Platform · one box you own · Debian or Ubuntu · Docker or bare metal

Everything between the alert and the decision. On one box you own.

Seculogik is not a SIEM, so it never charges for what you ingest. It is not a sensor, so it never competes with your EDR or your NDR. It is the decision layer above the stack you already run: it consolidates the alerts, qualifies the few that matter, helps your analyst decide, runs the response with a person at every gate, and keeps a trail an auditor can read a year later.

23
Vendor connectors
plus open-source stacks, webhooks and custom connectors on request
72
Detection packs
MITRE-mapped, importable from a screen
9
Correlation strategies
each looks at every alert from a different angle and votes
3
Editions
Free, Client, MSSP — and six add-ons, quoted per deployment
1
Box you own
VPS or on-prem, no GPU, no per-GB meter
Integrations

Source-agnostic. Whatever you run today is where we start.

Seculogik sits above the detection stack you already have. Open-source SIEM and data stacks: Wazuh, OpenSearch, Elastic / ELK, ClickHouse. Market platforms: Splunk, Microsoft Sentinel, CrowdStrike, Microsoft Defender, SentinelOne, Cortex XDR, Fortinet, Suricata, Zeek, AWS, Azure, Microsoft 365, Okta, Entra ID, ServiceNow, Jira, TheHive. Alerts reach the platform three ways — a connector pulls them, your tools push them through a webhook, or the platform quietly tails the SIEM index you already maintain — so nothing has to be re-plumbed and nothing has to move.

Not on the list? We build the connector, or you push events through the generic webhook and map them once in the universal data map. Replacing your log store is never part of the deal.

Universal data map

One language for every alert, whatever produced it.

Every source lands as the same canonical alert, so a failed login from your identity provider and one from your endpoint agent read the same way to the correlation engine, to the analyst and to the report. Mappings ship ready for the common sources and can be adjusted per client without a code change. Repeats are recognised on arrival, so a noisy sensor never inflates your queue.

Detection content and correlation

Seventy-two MITRE-mapped detection packs ship with the platform and import from a screen, so coverage grows without a consulting engagement. Above them, the Correlation Engine — nine independent strategies that vote on one verdict — turns the flood into a small number of cases that read as a story. And when a case needs a second opinion, SIROC, the AI analyst, lists its hypotheses and evidence before its verdict, with that evidence checked against your own alerts.

Cases and the decision queue

The default screen answers “what do I do now?”

The Operations Deck is not a monitoring wall. It opens on the decision queue — awaiting triage, SLA at risk, high risk, unassigned critical — ranked by rules you can read, the same way every time, with every item one click from its case.

An explicit act of decision

A case does not drift from new into investigating. Somebody triages it, and that moment is recorded — who, when and on what grounds. Cases that should never have existed can be retired and brought back, and the trail survives either way.

SLA clocks your contract can trust

Time to acknowledge and time to resolve, per severity, with pause and resume for the legitimate waits and a warning before the breach rather than after it. The queue ranks on the clock, so the case about to breach is the case on top.

Assignment by capacity, not by habit

New cases go to the analyst with the most room, within the roles your escalation policy allows, drawn from the people who opted into the pool. Nobody finds a critical case in the morning because it went to whoever was listed first.

A risk gauge you can explain to the board

Each case carries a risk score built from factors a CISO can read — how severe, how far the attack has progressed, how confident the attribution, how much time is left on the clock. Explicit, auditable, explainable. No opaque model in the score, on purpose.

Decision trace and counterfactual

Every case keeps a readable record of why it exists: which signals mattered, how the verdict was reached, and what would have had to differ. Read it a year later, in front of a regulator, without re-running anything.

Kill chain and MITRE coverage

A case's kill-chain position advances with the evidence, so a phishing case that turns into lateral movement climbs the queue. And the coverage matrix is built from the detections actually running, not from a spreadsheet of what was meant to run.

Multi-client for MSSPs

One deployment per MSSP. Hard walls between your clients inside it.

Each client gets its own case space, enforced at several independent layers rather than by one filter somebody could forget. An alert that cannot be attributed with confidence waits in a quarantine queue for a human — it is never guessed into the wrong client. Reports, the vulnerability centre and the AI analyst all narrow to the client in scope, so an analyst working one account never sees another's.

White-label per client: logo, colours, favicon and page title, with contrast kept readable whatever palette a client picks. Your clients see your brand. Your analysts see one console.

Response

Response that pauses for a human — and picks up where it left off.

Workbooks chain the everyday actions — triage, tag, reprioritise, assign, escalate, open a task, notify the right channel, enrich — and the enforcement steps behind them, through the connectors you already have. Destructive actions such as isolating a host always wait for a person. An approval gate is durable: if the platform restarts while a run is waiting, the run resumes at the gate, and approving twice does nothing twice. Branch on success or failure; a workflow that would loop forever is refused before it starts.

And the platform reports what actually happened. A host that was not isolated never gets a green tick because a message was sent — you see whether the action was done, whether it failed, or whether nothing was in a position to do it, and why.

Vulnerability Operations Centre

Vulnerabilities are not incidents. They get their own queue, SLA and lifecycle.

Findings from your scanners — agent-based, agentless, or already sitting in your SIEM index — come together in one place where the source stays part of the record, so two scanners agreeing on one exposure is corroboration rather than a duplicate. Coverage is stated on every screen: you always know how much of the estate was actually looked at, and a scanner outage never reads as a clean bill of health.

  • A remediation lifecycle with owners and due dates, so every exposure is somebody's job by a date.
  • A risk-acceptance register with an expiry, so nothing is accepted forever by accident.
  • Known-exploited and ransomware-linked exposures escalated ahead of the rest.
  • A committee-ready report that states its coverage before it states a figure.
Reporting

MSSP-grade, with the methodology attached.

Case reports that read as a story, with the kill chain drawn in. Per-client reports delivered on a schedule. Compliance scorecards for NIST CSF, ISO 27001, GDPR, DORA and NIS2, and evidence packs that label each control as implemented, a gap or insufficient — and describe themselves as a self-assessed coverage signal, never an attestation.

The evidence rule

Every number on a report carries the evidence behind it. A metric that cannot be computed from your real data says so, in plain words, instead of showing a figure that merely looks reassuring. Nothing is extrapolated. A zero has to be explainable.

Security controls, built in

A security product should be the hardest thing on your network to abuse.

Identity

Single sign-on over SAML, multi-factor authentication, role-based access that separates reading from acting from administering, and scoped keys for your own automation.

Secrets

Connector credentials and integration keys are encrypted at rest, never written to a log, and never shown again once entered — not even to an administrator. Response agents on your hosts keep vendor credentials there; the platform never holds them.

Audit

Every action that changes state lands in a tamper-evident audit trail, kept per client, that cannot be edited or deleted afterwards — the trail a regulator asks for in the first hour of an incident.

Updates and disclosure

Signed updates that roll back on their own when a health check fails, a software bill of materials for every release, and a coordinated vulnerability disclosure process you can hold us to.

The full trust page →

Install

One box. Minutes to install. Yours to keep.

A VPS or an on-prem server, Debian or Ubuntu, Docker or bare metal, no GPU required. Bring your own certificate or start with ours. Updates are signed and roll back on a failed health check, so an upgrade is not a weekend. And the demo runs on your telemetry, not ours.