Skip to main content
Stratum Labs

About Stratum Labs

We build security and compliance analytics for people who have to justify their findings.

Why this exists

Security analytics has a credibility problem. A tool surfaces a risk score, an analyst escalates it, and somewhere downstream a person has to explain the decision to a regulator, a client or a court — with nothing to point at but a number. Meanwhile the detections that produce those numbers are frequently untested against real data, tuned on one customer's environment, and silent about their own limits. Stratum Labs builds the opposite: analytics where every threshold is published, every rule is measured against real exports, and the tool admits when it cannot answer.

How we work

01

Every threshold is published

Each detection ships with its exact criteria — the count, the window, the baseline, the MITRE ATT&CK technique — documented in public. If something is flagged, you can state precisely why to whoever asks. A score you cannot decompose is not a finding, it is a rumour.

02

Measured, not guessed

Thresholds come from running against production-scale exports and counting what happens. Before a rule ships we measure its firing rate on real data, review a sample of what it caught, and establish which of those hits reflect user behaviour rather than the platform and service traffic that surrounds it. Synthetic data cannot settle that question, because it contains only what its author already thought to put in it.

03

Nothing assumed about your business

Detections that depend on a working rhythm learn it from your data, per user. Monday-to-Friday, 24/7, Sunday-to-Thursday and weekend-heavy operations are handled by identical code with identical settings, because a threshold calibrated on one organisation tells you nothing about the next.

04

Honest about limits

When a dataset is too short or too sparse for an analysis, our tools say so rather than returning an empty result that reads like an all-clear. "We found nothing" and "we could not look" are different answers, and a tool that blurs them is actively dangerous in an investigation.

Where this is going

Corelog covers Microsoft 365 audit logs and runs entirely in the browser, because that problem fits in a browser. The wider problem does not: applying the same standard across more security and compliance data means analytics that run at a scale no browser tab reaches, and we would rather let the architecture follow the problem than a slogan. That work is under way and will be described here in concrete terms, not teased. In the meantime, if you use Corelog on a real case and it falls short somewhere, that is the most useful thing you can send us.

Products

Get in touch

For questions, feedback, bug reports or security disclosures, email us directly. We read everything.

hello@stratumlabs.es