Skip to content
crafted signal
Trust

Your raw logs stay in your SIEM.
Every control stays visible.

CraftedSignal is a control plane for detections, not a data lake. It queries connected SIEMs for tests and health checks, stores governance data and derived statistics, and does not replicate raw log streams into CraftedSignal. Credentials are encrypted with per-tenant keys and every action is logged.

Data boundaries

We manage rules, not raw log storage

CraftedSignal stores detection rules, tests, approvals, evidence metadata and derived SIEM statistics. Telemetry storage stays in the SIEM you already run.

Your raw logs stay in your SIEM

We query SIEM APIs for validation, health and evidence workflows, and store returned statistics/results. We do not ingest or persist raw log streams as a CraftedSignal data lake.

Outbound-only agents

Agents initiate connections from your network to your SIEM. No inbound ports to open, nothing listening on your perimeter.

Never trained on your data

AI assists and suggests, it never auto-deploys and never trains on your data. Disable it entirely, or run it locally via Ollama.

Cloud sovereignty

Choose where trust lives

Use the secured SaaS platform, bind key access to attested workloads, or run CraftedSignal on infrastructure you control.

Secured SaaS

Managed CraftedSignal runs on hardened GCP infrastructure: private GKE, private Cloud SQL, regional KMS/CMEK, Cloud Armor, signed releases and Binary Authorization attestations.

Customer-controlled keys

Application-level encryption wraps tenant data-encryption keys with a platform KEK. Sovereign GCP deployments can tie key access to Confidential Space attestations and supported encrypted-memory runtimes.

Private cloud or on-prem

Run the same control plane on-premises, in your private cloud, or fully air-gapped when policy requires customer-owned infrastructure and network boundaries.

Security architecture

Secure by default

Encryption everywhere

AES-256-GCM at rest with per-company keys, TLS 1.2+ in transit. GCP deployments add KMS/CMEK and a brokered platform KEK for tenant key wrapping.

Immutable audit trail

Every rule change, approval, deployment and rollback is logged and exportable to your SIEM or GRC system.

SSO + passkey MFA

OIDC providers (Okta, Azure AD, Google Workspace) with WebAuthn/FIDO2 passkeys or IdP-managed MFA. No shared secrets.

RBAC + separation of duties

Admin, User and Viewer roles. Authoring and approval are separated and enforced by the platform.

Testing & supply chain

Proof you can inspect

Security claims are backed by repeatable engineering controls, release artifacts and vulnerability handling processes.

Independent security testing

CraftedSignal uses third-party penetration testing and security reviews for significant changes. Findings are triaged, remediated and tracked through closure.

SBOM per release

Each release includes a Software Bill of Materials so buyers and operators can inspect shipped components and track dependency exposure.

Signed artifacts

Binaries and container images are signed, deployed by digest and attested so Binary Authorization can enforce approved production workloads.

Advisories & disclosure

Security advisories, vulnerability disclosure and remediation notes give customers a clear path to report issues and track affected versions.

How it's built

Engineered to be trusted

Single binary

One self-contained binary with no external runtime dependencies. A small attack surface that is simple to audit, deploy and air-gap.

Memory-safe by design

Built in a memory-safe language, eliminating whole classes of vulnerabilities such as buffer overflows and use-after-free.

Security tested every release

Static analysis (SAST), dynamic analysis (DAST) and AI-assisted security review run in CI on every change before it ships.

Hardened CI/CD supply chain

Signed binaries and container images, SBOMs per release, automated vulnerability scanning and manual production gates in GitHub Actions.

Hardened GCP runtime

Private GKE, private Cloud SQL, KMS/CMEK, Cloud Armor and Binary Authorization are managed as Terraform-backed infrastructure controls.

Regular updates, included

Continuous security and feature updates at no extra cost, across the supported lifetime, on SaaS and self-hosted alike.

No phone-home telemetry

CraftedSignal does not send usage telemetry off your network. It runs fully offline, including fully air-gapped.

Hardened by default

CSRF protection, a strict Content-Security-Policy, per-IP rate limiting and server-side input validation on every endpoint.

No lock-in

Detections are authored in portable Sigma and exportable at any time. Bring your own git repository for backup and full history.

Attested content

Rules from the threat feed carry provenance and attestation metadata, so you can verify exactly what you deploy.

Evidence

Audit trails for detection work

CraftedSignal records the evidence security teams need when detection changes are reviewed, questioned, or audited.

NIS2

Export review history, deployment records, test evidence and incident-response support data for detection-related operational controls.

DORA

Preserve ICT change records, rollback history, testing evidence and operational-resilience context for detection lifecycle work.

GDPR

We process account data, detection content, metadata and derived SIEM query results as a data processor. Raw SIEM event-stream ingestion is out of scope; DPIA and RoPA templates are available.

Change evidence and exports

Every rule change, approval, deployment, rollback, drift decision and access-control action is logged immutably and exportable to your SIEM or GRC in CSV/JSON.

Deployment & residency

Deploy on your terms

SaaS

Managed by CraftedSignal with EU or US data residency, hardened GCP infrastructure, private networking and KMS-backed controls. Raw log storage stays in your SIEM.

Self-hosted

A single binary with no external dependencies, SQLite built in or optional PostgreSQL. You control infrastructure, upgrades, backups and availability.

Air-gapped

Full functionality with no internet access. AI runs locally via Ollama. Agents are outbound-only, no inbound ports required.

Questions about our security posture?

Read the technical detail, or send your security and procurement questions straight to us.