01 · How it works

From kickoff to steady state, in five weeks.

Here is exactly what happens after you sign. No "phase three, optimization" black boxes. Six steps, five weeks to a SOC that reads instead of screams. Every step has a deliverable you can hold.

01

Discovery call

Thirty minutes. You talk, we listen.

You describe your stack. We describe what we would monitor first. You leave with a draft coverage plan. Either you like it or you do not. No slides, no pitch.

30 minWeek 0Draft plan
02

Environment audit

We find what you are not seeing.

Read-only access for one week. We map your assets, flag the unmonitored ones, and show you the gap before you sign anything. On a typical run that is 847 assets found, 119 unmonitored, 41 stale IAM grants.

Read-onlyWeek 1No commitment
03

Coverage plan

A written plan, in plain terms.

What we will ingest, what we will alert on, what we will suppress, and what we expect to catch. Sources across CloudTrail, Okta, GitHub, and Wazuh endpoints. Retention tiered hot, warm, cold.

Week 2WrittenNo black box
04

Deployment

Rolled out quietly, no downtime.

Wazuh agents go out on a canary rollout. Log pipes get wired up. No production touch, no maintenance window required. First event usually lands within the hour.

Weeks 2 to 3CanaryZero downtime
05

Tuning window

The noise drops. The signal stays.

We tune aggressively. False-positive rate falls from around 40% to under 2%. On a real deployment that is 4,180 alerts a day down to 38. You stop ignoring alerts and start reading them. This is where we earn the retainer.

Weeks 3 to 599% signalThe real work
06

Handoff, you own it

The keys are yours. So is the SOC.

Two training sessions, written runbooks, and architecture docs handed over. The Community platform is already running. Upgrade to Team or Enterprise when your team is ready for the ops layer. Open source, so when you leave, the keys come with you.

Week 5RunbooksYou own it
02 · The audit comes first

We show you the gap before you sign.

Most vendors ask you to trust the plan. We would rather prove it. Week one is read-only. We walk your environment, count what is monitored and what is not, and hand you the blind spots in writing. If the gap is small, we will tell you that too.

Nothing is changed and nothing is billed until you have seen the audit. The plan you sign is the one the evidence supports, not the one that sounds good on a call.

Read-only, week 1
Environment audit · read-only week 1 ●
mode read-only, no changes before you sign
assets discovered 847
unmonitored blind spots 119 · 14%
exposed services 3
iam stale grants 41
output the gap, in writing delivered ✓
trustyou see the gap before you pay
Ready to scope it

Five weeks from here. Or self-serve today.

SOC Setup is the full guided path, starting at $3,299 over roughly five weeks. Or skip the setup and run the Community platform on Wazuh you already have. Either way, you own the result.