Every signal.
One platform.
Signum turns the noise of your security stack into decisions: ingest alarms from every source, group them intelligently, respond with AI-enriched incidents and automated playbooks. Per tenant, by design.
From raw alert to closed incident,
without leaving Signum
One pipeline for the whole SOC lifecycle, built for teams that manage many organizations at once.
Triage at scale
Every alarm lands normalized: severity mapping from any source format, deduplication by alarm id, and unified alarms that fold storms of related alerts into a single actionable group.
Respond with context
Promote alarms to incidents carrying their full history. AI enrichment scores the threat, extracts IOCs and recommends actions; sandboxed Python playbooks execute the response.
Prove the work
Truthful dashboards, full audit trail, and polished per-tenant PDF reports (MTTA/MTTR, top sources, incident timelines) generated in one click for your monthly review.
A complete SOC toolkit
Everything an operations team needs, in one self-hosted platform.
Unified alarms
Group related alerts into one entity with shared status, notes and timeline: triage hundreds as one.
Incident management
Status workflow, assignment, merge & promote, optimistic concurrency. No lost updates between analysts.
AI enrichment
AI-powered analysis on alarms and incidents: threat level, IOC extraction, similar incidents, next actions.
SOAR playbooks
Tenant-authored Python automations run in ephemeral, network-restricted containers: power without risk.
Auto status-sync
Close an incident and Signum pushes the status back to the originating platform, tickets included.
DMARC monitoring
Automatic aggregate-report collection straight from your report mailboxes, SPF/DKIM analytics per tenant.
Certificates & IP lists
TLS expiry monitoring and firewall-ready allow/block lists served as plain-text feeds your appliances pull.
Threat intelligence
One-click IP/domain reputation through your configured providers, cached and rate-limit aware.
Many organizations.
Zero data bleed.
Tenant isolation is not a filter bolted on top: it is enforced at the query layer on every read and every write, with fail-closed defaults.
- Seven granular roles: from super admin to read-only viewer, with per-permission checks on every endpoint.
- Cross-tenant analysts: grant an analyst exactly the organizations they cover, nothing more.
- SSO per tenant: any OpenID Connect identity provider, with signature-verified tokens and safe auto-provisioning.
- Tenant-scoped API keys: ingest keys are pinned to their organization and can never widen their reach.
Your analysts decide.
The AI does the legwork.
Trigger enrichment on any alarm, unified group or incident: Signum sends the full context to your configured AI integration and stores a structured verdict alongside the case.
- Structured output: threat level, confidence, attack pattern, IOCs, affected assets, recommended actions.
- Travels with the case: enrichment follows the alarm when it is promoted to an incident.
- Treated as untrusted: AI output is rendered escaped and validated, never executed.
A security product should be
the most secure thing you run
Signum is hardened the way we would demand of any vendor, and continuously verified by an automated test suite.
Bring your SOC under one signal
See Signum on your own data: a guided demo with your sources, your tenants and your playbooks. Self-hosted, in your infrastructure.