting, and server-side input validation on every endpoint.

No lock-in

Detections are authored in portable Sigma and exportable at any time. Bring your own git repository for backup and full history.

Attested content

Rules from the threat feed carry provenance and attestation metadata, so you can verify exactly what you deploy.

Compliance

Helping you stay compliant

Detection governance, audit trails, and exportable evidence to meet the regulations your organization is subject to.

NIS2

A detection governance framework with evidence generation, incident-response support through audit trails, and configurable retention and reporting.

DORA

ICT change and incident audit trails for operational-resilience reporting, detection testing evidence, and records for your ICT third-party risk register.

GDPR

We process rules and metadata as a data processor, never your logs or PII. Data minimization by design, EU or US residency, DPIA and RoPA templates available.

SOC 2 evidence and exports

Change management, access control, and monitoring controls map to the SOC 2 trust criteria your auditors assess. Every rule change, approval, deployment, and rollback is logged immutably and exportable to your SIEM or GRC in CSV/JSON.

Deployment & residency

Deploy on your terms

SaaS

Managed by CraftedSignal with EU or US data residency. Automatic updates, zero infrastructure overhead. Your logs never leave your SIEM.

Self-hosted

A single binary with no external dependencies, SQLite built in or optional PostgreSQL. You control upgrades, backups, and availability.

Air-gapped

Full functionality with no internet access. AI runs locally via Ollama. Agents are outbound-only, no inbound ports required.

Questions about our security posture?

Read the technical detail, or send your security and procurement questions straight to us.