SIEM
The SIEM your insurer wants
Every log source from every client, ingested every few minutes and held for the retention window your carrier asks about. Microsoft 365, Google Workspace, Entra ID sign-ins, Windows event logs, network gear — all in one place, priced by identity rather than by how many gigabytes you happen to ingest.
Every source carries its own status, last-activity time, and a silence threshold Hal watches. A feed that goes quiet becomes a flag, not a gap you discover during an incident.
What you get:
- Microsoft 365, Google Workspace, Entra ID, Windows event logs, and network devices — the full list is on Integrations
- Retention matched to what cyber-insurance carriers and auditors ask for
- Per-identity pricing, so one noisy client doesn’t blow up the bill — see Pricing
- An audit trail of every source, every ingest, every silence
Read-only by architecture
Hal reads your logs. He never writes back. Cloud sources connect by read-only API, and the only thing on an endpoint is a userspace log shipper — not an EDR, not a kernel driver. That read-only design is what makes a CrowdStrike-style outage impossible here.
