Verified automation, for systems that handle the work that matters.
Signum turns every incident in Slack or Teams into a sealed, regulator-ready record on your ITSM ticket — then tells you what a regulator would find, before they do.
Less toil, every incident on the record.
Capture happens where the work does — Slack or Teams — and the summary, RCA and customer note are drafted on demand, written back to the ticket you already trust. See the platform →
Regulator-ready, on a button.
The same sealed evidence powers on-demand gap, policy-conformance and process reports — cited to source, categorised by obligation and priority. See the intelligence →
Signal · Sign · Seal.
Latin signum — sign, mark, seal, signal. Three faces of one idea, and the architecture of the platform: receive, interpret, act.
Signal
Lat. information receivedAn incident channel lights up; a ticket is raised. Signum captures the conversation losslessly, where the work already happens — no new tool to adopt.
Sign
Lat. meaning conveyedThe transcript becomes structured signals and regulator-ready analysis — interpreted on demand, grounded in citations back to the source timeline.
Seal
Lat. authority grantedEvery report, config and decision is drafted, approved, propagated and reversible — written back to your system of record under an append-only audit trail.
A platform that knows what it just did, and why.
One record. At your pace.
Real screens from the operator console. Click through the loop — capture, interpret, govern, report.
Signal — capture. An incident channel binds to its ticket by naming convention — no webhook into your ITSM, no second place for the conversation to live. The transcript is written back as versioned attachments as it unfolds.
Sign — interpret. Generate a regulator-ready RCA, a customer note or an internal analysis. The model runs only when you ask, and each result is cached by the incident's content hash — re-read it free, regenerate only when the logs change.
Seal — govern. Configuration, report types and policy are drafted, reviewed and propagated only on admin confirmation — each change in a hash-chained, append-only trail, with a last-known-stable you can restore in one step.
Report — assure. On demand, read the incident against the regulations, your own process and policy, and good practice — every finding cited and categorised. See the five reports →
Know what a regulator would find — before they do.
On demand, Signum reads an incident — or your whole quarter — against the regulations, your own ITIL/ITSM process and policy, and good practice, and shows exactly where to improve. Regulator-ready, on a button.
- ITSM process analysis
- Your enacted incident process assessed against ITIL and your designed process — SLA/OLA, classification, escalation, approvals, RACI gaps.
- Regulatory gap analysis
- Findings vs FCA · DORA · MiCA · MAS · ADGM, categorised by obligation and priority, with a notification-trigger checklist and remediation backlog.
- Policy conformance & document gap
- Did the handling follow your documented process — and where are the gaps in the policy documents themselves?
- To-be process & implementation guide
- On request, a redesigned process mapped to your tool with implementation steps — a draft for humans to review and apply.
- Improvement / automation blueprint
- Automations achievable in your own ITSM tool's primitives, mapped to the gaps — proposals for your team, never auto-applied.
Run it on a single incident or a selection — every finding traceable to its incident and the regulation, grounded in citations, redacted per reader, and a draft for human sign-off. Explore the five reports →
The decisions used to vanish when the bridge call ended. Now the timeline, the root cause and the evidence are on the ticket before the channel goes quiet — and the auditor reads the same record we do.
Head of Service Delivery · regulated digital-asset custodian Illustrative of the current deployment pattern — named references are published only with the customer's agreement.
Connect what you already run.
A pure core behind ports and adapters. Swap the collaboration tool, the ITSM or the model without rewriting a line of business logic.
Trust is structural, not a footer.
Architecture you can hand to a CISO, and an evidence chain you can hand to a regulator.
- Architecture
- Vendor-agnostic core, ports-and-adapters; no business data in a Signum-owned store — your ITSM ticket is the system of record.
- Encryption
- AES-256-GCM at rest and field-level encryption for governed content; TLS enforced on every adapter; secrets referenced by environment, never inline.
- Audit
- Append-only, hash-chained audit log per tenant; verifiable evidence export; access is granted and recorded, never assumed.
- Privacy
- Read-time redaction — raw, redacted and pseudonymous modes applied per consumer; names retained for investigators, tokenised for analytics and regulators.
- Residency
- Deploy in your own cloud (self-managed) or as SaaS; data partitioned by deployment; customer-managed keys available.
Built to be defensible under
This is the scope the platform is built to be defensible under — not a claim of held certification. SOC 2 and ISO 27001 are on the roadmap; ask for current attestation status and the security pack.
Three tiers. No dark patterns.
Real numbers, not a "book a call to see pricing" wall. Self-managed or fully hosted.
Team
For a single service-delivery team adopting governed incident knowledge.
- Up to 200 incidents / month
- One collaboration + one ITSM connector
- On-demand reports, content-hash caching
- Hash-chained audit trail
Business
For multi-team operations needing governance, SSO and cost control.
- Unlimited incidents
- All connectors · multi-tenant
- SSO (OIDC) · SAML · SCIM
- Governance workflow · cost budgets
- Custom report types
Enterprise
Self-managed in your cloud, customer-managed keys, bespoke regulatory scope.
- Self-managed or private SaaS
- Customer-managed encryption keys
- On-prem / private model serving
- Dedicated support & onboarding
- Security & DPA review
See your next incident, sealed.
A 30-minute walkthrough against your own stack. We will show the capture, the provenance and the audit chain — no slideware.