Skip to content

SIEM

The SIEM your insurer wants

Every log source from every client, ingested every few minutes and held for the retention window your carrier asks about. Microsoft 365, Google Workspace, Entra ID sign-ins, Windows event logs, network gear — all in one place, priced by identity rather than by how many gigabytes you happen to ingest.

Hal’s Sources view: every client’s log sources with status, last activity, stored volume, and a per-source silence threshold

Every source carries its own status, last-activity time, and a silence threshold Hal watches. A feed that goes quiet becomes a flag, not a gap you discover during an incident.

What you get:

  • Microsoft 365, Google Workspace, Entra ID, Windows event logs, and network devices — the full list is on Integrations
  • Retention matched to what cyber-insurance carriers and auditors ask for
  • Per-identity pricing, so one noisy client doesn’t blow up the bill — see Pricing
  • An audit trail of every source, every ingest, every silence

Read-only by architecture

Hal reads your logs. He never writes back. Cloud sources connect by read-only API, and the only thing on an endpoint is a userspace log shipper — not an EDR, not a kernel driver. That read-only design is what makes a CrowdStrike-style outage impossible here.