Your raw logs stay in your SIEM.
Every control stays visible.
CraftedSignal is a control plane for detections, not a data lake. It queries connected SIEMs for tests and health checks, stores governance data and derived statistics, and does not replicate raw log streams into CraftedSignal. Credentials are encrypted with per-tenant keys and every action is logged.
Data boundaries
We manage rules, not raw log storage
CraftedSignal stores detection rules, tests, approvals, evidence metadata and derived SIEM statistics. Telemetry storage stays in the SIEM you already run.
Your raw logs stay in your SIEM
We query SIEM APIs for validation, health and evidence workflows, and store returned statistics/results. We do not ingest or persist raw log streams as a CraftedSignal data lake.
Outbound-only agents
Agents initiate connections from your network to your SIEM. No inbound ports to open, nothing listening on your perimeter.
Never trained on your data
AI assists and suggests, it never auto-deploys and never trains on your data. Disable it entirely, or run it locally via Ollama.
Cloud sovereignty
Choose where trust lives
Use the secured SaaS platform, bind key access to attested workloads, or run CraftedSignal on infrastructure you control.
Secured SaaS
Managed CraftedSignal runs on hardened GCP infrastructure: private GKE, private Cloud SQL, regional KMS/CMEK, Cloud Armor, signed releases and Binary Authorization attestations.
Customer-controlled keys
Application-level encryption wraps tenant data-encryption keys with a platform KEK. Sovereign GCP deployments can tie key access to Confidential Space attestations and supported encrypted-memory runtimes.
Private cloud or on-prem
Run the same control plane on-premises, in your private cloud, or fully air-gapped when policy requires customer-owned infrastructure and network boundaries.
Security architecture
Secure by default
Encryption everywhere
AES-256-GCM at rest with per-company keys, TLS 1.2+ in transit. GCP deployments add KMS/CMEK and a brokered platform KEK for tenant key wrapping.
Immutable audit trail
Every rule change, approval, deployment and rollback is logged and exportable to your SIEM or GRC system.
SSO + passkey MFA
OIDC providers (Okta, Azure AD, Google Workspace) with WebAuthn/FIDO2 passkeys or IdP-managed MFA. No shared secrets.
RBAC + separation of duties
Admin, User and Viewer roles. Authoring and approval are separated and enforced by the platform.
Testing & supply chain
Proof you can inspect
Security claims are backed by repeatable engineering controls, release artifacts and vulnerability handling processes.
Independent security testing
CraftedSignal uses third-party penetration testing and security reviews for significant changes. Findings are triaged, remediated and tracked through closure.
SBOM per release
Each release includes a Software Bill of Materials so buyers and operators can inspect shipped components and track dependency exposure.
Signed artifacts
Binaries and container images are signed, deployed by digest and attested so Binary Authorization can enforce approved production workloads.
Advisories & disclosure
Security advisories, vulnerability disclosure and remediation notes give customers a clear path to report issues and track affected versions.
How it's built
Engineered to be trusted
Single binary
One self-contained binary with no external runtime dependencies. A small attack surface that is simple to audit, deploy and air-gap.
Memory-safe by design
Built in a memory-safe language, eliminating whole classes of vulnerabilities such as buffer overflows and use-after-free.
Security tested every release
Static analysis (SAST), dynamic analysis (DAST) and AI-assisted security review run in CI on every change before it ships.
Hardened CI/CD supply chain
Signed binaries and container images, SBOMs per release, automated vulnerability scanning and manual production gates in GitHub Actions.
Hardened GCP runtime
Private GKE, private Cloud SQL, KMS/CMEK, Cloud Armor and Binary Authorization are managed as Terraform-backed infrastructure controls.
Regular updates, included
Continuous security and feature updates at no extra cost, across the supported lifetime, on SaaS and self-hosted alike.
No phone-home telemetry
CraftedSignal does not send usage telemetry off your network. It runs fully offline, including fully air-gapped.
Hardened by default
CSRF protection, a strict Content-Security-Policy, per-IP rate limiting and server-side input validation on every endpoint.
No lock-in
Detections are authored in portable Sigma and exportable at any time. Bring your own git repository for backup and full history.
Attested content
Rules from the threat feed carry provenance and attestation metadata, so you can verify exactly what you deploy.
Evidence
Audit trails for detection work
CraftedSignal records the evidence security teams need when detection changes are reviewed, questioned, or audited.
NIS2
Export review history, deployment records, test evidence and incident-response support data for detection-related operational controls.
DORA
Preserve ICT change records, rollback history, testing evidence and operational-resilience context for detection lifecycle work.
GDPR
We process account data, detection content, metadata and derived SIEM query results as a data processor. Raw SIEM event-stream ingestion is out of scope; DPIA and RoPA templates are available.
Change evidence and exports
Every rule change, approval, deployment, rollback, drift decision and access-control action is logged immutably and exportable to your SIEM or GRC in CSV/JSON.
Deployment & residency
Deploy on your terms
SaaS
Managed by CraftedSignal with EU or US data residency, hardened GCP infrastructure, private networking and KMS-backed controls. Raw log storage stays in your SIEM.
Self-hosted
A single binary with no external dependencies, SQLite built in or optional PostgreSQL. You control infrastructure, upgrades, backups and availability.
Air-gapped
Full functionality with no internet access. AI runs locally via Ollama. Agents are outbound-only, no inbound ports required.
Questions about our security posture?
Read the technical detail, or send your security and procurement questions straight to us.