The short answer
- Your dataConfiguration and telemetry metadata only. Never raw events.
- Where it runsHosted single-tenant, or in your tenant where policy requires. Deployment and access are agreed before data is shared.
- Model accessYour own endpoint, or ours, agreed with your security team before the assessment.
- Supported platformsSplunk, Google Security Operations (Chronicle), and Microsoft Sentinel. We confirm the checks and inputs available for your platform when we agree the scope.
- ReassessmentNew approved exports or read-only API inputs support a fresh assessment. Ongoing engagements have an agreed collection method and cadence.
What we read
Rule definitions, dependency inventories (macros, lookups, enabled state), and telemetry metadata: which sources and fields exist, their event counts and field population, and when each was last seen. Through exports your team reviews, or read-only API access you authorize.
What we keep
Assessment inputs and findings are held for the engagement, then returned to you and deleted from Dectyl, along with access credentials. Ongoing engagements retain prior assessments only as agreed: data handling and retention.
What never happens
NOTHING INSTALLED FOR THE ASSESSMENT
WE NEVER RUN ATTACKS
NO RAW EVENTS COLLECTED
WE NEVER CHANGE YOUR RULES
WE NEVER ALERT INTO YOUR QUEUE
What we do
VERIFY
READ-ONLY
HAND YOU THE EVIDENCE