The iG2 AI SOC · Managed XDR

A managed SOC in a box.On your premises.

Managed extended detection and response (MXDR), delivered as one rack inside your own network. AI triages every alert on-site, iG2 analysts watch over it around the clock, and your security data never leaves your building.

Request a briefing

SOC in a box

Most MXDR services ship your logs to someone else's cloud. The iG2 AI SOC turns that around: the detection, the analytics and the AI all run in a rack on your floor, and the service comes to you.

Illustration.

How it works

From raw telemetry to a closed incident. All on-site.

Sensors feed the rack, AI does the first pass, and people make the calls that matter. Only the decisions travel; the data stays put.

1CollectEndpoints, network, cloud, identity and OT logsON-PREM
2DetectXDR and SIEM correlation with CRISPERON-PREM
3TriageA local AI model enriches, scores and explains every alertON-PREM
4RespondSOAR playbooks plus iG2 analysts, 24/7MANAGED
The analyst console

One console. Every alert, explained.

What your team and ours see on the AI SOC. Click through it below.

iG2 AI SOCMONITORING · ON-PREM

Alert queue

Raw events1.2M

Collected in the last 24 h

Alerts340

Raised by detection rules

Need a human6

After AI triage

Suspicious PowerShell on FIN-WS-22High · with analyst
Impossible-travel sign-in, j.martinMedium · awaiting user
Port scan from guest Wi-FiLow · auto-contained

Illustrative example. Not live data.

What's in the box

A whole security operations centre, not a log forwarder. Detection, storage, AI and response in one rack, with a secure link back to the iG2 team.

Secure management link Outbound only
AI triage engine Local LLM · GPU
CRISPER XDR / SIEM Detection
SOAR Playbooks
Security data lake Retention
  • CRISPER detectionXDR, SIEM, file integrity and vulnerability management
  • On-prem AI analystA local language model that triages, explains and drafts reports
  • SOAR automationPlaybooks for isolation, blocking and account lockout
  • Security data lakeYour logs, retained and searchable inside your walls
  • Threat intelligenceIndicator feeds synced in, nothing synced out
  • Secure management linkHow the iG2 team operates the box, under your control
Cloud MXDR vs. the AI SOC

Same managed service. Different address for your data.

Typical cloud MXDRiG2 AI SOC
Where your logs are storedVendor's cloudA rack on your premises
Where the AI runsShared, multi-tenantOn your hardware, for you only
If the internet goes downDetection goes darkDetection and response keep running
Data residencyDepends on the vendorCanada, inside your perimeter
Who watches itVendor analystsiG2 analysts, with your team

Run it the way your organization needs

Fully managed

  • iG2 runs detection and response 24/7
  • Escalation only when you are needed
  • Monthly reporting and reviews

Co-managed

  • Your analysts and ours, one console
  • Shared playbooks and approvals
  • Hands-on mentoring for your team

Air-gapped

  • No outside connection at all
  • Your team runs it, AI does the triage
  • iG2 support on-site when called

Built for organizations that can't send logs away

Where security data is itself sensitive data.

Defence
Healthcare
Public sector
Critical infrastructure
Every AI SOC includes
CRISPER XDROn-prem AI triageSOAR playbooks24/7 iG2 analystsCanadian data residency

Managed detection that stays where your data is

No log shipping, no shared tenancy, no data leaving your network. Rack it, connect your sensors, and iG2 starts watching.

Request a briefing

For years, MXDR meant sending your logs away. Now the SOC comes to you.

Request a briefing