Frequently asked questions
Common questions from analysts, SOC leads and security buyers.
Does FactPattern replace my SIEM or EDR?
No. FactPattern sits beside the existing security stack and reads from it. Customers continue to operate their SIEM, EDR and identity providers.
Will FactPattern take action without an analyst?
No. High-impact actions (isolate, disable, rotate, block) always require human approval. Read-only mode is the default for new deployments.
How is customer data isolated?
Per-tenant encryption keys, row-level security on every table, and per-integration scoped credentials. Cross-tenant access is impossible at the database layer.
What happens to my data if we cancel?
Hard-delete on schedule per the customer's retention configuration. Exports remain available until the cancellation date.
Can analysts override the model?
Always. Every verdict is shown with its underlying evidence so analysts can override. Overrides feed back into triage learning.
Is FactPattern certified?
No. A SOC 2 Type II audit is in progress, with the audit window started Q1 2026. FactPattern is not certified under SOC 2, ISO 27001, GDPR, HIPAA, or PCI.