"The signal in the noise" has been our tagline since day one. Usually that's a metaphor — cutting through alert fatigue, surfacing the connection that matters out of the thousands that don't. We're building the version where it's not a metaphor anymore.
The problem with collective threat intelligence
Every security vendor wants to say some version of "when we see a threat at one customer, we protect all our customers." It's the right idea. It's also usually built one of two ways, and neither one is comfortable if you're the customer:
- Everyone's data gets pooled somewhere. Your traffic, your indicators, your incidents — sitting in a shared analytics store the vendor can see, alongside every other customer's. You're trusting the vendor not to look, not to leak, not to get breached themselves.
- Nobody's data gets shared at all. Safer, but it throws away the entire point. Your fleet's local sighting of a new threat stays local. The other customer who gets hit by the same thing tomorrow gets no warning.
We think there's a third option, and we're building it.
What if the vendor couldn't see it either?
The architecture we're building lets an organization's devices flag a suspicious pattern — a beacon, an anomalous traffic signature, a known-bad indicator — and contribute it toward a fleet-wide picture, without that organization's raw data ever being visible in plaintext to anyone. Not to other customers. Not to us.
Here's the shape of it:
Locally, every device is already listening. Each enrolled endpoint watches its own network behavior in real time — not just "is this connection allowed," but the underlying pattern: is this process talking to the internet on a suspicious cadence, is there a periodic beacon buried in traffic that otherwise looks like noise. This part runs entirely on your own infrastructure, on your own data, and never needs to leave your organization at all to be useful — every fleet gets this analysis for itself, immediately, with nothing shared.
The interesting part happens when a pattern might matter beyond one customer. Instead of sending us your data to find out, we use privacy-preserving cryptography — techniques originally developed for exactly this kind of problem — to let your systems ask a much narrower question: "has anyone else seen this specific indicator?" And critically, the answer to that question can be computed without ever decrypting your submission, or anyone else's, in the process.
This is where fully homomorphic encryption and private set intersection come in — both are established cryptographic techniques for computing on data while it stays encrypted the entire time. We didn't invent the math. We're building the pipeline that applies it to the specific shape of network threat intelligence: match an indicator, count how many organizations have independently seen it, and only then — and only as an aggregate, never as "which organizations" — surface the result back out.
Nobody holds the key alone
The part we think matters most: even the final decryption isn't something we control unilaterally. Confirming a cross-organization pattern requires cooperation between our systems and at least one of the organizations that actually observed it. We can't unlock anyone's data by ourselves. No customer can unlock another customer's contribution by themselves. The only thing that ever comes out the other end is the confirmed signal — "this pattern has now been independently observed across multiple organizations" — never the underlying data that produced it.
And when that signal is confirmed, it goes back out to everyone who might need it. One customer's local sighting becomes every customer's advance warning, without a single byte of that customer's actual traffic ever being something we, or anyone else, could read.
Signal in the noise, literally
There's a nice piece of symmetry here that we didn't have to force. The actual technique for separating a real threat pattern from background traffic noise is, mechanically, a noise-cancellation problem — model what normal looks like, subtract it out, and whatever's left over is the signal. It's the same idea whether it's happening locally on one device or across an encrypted aggregate spanning a hundred organizations.
We've said "the signal in the noise" since before we knew exactly how literal we'd eventually make it. This is that.
Where this is headed
This is a multi-phase build, not a switch we're flipping tomorrow. The local, per-organization half of this — noise cancellation and pattern detection on your own fleet, with zero data ever leaving your organization — comes first, because it stands on its own and delivers value immediately. The cross-organization layer, with the privacy-preserving cryptography described above, follows once that foundation is solid.
We'll be sharing more as each phase lands. For now: the thesis is that collective defense and airtight data privacy were never actually in tension. We just needed the right cryptography to prove it.