M ManySignal
ManySignal MDR

Managed detection and response, in your tenant

24/7 analyst coverage. Verdicts in minutes. Full evidence in your environment, not a black box portal.

24/7 coverageVerdicts in minutesAudit-ready reporting

MDR without the black box

Head-to-head: traditional MDR provider vs ManySignal MDR.

Capability Traditional MDR ManySignal MDR
Transparency of verdicts Black box — you get a ticket, not reasoning Full evidence chain, agent reasoning, and confidence score in your tenant
Data location Ingested into provider's SIEM — your data leaves your environment Your data stays in your tenant. Analysts access in-environment, not via VPN to theirs
Custom detection support Ruleset owned by provider — change requests take weeks Detection-as-code in your repo. MDR team co-authors detections with you
Containment actions Phone call required to authorise response In-tenant automation with your pre-approved playbooks — no phone tag
Monthly reporting depth PDF with alert count and SLA adherence Drill-down report: entity timelines, detection coverage map, MTTR trends
Exit costs Data locked in provider SIEM. Export takes months and costs extra Your data, your tenant. Leave any time. Detection library stays with you

What your MDR shift looks like

Midnight P1, resolved in 3 minutes, morning brief on your desk.

01
02:14 UTC

Impossible travel flagged

ManySignal agent detects a login from Singapore 8 minutes after a confirmed session in London. Risk score: Critical. Agent enriches with entity history and drafts a containment recommendation.

02
02:15 UTC

MDR analyst reviews in your tenant

On-call analyst opens the case directly in your ManySignal tenant — not a separate portal. Raw logs, entity graph snapshot, similar historic events. No context switching.

03
02:17 UTC

Session terminated in 3 minutes

Analyst approves the pre-authorised containment playbook. Okta session revoked, Slack notification to your security lead, case escalated to P1. Alert to containment: 3 minutes.

04
09:00 UTC

Morning brief in your inbox

Overnight shift summary: 1 P1 resolved, 3 P2 analyst-reviewed false positives documented, 0 missed SLAs. Your team starts the day with full situational awareness.

Service level agreements

SLA credits applied automatically — no claim needed.

Severity Acknowledge Contain Resolve
P1 — Critical 5 min 15 min 2 hours
P2 — High 15 min 1 hour 8 hours
P3 — Medium 1 hour 4 hours 24 hours
P4 — Low 4 hours 24 hours 72 hours

Onboarding timeline

From contract signature to 24/7 production coverage in four weeks.

Week 1

Connectors & baseline

Connect primary telemetry — EDR, IdP, cloud logs, email. MDR team validates coverage against your MITRE ATT&CK priorities.

Week 2

Baseline learning

Agents learn your entity landscape: normal working hours, typical cloud API patterns, expected data flows to seed detection thresholds.

Week 3

Shadow run

MDR team monitors alongside your existing process. Every verdict recorded, no autonomous actions. You review daily and calibrate.

Week 4

Production handover

Autonomy ladder configured per your approved playbooks. MDR team takes 24/7 primary responsibility. You govern; ManySignal executes.

Pricing

Priced by monthly telemetry volume and entity count — no per-alert charges. Talk to sales for enterprise pricing.

Talk to sales
"I was sceptical of MDR — every provider I tried was a black box. ManySignal MDR is the first service where I can see exactly what the analysts saw, why they made the call they made, and what was executed. That transparency is what convinced my board."

CISO — Series D Fintech, London

ManySignal MDR: frequently asked questions

Do we lose visibility into what the MDR team is doing?
Every action is recorded in your tenant's audit log with analyst identity, timestamp, and evidence reviewed. You see more than with a traditional MDR.
Can we keep our own detections?
Yes. Your detection library is yours. The MDR team operates on your rules, with detection-as-code co-authoring available so your engineers and our analysts collaborate in the same repo.
What is the exit path if we want to bring the SOC in-house?
Your data stays in your tenant. Your detection library, entity baselines, and case history come with you. Offboarding is removing MDR team access — no export project, no ransom pricing.
How is MDR priced?
Priced by monthly telemetry volume plus entity count — no per-alert charges. Enterprise volume discounts available. Talk to sales for a custom quote based on your environment.
Are SLA credits automatic?
Yes. If we miss a documented SLA for a confirmed incident, a credit is automatically applied to your next invoice. You do not need to file a claim.
What detection coverage do MDR analysts use, and can we influence it?
MDR analysts operate on ManySignal's 500+ shipped detection rules plus any custom rules your team has authored. Detection-as-code co-authoring is available: your detection engineers and ManySignal MDR analysts can collaborate in the same Git repository, propose new rules, and review each other's changes. Custom detection rules built during the MDR engagement are your intellectual property.
How does the MDR team handle an active incident at 3 AM?
When the triage agent escalates a P1 finding overnight, the on-duty MDR analyst reviews the pre-assembled evidence package and executes approved containment actions within the P1 SLA window — typically 15 minutes from initial escalation. You receive a Slack and PagerDuty notification simultaneously showing the analyst's actions in real time. For incidents requiring customer approval (higher-risk actions), the analyst pages your designated approver with a one-click approve/deny.
What certifications does the MDR team hold?
ManySignal MDR analysts hold industry-standard certifications including GCIH, GCIA, GCFE, and CISSP across the team. The team operates a documented incident response methodology aligned with NIST SP 800-61. Certification details and the MDR team's operational methodology are available for review under NDA as part of the vendor assessment process.
How does ManySignal MDR compare to traditional MDR providers like Secureworks, Arctic Wolf, and Rapid7 MDR?
Traditional MDR providers use proprietary tooling and deliver outcomes through a managed portal — you see summaries and recommendations, not the underlying investigation. ManySignal MDR operates inside your tenant: all investigation evidence, triage reasoning, and action records are in your environment, not a vendor-controlled portal. When you transition away from MDR or bring the SOC in-house, all evidence and detection logic travel with you. Traditional MDRs typically create data lock-in; ManySignal MDR is structured around data portability.

Explore ManySignal MDR

Book a session to see 24/7 analyst coverage, live verdict trails, and P1 containment in action — in your environment.