M ManySignal

Customer stories

Security teams that changed how they operate

These are not sanitised case studies. They are real problems, real constraints, and outcomes that show up in the data.

80+

Enterprise customers

128%

Net Revenue Retention

4.8/5

G2 average rating

< 30 days

Median time to value

Healthcare

Meridian Health Network

12,000 employees · US Midwest

87%

Alerts auto-triaged

4.2hr → 18min

MTTD reduction

3x

SOC capacity multiplier

The challenge

A 4-person security team was manually triaging 600–900 alerts per day across three hospital systems and two insurance subsidiaries. P1 incidents were routinely buried in noise. After a near-miss ransomware event, the CISO had six weeks to demonstrate measurable improvement or face outsourcing the SOC entirely.

The outcome

After 90 days on ManySignal, 87% of alerts are closed autonomously with evidence trails that satisfy both the security team and the compliance auditor. The 4-person team now operates with the capacity of a 12-person SOC. Mean time to detect dropped from 4.2 hours to 18 minutes.

"We went from drowning to being ahead of the queue. That is not an exaggeration — it is what the ticket data shows."

— CISO, Meridian Health Network
Financial Services

Vantage Financial Services

3,200 employees · New York, NY

3 weeks → 2 days

Audit prep time

Zero exceptions

SOC 2 findings

320+

Analyst hours recovered/quarter

The challenge

The VP of Security Engineering needed SOC 2 Type II-ready audit trails for every alert disposition. Existing tooling produced verdicts but not explainable evidence. External auditors were requesting documentation that the team could not produce quickly enough without burning analyst time on report writing.

The outcome

ManySignal's immutable audit log with structured evidence summaries satisfied the auditors on the first pass. Audit prep time dropped from three weeks per quarter to two days. The security team now spends the recovered time on proactive threat hunting rather than compliance paperwork.

"The audit log is not just for compliance — it is also how our analysts learn from verdicts they did not author. That side effect surprised us."

— VP, Security Engineering, Vantage Financial Services
Critical Infrastructure

Canary Infrastructure Systems

1,800 employees · Denver, CO

14 in 30 days

New sources onboarded

86%

ICS ATT&CK coverage

14 days

Time to first production detection

The challenge

An OT/IT convergence project introduced 14 new telemetry sources in six months. The security team's existing SIEM could not normalise the new log formats fast enough, and detection coverage for the OT layer was effectively zero. The CISO needed coverage within 90 days or halt the convergence programme.

The outcome

ManySignal's ingestion layer normalised all 14 source types within 30 days using the connector SDK. A dedicated OT detection rule pack developed in partnership with the ManySignal detection team provided 86% MITRE ATT&CK ICS technique coverage within 60 days of onboarding.

"The fact that their detection engineers flew out to understand our environment before writing rules — that level of partnership is what made the timeline possible."

— CISO, Canary Infrastructure Systems

Ready to see ManySignal in your environment?

We will run a live proof-of-concept against a sample of your alert queue — no fake data, no scripted demos.