SXGuard — Swiss Security
Defensive Services
Defensive Security

AI-Integrated SOC, Incident Response & Log Plumber

Clear the log pipes, monitor continuously, and respond with evidence when an incident happens.

  • 24/7 hotline
  • NDA before any technical detail
  • You don't have to be a client already
What we do

Three Services. One Defensive Operating Model.

Start by making security telemetry usable, monitor it continuously, and respond with the same evidence when an incident occurs. Explore each service in detail below.

Service 1

24/7 SOC monitoring

Round-the-clock monitoring. The AI reads first. A human decides.

View details
Service 2

Incident Response

When it happens, you don't start from zero.

View details
Service 3

Log Plumber

Before you buy anything else, find out whether what you already own is talking.

View details
Positioning

Breaches Happen When Logs Never Arrive, Not Because You Lack Tools.

You bought the firewall. You bought the EDR. You bought the IPS.

Then an incident happens, and what's missing isn't analysis — it's data. A sensor that's switched on but not recording the event class that matters. Logs that stop at the appliance. A source that went quiet six months ago and nobody noticed. Or logs that arrive carrying nothing to say which system they came from.

So we work in this order: clear the log pipes, monitor 24/7 on an AI-integrated platform, respond when it happens. Skip the first and the other two are theatre.

Rack-mounted network hardware streaming telemetry
Deployment

On-Premise, On-Cloud, Or Split. Same Platform, Different Address.

The platform runs entirely inside your infrastructure, on infrastructure we operate, or across both. This doesn't change what gets detected. It changes where the trust boundary sits — and that's your call, not your vendor's.

On-premise

Entirely inside your infrastructure

Where your data sits: with you, full stop.

Choose this when: data residency obligations. Isolated networks. You already have an infrastructure team.

SOC-as-a-service

On-cloud, separated per client

Where your data sits: infrastructure we run, isolated per client.

Choose this when: you want a SOC quickly and don't want to run a platform or staff a 24/7 rota.

Hybrid

Collected locally, analysed centrally

Where your data sits: collected and normalised on site, analysed centrally.

Choose this when: sensitive data has to stay put, but you still want an outside monitoring team.

One thing holds across all three: the AI runs on local GPUs, and your logs are never sent to a public AI service. For fully isolated networks, the platform can demonstrate continuously that it has no route to the internet — evidence you can hand an auditor.

Jurisdictions. We operate from Vietnam and the UAE. So a data residency conversation in Southeast Asia or the Gulf starts with a team already in the region, not one flying in.

What makes us different

Four Things A Spec Sheet Won't Show You

Two centres, two countries

Our analysts work from Ho Chi Minh City and Dubai, both on a 24/7 rota. Two power grids, two internet paths, two public holiday calendars. When one centre goes dark, the other is already watching.

The AI runs inside your estate

None of your logs go to a public AI service. If you're under data residency rules, that's the difference between workable and not — not a feature to compare on a grid.

Analyst coverage from Ho Chi Minh City and Dubai plotted on a world map

A human signs the verdict

The AI does the heavy, repetitive work. An analyst reaches the conclusion and owns it. We don't sell automated response, because a wrong action on a production system usually costs more than the incident that triggered it.

We can measure what we detect

We separate rules that are wired from rules that are proven to fire. Every reporting cycle you get both numbers and the list of what's still a blind spot. A coverage figure nobody can check isn't a coverage figure.

SXGuard analyst reviewing a detection dashboard

In An Incident, Or Trying To Avoid One?

In one. Call the hotline. We take the call first and do the paperwork after.

Not in one. Start with a log coverage assessment. Fixed scope, fixed duration. The findings will tell you what to do next — including when the answer is "you don't need a managed SOC yet."