SOCPilots

Many customers. One operation.

Managed security providers lose margin in the gaps between customers — a different console per client, a different SIEM per contract, and a reporting pack assembled by hand every month. SOCPilots is built around that problem rather than retrofitted to it.

A workspace per customer

Each client is a workspace holding its own SIEM connection, data, policies, service levels and users. Onboarding one is a configuration task, not a deployment.

Their SIEM, not yours

per workspace

One customer on Elastic and another on QRadar is the normal case, not an exception. Each workspace connects to its own backend and the console adapts to what that backend supports.

4 backends

Separated in the database

isolation

Customer data is separated by row-level security rather than by careful querying, and a workspace without a configured connection returns nothing instead of falling back to somebody else’s.

enforced

One queue across all of them

all tenants

Operators with the right permission get a view that spans every customer, with alerts and cases tagged by client and filterable down to one. Your analysts work a single prioritised queue instead of rotating through consoles.

taggedfilterable

Per-customer service levels

sla

Each contract gets its own response and resolution targets and its own business hours. Breach prediction warns while there is still time to act, which is the only point at which a warning is worth anything.

business hours

Assignment that respects the roster

workforce

New cases route to analysts who are actually on shift, under their capacity limit and qualified for the work — across every customer at once, with the decision logged.

shift awarelogged

A portal you can hand over

client view

Give the customer read-only visibility into their own activity, posture and resolved work, scoped strictly to their workspace. It replaces the monthly slide deck with something they can open themselves.

read onlyscoped

Reporting that assembles itself

The monthly pack is where managed service margin quietly goes. Volumes handled, response times against the contract, coverage gained, incidents closed and what changed since last month are produced from the same records the analysts worked in.

Because coverage is measured per workspace against ATT&CK, the improvement conversation stops being about ticket counts and becomes about which techniques the customer could not see in January and can see now.

all workspaces6 clients
  • CRITNorthwind · credential accesselastic
  • HIGHHalvorsen · lateral movementqradar
  • HIGHMeridian · exfiltration attemptsplunk
  • MEDOkonkwo Ltd · new admin accountwazuh
interface illustration · illustrative names, not customers

Tell us how many customers and which SIEMs

That is usually enough for us to show you something that looks like your actual operation.