Critical Start does the one thing I said in this series that nobody in this market does: it publishes a service level with a defined clock and a financial remedy attached, and puts it in the contract rather than on a slide. That single decision makes it worth a profile even though it is a smaller company than most of the names around it, because it demonstrates that the vagueness everywhere else is a choice rather than an industry constraint.
The company is Plano-based, founded in the early 2010s, took a growth investment of more than two hundred and fifteen million dollars from Vista Equity Partners, and runs at around three hundred people. It sits in the operate-your-stack cohort alongside Expel and Red Canary: technology-agnostic, working through your existing tools rather than deploying its own agent, with more than a hundred integrations and over thirty of those supporting bidirectional response so analysts contain threats directly in the tooling you already run.
The service level, and why it matters beyond this vendor
Read the definition first, because that is the part that is usually missing. Their published measurement starts the clock when an alert is ingested by their platform and stops it when an analyst documents a disposition, running around the clock rather than during business hours. Every element of that sentence is a decision another vendor declined to make public.
The commitments themselves are tiered. All tiers carry platform availability and a mean time to respond across threat alerts of every severity, with the top tier adding per-alert response times for critical and high severity. Critical alert notification is published at ten minutes. Their stated actuals run ahead of the commitments, at around five minutes to detect and twelve to respond across their customer base, which is a vendor figure and should be read as one. And when they miss, the contract carries service credits.
A number with a defined start, a defined stop, a measurement methodology and a remedy is a commitment. Everything else in this market is a statistic.
I want to be careful about what this proves. Service credits are a modest financial instrument and nobody is made whole by a month of fees during a breach. The value is not the money, it is that a defined clock and a documented measurement methodology force the vendor to say what they actually do and give you something auditable to point at during a review. When your board asks how you know the provider is performing, an SLA report drawn from a defined metric is an answer. A marketing figure is not.
Use this as the benchmark question with everyone else on your shortlist. Ask what starts your clock, what stops it, whether the measurement runs outside business hours, and whether missing it costs you anything. One provider in this market answers all four in public. The rest can be asked to answer them in a contract.
Resolving every alert, and the machine that makes it possible
The founding proposition is that every alert gets resolved rather than filtered by severity, which sounds like marketing until you look at how they make the economics work. The mechanism is a registry of known-good behaviour, built up over time, which deterministically auto-resolves things it has already established are benign. Their published figure is that it clears the overwhelming majority of false positives, and what remains reaches a human.
The architectural argument is the inverse of the industry norm and it is a defensible one. Most detection pipelines suppress by confidence and severity, which means low-severity signal is discarded in bulk and the intrusion that begins as a low-severity anomaly is discarded with it. Registering known-good behaviour instead, and investigating everything that is not on the list, changes what falls through the gap. It also builds an asset that improves with tenure, which is a genuine argument for staying with one provider.
The corresponding risk is worth naming. A registry of known-good behaviour is a suppression list by another name, and its quality determines what never reaches an analyst. Ask how entries are added, who reviews them, whether an attacker living off legitimate tooling ends up matching a registered pattern, and how the registry is audited. Those are the right questions for this architecture and they are not adversarial; a vendor confident in the mechanism will have answers.
Critical findings carry two-person verification before disposition, which is a meaningful control and one nobody else in this series publishes.
Transparency as an architectural position
Their platform is built around showing the work: every alert, the analyst reasoning, every action taken with timestamps, and the recommended follow-ups, visible to your team as investigations proceed rather than summarised afterwards. Alongside it sits a mobile application for reaching analysts directly, and compliance reporting that maps detections and investigations to the frameworks a regulated organisation has to evidence against.
This matters more than it sounds. The recurring complaint about managed detection is opacity: you receive conclusions without the reasoning, and during an incident you are negotiating for detail rather than reading it. A provider that treats visibility into its own work as a product feature has made a structural choice about the relationship, and it is the choice I would want from anyone holding response authority in my tenant.
The independent commentary is not uniformly glowing, and the criticisms are consistent enough to raise during evaluation: onboarding communication during complex enterprise rollouts, and pricing that is entirely opaque until you engage sales. Neither is unusual in this market. Both are fair questions to put on the table early.
Where it lands in a Microsoft estate
Technology-agnostic means they operate what you have, so the overlap position is the same as the other operate-your-stack providers: minimal duplication, and a dependency on the telemetry you licensed. They market Microsoft coverage specifically, and the bidirectional response integrations are the mechanism that matters, since containing a threat in your own Defender tenancy rather than in a vendor console is the difference between a service and a notification feed.
Two things are absent that some organisations require. There is no breach warranty, which is a deliberate difference in philosophy from providers who replace the service level with insurance. And identity is covered as a signal domain rather than as an engineered discipline; there is nothing here comparable to inline authentication decisions, or to the specific hybrid directory guard that two other providers in this series built. If your incidents start at identity, and most do, weigh that.
The distinctive coverage is at the other end: operational technology and industrial control systems, monitored alongside the corporate estate through integrations with the specialist platforms in that space. Nobody else in this series touches it. For a manufacturer, a utility or anyone with a plant floor attached to the same organisation as the office network, that is not a footnote, it is potentially the deciding factor.
Scale, and what it does and does not tell you
At roughly three hundred people this is a smaller organisation than most of the names in this series, operating from two United States security operations centres with an engineering function in India that is not a monitoring site. If you require follow-the-sun coverage from geographically distributed analysts, establish how that is actually delivered rather than assuming it from a round-the-clock claim.
Size cuts both ways and I would not treat it as a mark against them. A smaller provider with private equity backing is more accessible to a mid-market customer than a platform vendor with a two hundred endpoint floor, and direct access to analysts and leadership without tiered gatekeeping is a recurring theme in their customer feedback. The counterweight is the one that applies to every private-equity-held business in a consolidating market: ownership is a fact about today. Ask the vendor-neutrality and roadmap questions you would ask of anyone in this field, and read the acquisition context in the anchor article before you sign a three-year term.
The AI claims
Applying the two tests I use throughout. On governing your users’ generative AI usage there is nothing here, and I record that as an absence rather than implying otherwise; it is the same finding as three others in this series.
On AI inside their own operations the position is more interesting than most because the mechanism predates the vocabulary. The known-good registry is deterministic automation doing triage at scale, and it was doing that before anyone marketed it as artificial intelligence. Newer material adds agentic investigation language on top. Judge the newer claim by the standard I apply to everyone: a named mechanism and a clear statement of where a human makes the decision. The older mechanism already meets that bar, which is more than can be said for several competitors making louder claims.
Where this lands
If contractual accountability is what your organisation needs, because you are regulated, because your board asks how the provider is performing, or because you have been burned by a service level that turned out to be a statistic, this is the provider on the list that has already answered the question in public.
If your threat model is identity-first, or you need the depth that comes with a large platform vendor’s research organisation, others in this series go deeper. And if you have operational technology sitting alongside your corporate estate, this is the only profile here that covers it at all.
MDR
‹ Previous: [MDR 7] Red Canary Under Zscaler: When Your Zero Trust Vendor Owns Your SOC
Next: [MDR 9] Palo Alto Unit 42 Managed XSIAM: Buying a Security Data Platform With Operators Attached ›




