Your data stays yours.
Every control stays visible.
CraftedSignal is a control plane for detections, not a data lake. Your logs never leave your SIEM, every credential is encrypted with per-tenant keys, and every action is logged. Run it as SaaS, self-hosted, or fully air-gapped.
Data boundaries
We manage rules, not your logs
CraftedSignal stores detection rules, tests, approvals, and metadata. Your telemetry stays in the SIEM you already run.
Your logs stay in your SIEM
We store rules, tests, approvals, and metadata, never your log data or telemetry. Health metrics are derived from SIEM APIs, not raw logs.
Outbound-only agents
Agents initiate connections from your network to your SIEM. No inbound ports to open, nothing listening on your perimeter.
Never trained on your data
AI assists and suggests, it never auto-deploys and never trains on your data. Disable it entirely, or run it locally via Ollama.
Security architecture
Secure by default
Encryption everywhere
AES-256-GCM at rest with per-company keys, TLS 1.2+ in transit. One tenant's key cannot decrypt another's.
Immutable audit trail
Every rule change, approval, deployment, and rollback is logged and exportable to your SIEM or GRC system.
SSO + passkey MFA
OIDC providers (Okta, Azure AD, Google Workspace) with WebAuthn/FIDO2 passkeys or IdP-managed MFA. No shared secrets.
RBAC + separation of duties
Admin, User, and Viewer roles. Authoring and approval are separated and enforced by the platform.
Standards
Built to recognized standards
SOC 2 Type II
Designed with SOC 2 controls built in: change management, access control, and monitoring across the detection lifecycle.
EU Cyber Resilience Act
The self-hosted and air-gapped builds are products with digital elements, so the CRA applies. We are building for CRA readiness, SBOM, signed artifacts, secure defaults, ahead of the 2026 reporting and 2027 secure-by-design deadlines.
How it's built
Engineered to be trusted
Single binary
One self-contained binary with no external runtime dependencies. A small attack surface that is simple to audit, deploy, and air-gap.
Memory-safe by design
Built in a memory-safe language, eliminating whole classes of vulnerabilities such as buffer overflows and use-after-free.
Security tested every release
Static analysis (SAST), dynamic analysis (DAST), and AI-assisted security review run in CI on every change before it ships.
Hardened CI/CD supply chain
Signed binaries and container images, an SBOM published per release, and automated dependency and vulnerability scanning enforced in the pipeline.
Regular updates, included
Continuous security and feature updates at no extra cost, across the supported lifetime, on SaaS and self-hosted alike.
No phone-home telemetry
CraftedSignal does not send usage telemetry off your network. It runs fully offline, including fully air-gapped.
Hardened by default
CSRF protection, a strict Content-Security-Policy, per-IP rate limiting, and server-side input validation on every endpoint.
No lock-in
Detections are authored in portable Sigma and exportable at any time. Bring your own git repository for backup and full history.
Attested content
Rules from the threat feed carry provenance and attestation metadata, so you can verify exactly what you deploy.
Compliance
Helping you stay compliant
Detection governance, audit trails, and exportable evidence to meet the regulations your organization is subject to.
NIS2
A detection governance framework with evidence generation, incident-response support through audit trails, and configurable retention and reporting.
DORA
ICT change and incident audit trails for operational-resilience reporting, detection testing evidence, and records for your ICT third-party risk register.
GDPR
We process rules and metadata as a data processor, never your logs or PII. Data minimization by design, EU or US residency, DPIA and RoPA templates available.
SOC 2 evidence and exports
Change management, access control, and monitoring controls map to the SOC 2 trust criteria your auditors assess. Every rule change, approval, deployment, and rollback is logged immutably and exportable to your SIEM or GRC in CSV/JSON.
Deployment & residency
Deploy on your terms
SaaS
Managed by CraftedSignal with EU or US data residency. Automatic updates, zero infrastructure overhead. Your logs never leave your SIEM.
Self-hosted
A single binary with no external dependencies, SQLite built in or optional PostgreSQL. You control upgrades, backups, and availability.
Air-gapped
Full functionality with no internet access. AI runs locally via Ollama. Agents are outbound-only, no inbound ports required.
Questions about our security posture?
Read the technical detail, or send your security and procurement questions straight to us.