SOFTNET USP unifies SIEM, XDR, endpoint and network detection, unified device management and a licensed 24×7 managed SOC — with strict tenant isolation and Malaysia data residency built in from the first event.
Every layer shares the same raw-first evidence store, entity model and audit trail — so an alert on an endpoint, an identity and the network resolve into a single case.
Ingest logs over Syslog/TLS, OTLP, webhooks and cloud APIs. Raw evidence is committed with a content hash before any transform, normalized to OCSF, and searchable with our own query language.
Streaming, threshold and sequence rules mapped to MITRE ATT&CK, versioned and ring-deployed. Related signals correlate into prioritized cases with an evidence timeline.
Memory-safe agent for Windows and Linux with typed, signed response actions — isolate, quarantine, terminate — always reversible and preserving the management channel.
Federated management through Intune, Apple MDM and the Android Management API. One management authority per device — always — with ownership-gated wipe.
Passive sensors and flow logs resolved to entities and correlated with endpoint and identity evidence. Metadata-first, with tightly governed packet retention.
Optional 24×7 monitoring, threat hunting and DFIR, staffed separately and licensed under Malaysia's Cyber Security Act 2024. Sold on measurable MTTA/MTTR outcomes.
Server-side tenant filters injected on every query path. Cross-tenant reads return zero rows — verified in CI and by independent testing.
Raw events committed immutably with hashes and full lineage; an append-only, hash-chained audit trail proves the platform's own integrity.
Destructive actions need two-person approval, blast-radius limits and a per-tenant kill switch. Nothing touches a device without a signed, expiring command.
Tenant data never silently leaves its region. Built to PDPA 2010 (2024 amendments), with RMiT support packs and dedicated Malaysia cells.
Subscriptions meter what actually drives cost — sustained event rate, retained volume, managed endpoints and analyst seats. Move up a tier or add the managed SOC at any time.
Add a licensed 24×7 SOC to any tier: monitoring, triage, proactive hunting and DFIR retainer, with MTTA of 15 minutes for priority-1 alerts and monthly service reviews. Delivered under a CSSP licence (Act 854).
Indicative packaging. Final pricing is set per workload against measured event volume, retention and endpoint count. All tiers include tenant isolation, evidence integrity and the full audit trail.
Certifications and control mappings maintained under DPO oversight, available to customers under NDA through the trust portal.
Pilot programmes run on a dedicated evaluation tenant with your sources, shipped detection content and a full case workflow. Talk to us about scope and timelines.