Security tools that never see your data
Investigation software has a habit of asking you to upload the very evidence you are trying to protect. We build the other kind: tools that run entirely inside your browser, where the data already is.
- Browser-only
- No account
- No telemetry
- Open detection logic
What we build
One tool is live and free. The next is in development.
Corelog
Forensic investigation for Microsoft 365 audit logs
Drop a Microsoft Purview Audit Search CSV export and get a stratified activity matrix, 11 MITRE ATT&CK-mapped anomaly heuristics, geolocation mapping and an exportable incident report — instantly, in your browser.
A second tool, same approach
We are extending the local-first model beyond Microsoft 365. Nothing to sign up for yet — it will appear here when it exists.
Why local-first matters in an investigation
The evidence stays where it is
An audit log export is a complete record of everything your people did — email addresses, IP addresses, device identifiers, file names. Uploading it to analyse it means creating a second copy of your worst-case breach data, on someone else's infrastructure. We think that trade is a bad one, so we removed the upload.
Data residency by construction
There is no region to choose, no data processing agreement to negotiate, no sub-processor list to audit. The file is read by your browser and never transmitted. For teams working under GDPR, client NDAs, or cross-border restrictions, that is not a feature — it is the whole reason the tool is usable at all.
Detection logic you can read
Every heuristic is documented with its exact threshold, its window, and the MITRE ATT&CK technique it maps to. You should be able to explain to a regulator, a client, or a court why a specific event was flagged. "The model said so" is not an explanation.
Nothing to lock into
No account, no tenant, no ingestion pipeline, no minimum commitment. Open a tab, drop a file, close the tab. If we disappeared tomorrow, you would lose a bookmark.
Who we build for
Incident responders
Reconstruct attacker timelines in compromised M365 tenants directly from Purview exports. No SIEM ingestion lag, no cloud account required, no data sharing.
Security analysts
Surface anomalous patterns across users, operations, and workloads in minutes. The activity matrix makes outliers visible that are invisible in raw log files.
Compliance investigators
Produce a reproducible, auditable Markdown report of findings — including exact event timestamps, operation counts, and flagged anomalies — suitable for regulatory or legal documentation.
MSSPs & consultants
Investigate client data without ingesting it into your own infrastructure. The browser-only architecture satisfies most data residency requirements by default.
What comes next
Corelog covers Microsoft 365 audit logs. We are working on a second tool that applies the same local-first approach to a wider set of investigation sources. It will be announced here when there is something real to show — no waitlist, no countdown, no pre-orders.
Get in touchCorelog is free and available now
Drop a Microsoft Purview audit export and start investigating. No sign-up.