M ManySignal

Platform

One pipeline from telemetry to governed response

ManySignal owns the whole line — ingestion, understanding, detection, triage, investigation, and response — so no context is lost between tools.

  1. 1

    Connectors and ingestion

    Declarative connector manifests pull telemetry from AWS CloudTrail, Okta, CrowdStrike, GitHub, GCP and more. Idempotency keys dedupe at the gate; a dead-letter queue catches what fails; silent connectors are flagged automatically.

  2. 2

    Entity graph and baselines

    Events normalise into a temporal graph of identities, assets, and the edges between them. A baseline worker continuously computes per-entity behavioural profiles — active hours, geographies, event volume — with confidence that grows as data warms.

  3. 3

    Detection engine

    Deterministic rules with streaming, threshold, and windowed evaluation. Rules run in stages — active or alert-only — so new detections prove themselves before they page anyone. Findings are deduped by entity and window.

  4. 4

    AI triage

    The triage agent runs a question set matched to the detection type: intel enrichment, historical frequency, correlated findings, graph proximity to critical assets, behavioural deviation, business context. Weighted signals synthesise into a verdict with a confidence score, and the full reasoning trace is stored.

  5. 5

    Cases and investigation

    Escalations become numbered cases with priority, SLA clocks, and an immutable timeline. The investigation agent reconstructs the attack chain and maps affected entities before a human ever opens the case.

  6. 6

    Workflows and response

    Response playbooks are DAGs of governed actions with confirmation nodes. Dry-run shows exactly what would execute, require approval, or be blocked. Reversible actions record rollback state; the kill switch stops everything.

  7. 7

    Reporting

    Incident, executive, control-effectiveness, and MDR client reports are generated straight from case and finding data — cases opened and resolved, false-positive rates, MTTR, severity mix.

The technical bet

A maintained, temporal entity graph plus statistical behavioural baselines makes autonomous triage defensible in a way that prompting an LLM over raw logs never will. Agents answer structured questions against structured context — so every verdict can be audited signal by signal.

Grounded, not guessed

Agents query the graph, baselines, and intel stores. No free-form log prompting, no hallucinated evidence.

Traced end to end

Every question, answer, weight, and verdict is stored as a reasoning trace on the agent run.

Staged rollout

Detections and autonomy levels graduate through stages, so trust is earned with evidence.

18B
events processed monthly
94%
alerts triaged autonomously
3m
median time to verdict
180+
enterprises trust ManySignal

Customer story

"We used to have a six-analyst queue that never emptied. ManySignal reduced triage work to governance reviews — our team now focuses on what only humans should decide."

VP Security Operations

Fortune 500 fintech, 40B+ transactions annually

See how it works

Outcomes delivered

10x
faster alert triage
72%
autonomous verdicts
SOC hiring paused
backlog cleared by agents

What security leaders say

“The autonomy ladder is the feature nobody else has. Recommend-only to approve-gated to autonomous, per action class, revocable any time.”

Tomás Herrera

Security Engineering Lead, Meridian Retail

“Behavioural baselines cut our impossible-travel false positives to near zero. The agent knows what normal looks like per identity.”

Aisha Bello

SOC Manager, Skyfarer Air

“Month-end MDR client reports used to take my team three days. Now the report agent generates them from case data in minutes.”

Grace Whitfield

MDR Practice Director, Quillstone Legal

Platform: frequently asked questions

Is ManySignal a SIEM, SOAR, or MDR?

It's an agentic SOC platform that spans all three: SIEM-grade ingestion and detection, SOAR-grade governed response, and MDR-grade 24/7 outcomes and reporting — in one pipeline with one audit trail.

What is the entity graph?

A temporal graph of identities, assets, and their relationships, built from normalised telemetry. Agents reason over it — with behavioural baselines per entity — instead of prompting raw logs.

How does response stay safe?

The autonomy ladder gates every action class (recommend-only, approve-gated, autonomous), with blast-radius limits, dry-run previews, rollback state, and a tenant kill switch.

How quickly can we deploy?

Declarative connectors and shipped detections mean most teams see agent verdicts on live alerts within days.

What are the five AI agents and what does each do?

Detect identifies suspicious events using deterministic rules and behavioural baselines. Triage evaluates every finding with a structured question set and produces a confidence-scored verdict. Investigate reconstructs the attack chain and blast radius. Respond executes governed containment actions. Report generates case summaries, monthly MDR reports, and compliance evidence packages.

How does ManySignal handle our existing security tool stack?

ManySignal integrates with your existing tools via 300+ pre-built connectors. Your EDR, IdP, cloud audit logs, and SIEM can all feed into ManySignal as data sources. Response actions write back to the same tools — isolate via CrowdStrike, disable via Okta, block via Palo Alto — without replacing them.

What does the implementation and onboarding process look like?

Week 1: connector configuration and first live alerts. Weeks 2–3: detection tuning and baseline warm-up. Week 4: analyst workflow integration and autonomy ladder configuration. A named implementation engineer is assigned throughout; the programme is included with every subscription.

How is ManySignal priced and is there a free trial?

Pricing scales with protected assets and autonomy tier — not per-GB or per-alert. A sandboxed trial tenant with pre-loaded detections and simulated alert data is available after a 30-minute demo session. Production trials on your own data are available for qualified enterprise prospects.

What is the difference between an in-house deployment and the MDR option?

In-house: your team governs the autonomy ladder, reviews escalations, and manages the platform. MDR: ManySignal's 24/7 analyst team manages triage escalations, governs responses, and delivers monthly client reports — on the same platform, in your tenant, with full transparency into every decision.

What compliance certifications does the platform itself hold?

SOC 2 Type II (audited annually), ISO 27001, and HIPAA-eligible infrastructure. The current SOC 2 report and penetration test summary are available under NDA. FedRAMP Moderate authorisation is in progress for the GovCloud deployment.

See the agentic SOC in action

Watch AI agents work a real alert queue — verdicts, evidence, and confidence scores included. In-house SOC or MDR, your call.