Org

Graph

Sources

halyard-prod

1,204 identities · 3 clouds

1,204 identities

cloud · idp · edr · git

UTC

user

service

laptop

bucket

(00)

Detection & response · for teams without a SOC

Most alerts
are noise.

Signal reads every one anyway. An AI analyst triages your cloud, identity and endpoint alerts around the clock — and when one is real, hands a human a one-tap fix. The night shift you were never going to hire.

Events read today

2,481,093

31/s · 99.7% closed without waking anyone

Events read today

2,481,093

31/s · 99.7% closed without waking anyone

Events read today

2,481,093

31/s · 99.7% closed without waking anyone

(01)

On night shift for

212 engineering teams who would rather be asleep at 3 a.m. — and now are.

Halyard

01

fintech · 840 ids

Halyard

01

fintech · 840 ids

Oxbow

02

logistics · 1,310 ids

Oxbow

02

logistics · 1,310 ids

Parsec

03

devtools · 220 ids

Parsec

03

devtools · 220 ids

Quillmark

04

legal tech · 390 ids

Quillmark

04

legal tech · 390 ids

Ferrous

05

materials · 1,760 ids

Ferrous

05

materials · 1,760 ids

Kitebase

06

marketplace · 610 ids

Kitebase

06

marketplace · 610 ids

Orrery

07

space data · 140 ids

Orrery

07

space data · 140 ids

Tessel

08

design tools · 480 ids

Tessel

08

design tools · 480 ids

(02)

The problem, briefly

A 400-person company throws off about eleven thousand security alerts a month. Roughly eleven of them matter. Signal reads all eleven thousand, argues with itself about the eleven, and wakes a human only when there’s an actual decision to make.

11,000 alerts / month

10,989 closed by the analyst

11 worth a human

1 tap each

(03)

Product

Detect.
Decide.
Contain.

Three verbs, one screen, forty-one seconds. Signal does the reading and the reasoning. You keep the say-so.

signal/halyard-prod/detections

Live event stream

31 ev/s99.7% auto-closed0 escalated

03:11:58.612cloud.auditAssumeRole deploy-bot → prod-deployerbenign
03:11:59.207idp.authlogin ok · a.kim@ · Seoul · known deviceknown-good
03:11:59.749edr.procnode → esbuild · mbp-412 · signedbaseline
03:12:00.347cloud.auditPutObject bkt/logs-eu/2026/09/24/part-219.gzbenign
03:12:01.017cloud.auditDescribeInstances by ci-runner-02baseline
03:12:01.489edr.procbrowser auto-update 129.0 · 189 hostsbaseline
03:12:02.265git.auditpush main · svc-ledger · 3 commits · signedexpected
03:12:02.839idp.authpassword reset · r.silva@ · self-serviceknown-good
03:12:03.436edr.procusb mount · mbp-463 · allow-listeddup · suppressed
03:12:04.244idp.authmfa push approved · t.berg@ · 1.4 sbenign
03:12:04.845idp.authlogin ok · p.nair@ · Bengaluru · known devicebenign
03:12:05.306edr.procmalware scan clean · mbp-386baseline
03:12:06.018cloud.auditUpdateSecurityGroup sg-web · ingress 443 unchangedbaseline
03:12:06.570git.auditdeploy key used · ci-runner-04 · expectedbenign
INC-2291 opened · 5 signals correlated

signal/halyard-prod/detections

Live event stream

31 ev/s99.7% auto-closed0 escalated

03:11:58.612cloud.auditAssumeRole deploy-bot → prod-deployerbenign
03:11:59.207idp.authlogin ok · a.kim@ · Seoul · known deviceknown-good
03:11:59.749edr.procnode → esbuild · mbp-412 · signedbaseline
03:12:00.347cloud.auditPutObject bkt/logs-eu/2026/09/24/part-219.gzbenign
03:12:01.017cloud.auditDescribeInstances by ci-runner-02baseline
03:12:01.489edr.procbrowser auto-update 129.0 · 189 hostsbaseline
03:12:02.265git.auditpush main · svc-ledger · 3 commits · signedexpected
03:12:02.839idp.authpassword reset · r.silva@ · self-serviceknown-good
03:12:03.436edr.procusb mount · mbp-463 · allow-listeddup · suppressed
03:12:04.244idp.authmfa push approved · t.berg@ · 1.4 sbenign
03:12:04.845idp.authlogin ok · p.nair@ · Bengaluru · known devicebenign
03:12:05.306edr.procmalware scan clean · mbp-386baseline
03:12:06.018cloud.auditUpdateSecurityGroup sg-web · ingress 443 unchangedbaseline
03:12:06.570git.auditdeploy key used · ci-runner-04 · expectedbenign
INC-2291 opened · 5 signals correlated

signal/halyard-prod/detections

Live event stream

31 ev/s99.7% auto-closed0 escalated

03:11:58.612cloud.auditAssumeRole deploy-bot → prod-deployerbenign
03:11:59.207idp.authlogin ok · a.kim@ · Seoul · known deviceknown-good
03:11:59.749edr.procnode → esbuild · mbp-412 · signedbaseline
03:12:00.347cloud.auditPutObject bkt/logs-eu/2026/09/24/part-219.gzbenign
03:12:01.017cloud.auditDescribeInstances by ci-runner-02baseline
03:12:01.489edr.procbrowser auto-update 129.0 · 189 hostsbaseline
03:12:02.265git.auditpush main · svc-ledger · 3 commits · signedexpected
03:12:02.839idp.authpassword reset · r.silva@ · self-serviceknown-good
03:12:03.436edr.procusb mount · mbp-463 · allow-listeddup · suppressed
03:12:04.244idp.authmfa push approved · t.berg@ · 1.4 sbenign
03:12:04.845idp.authlogin ok · p.nair@ · Bengaluru · known devicebenign
03:12:05.306edr.procmalware scan clean · mbp-386baseline
03:12:06.018cloud.auditUpdateSecurityGroup sg-web · ingress 443 unchangedbaseline
03:12:06.570git.auditdeploy key used · ci-runner-04 · expectedbenign
INC-2291 opened · 5 signals correlated

(04)

Incident replay · INC-2291

03:12 UTC.
Nobody’s awake.
That’s fine.

A real night at a customer, replayed straight from Signal’s audit log. Names changed, timings untouched, zero adjectives added.

  1. 03:12:07First suspicious event
  2. 03:12:15Verdict · 0.94
  3. 03:12:39A human says yes
  4. 03:12:48Contained · 41 s total
signal replayINC-2291 · 1× speed-ish

$ signal replay INC-2291 --from 03:12:00Z

  1. 03:12:07.214idp.authlogin ok j.okafor@halyard.dev · 103.28.54.19 · Singapore · new device
  2. 03:12:07.380detectimpossible_travel: Lisbon → Singapore in 14 min (11,870 km). Physics disagrees.
  3. 03:12:08.002triagepulled 36 related events across idp, workspace, chat, calendar
  4. 03:12:11.640triagemfa push approved 2.1 s after 6 denials → push-fatigue pattern (+0.27)
  5. 03:12:13.905triageoauth grant “Drive Sync Pro” · scopes mail.read files.read.all (+0.19)
  6. 03:12:15.117verdictlikely account takeover · confidence 0.94 · sev HIGH
  7. 03:12:15.230pagepaged on-call m.reyes via chat + SMS · playbook ato-contain attached
  8. ··· 24 seconds pass. m.reyes wakes up, reads one card, taps approve. ···
  9. 03:12:39.482humanm.reyes approved ato-contain (3 actions) from phone
  10. 03:12:40.010actrevoked 4 active sessions ✓
  11. 03:12:43.771actreset MFA factors · re-enrolment link sent to manager ✓
  12. 03:12:46.302actrevoked oauth grant “Drive Sync Pro” ✓
  13. 03:12:48.119containINC-2291 contained · 41 s from first event
  14. 03:13:02.550reportsummary queued for the 09:00 standup. Back to reading logs.

events read 36human time spent 24 sactions run 3 / 3customer impact none

(05)

Capabilities

Everything a SOC does at 3 a.m.

Minus the SOC.

Six jobs that usually need a room full of people and a lot of coffee. Each tile below is running live, like the product.

(05)

Capabilities

Everything a SOC does at 3 a.m.

Minus the SOC.

Six jobs that usually need a room full of people and a lot of coffee. Each tile below is running live, like the product.

Identity

logins · live

Every login, everywhere

Signal learns where and how each person signs in, then notices when physics gets involved.

Triage

today

The queue is empty. It usually is.

0 alertswaiting on you

alerts read11,204

closed, with reasons11,193

escalated11

0 alertswaiting on you

alerts read11,204

closed, with reasons11,193

escalated11

0 alertswaiting on you

alerts read11,204

closed, with reasons11,193

escalated11

Endpoint

fleet

Laptops check in from lounges, too

98.6%

1,187 of 1,204 reporting
17 asleep. It’s 3 a.m.

Cloud

api calls

Audit logs, read in full

Not sampled. Every call, every region.

4,164 / min3 regions

Secrets

rotation

Tokens that rotate themselves

A leaked key expires before anyone finishes pasting it.

tok_ci_deploy••••••••7f3a
rotated 4 s ago
next rotation in 6 h

Control

try it

Nothing happens without a yes

Signal · INC-2291now

Revoke 4 sessions for j.okafor?

confidence 0.94 · reversible for 24 h

(06)

Before / after

The boring numbers.

Which are the point.

Medians across 212 customer orgs: the 90 days before onboarding against the 90 days after.

(06)

Before / after

The boring numbers.

Which are the point.

Medians across 212 customer orgs: the 90 days before onboarding against the 90 days after.

Metric

Before

Scale

With Signal

Change

Mean time to detect

first event → someone knows

9h 42m

38s
38s
38s

919× faster

Mean time to contain

first event → threat can’t act

2.6 days

4m 12s
4m 12s
4m 12s

891× faster

Alerts a human reads

per week, per org

1,340

6
6
6

−99.6%

Night-time pages

per month, 22:00–07:00 local

23

2
2
2

−91%

Methodology: customer-reported baselines, verified against their own ticketing history where it existed. Jan–Jun 2026, n = 212. We’ll show you the SQL if you ask nicely, and also if you ask rudely.

(07)

Integrations

Plugs into the
forty-odd tools
you already
pay for.

Read-only by default. Signal asks for write access one action at a time, and only for playbooks you switch on. Most teams are fully connected before their first meeting ends.

46
46

integrations

11m
11m

median setup

0
0

agents to install

Cloud

Identity

EDR

Git

Chat

Paging

Containers

SIEM

MDM

Email

DNS

Ticketing

Secrets

CI/CD

(08)

From the other end of the pager

“In our first quarter, Signal woke me up twice. Both times it was right, and both times the fix was one tap from done. I’ve started charging my phone in the kitchen.”

Ines Albuquerque

Ines Albuquerque

CISO · Halyard · 840 engineers

312,044

alerts read

2

pages at night

0

incidents past containment

(09)

Pricing

Priced per identity.

That’s what gets phished.

Every employee, contractor and service account Signal protects counts once. Laptops, buckets and clusters are free — attackers don’t bill by the server either.

(09)

Pricing

Priced per identity.

That’s what gets phished.

Every employee, contractor and service account Signal protects counts once. Laptops, buckets and clusters are free — attackers don’t bill by the server either.

400

Team

Fits your size

25–250 identities

$7/ identity
/ month

Team tops out at 250 identities

For teams who want someone reading the logs, starting tonight.

  • Cloud & identity detection
  • AI triage on every alert, with reasons
  • Paging via chat, SMS and phone
  • One-tap containment · 8 playbooks
  • 30 days of searchable history
Start with Team

Growth

Fits your size

100–2,000 identities · most teams

$12/ identity
/ month

≈ $4,800 / mo, billed annually

For orgs where “we’ll look at it Monday” stopped being an answer.

  • Everything in Team
  • Endpoint signal from your EDR
  • Custom playbooks & approval chains
  • 13 months of history, audit-ready exports
  • SSO, SCIM and role-based access
  • Quarterly threat review with a human
Choose Growth

Enterprise

Fits your size

1,000+ identities or regulated

$15/ identity
/ month, from

Usually starts around 1,000 identities

For when the auditor, the board and the insurer all want the same PDF.

  • Everything in Growth
  • Human analyst escalation, 24/7
  • Single-tenant, EU or US region
  • Control mappings: SOC 2, ISO 27001, NIS2
  • 99.95% uptime SLA, named engineer
Talk to a human

Read-only by default

SOC 2 Type II

Your data stays in your region

Monthly plans cancel any time

No per-alert surprises, ever

(10)

Free threat review

Get a free
threat review.

Give us read-only access for 14 days. You get a written report of what’s already happening in your cloud and identity stack — the boring, the weird, and the “wait, how long has that been public?” No agents to install. No sales theatre.

14 days

read-only access

1 written report

0 obligations

We never ask for write access during a review. That promise is section 4.2 of the review terms, in plain English.

Create a free website with Framer, the website builder loved by startups, designers and agencies.