Skip to content
Torjua Cybersecurity Division

L7 · Signal — a Torjua product

Ten thousand alerts.
One story.

Cloud Intelligence takes telemetry from your cloud accounts, SaaS tools and on-premise systems and correlates it into a single narrative per incident — then contains the routine cases before anyone is paged.

At current scale
Signals ingested 2.8M / sec
Assets watched 41,000
Median time to resolve 72% lower
Baseline learning 24–48 hours

Live demo

The command view, running.

A working simulation of the Cloud Intelligence dashboard. Hover a threat marker to inspect the campaign behind it. Every figure below is generated, not from a customer.

Interactive — simulated data Torjua / Cloud Intelligence

Capabilities

Built to reduce the number of things a human has to read.

One ingestion pipeline

Cloud providers, SaaS tools and on-premise systems land in the same normalised stream, searchable within seconds of arriving.

Correlation, not alerting

Signals from different sources are stitched into a single narrative per incident, so your team reads one story instead of forty rows.

Containment playbooks

Routine cases — a leaked token, a compromised session, a known-bad IP — are isolated automatically, with the action logged for review.

Campaign map

Active campaigns, attacker infrastructure and the paths between them, drawn geographically so scope is obvious at a glance.

Posture scoring

Continuous assessment across AWS, Azure, GCP and Kubernetes. Misconfigurations, exposed workloads and drift surface before they are found for you.

Audit artefacts

NIS2, GDPR and SOC 2 evidence generated from live system state, with the dates and configuration an auditor actually asks for.

Deployment

Connected in an afternoon. Useful by the next morning.

  1. 01

    Connect the sources

    Pre-built connectors for AWS, Azure, GCP, GitHub, Microsoft 365 and Slack. Each one is an API key and under five minutes; nothing is installed on your hosts.

  2. 02

    Let it learn the baseline

    For 24 to 48 hours it watches what normal looks like in your organisation and builds a behavioural model. No rule-writing, and no tuning session with a consultant.

  3. 03

    Read narratives, not alerts

    Findings arrive with context and a recommended action. Playbooks handle the routine containment while your team reads what happened and decides the rest.

Detection register

What it is looking for, in plain terms.

The full rule set is larger and changes daily. These are the eight techniques customers ask about most often.

Credential stuffing
Botnet-driven login attempts across edge nodes, correlated against known leaked-credential sets.
Data exfiltration
Unusual outbound volume, DNS tunnelling, and large transfers to autonomous systems you have never used.
C2 beaconing
Command-and-control timing patterns inside container runtimes and serverless functions.
Lateral movement
East-west traffic anomalies across Kubernetes service meshes and VPC boundaries.
Privilege escalation
IAM policy changes, role assumptions and token reuse on the path to account takeover.
Impossible travel
Administrative sessions appearing from two continents inside a single flight time.
Reconnaissance
Port scanning, metadata probing and enumeration against public-facing workloads.
Supply-chain tampering
Dependency drift, container image mutation and unexpected changes in the CI/CD pipeline.

Pricing

Priced on sources, not on how much trouble you are in.

Starter

For small teams putting monitoring on a cloud estate for the first time.

99 / month

  • Up to 5 sources
  • 7-day retention
  • Email alerts
  • Campaign map
Start a trial

Business

Recommended

Full detection with automated containment for organisations with something to lose.

349 / month

  • Unlimited sources
  • 90-day retention
  • Containment playbooks
  • Slack and webhook routing
  • Posture scoring
Start a trial

Enterprise

Custom deployment, a named analyst, and a response time written into the contract.

Custom

  • Named threat analyst
  • 1-year retention
  • On-premise option
  • 15-minute response SLA
Talk to us

Find out what is already in your logs.

Fourteen days, full access, every connector. Most teams find something they did not know about in the first week — which is uncomfortable, and the entire point.