DECTYL

Where it runs · For your security team

Your detections stay yours.

← dectyl.io

  • Your dataConfiguration and telemetry metadata only. Never raw events.
  • Where it runsHosted single-tenant, or in your tenant where policy requires. Deployment and access are agreed before data is shared.
  • Model accessYour own endpoint, or ours, agreed with your security team before the assessment.
  • Supported platformsSplunk, Google Security Operations (Chronicle), and Microsoft Sentinel. We confirm the checks and inputs available for your platform when we agree the scope.
  • ReassessmentNew approved exports or read-only API inputs support a fresh assessment. Ongoing engagements have an agreed collection method and cadence.
What we read

Rule definitions, dependency inventories (macros, lookups, enabled state), and telemetry metadata: which sources and fields exist, their event counts and field population, and when each was last seen. Through exports your team reviews, or read-only API access you authorize.

What we keep

Assessment inputs and findings are held for the engagement, then returned to you and deleted from Dectyl, along with access credentials. Ongoing engagements retain prior assessments only as agreed: data handling and retention.

NOTHING INSTALLED FOR THE ASSESSMENT
WE NEVER RUN ATTACKS
NO RAW EVENTS COLLECTED
WE NEVER CHANGE YOUR RULES
WE NEVER ALERT INTO YOUR QUEUE

What we do

VERIFY
READ-ONLY
HAND YOU THE EVIDENCE