Contact

Tell us what
happened. We respond in one business day.

Grail handles active incidents and partnership conversations on separate tracks. Pick the one that fits — we'll route you correctly. If it's actually on fire, use the phone number.

Active incident If a breach is in progress, call us directly for a same‑hour callback. +1 (214) 555‑0148
For security teams

Request a demo.

Thirty minutes, live. We'll run the pipeline against a sanitized case file and walk you through the agent trace, the validation step, and the final report.

For carriers & partners

Let's talk partnership.

For cyber insurance carriers, MGAs, brokers, and reseller partners exploring Grail as a panel alternative or integrated claims workflow.

Partnerships
partnerships@grail‑dfir.io Replies within one business day. Direct line to our head of partnerships.
Claims integration
claims@grail‑dfir.io API‑driven case intake. We'll send architecture docs on first contact.
Response brief
Download brief (PDF) Eight‑page overview for underwriters. {{ carrier_brief_pdf }}
Sales
Support
Mailing address
1717 Main St, Suite 2400
Dallas, TX 75201
Response times
Within 1 business day
Active incidents: < 1 hour
Before you ask

The six things
everyone asks first.

01

How long does deployment take?

For most environments, under a day. Grail collects evidence via Velociraptor — there's no persistent agent to roll out, no MDM push, no change window needed. We can run against a fresh case without deploying anything.

02

Do we need to install anything on endpoints?

No persistent install. Velociraptor runs on demand when King Arthur orchestrates a collection, then removes itself. Nothing sits on your endpoints between investigations.

03

How do you handle our data?

Evidence is collected into a tenant‑isolated workspace, encrypted at rest with a customer‑held KMS key, and scheduled for purge after report delivery. We never train any model on customer evidence — contractually and architecturally.

04

What integrations do you support?

Alert intake from most SIEM and EDR platforms out of the box (Sentinel, Splunk, CrowdStrike, SentinelOne, Elastic). Case output pushes to Jira, ServiceNow, and carrier claims APIs. Full webhook surface for anything custom.

05

Is Grail's output admissible in court?

Outputs are structured to meet Daubert standards — reproducible methodology, signed chain of custody, full provenance for every claim. We work with outside counsel on cases that escalate to litigation and will testify to our methodology.

06

What if the pipeline misses something?

The Black Knight validator drops unverifiable claims rather than softening them, and every case is reviewable by a human analyst before report delivery. If a finding is missed, we re‑open the case at no cost. We've re‑opened two in the last quarter.