Crogl 2.4: Sovereign, Deterministic, Extensible, Predictable
Drew Oetzel
Marketing, Crogl

Ask a team that built its own AI investigation stack how it is going.
The demo worked in a week. Then the schemas drifted, the glue code piled up, the token bill doubled, and legal asked where the data goes. The pattern is so common we hear it in nearly every conversation.
We built Crogl as an on-prem AI SOC agent, around four commitments. Sovereign: your data and your AI stay in your environment, under your control. Deterministic: the reasoning is consistent and inspectable, never a black box. Extensible: any tool, any skill, any schedule, without waiting on a vendor roadmap. Predictable: you always know what it costs.
The 2.4 releases span the knowledge graph, connectors, scheduling, isolation, and pricing. Every feature in them pays into one of those four commitments. Here is what is in them, and why it matters.
One knowledge graph: ask the question, skip the plumbing
Here is what changed. You can now query across tens of data lakes and tens of tools without memorizing a single schema. You do not need to know which store holds the proxy logs. You do not need to remember which tool wants SPL and which wants KQL. You ask the question. Crogl knows where the data lives and writes the query in the language that store speaks.
That is the knowledge graph. In this set of releases we rewrote it so that every connector feeds one unified knowledge graph, the ones we built and the ones you built, with no limits on data volume or schemas. It keeps itself current as your environment changes.
We are proud of this one, and here is why. Knowing where the data lives is the tax every analyst pays for years. It is the reason a new tool takes a quarter to become useful. It is the knowledge that walks out the door when your senior analyst leaves.
The knowledge graph pays that tax for you. Investigations get faster, because nobody pivots across ten consoles hunting for the right index. They get more complete, because no source gets skipped for want of its query language. And your intuition finally gets room to work: the moment you wonder about a host, you ask about the host.
One honest boundary: when data is missing, Crogl flags it as an investigation gap. It does not guess. That is the difference between an answer and evidence.
This is what extensible means in practice. Everything you connect becomes something you can reason over.
Any tool: if it exists, it connects
The biggest improvement: you can now write your own connectors in plain language. Describe the tool in chat, and Crogl assembles the connector. No SDK, no integration project, no ticket in someone else's queue. If your team can explain how a tool works, your team can connect it.
MCP connectivity gets deeper too. Crogl already connects to tools that expose MCP servers. In 2.x you can upload your own connectors, run multiple instances of the same connector, and manage all of them from a redesigned, search-first Connectors page. Multiple instances matter because two SIEMs and three ticketing systems is a common setup, not an exception. One government customer runs three SIEMs and two SOAR platforms across 100TB of data. Real environments look like that.
Authentication meets your infrastructure where it is: session-token exchange, AWS SigV4 request signing, GCP service accounts, and OAuth2 for custom connectors. Crogl can reach APIs that do not fit a static header and can use machine identities that rotate themselves.
What this does for you: no data pipelines to build, no normalization project, no feature request sitting in someone else's backlog. Your data stays where it is, in its native format. You extend the platform yourself, on your timeline.
That is the extensibility commitment, kept.
Any schedule: the second queue gets an owner
Every SOC has a second queue that nobody tracks.
The overnight advisory that should be checked against your environment. The vulnerability sweep that should run on the compliance clock, not the calendar. The skill your team wrote last month that should be tested before production trusts it. The investigation stalled on a ticket someone else owns.
None of it is urgent at 9 AM. All of it matters. It waits for a free hour that never comes.
Jobs put that work on a schedule. A job is investigation work you define once and Crogl runs on the cadence you choose: hourly, nightly, weekly, or when a condition is met. A new advisory drops overnight, and Crogl has assessed your exposure by morning. Vulnerability checks run on the cadence your regulator demands, and the evidence is ready before the auditor asks. New skills get exercised on a schedule instead of when someone remembers. A blocked investigation watches for the blocking ticket to close, then picks itself back up.
Scheduled work only helps if you can see what it did. That is what the new dashboards are for. Dashboards in 2.x are persona-sensitive: practitioners see their queue, their investigations, and their scheduled jobs, while admins see system health and connector status. You open one screen in the morning and see what ran overnight, what it found, and what needs your call. Investigation reports are richer too, written for the person who has to sign off on the finding.
Crogl already investigates your alerts. Jobs extend that same discipline to everything between the alerts.
Sovereign: your data, your model, your walls
Crogl runs in your environment: on-premise, in your cloud, or fully air-gapped. Your data never leaves. In 2.x, we extended that commitment from where the system runs to how it runs.
Every conversation now runs in its own isolated container. One investigation cannot see another. A misbehaving session is contained by architecture, not by policy.
The LLM proxy goes further: credentials never reach the language model at all. The proxy holds the secrets and brokers the calls. The model reasons over evidence, not over your API keys. It cannot leak what it never had.
And every query, inference, and determination is logged and traceable back to source data. Auditable, repeatable, inspectable. Sovereignty is not a deployment diagram. It is proof you can hand to an auditor.
Deterministic: the same evidence, the same answer
An LLM on its own is not repeatable. Ask it the same question twice and you can get two answers. That is a problem when the output is a security determination someone has to stand behind.
Crogl pairs the language model with a governable harness and the semantic knowledge graph, so the reasoning stays consistent and inspectable. The same evidence produces the same determination, and an analyst can interrogate the path that led there, not just the conclusion. Reasoning you can reproduce is reasoning you can trust.
Predictable: the bill is not a plot twist
Crogl is a flat license. The AI costs stay yours to control: bring a frontier model and manage token spend directly with that provider, or run a model on your own hardware and bring your tokens in-house.
That matters more now, not less. When jobs run every night and connectors multiply, a per-token platform markup turns growth into a penalty. With Crogl, doing more security work does not mean renegotiating your budget. You can plan the year, not the month.
Direct experience, not demos
These claims should not require trust. We made Crogl a free download so they do not.
Download the latest version of Crogl. Connect a tool we have never heard of. Ask a question across every data lake you own without writing a query. Schedule a job against last night's advisories. Then check what it cost you.
Not magic AI. Operationally relevant AI.
Download Crogl free and put it to work in your own environment.