Threat detection for security teams too small to staff a night shift.

Wardell reads your cloud, identity and endpoint logs, groups related alerts into one case, and pages a Wardell analyst when something needs a human at 3 am.

Wardell alert queue: 23 open alerts grouped into 9 cases, with severity chips and owners

Reads the logs you already have, with read-only access

AWS logo

AWS

Okta logo

Okta

Microsoft 365 logo

Microsoft 365

Google Workspace logo

Google Workspace

GitHub logo

GitHub

Cloudflare logo

Cloudflare

Slack logo

Slack

1Password logo

1Password

What stops landing on your desk in the first week

What stops landing on your desk in the first week

Three jobs a small team does by hand today, and what Wardell does instead.

Cases, not a wall of alerts

Wardell groups alerts that share a user, a host or an app into one case with a timeline. A phishing click, an OAuth consent and three inbox rules read as one story. Known-good noise closes itself and stays searchable.

A Wardell case timeline grouping six alerts from Microsoft 365 and Proofpoint

Detections you can read and change

Every rule is plain YAML you can open, test against the last 30 days and edit. Start with 312 managed detections, then write your own for the systems only you run.

A Wardell detection rule in YAML with 30-day test results

A person on call when your team is not

From 6 pm to 8 am and all weekend, a Wardell analyst takes the page, acknowledges in under five minutes, contains what they can and writes up what they did before your team logs in.

The Wardell on-call schedule and this week's page log

See which attacks your logs can catch, and which they cannot

See which attacks your logs can catch, and which they cannot

The coverage map lines every connected source up against the MITRE ATT&CK matrix, so gaps show up before an auditor or an attacker finds them.

Wardell ATT&CK coverage matrix: 142 of 201 techniques covered, with recommended gaps marked

142 of 201 techniques

covered for a typical 400-person company on four sources

One source away

each gap names the log source that would close it

Audit-ready

exports as PDF and CSV evidence for SOC 2 and ISO 27001

Useful in a week, not a quarter

Useful in a week, not a quarter

No agents to install. Read-only keys, a week of tuning with an engineer, then night coverage switches on.

Day 1

Day 1

Connect your first sources

Connect your first sources

Okta or Google Workspace, Microsoft 365 and AWS take about 20 minutes each with read-only keys. Alerts start grouping into cases the same afternoon.

Okta or Google Workspace, Microsoft 365 and AWS take about 20 minutes each with read-only keys. Alerts start grouping into cases the same afternoon.

Days 2 to 6

Days 2 to 6

Tune with a detection engineer

Tune with a detection engineer

For five business days an engineer closes the noise specific to your company with you in a shared Slack channel, and writes down every exception.

For five business days an engineer closes the noise specific to your company with you in a shared Slack channel, and writes down every exception.

Day 7

Day 7

Turn on night coverage

Turn on night coverage

Paging starts. Every Monday you get a written report of what fired, what closed itself and why, and what the night shift did.

Paging starts. Every Monday you get a written report of what fired, what closed itself and why, and what the night shift did.

Teams of two to ten, covering hundreds of people

Teams of two to ten, covering hundreds of people

What changed for three customers in their first quarter.

96%

fewer alerts to read, six weeks in

“We used to start every Monday with 400 unread alerts. Now it is nine cases and a note from whoever was on call.”

Renata Oyelaran

Head of Security, Tallis Health, Nashville, TN

2m 38s

from the page to a person on the case

“The consent phishing case came in at 2:51 am. By the time I woke up it was contained and written up for our auditors.”

Marcus Heller

IT Director, Brightwater Freight, Columbus, OH

3 people

covering 1,400 employees around the clock

“We are three people. Wardell is the only reason we have a night shift at all, and it costs less than one hire.”

Leah Sandoval

Security Lead, Loomis Pay, Austin, TX

Priced per employee, never per gigabyte

Priced per employee, never per gigabyte

Add every log source you have. The bill does not move.

Yearly saves about two months.

Team

For companies with 50 to 250 employees and one person on security.

$9per employee a month, billed yearly
  • Up to 6 log sources
  • Alerts grouped into cases, noise auto-closed
  • 312 managed detections
  • Analyst help on weekdays, 8 am to 6 pm
  • 90 days of searchable history
Get a 48-hour threat review

Business

Most teams pick this

For 250 to 2,000 employees. Nights and weekends are covered.

$15per employee a month, billed yearly
  • Unlimited log sources
  • A Wardell analyst on call nights and weekends
  • 5-minute acknowledge target on every page
  • Write your own detections in YAML
  • One year of searchable history
  • ATT&CK coverage and audit exports
Get a 48-hour threat review

Enterprise

Over 2,000 employees, or a regulated industry.

CustomPriced with you
  • Everything in Business
  • US or EU data residency
  • A named detection engineer
  • SSO, SCIM and an audit log API
  • Three years of history, 99.9% uptime SLA
Talk to our team

Prices in USD. Log volume never changes the price. Every plan starts with a 48-hour threat review of one log source.

Questions security leads ask us first

Something else on your mind? Our team answers within one business day.

In the US region you pick (Oregon or Virginia) or in Frankfurt for EU teams. Logs are encrypted at rest with keys per customer, and you can export or delete everything from Settings at any time.

It should remove them. Wardell groups related alerts into one case and closes the ones that match known-good patterns. Teams in their first month see a median of 214 alerts a day become 9 cases.

Per monitored employee, not per GB. Log volume does not change your bill, so you never have to choose between visibility and budget.

On Business and Enterprise, a Wardell analyst is on call from 6 pm to 8 am your time and on weekends. They acknowledge pages in under five minutes, contain what they can, and write up what they did before your team logs in.

Yes. Plans are yearly or monthly, and every detection you wrote exports as plain YAML. Your logs stay in the format they arrived in.

The coverage matrix, case history and on-call log export as PDF and CSV evidence that auditors accept for monitoring and incident response controls.

Send us one week of logs. We send back what we found.

Connect one source with a read-only key. Within 48 hours you get a written report of what Wardell would have caught. No contract, and you can disconnect at any time.

Use this free template

Create a free website with Framer, the website builder loved by startups, designers and agencies.