SearchCentral watches your tenant's sign-in and audit logs, explains every detection in plain English, and lets your officer acknowledge or remediate it from their phone. No agents on a single endpoint.
Sample tenant data. The simulator below writes into it as you use it.
Pick one of three Microsoft 365 attack paths and launch it. The attack is simulated — the detection logic, the MITRE mapping and the alert your officer receives are exactly what ships. Nothing here is pre-recorded.
No query language to learn, no endpoint rollout to negotiate, no data leaving your tenant.
Every detection arrives with what it means and what to do, written for a human on a Sunday morning — not a KQL snippet.
Reads Microsoft 365 audit and sign-in logs through Graph. Nothing to install, package or defend on staff machines.
Acknowledge or apply a named remediation from the phone, behind an explicit confirm. Hunting stays on the SearchCentral host, by design.
Every rule carries its technique ID, so your board reporting and your auditor's framework already line up.
Runs on hardware you own, authenticated with your own Entra ID app registration. The audit buffer never leaves the tenant.
Prove the detections fire before you need them. Three real Microsoft 365 attack paths, on demand, against a test account.
That is the SearchCentral side — the app registration, the poller, and your first real detections. No endpoint rollout to schedule and no forwarder to babysit. Reaching the host from a phone is separate work on your network, and how long it takes depends entirely on what you already run.
Create a read-only Entra ID app registration and point SearchCentral at it. Nothing is installed on staff machines and nothing changes on your network.
READ-ONLY BY DEFAULTThe poller reads sign-in and audit logs continuously, maps every hit to a MITRE ATT&CK technique and writes it to an audit buffer on your own host.
FIRST ALERTS SAME DAYAlerts arrive on the phone in plain English with what it means and what to do. Acknowledge, or confirm a named remediation. Hunting and dossiers stay on the SearchCentral host.
This step is the one that needs a route from the phone to your host — published through Entra, or over a tunnel you already run. Both routes are in the FAQ.
CONFIRM BEFORE ANY ACTIONAll three run on the same audit buffer as the core platform — no second agent to deploy, no second console to learn, no extra licence to reconcile.
Live in the product today — not a promise.
Detection ships today. Containment is the work in progress.
Designed, not started. Shaped by what pilot tenants ask for.
Banded by user count, so a small team is not paying enterprise rates. One licence covers the poller, the console and the mobile companion — no per-seat agent fee, because there is no agent.
All prices are in GBP and exclude VAT, charged at the prevailing UK rate.
If something here is missing, ask us directly — we would rather answer it before you buy than after.
No. SearchCentral reads Microsoft 365 audit and sign-in logs through Microsoft Graph. There is no endpoint agent to package, deploy, exempt from AV, or explain to your users.
Onto a host you own. The audit buffer, the index and the dossiers all stay on your hardware — there is no vendor cloud in the path and nothing to sign a data processing agreement about.
A read-only Entra ID app registration with directory audit and sign-in log scopes. Remediation runs under a separate, explicitly approved write identity — the poller itself can never change anything.
Remediation is a job for either surface — the console or the phone app. Both apply the same named actions behind a typed confirmation, a named officer and an append-only audit log, under a separate write-scoped identity. Nothing ever acts on its own, and every action carries a signature.
Hunting and dossiers are console-only, by design. The console also carries the full picture for deep work; the phone is the out-of-hours half — see it, understand it, acknowledge or fix it.
Two ways, and you pick by what you already own. If you have Entra Application Proxy or Private Access, publish SearchCentral through it — your conditional access is enforced before a request ever reaches the host, and with Application Proxy there is nothing to install on the phone at all.
If you don't, any tunnel you already run works: the corporate VPN client your staff already have, Cloudflare Tunnel, or a WireGuard mesh such as Tailscale. We only need two things and don't mind how you provide them — the phone can reach the SearchCentral host on its port, over TLS the phone already trusts. (Site-to-site VPN on its own won't do it: a handset on mobile data is on neither network.)
And if you have neither, nothing is lost. The phone is a convenience, not a requirement — the desktop console does everything it does and more. You would be choosing not to carry alerts in your pocket, not doing without a feature.
No, and no. There is no SearchCentral relay or broker in the middle — the phone talks to your host directly across your own transport, so we never hold, proxy or see your logs. That is also why there is no data processing agreement to negotiate.
The one exception is push notification delivery, which has to travel via Apple and Google to reach a locked phone. Those messages are content-free by design: they say “open the app”, never what happened or to whom.
Run them. The attack simulator on this page is the same one that ships with the product — three real Microsoft 365 attack paths you can fire against a test account whenever you want proof.
Pick a plan or stop. If you stop, detections stop and the data stays yours — the audit buffer and any dossiers already generated are just files on your host, to keep or delete as you like.
Removing it is one host, not a fleet: stop the poller service, delete the application directory, and revoke the Entra app registration. There is nothing to clean off staff machines, because nothing was ever put there.
One month, the full product, your real Microsoft 365 logs.
Read-only to begin with, so the first month cannot change anything in your tenant. Turn remediation on only when you are satisfied the detections are right.
Pricing, procurement paperwork, and a guided demo run against your own tenant.
Setup help, detection tuning, and questions about a live incident.
Found a flaw in SearchCentral itself? Tell us here. We answer every report.
You do not have to take our word for any of this — the demo on this page runs the same detections the product ships with.
RUN A LIVE SIMULATION