# How we measure the Intelligence Fabric

Every number we quote on the platform page is grounded in named customer deployments, including BT, Kingspan (3,500+ employees), Advantage Solutions, Miller Insurance, ED&F Man, and IPSL, plus aggregate production telemetry from the SenseOn Intelligence Fabric. This page documents the sample sizes, date ranges, and definitions behind each claim so that CISO and SecOps buyers can verify, reproduce, or challenge the numbers. Where a figure depends on a specific deployment, the customer is named. Where it depends on an aggregate, the denominator is stated.

## Three rules every number on /platform obeys

### Named, not anonymous

Customer proof points name the customer (with their written consent) and cite the deployment scope. No composite customers, no hypothetical examples.

### Falsifiable, not marketing

Every metric states a denominator, a sample window, and a measurement definition. If you ran the same query against your own environment, you would get a comparable answer.

### Updated quarterly

Numbers roll forward on a published cadence. Old values are archived so you can see how the fabric has performed over time.

## Per-metric detail

## Every number on the platform page, traceable

Each card below maps to a claim on /platform. Links on the platform page deep-link to the matching card here.

### 92.5% Agent cases completed end-to-end

- **Denominator**: All cases raised across all production customer environments during the measurement window  
- **Date range**: Rolling 30-day window, updated quarterly  
- **Sample size**: Aggregate across all production customer environments. Individual enterprise environments (including Fortune 500 deployments) exceed this figure.  
- **Methodology**: A case is counted as 'completed end-to-end' when Resolve closes the incident autonomously with full decision-trace evidence, without a human analyst taking over the investigation or response action. Cases escalated to the 24/7 managed-response team are excluded from the numerator but remain in the denominator. The 92.5% is the blended conservative floor across the full customer base.

**Caveats**:  
- The figure is an aggregate across all deployed customers, not a single environment or sampled cohort.  
- Cases that required human judgment by design (e.g. policy exceptions) are classified as escalations, not failures.  
- When Resolve escalates to a human analyst, no credits are consumed for that case.

### ~40% Data reduction at the edge

- **Denominator**: Raw telemetry volume entering the Edge Processing pipeline, measured in bytes before enrichment and deduplication  
- **Date range**: Rolling 30-day window, aggregate across production tenants  
- **Sample size**: Aggregate across all production tenants  
- **Methodology**: Calculated as (1 − egress_bytes / ingress_bytes) across the Edge Processing pipeline, built on Fluent Bit (CNCF graduated) and OpenTelemetry. Reduction driven by deduplication, field pruning of irrelevant telemetry, and intelligent aggregation of high-cardinality log sources. For industry context: Chronosphere (corporate steward of Fluent Bit) reports 60–84% data reduction across their observability customers; Cribl reports ~41% in published case studies. SenseOn's ~40% is a conservative aggregate across security-specific telemetry, which compresses less than pure observability data.

**Caveats**:  
- Reduction varies by source mix and log cardinality; endpoints compress less than verbose network or cloud audit logs. Customer-specific figures available on request.  
- The '~' prefix reflects variance across the tenant population; individual customers see a range.  
- Industry benchmarks from Chronosphere and Cribl demonstrate that Fluent Bit-based edge processing routinely delivers 40–80%+ reduction depending on source type.

### Unlimited, configured per pipeline Security Data Lakehouse retention

- **Denominator**: Not a sampled measurement. This is a product configuration capability  
- **Date range**: Current as of Q2 2026  
- **Sample size**: Product capability (not a sampled measurement)  
- **Methodology**: 30 days hot storage is included in the detection and response pipeline cost. Beyond that, compressed cold-tier retention is unlimited, priced per pipeline via Flex Intelligence Credits. Customers set retention to match compliance obligations (NYDFS 7 years, DORA 5 years, NIS2, SOC 2 Type II evidence retention). Cold-tier data remains queryable via standard APIs throughout the retention window.

**Caveats**:  
- Default minimum: 30 days hot storage included in the base detection and response pipeline.  
- Retention beyond 30 days is priced on a per-pipeline basis via the FIC credit model.  
- No hard upper limit. Retention period is customer-configured based on compliance requirements.

### 0.68% True-positive density across investigated cases

- **Denominator**: Total cases investigated by Resolve across all customer environments, including alerts from SenseOn analytics and integration partner sources (CrowdStrike, Splunk, Defender, etc.)  
- **Date range**: Rolling 12-month window, updated quarterly. Last confirmed: April 2026  
- **Sample size**: 30 million+ cases  
- **Methodology**: Of 30M+ cases investigated by Resolve, 0.68% were confirmed true positives requiring action. The inverse (99.32%) represents cases correctly identified as non-threats. This metric illustrates the fundamental signal-to-noise challenge: as data volumes grow exponentially, the true-threat rate shrinks, requiring compounding AI compute to find increasingly subtle signals within noise.

**Caveats**:  
- The sample has grown beyond 30M since the January 2026 snapshot. Updated figures roll forward quarterly.  
- True-positive density varies by customer environment, industry vertical, and integration source mix.

### <20 min Mean time to detect and respond

- **Denominator**: Aggregate across managed-service customer environments  
- **Date range**: Rolling 30-day window  
- **Sample size**: Aggregate across managed-service customers  
- **Methodology**: SenseOn's case management system tracks Mean Time to Acknowledge (MTTA), Mean Time to Investigate (MTTI), and Mean Time to Respond (MTTR) for every customer environment in real time. Customers with the SenseOn managed service see these metrics in their dashboard week on week and month on month. The <20 min figure is the aggregate across managed-service customers. Every customer can verify their own MTTA/MTTI/MTTR against their live data.

**Caveats**:  
- Individual customer metrics vary based on environment complexity, case severity distribution, and service tier.  
- Per-customer MTTA, MTTI, and MTTR are visible in the SenseOn dashboard in real time. This is a platform capability, not a static benchmark.

## Questions, objections, or due-diligence requests

CISOs and SecOps leads running formal evaluations can request the underlying query definitions, audit logs, and customer references. Contact your SenseOn account team or reach us via the platform enquiry form.
