Construal
Touchstone
TOUCHSTONE · OBSERVABILITY PIPELINE WITH A STREAMING DETECTION PLANE

Dramatically less data.
Nothing verifiably lost.

Touchstone sits between your log sources and the log analytics platforms you already pay for. It turns raw lines into structured events, cuts delivered volume by a measured 50% – 80%, and can be audited for correctness. Optionally run detection and correlation in the stream itself.

Book a demo
ONE BINARY · SELF-HOSTED
The trust gap

Touchstone is verifiably correct.

Reduction is deletion applied to your evidence. The category's claims — “up to 40%”, “50% or more”, “30–80%” — are marketing ranges with no methodology, and “no data loss” in those docs means transport, never information.
As a counterpoint, Touchstone has audit built in to prove that reduction does not lose information.

How it works

Build Structure, Reduce, Detect

Ingest, parse, reduce, enrich, detect, correlate, deliver — each stage optional, all of it declarative configuration validated as code.

01
Structure
Syslog, HEC, OTLP, JSON or replayed archive in. Grok patterns, typed captures, extensible patterns — every line is classified.
02
Reduce
Filter, aggregate, prune and log-to-metric, all windowed on event time. The pruner refuses to drop a field a live detection rule consumes.
03
Prove
Every run emits conservation identities — landed equals passed plus summarized plus counted loss — and an audit twin recomputes each summary from ground truth.
04
Detect
Sigma-compatible rules plus threshold, sequence and absence correlation, streaming on watermarks. Verdicts delivered at most once, or counted.
WORKS AT ANY SCALE

Works on ingest volumes of 100GB or 100TB+ per day. 

77k
lines/s/core
Measured throughput
Stateless parse, extract and fingerprint — roughly 490 GB/day/core end to end, clearing the category leader's published ~200 GB/day/vCPU sizing guidance. Native code: no JVM, no warm-up, no external runtime. A laptop runs the full evaluation loop.
1 .. N
nodes
Scale with your ingest
Individual pipeline stage components scale by adding new nodes. Start with one host for evaluation and pilot, scale to thousands if needed in production.
50%
of the codebase is tests
Tested to a release gate
About half the codebase, across unit, property, integration, live-cluster and fault-injection tiers, run as a mechanized qualification gate a release cannot ship without.
Prices

Owned, not rented.

No subscription, and no per-gigabyte toll on your own traffic. A perpetual licence, an optional maintenance contract for new releases, and support bought in incident packs when you want it.

One-time
Perpetual license
Buy the release you evaluated and run it for as long as you like, on your own machines. No subscription needed.
Optional, annual
Maintenance contract
The optional maintenance fee, paid yearly,  gets you free updates to the latest releases as long as the contract is current.
Per incident
Support packs
Engineering support in packs of five or ten incidents, drawn down as you use them. 

Bring one week of logs from your most expensive source.

The evaluation runs offline on your corpus, on your machines. It returns parse coverage, line and byte reduction, and the conservation identities that prove the accounting balances. If the ledger-verified number doesn't justify the conversation, it ends there.

Book a demo
Hours, not a services engagement