Our headline number is that CloudPeek delivers 100% alert coverage. It is the first figure on our site, and it deserves the first challenge it usually gets: of course a machine touches every alert. Touching is not covering. A script that closes everything achieves 100% coverage by that standard, and so does a team that bulk closes a queue on a Friday afternoon.
The challenge is correct, and it points at the actual problem. Coverage figures in this market are mostly unfalsifiable, because almost nobody selling one states what counts as covering an alert. So here is the definition we hold ourselves to, in public, where it can be used against us.
What the definition requires
Three things, each of them checkable. An investigation, meaning the alert was enriched and correlated against the estate rather than pattern matched against a rule. A verdict, meaning a decision was reached: escalate, or close, with a confidence attached. And reasoning, written down, specific to this alert, such that an analyst reading it later could say no, that is wrong, and point at why.
The last clause is the one that matters. A verdict nobody could disagree with is not a verdict, it is a rubber stamp. The test of whether an alert was genuinely worked is whether the record of it is substantial enough to be challenged.
What it excludes
Quite a lot of what currently passes for coverage. Bulk closure is out, however sophisticated the rule that triggered it, because a rule is not an investigation of this alert. Tuning detections down until the queue is manageable is out, because an alert that was never raised was never covered. Sampling is out, because covering a representative subset is a defensible resourcing decision but it is not coverage, and it should not be reported as if it were. And closure without a written reason is out, even when the closure is correct, because a right answer that cannot be audited is indistinguishable from a lucky one.
Why publish the standard
Partly because it is the only way the number means anything. A coverage figure without a stated definition is an advertising claim; with one, it is a testable assertion, and we would rather make the second kind.
Partly because it changes the conversation we have with prospects. When we say 100% against an industry average of roughly 19%, the useful follow up is not whether our number is real. It is whether the comparison is on the same definition, and mostly it is not, because most published figures count touched rather than covered. We would genuinely welcome competitors publishing their definitions. The market gets better when the numbers become comparable.
And partly because the definition is the product. The reason CloudPeek can meet this standard at volume is not that the model is fast, although it is. It is that every investigation produces its reasoning as a side effect of doing the work, rather than as documentation written afterwards. When the reasoning is the work, coverage stops being a trade off against depth.
Check it
If you run a security operation, the exercise takes an afternoon. Pull last week’s closed alerts and sample fifty. For each one, ask whether the record contains a reason specific to that alert that you could disagree with. The percentage that pass is your coverage on this definition. Most teams who run this exercise find the honest number is uncomfortable, and it is not because their analysts are bad. It is because the volume made the standard impossible to hold by hand.
That is the gap we built for.