(00)Detection & response · for teams without a SOC

Most alerts are noise.

Signal reads every one anyway. An AI analyst triages your cloud, identity and endpoint alerts around the clock — and when one is real, hands a human a one-tap fix. The night shift you were never going to hire.

Events read today

2,481,093

31/s · 99.7% closed without waking anyone

(01)On night shift for

212 engineering teams who would rather be asleep at 3 a.m. — and now are.

  • Halyardfintech · 840 ids
  • oxbowlogistics · 1,310 ids
  • PARSECdevtools · 220 ids
  • Quillmarklegal tech · 390 ids
  • 26FeFERROUSmaterials · 1,760 ids
  • kitebasemarketplace · 610 ids
  • ORRERYspace data · 140 ids
  • tessel.design tools · 480 ids

(02)The problem, briefly

A 400-person company throws off about eleven thousand security alerts a month. Roughly eleven of them matter. Signal reads all eleven thousand, argues with itself about the eleven, and wakes a human only when there’s an actual decision to make.

11,000 alerts / month 10,989 closed by the analyst 11 worth a human 1 tap each

(03)Product

Detect. Decide. Contain.

Three verbs, one screen, forty-one seconds. Signal does the reading and the reasoning. You keep the say-so.

signal/halyard-prod/detections

Live event stream

31 ev/s99.7% auto-closed0 escalated

03:11:58.612cloud.auditAssumeRole deploy-bot → prod-deployerbenign
03:11:59.207idp.authlogin ok · a.kim@ · Seoul · known deviceknown-good
03:11:59.749edr.procnode → esbuild · mbp-412 · signedbaseline
03:12:00.347cloud.auditPutObject bkt/logs-eu/2026/09/24/part-219.gzbenign
03:12:01.017cloud.auditDescribeInstances by ci-runner-02baseline
03:12:01.489edr.procbrowser auto-update 129.0 · 189 hostsbaseline
03:12:02.265git.auditpush main · svc-ledger · 3 commits · signedexpected
03:12:02.839idp.authpassword reset · r.silva@ · self-serviceknown-good
03:12:03.436edr.procusb mount · mbp-463 · allow-listeddup · suppressed
03:12:04.244idp.authmfa push approved · t.berg@ · 1.4 sbenign
03:12:04.845idp.authlogin ok · p.nair@ · Bengaluru · known devicebenign
03:12:05.306edr.procmalware scan clean · mbp-386baseline
03:12:06.018cloud.auditUpdateSecurityGroup sg-web · ingress 443 unchangedbaseline
03:12:06.570git.auditdeploy key used · ci-runner-04 · expectedbenign
INC-2291 opened · 5 signals correlated

(04)Incident replay · INC-2291

03:12 UTC. Nobody’s awake. That’s fine.

A real night at a customer, replayed straight from Signal’s audit log. Names changed, timings untouched, zero adjectives added.

  1. 03:12:07First suspicious event
  2. 03:12:15Verdict · 0.94
  3. 03:12:39A human says yes
  4. 03:12:48Contained · 41 s total
signal replay INC-2291 · 1× speed-ish

$ signal replay INC-2291 --from 03:12:00Z

  1. 03:12:07.214idp.authlogin ok j.okafor@halyard.dev · 103.28.54.19 · Singapore · new device
  2. 03:12:07.380detectimpossible_travel: Lisbon → Singapore in 14 min (11,870 km). Physics disagrees.
  3. 03:12:08.002triagepulled 36 related events across idp, workspace, chat, calendar
  4. 03:12:11.640triagemfa push approved 2.1 s after 6 denials → push-fatigue pattern (+0.27)
  5. 03:12:13.905triageoauth grant “Drive Sync Pro” · scopes mail.read files.read.all (+0.19)
  6. 03:12:15.117verdictlikely account takeover · confidence 0.94 · sev HIGH
  7. 03:12:15.230pagepaged on-call m.reyes via chat + SMS · playbook ato-contain attached
  8. ··· 24 seconds pass. m.reyes wakes up, reads one card, taps approve. ···
  9. 03:12:39.482humanm.reyes approved ato-contain (3 actions) from phone
  10. 03:12:40.010actrevoked 4 active sessions ✓
  11. 03:12:43.771actreset MFA factors · re-enrolment link sent to manager ✓
  12. 03:12:46.302actrevoked oauth grant “Drive Sync Pro” ✓
  13. 03:12:48.119containINC-2291 contained · 41 s from first event
  14. 03:13:02.550reportsummary queued for the 09:00 standup. Back to reading logs.

events read 36human time spent 24 sactions run 3 / 3customer impact none

(05)Capabilities

Everything a SOC does at 3 a.m. Minus the SOC.

Six jobs that usually need a room full of people and a lot of coffee. Each tile below is running live, like the product.

Identity

Every login, everywhere

Signal learns where and how each person signs in, then notices when physics gets involved.

Triage

The queue is empty. It usually is.

0 alertswaiting on you

alerts read11,204

closed, with reasons11,193

escalated11

Endpoint

Laptops check in from lounges, too

98.6%

1,187 of 1,204 reporting
17 asleep. It’s 3 a.m.

Cloud

Audit logs, read in full

Not sampled. Every call, every region.

4,812 / min3 regions

Secrets

Tokens that rotate themselves

A leaked key expires before anyone finishes pasting it.

tok_ci_deploy••••••••7f3a
rotated 4 s ago
next rotation in 6 h

Control

Nothing happens without a yes

Signal · INC-2291now

Revoke 4 sessions for j.okafor?

confidence 0.94 · reversible for 24 h

(06)Before / after

The boring numbers. Which are the point.

Medians across 212 customer orgs: the 90 days before onboarding against the 90 days after.

Mean time to detectfirst event → someone knows

Before: 9h 42m

With Signal: 38 seconds

919× faster

Mean time to containfirst event → threat can’t act

Before: 2.6 days

With Signal: 4 minutes 12 seconds

891× faster

Alerts a human readsper week, per org

Before: 1,340

With Signal: 6

−99.6%

Night-time pagesper month, 22:00–07:00 local

Before: 23

With Signal: 2

−91%

Methodology: customer-reported baselines, verified against their own ticketing history where it existed. Jan–Jun 2026, n = 212. We’ll show you the SQL if you ask nicely, and also if you ask rudely.

(07)Integrations

Plugs into the forty-odd tools you already pay for.

Read-only by default. Signal asks for write access one action at a time, and only for playbooks you switch on. Most teams are fully connected before their first meeting ends.

46integrations

11mmedian setup

0agents to install

  • Cloud
  • Identity
  • EDR
  • Git
  • Chat
  • Paging
  • Containers
  • SIEM
  • MDM
  • Email
  • DNS
  • Ticketing
  • Secrets
  • CI/CD

(08)From the other end of the pager

“In our first quarter, Signal woke me up twice. Both times it was right, and both times the fix was one tap from done. I’ve started charging my phone in the kitchen.”

Ines AlbuquerqueCISO · Halyard · 840 engineers

312,044alerts read

2pages at night

0incidents past containment

(09)Pricing

Priced per identity. That’s what gets phished.

Every employee, contractor and service account Signal protects counts once. Laptops, buckets and clusters are free — attackers don’t bill by the server either.

400

Team

Fits your size

25–250 identities

$7/ identity
/ month

Team tops out at 250 identities

For teams who want someone reading the logs, starting tonight.

  • Cloud & identity detection
  • AI triage on every alert, with reasons
  • Paging via chat, SMS and phone
  • One-tap containment · 8 playbooks
  • 30 days of searchable history
Start with Team

Growth

Fits your size

100–2,000 identities · most teams

$12/ identity
/ month

≈ $4,800 / mo, billed annually

For orgs where “we’ll look at it Monday” stopped being an answer.

  • Everything in Team
  • Endpoint signal from your EDR
  • Custom playbooks & approval chains
  • 13 months of history, audit-ready exports
  • SSO, SCIM and role-based access
  • Quarterly threat review with a human
Choose Growth

Enterprise

Fits your size

1,000+ identities or regulated

$15/ identity
/ month, from

Usually starts around 1,000 identities

For when the auditor, the board and the insurer all want the same PDF.

  • Everything in Growth
  • Human analyst escalation, 24/7
  • Single-tenant, EU or US region
  • Control mappings: SOC 2, ISO 27001, NIS2
  • 99.95% uptime SLA, named engineer
Talk to a human

Read-only by defaultSOC 2 Type IIYour data stays in your regionMonthly plans cancel any timeNo per-alert surprises, ever

(10)Free threat review

Get a free threat review.

Give us read-only access for 14 days. You get a written report of what’s already happening in your cloud and identity stack — the boring, the weird, and the “wait, how long has that been public?” No agents to install. No sales theatre.

  • 14 days
  • read-only access
  • 1 written report
  • 0 obligations

We never ask for write access during a review. That promise is section 4.2 of the review terms, in plain English.