Skip to content
Phalanx
roRequest a quote
Menu+

SOC as a service

Security and compliance in one console.

Alerts, cases, policies and audit evidence in one place. No moving data between tools to prove you did the work.

Where to start

I run security for other companies

Run a SOC for your clients. Without running a SOC.

One platform, many clients. Each sees only their own data. Your team sees all of it, from one screen.

  • Isolation between clients is enforced by Postgres, not by application code
  • Each client's own name and mark, in their console and on exported documents
  • One login for your team, however many clients you carry
See how it works

I need to prove compliance

ISO 27001 without the consultant hours.

Your policy set arrives drafted and you approve it. Evidence accumulates as you work, not in the week before the audit.

  • Policies drafted for the controls you are missing, approved by a human
  • Analysis that separates what exists, what is missing and what you cannot prove
  • NIS2 and CRA deadlines counted in the platform, not in a calendar somewhere
See what it covers

What it does

From raw alert to signed evidence.

ISO policies

Your ISO 27001 policy set arrives drafted. A human approves it.

The platform reads the controls you have activated and drafts the missing policy for each one. An analyst reviews and signs before anything reaches the client. Nothing publishes itself.

Gap analysis

Know what exists, what is missing, and what you cannot prove.

Three states, not two. The difference between a policy that does not exist and one that exists but shows no sign of being practised is exactly what an auditor asks about.

Isolation

Tenant isolation is not a promise in code. It is a rule in the database.

Every row carries its client identifier and Postgres enforces Row Level Security in the engine. The application connects as an unprivileged role, so a wrong query returns nothing rather than another tenant's data.

Scanning

Scans scoped to the controls an auditor actually asks about.

HTTPS redirect, certificates, weak protocols, HSTS, CSP, SPF, DMARC, exposed paths. Every check maps to an ISO 27001, NIS2 or SOC 2 control, and each failure becomes a finding carrying that label.

Cases

From alert to audit evidence without leaving the app.

An alert becomes a case in one click, the case keeps the full investigation timeline, and a closed case attaches to the audit report as structured evidence.

NIS2

NIS2 gives you 24 hours, then 72. The clock runs in the platform.

The incident register holds the statutory notification deadlines, flags what has run past them, and keeps the state of every filing.

Post incident report

Every closed case leaves a report behind, not a memory.

Root cause, impact, affected systems, corrective actions, lessons learned. The draft fills itself from the case rather than from a blank form, and exports as a signable document.

White label

Your platform. Your name on it.

Each client gets their own name, colour and logo in the console and on the cover of exported documents. Your own team's console stays yours.

Coverage

What it covers today

One set of controls with several regimes laid over it. You do not keep four parallel folders for four auditors.

ISO 27001Annex A and clauses 4 to 10All 93 controls plus the 27 management system requirements, each with a document, an approval and an audit log entry.
NIS2Article 21, points a to jMapped onto the ISO controls you already run, plus an incident register carrying the 24 and 72 hour deadlines.
CRARegulation (EU) 2024/2847Scope determination, the four reporting deadlines, SBOM ingestion, and Annex I laid over your ISO controls.
ISO 9001Quality management systemThe same document, approval and evidence flow as ISO 27001.
SOC 2Trust Services CriteriaAlert filtering and scan checks carry criteria labels, and evidence attaches to the report.
GDPRIncluding Romanian Law 190/2018Processing register and evidence workflow, with policies drafted in the right legal context.
Compliance

Built on

Open source, pinned versions, no proprietary lock in.

Nothing running here ties you to us. Choose the self hosted option and you get exactly the same components.

Wazuh
SIEM, agents, rule engine
Keycloak
Identity, roles, authentication
Postgres
Data, with per client Row Level Security
MinIO
Object storage for evidence files
Spring Boot
API
React
Console

Let us find out whether this fits.

Tell us how many clients you carry, which frameworks matter, and whether you want this hosted by us or by you. You get an answer from a person, not a qualification form.

Request a quote