Observed arrival · 2026-09-02
SignalArray Wants Four Alerts to Become One Cited Incident
SignalArray is a proposed open-source, self-hostable security layer that normalizes findings, correlates them with deterministic rules, and has a read-only agent investigate the resulting cases.
Field notes
The page separates detection, correlation, investigation, and response rather than treating them as one model-driven pipeline. Its proposed signal contract is versioned as signalarray.signal/v1alpha1, preserves native provenance, and uses immutable updates instead of overwriting evidence. Correlation is described as a data-defined proof with replayable rules, while the investigator receives bounded read-only access and must cite the evidence behind its conclusions. The project is explicitly marked as a specification draft with contracts under review.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue