SocSage is a product of Reddome — a UK cybersecurity firm that has defended banks, hospitals, fintech unicorns and high-street retail. We built the tool we always wished we had.
Bazam has spent his career inside security operations at the sharp end — leading teams across fintech, banking, healthcare and critical infrastructure. He has built, rescued and re-platformed SOCs for every scale of organisation: from neobanks under live incident, to NHS trusts under regulatory pressure, to PE-backed retail chains with Sentinel deployments going sideways.
The pattern was always the same: Tier-1 analysts drowning in alerts, two senior people doing the work of ten, and a monthly retainer to an MSSP nobody trusted. SocSage is his answer — a visionary bet that agentic AI, run with strict human-in-the-loop gates, can give every MSP and SME the SOC they deserve.
Full automation of destructive security actions is a bad idea. SocSage is aggressive on triage and investigation. It is deliberate on approval gates.
Every tool call is logged. Every reasoning step is inspectable. If we can't explain a decision, we won't ship the feature.
When your client looks at the SOC, they should see you — not us. White-label isn't a feature we grudgingly offer; it's a belief.
From the first MSSP retainer we signed in 2009, through the first Sentinel workspace we stood up in 2019, to the first SOC agent we shipped in 2024.
Bazam signs the first outsourced MSSP contract for a UK fintech. Six months in, the quality-vs-price gap becomes obvious.
Leads IR at a London NHS trust ransomware event. Lesson: 80% of incident work is enrichment and context — perfect for automation, if you trust it.
Deploys Microsoft Sentinel across 40+ banking tenants. Codifies the 14-step investigation runbook that would later become SocSage's core pipeline.
Founds Reddome as a UK-sovereign security consultancy. Advisory work reveals the real customer: MSPs with 5–50 SME tenants and no viable SOC option.
Ships the Blue Team Tier-1 agent on Azure OpenAI. Sub-90-second triage is proven at 47 live tenants.
14-step pipeline, SocSage swarm, full HITL gates, multi-tenant white-label console. You are reading the website.
Reddome is a UK-sovereign cybersecurity firm building the offensive, defensive and governance capabilities the UK mid-market needs. SocSage is our flagship product. Our consultancy arm still does IR, red-team, and SOC transformation for the organisations most people have heard of.
Every onboarding is done by someone who has run a real SOC. No BDR, no SDR, no bot.