Security teams drown in data they can’t use. Every tool speaks its own dialect, every source needs its own parser, and the people we trust to defend us spend their days on plumbing. We believe the data layer should be invisible — clean, consistent, and current — so defenders can do the work that actually matters.
Built by the people who lived the problem.
We’ve seen these issues everywhere — from critical national infrastructure to some of the largest names in their respective industries. We kept hitting the same wall: the hardest part of security engineering wasn’t the detection — it was getting the data into a shape you could trust. Derwent Labs is the platform we always wished we had.
- 2025FoundedTwo ex-SOC engineers start Derwent Labs in the UK, frustrated by years of brittle log parsers.
- 2025Version 1 tested and liveThe first version of the pipeline goes into production. Clunky, but it works — the first OCSF-normalised telemetry is flowing end to end.
- 2026The modern pipeline is bornAfter many iterations, improvements and full architectural redesigns, the pipeline we know and love today is finalised.
- 2026200+ connectors liveAny security source, mapped to OCSF effortlessly — with international coverage and growing.
The principles behind every decision
Make the hard part invisible
The best infrastructure disappears. If our customers are thinking about us, something has gone wrong. We obsess over the boring, fiddly work so they never have to.
Open over proprietary
OCSF, open APIs, detections as code, no lock-in. Security gets stronger when data is portable — so we build for an ecosystem, not a walled garden.
Earn trust every day
We sit in the path of our customers' most sensitive data. That privilege is earned continuously — through rigour, transparency, and never cutting a corner that matters.