SOC-as-a-Service · 24/7 · UK-sovereign

Your SOC, running while you sleep. Without the ten-person team.

Agentic AI triages every Sentinel, Microsoft 365 and Google Workspace alert in under two minutes — with a human analyst approving every destructive action. Built for UK MSPs who need to say "yes" to 24/7 without hiring a night shift.

Start free scan See how it works
62sMedian investigation time, alert to verdict
60%Of alerts auto-resolved without waking a human
3 minFrom OAuth to first triaged alert
SOC feed · #soc-meridian-it
Live — 14:22:47
Alerts today
347
Auto-closed
208 60%
HITL queue
4
MTTR
2m 18s
INC-4817 Impossible travel · [email protected]T1078.004 · IOC 72/89 VT · forwarding rule created HITL 62s
INC-4816 Anomalous PowerShell · wks-fin-12Scheduled WSUS task — signed by Microsoft Benign 11s
INC-4815 Brute-force OWA · externalCA policy blocked · 14 attempts, 0 success Contained 8s
INC-4814 Mass file access · SharePoint-LegalPartner + 4 docs · matches matter brief pattern Benign 19s
INC-4813 Suspicious OAuth grant · k.adeyemiUnknown app · mail.read + files.readall Malicious 1m 04s
The problem, in one paragraph

Your two analysts can't triage 25,000 alerts a month.

A mid-sized UK MSP running 30 tenants generates 600,000+ alerts a year. 85% are noise, but someone has to read them to know which 15% aren't. Hiring a night shift costs £400k+. Outsourcing to an MSSP kills your margin and your brand. Doing nothing gets you breached. SOC-as-a-Service from SocSage is the fourth option.

How it works

One alert, 14 steps, 62 seconds.

An impossible-travel alert on a finance manager's M365 account. Here's exactly what happens — with real timings from our platform.

See the full pipeline
T+00:00

Alert lands in the queue

Microsoft Sentinel fires an impossible-travel incident. SocSage ingests via the workspace API, raw signals intact.

T+00:04

MITRE mapping + IOC enrichment

Triage agent classifies as T1078.004. IOC agent queries VirusTotal + AbuseIPDB — source IP scores 72/89 malicious.

T+00:16

Identity, lateral movement, EDR

Entra ID lookup. 24h sign-in scan. SentinelOne interrogated across three devices. Blast radius computed.

T+00:45

Timeline + D3FEND countermeasures

14 events stitched into a chronology. Phishing precursor found at 10:14. Recommended actions ranked.

T+01:02

HITL card posted to Slack

Block Kit card with verdict (92% malicious), evidence, blast radius, and three buttons: Approve · Quarantine · Reject.

T+02:17

Human clicks approve. Action executes.

Sessions revoked, password reset forced, forwarding rule removed, CA policy tightened. All logged, all timestamped, all signed.

Coverage

The stack a UK MSP actually runs.

Not a "platform for everything" — a SOC built for the Microsoft + Google surface where 95% of SME alerts actually live.

Microsoft Sentinel

Incidents ingested bi-directionally. 2,000+ MITRE-mapped KQL detections deployed — with our detection engineers shipping new rules every week. Sentinel remains the source of truth.

Microsoft 365

Entra ID, Exchange Online, SharePoint, Teams, Defender for Office 365, Intune. Delegated access, no agents.

Google Workspace

Gmail, Drive, Calendar, Admin console, Chronicle. Same triage quality, same HITL pattern.

EDR (SentinelOne, Defender)

Endpoint signals pulled into every investigation. Device posture factors into blast radius.

Ticketing (Jira, Freshdesk)

Every investigation writes into your ticketing system. No double data-entry. Status syncs both ways.

Slack / Teams / PagerDuty

HITL cards posted where your analysts already live. Approvals logged with user identity + rationale.

330+ compliance checks

Continuous CE+, ISO 27001, SOC 2 posture monitoring. Evidence captured automatically for audits.

UK data boundary

All processing in UK South. No logs leave the boundary. GDPR-aligned sub-processor list.

Plans

Start free. Scope cost after onboarding.

The Compliance Scanner is free forever. For agentic triage or fully-managed MDR, onboard today and we'll scope cost & payment with you after a short call.

Compliance Scanner

Posture assessment against CIS, CISA SCuBA, EIDSCA, Core Security and ORCA baselines.

Free forever
One tenant · no credit card
  • 330+ compliance checks
  • M365 & Google Workspace coverage
  • Configuration Health Index score
  • HTML report + CSV exports
  • Weekly re-scan & drift detection
  • No agent deployment required
Start free scan

Zerotouch

Every alert triaged by the agent swarm. Your team owns the HITL decision.

Contact us
Per-tenant pricing · volume tiers for MSPs
  • Everything in Free
  • 24/7 agent triage on every alert
  • InvestigationViz live stream & Replay
  • 2,000+ MITRE-mapped detections (KQL, FQL, DVQL, LogScale) — evolving daily
  • HITL approvals in Slack / Teams
  • 23+ integrations out of the box
Onboard — talk cost after

Managed MDR

Agent swarm plus our human SOC analysts on the HITL gates. White-label for partners.

Contact us
Custom scope · partner-margin economics
  • Everything in Zerotouch
  • Reddome analysts on HITL gates
  • Herd Intelligence Board access
  • White-label partner console
  • Dedicated onboarding engineer
  • Signed SLAs & tamper-evident audit
  • Sovereign-deploy options
Onboard — talk cost after

See the full pricing page →

vs white-label MSSP

Your logo. Your clients. Your margin.

White-label MSSPs take your margin to zero and put a middleman between you and your clients. SocSage runs inside your PSA, under your brand, with you on every decision.

Full comparison
White-label MSSP SocSage
Client sees your brandPartiallyAlways
Your analysts on the caseNoYes
Contract length24–36 monthsMonthly rolling
Detection qualityPortfolio-averageTenant-tuned
FAQ

The questions we get every week.

What does "human-in-the-loop" mean in practice?

Every destructive action — session revoke, account disable, firewall rule, file quarantine — requires a human analyst to approve. The AI does the full investigation autonomously, posts a decision card with evidence and confidence score, and waits. Approvals are logged with timestamp, user identity, and optional rationale. No destructive action is ever fully automated.

How does the free trial work?

You pick one or more tenants. We onboard them in an afternoon via delegated access (Azure Lighthouse for Microsoft, service account for Google). SocSage runs alongside your existing process in read-only investigation mode. You see every alert we would have handled, how we would have handled it, and the time we would have saved. No credit card. No commitment to continue.

Where does the data live?

All processing in UK South (Azure). No data leaves the UK boundary. Sub-processor list published at socsage.com/sub-processors. We do not train models on customer data.

What happens if SocSage gets it wrong?

For investigation: the HITL gate is the safety net — a human reviews the AI verdict before anything destructive runs. For auto-closed alerts (the ones marked benign): every decision is logged and reviewable. If an auto-closed alert turns out to be a true positive, you get a post-mortem, the detection is re-tuned, and your next month is credited if our MTTD exceeds the SLA.

Can we keep our existing MSSP during a transition?

Yes — many MSPs run dual for 30–60 days. SocSage in read-only mode, MSSP in production. Compare the triage quality and response time side-by-side. Most partners cut over fully by day 45.

Do you work with SMEs directly, or only through MSPs?

SocSage is built for MSPs. We sell directly to SMEs with 200+ seats if they run their own IT team, but the sweet spot is MSPs serving 10–80 SME tenants. If you're an SME reading this, ask your IT partner about us.

See a real alert investigated in 62 seconds.

Free Compliance Scanner in under three minutes — no card, no agents to deploy. Or onboard for agentic triage and we'll scope cost & payment with you after a short call.