Pilot

Evaluate it properly, on your own network

A pilot is a structured evaluation, not a demonstration. The platform is deployed into your environment, your team is trained to operate it, and success is measured against goals agreed in advance.

Scope

What a pilot includes

A complete working system, sized for evaluation rather than for production. Everything runs inside your environment for the duration.

  • A Guardian appliance Placed on a network segment you nominate and have authorised for observation.
  • A Lab Station The analyst environment, running on hardware in your facility.
  • Mobile Sensors For the devices in scope, on the platforms relevant to your work.
  • Training and operating guidance So your analysts run the workflow themselves rather than watching us run it.

Process

How a pilot runs

The shape is consistent; the duration and depth are set with you before anything is deployed.

  1. Scoping

    We establish what you are trying to determine, which environment and devices are in scope, and what authorisation covers them. This is also where we confirm the engagement fits our responsible-use position.

  2. Acceptance goals

    Before deployment, we agree what the pilot has to show for it to be judged successful — in your terms, written down, so the evaluation has a defined answer rather than an impression.

  3. Deployment

    The Guardian and Lab Station are installed in your environment, and the Guardian is enrolled to the Station. Isolated and air-gapped deployments are supported configurations.

  4. Training

    Your analysts are trained on the operating workflow: running an engagement, ingesting and correlating evidence, interpreting findings, and producing reporting.

  5. Operation

    Your team runs the platform on real work, with support available. The point is to see how it behaves in your conditions, not in ours.

  6. Review

    We review the outcome against the acceptance goals agreed at the start, including what the platform did not show, and what that means for a production deployment.

Evaluation

What a pilot is designed to answer

Does it see what we need it to see?

Whether observation on your network and your devices produces material that is actually useful to your investigations.

Does correlation hold up?

Whether cross-source matches are ones your analysts agree with when they examine the basis for them.

Can our people operate it?

Whether your team can run the full workflow without us, which is the real test of whether a deployment will survive contact with normal workload.

Does it fit our constraints?

Whether it operates within your network, security and evidence-handling requirements — including isolation requirements.

Is the output defensible?

Whether the reporting and the integrity record stand up to the scrutiny your cases actually attract.

What does it not do?

An honest account of the limits we found in your environment. A pilot that only produces good news has not been run properly.

Get started

Request a pilot

Tell us what you are trying to determine and we will tell you honestly whether a pilot is the right way to determine it.

Before you write

Please do not include case material, evidence, or personal data about a third party in an enquiry. If your enquiry is sensitive, say so and we will agree a more appropriate channel before you send any detail.

Pilot request

A few sentences on the investigative or security problem you are addressing is more useful than a feature list. Please do not include case material, evidence, or personal data about a third party.

This opens a message in your own email application so you can review it before sending. Nothing is transmitted from this page.