Skip to main content
Stratum Labs
Local-first security tooling

Security tools that never see your data

Investigation software has a habit of asking you to upload the very evidence you are trying to protect. We build the other kind: tools that run entirely inside your browser, where the data already is.

What we build

One tool is live and free. The next is in development.

AvailableFree

Corelog

Forensic investigation for Microsoft 365 audit logs

Drop a Microsoft Purview Audit Search CSV export and get a stratified activity matrix, 11 MITRE ATT&CK-mapped anomaly heuristics, geolocation mapping and an exportable incident report — instantly, in your browser.

In development

A second tool, same approach

We are extending the local-first model beyond Microsoft 365. Nothing to sign up for yet — it will appear here when it exists.

Why local-first matters in an investigation

01

The evidence stays where it is

An audit log export is a complete record of everything your people did — email addresses, IP addresses, device identifiers, file names. Uploading it to analyse it means creating a second copy of your worst-case breach data, on someone else's infrastructure. We think that trade is a bad one, so we removed the upload.

02

Data residency by construction

There is no region to choose, no data processing agreement to negotiate, no sub-processor list to audit. The file is read by your browser and never transmitted. For teams working under GDPR, client NDAs, or cross-border restrictions, that is not a feature — it is the whole reason the tool is usable at all.

03

Detection logic you can read

Every heuristic is documented with its exact threshold, its window, and the MITRE ATT&CK technique it maps to. You should be able to explain to a regulator, a client, or a court why a specific event was flagged. "The model said so" is not an explanation.

04

Nothing to lock into

No account, no tenant, no ingestion pipeline, no minimum commitment. Open a tab, drop a file, close the tab. If we disappeared tomorrow, you would lose a bookmark.

Who we build for

Incident responders

Reconstruct attacker timelines in compromised M365 tenants directly from Purview exports. No SIEM ingestion lag, no cloud account required, no data sharing.

Security analysts

Surface anomalous patterns across users, operations, and workloads in minutes. The activity matrix makes outliers visible that are invisible in raw log files.

Compliance investigators

Produce a reproducible, auditable Markdown report of findings — including exact event timestamps, operation counts, and flagged anomalies — suitable for regulatory or legal documentation.

MSSPs & consultants

Investigate client data without ingesting it into your own infrastructure. The browser-only architecture satisfies most data residency requirements by default.

What comes next

Corelog covers Microsoft 365 audit logs. We are working on a second tool that applies the same local-first approach to a wider set of investigation sources. It will be announced here when there is something real to show — no waitlist, no countdown, no pre-orders.

Get in touch

Corelog is free and available now

Drop a Microsoft Purview audit export and start investigating. No sign-up.

Open Corelog