Pole 02

Managed SOC: AarSOC

AarSOC is a detection and incident response platform built exclusively on open-source components. It is deployed in your infrastructure: no data transits through our systems.

245,000

alerts processed in 30 days

On our own AarSOC production infrastructure. A measurement, not a projection.

< 90 s

alert → notification latency

Measured on our own AarSOC infrastructure in production: from ingestion to alert notification.

194 d

mean time to detect a breach

An organisation without continuous detection leaves an attacker operating for over six months. IBM, Cost of a Data Breach 2025.

68%

of breaches involve a human factor

Operator error, social engineering or privilege abuse. Verizon DBIR 2025.

Capabilities

Detection

Event collection from multiple simultaneous sources: systems, network, applications, cloud services. Normalisation, correlation and application of MITRE ATT&CK-aligned rules. Real-time alerts on detection of abnormal behaviour.

AI-assisted triage

Alerts are automatically classified, enriched and prioritised. Technical identifiers (hostnames, accounts, internal IP addresses) are pseudonymised before any processing by an external model. No sensitive decision is made without prior analyst validation.

Investigation

Each qualified alert provides access to full context: event timeline, correlation with prior activity, inventory of involved assets, associated indicators of compromise. The analyst has all the data without having to reconstruct it manually.

Response

Documented and tested containment procedures: network isolation, session revocation, account lockout. Evidence collection with certifiable timestamps. Every response action is subject to human validation; no irreversible automated action is triggered without explicit confirmation.

Deliverables

Incident reports are encrypted with AES-256 before export. A unique password is generated for each delivery and transmitted via a separate channel; it is never stored in plaintext in our systems. Reports are bilingual, in French and English.

Client isolation

Isolation is enforced across three layers: transport (TLS 1.3 with client certificates), storage (separate encryption keys per organisation), application layer (role-based access control, no cross-tenant visibility possible).

Traceability

Every action, human or automated, is logged with a timestamp, operator identifier and operation context. Audit logs are immutable and stored separately from operational logs.

Backups

Configuration data and operational data are backed up with encryption daily. Restoration procedures are tested periodically; results are documented.

Integrity of collected data

No collector communicates with the platform without mutual authentication: each agent presents a client certificate validated against our internal certificate authority. Authentication is bidirectional by design, with no shared secret or static token.

Roadmap

Available

  • Multi-source detection with MITRE ATT&CK rules
  • Investigation with full context and timeline
  • Response: containment, evidence collection
  • AES-256 encrypted incident reports, bilingual FR/EN
  • Client portal: dashboard, incidents, tickets
  • Full traceability of operator actions
  • Encrypted backups with tested restoration

In development

  • Autonomous triage agents for levels 1 and 2
  • Native incident management with qualification workflow
  • Local AI inference (no external data transmission)
Join the pilot program FAQ All services