Intelligence you act on has to be intelligence you can check. This page explains how Conundrum earns that trust: how findings are grounded in sources, how collection stays healthy, and how your data is protected.
Finished intelligence is only useful if you can trust it. We build the checks in, rather than asking you to take the output on faith.
Each factual statement in a report traces back to the source it came from. You can follow any finding to the original intelligence and see exactly where it came from and when.
Before a report is finished, its facts are checked against its sources. Anything that doesn't trace back, like an invented CVE or an unsupported attribution, is held for analyst review instead of being sent to you as finished intelligence.
We evaluate our own extraction and analysis against a labelled benchmark and hold the pipeline to it. Accuracy is something we measure and track, not an adjective on a slide.
A source count is easy to put on a slide. Keeping those sources actually flowing is the harder part, and it's the part that decides whether a gap in your coverage is one you can see.
Feeds move, change format, or go quiet. Conundrum monitors the health of every collection source and flags degradation, so a silently broken feed never becomes a silent gap in your intelligence.
Every source is tracked for reliability, not just counted. Failing or low-value sources are surfaced and managed, so collection stays a resource you can account for.
Every organisation's data lives in its own isolated database schema. Your PIRs, reports, notes, and files are never visible to another tenant. Isolation is enforced at the database layer, not just the application layer.
All data encrypted in transit (TLS 1.3) and at rest (AES-256). API keys and credentials are securely stored using environment-level encryption.
Role-based access control within each tenant: owners, admins, and analysts see and do only what their role allows. Session management on every account.
Conundrum aligns with the major cybersecurity and data-protection standards regulated organisations face (NIST CSF 2.0, NIS 2, GDPR, ISO 27001:2022, and DORA) and maps your intelligence coverage to those same standards, with gap analysis and auditor-ready exports. For security questionnaires, vendor-risk reviews, or RFP documentation, our team will work directly with yours.