EVIDENCE-LED SECURITY INVESTIGATION

Build the case before you make the call.

Matter of Proof assembles alerts, identity events, endpoint telemetry, and cloud activity into an evidence-linked investigation matter—so analysts can review what happened, what supports it, what remains uncertain, and what should happen next.

AI-assisted. Source-linked. Human-approved.

Investigation Matter · illustrative sampleMOP-SAMPLE-0418
Needs reviewSample data · no real incident

Improbable travel followed by finance file access

Evidence index
Known fact
Sign-in from Buffalo, NY, then a second sign-in from Warsaw 16 minutes later
identity · sample-idp · evt 4f21a9
Known fact
Legacy authentication used on the second sign-in; MFA not challenged
identity · sample-idp · evt 4f21c7
Known fact
Eight files opened in a finance file share within four minutes
cloud · sample-suite · audit 88d1
Contradictory
Endpoint agent reports the registered laptop asleep during both sign-ins
endpoint · sample-edr · host wks-1042
Unresolved
Outbound session to an unclassified hosting range, 2.1 MB transferred
network · sample-fw · flow 77120
Timeline
  1. 09:02First sign-in succeeds from the expected location
  2. 09:18Second sign-in succeeds from a second country
  3. 09:21Finance file share accessed, followed by the outbound session
Connected entities
  • user · a.reyes (sample account)
  • host · wks-1042
  • asset · finance file share
  • network · 203.0.113.24 (documentation range)
Confidence assessment
Moderate — account misuse

Basis: two sign-ins separated by an infeasible distance, corroborated by a file-share audit record. Reduced by one contradictory endpoint record that places the registered device asleep.

Unresolved question

Was the outbound session initiated by the same account, or by a scheduled backup job on the same subnet?

Recommended next step · human approval
Suspend the session and request a device check

AI may collect, correlate, summarize, score confidence, and draft; every matter receives human review; AI cannot close critical matters alone.

Assigned for review · T. Alvarez, Tier 2 — not yet approvedSample 09:24 UTC
The evidence standard
Source-linked
Every claim carries the system and record it came from.
Confidence stated
An assessment that states the basis it rests on.
Uncertainty visible
Unresolved questions and contradictory evidence stay on the page.
Human-approved
High-impact steps wait for a named analyst to approve them.
112 min → 28 min mean review time
18,400+ Investigation Matters
100% human review

Aggregate platform results · Jan 2024–Jun 15 2026 · Internal operational database and tenant analytics.

The workflow

Evidence before conclusion. Sequence before noise.

  1. 01Step
    Collect the record

    Alerts, identity events and telemetry are collected from your SIEM, EDR, identity provider and cloud control plane into one Matter, each row keeping its source reference.

  2. 02Step
    Reconstruct the matter

    Entities are connected and the sequence rebuilt, with known facts, contradictory evidence and unresolved questions kept apart.

  3. 03Step
    Approve the next step

    Recommended next steps reach a named analyst with confidence stated. A human approves, and the approval history stays on the record.

The artifact

Anatomy of an Investigation Matter.

A Matter is one connected record. It holds the evidence, the sequence, the uncertainty and the decision — in a form that survives review months later.

Evidence index
Every claim is a numbered row with its source system, record reference and collection time.
Connected entities
Accounts, hosts, assets and network endpoints linked across the systems that hold the record.
Reconstructed timeline
Events placed in sequence, with gaps left visible rather than smoothed over.
Confidence with a basis
A stated assessment, the evidence it rests on, and what would change it.
Known, unresolved, contradictory
Kept apart so a reviewer can see what is settled and what is not.
Approval history
Recommended steps, the named analyst who approved them, and an immutable record of the decision.
A structured evidence review with source tabs and timeline annotations.
Attack Path Mapper

The path between entities, with every step cited.

Entities are connected into a readable path rather than a decorative map. Each connection names the record that supports it, and a step with no supporting record is shown as an open question instead of a line.

See the investigation workflow
Connected path · illustrative sampleMOP-SAMPLE-0418
  1. 01
    Identity

    A sign-in is accepted, and the session it created is recorded with the source event.

  2. 02
    Endpoint

    Process and device records are placed against that session, including the ones that contradict it.

  3. 03
    Cloud

    Access to data and control-plane activity is connected to the same principal and time window.

  4. 04
    Network

    Outbound sessions are attached where a flow record supports the link, and left open where none does.

Unsupported links are listed as unresolved questions, not drawn as edges
A security team reviews evidence before approving a response action.
Human authority preserved

No response leaves without a named approval.

Recommended next steps are drafted with their supporting evidence attached and their uncertainty stated. A named analyst approves, requests more evidence, or rejects — and the decision stays on the record.

AI may collect, correlate, summarize, score confidence, and draft; every matter receives human review; AI cannot close critical matters alone.

Evidence sources

Connected to the systems that hold the record.

Browse integrations →
SIEM
EDR
Identity
Cloud
Email
Network
Ticketing
Compliance
How the work holds up

Uncertainty made visible. Human authority preserved.

Human authority preserved

Containment and identity actions wait for a named analyst; the approval stays on the record.

Evidence before conclusion

Every recommendation cites the alert, log line and identity event it rests on.

One connected record

An unbroken account of who decided what, when, and on which evidence.

Least-privilege access

Integrations request the minimum scopes needed — and we publish what we ask for.

Observe-only option

Run Matter of Proof in observe-only mode for the first weeks, with no write access.

Security analysts compare a source-linked incident timeline during a review.
Review is the product · evidence is read, questioned and signed off by a named analyst
Security leaders review an evidence-backed executive incident brief.
Executive Incident Brief

A brief a leader can read, and defend.

Impact, scope, what is known, what remains unresolved, and the actions approved — drafted from the Matter and prepared for review before it is sent.

See the investigation workflow
Pricing

Plans sized to the matters you open.

See full pricing →
Investigation Desk

Up to 5 analysts

$699/month
Start with Investigation Desk
For multi-shift teams
Evidence Operations

Up to 20 analysts

$1,799/month
Choose Evidence Operations
Enterprise Review

Custom volume, SSO/SAML, and residency controls

From $4,500/month

99.9% uptime commitment

Scope Enterprise Review

Save 15% with annual upfront billing

Bring one investigation. Leave with the evidence organized.

Matter of Proof connects to the systems you already run, builds the Matter, and waits for a named human to approve what happens next.