MAXI For MSSPs

Launch a 24/7 AI SOC service for every client — without building a platform of your own.

Humans augmented, not replaced.

AI Tier 1 for every client

Every alert from every client triaged around the clock — with evidence and a recommended response.

Your analysts decide

Your team escalates, closes and owns the client. A human makes every call that matters.

Second service line

Turnkey compliance per client — only the frameworks each client needs.

MAXI For MSSPs

Launch a 24/7 AI SOC service for every client — without building a platform of your own.

Humans augmented, not replaced.

AI Tier 1 for every client

Every alert from every client triaged around the clock — with evidence and a recommended response.

Your analysts decide

Your team escalates, closes and owns the client. A human makes every call that matters.

Second service line

Turnkey compliance per client — only the frameworks each client needs.

Why listen to us

Built and battle-tested inside a working MDR

Not a lab product — the platform the UnderDefense SOC works in every single day.

120+

companies protected by the SOC that runs on MAXI — the same platform you get

10 yrs

of 24/7 security operations for regulated business

Anywhere

your clients' data needs to live — deployed in the region their regulator expects

#1

of 92 teams at Splunk Boss of the SOC — the same team that runs on MAXI every day

Some of the group of companies managing their entities on MAXI
Betsson Group
ProCredit Holding
Pango Group
National Geographic
Invicti
Tyler Technologies
Smarter
monday.com
Aura
Helpware

Strong margin and recurring revenue opportunity

If you’re an MSP, UnderDefense not only offers superior security operations solutions, it also integrates effectively with your existing solutions to deliver a joint service to your customers. We offers:

  1. 01Sales and marketing support, enablement and training
  2. 02Strong margin and recurring revenue opportunity
  3. 03Predictable pricing, which allows MSPs to quickly scope customer needs
  4. 04Rapid and low-cost MSP onboarding for accelerated sales
  5. 05Simple billing processes for back-office efficiency
  6. 06Trouble ticketing integration for seamless handoffs of cybersecurity alerts
  7. 07Customizable and repeatable customer onboarding processes
The problem

Every new client adds a console, a queue and a night shift

A console per client

Every new stack means new runbooks, new training — and a slower analyst.

Drowning in alerts

Most of the queue is noise — but every alert burns analyst hours you pay for.

SLA held up by heroics

24/7 means 4–5 FTE per seat — the night shift eats your margin.

Reports by hand

Hours of unpaid QBR prep per client — and nothing sets you apart.

~75 min

to thoroughly investigate one alert by Human Tier 1 analyst

320 h

to onboard a single client

26%

of MSPs lack the people to onboard new clients

4.2 FTE

to keep one seat staffed 24/7

Revenue grows with headcount — and headcount is the ceiling → The unit of scale should be the platform.
Before · After

The same day in your SOC — before and after MAXI

BEFOREAFTER 08:00Analyst opens six consoles for six clientsOne queue, every client, sorted by severity09:30Still clearing overnight noiseOvernight noise already closed — with evidence11:00One real alert: ~75 min to investigateArrives as a case with 4Ws and a verdict — sign off in minutes15:00Client asks “what happened?” — write it up by handClient already sees the incident, in plain language17:00Monthly report stitched from five toolsReport generated in one click03:12Critical at client #7 — night analyst hunts for a phone numberEscalation chain calls the right contact — one button
Connect · Catalog

The stack your clients run — already supported

EDR

SentinelOne · CrowdStrike Falcon · Microsoft Defender XDR · Palo Alto Cortex XDR · Sophos Intercept X · Fortinet FortiEDR · Trend Micro Vision One · VMware Carbon Black · Symantec EDR · Trellix EDR · Cisco Secure Endpoint · Elastic Defend · Cisco XDR

SIEM & analytics

Splunk · Microsoft Sentinel · Elastic SIEM · Google SecOps · IBM QRadar · Datadog · Sumo Logic · LogRhythm · Logz.io · Coralogix · Gurucul · AlertLogic

Cloud, identity & response

AWS · Azure · Google Cloud · AWS GuardDuty · Wiz Defend · Orca · Prisma Cloud · Okta · Entra ID · CrowdStrike Identity · Microsoft 365 · Google Workspace · QRadar SOAR · ServiceNow · PagerDuty · Jira · Slack · Teams

MAXI Sources — integration templates
Grow · Margin

Understand your costs — down to every client and run

Per clientAI runs, tokens and spend for every tenant
Per agentTier 1, Summarizer, Copilot — cost by day
Per runEvery execution logged with its tokens and cost
Any periodFrom the last 7 days to a full year
AI usage — cost statistics by tenant
Daily AI cost by agent
Communicate · Dashboard

Your client sees your value — in hours and dollars

Their own dashboard shows every incident you handled, the time your team saved them and what it is worth — for any period.

Executive overview — incidents, time and money saved
Executive overview — incidents, time and money saved
Automation ROI — hours saved, FTE equivalent
Automation ROI — hours saved, FTE equivalent
Alert-to-resolution flow — every alert accounted for
Alert-to-resolution flow — every alert accounted for
Triage · One queue

One queue for every client — the most critical alert first

The problem

Analysts hop between consoles while the critical alert at client #7 waits.

How MAXI solves it

One Kanban across every tenant — sort by severity, group by client, drop into context.

Outcome

Group the queue your way — by client, severity, source or analyst.

Key facts

Waiting → Context → Analysis → Tier 2 → Client → Replied · T1 → T2 review & exclusions · Group by client · source · analyst

Alert Triage grouped by client
Triage · AI SOC

AI does Tier 1 — your analysts sign off

Your clients' data is never used to train AI models
The problem

A thorough manual investigation takes ~75 minutes per Analyst — and most of the queue is noise.

How MAXI solves it

Every alert from every client is enriched, investigated by the AI agent and handed to your analyst as a case with a verdict.

Outcome

Minutes per case instead of an hour per alert — one analyst covers more clients.

1,000raw alerts→~200clusters→~40incidents→~6cases
with
evidence
AI SOC investigation activity
Connect

Plug into the stack they already run

The problem

Every client runs a different stack — ripping it out kills the deal.

How MAXI solves it

119 integrations, each with a step-by-step guide the client's IT can follow — read-only API keys, nothing to install.

Outcome

No migration, no new agents — data flows on day one.

Key facts

119 integrations in 24 categories · 8 with MCP — AI queries SIEM/EDR live · No vendor lock-in — works with the tools they own

MAXI Integrations catalog
Communicate · Incidents

Every incident, every step of the investigation

The client sees the whole volume of your work: each incident, its timings, the verdict reasoning and every AI and analyst step behind it.

All incidents — searchable and exportable
All incidents — searchable and exportable
Findings — time to detect, triage and notify
Findings — time to detect, triage and notify
Investigation — every AI run and analyst step
Investigation — every AI run and analyst step
Triage · AI agents

AI agents do the legwork — your analyst makes the call

Your clients' data is never used to train AI models
Enrich

Every IoC checked against eight intel sources in parallel — reputation, geo, history

Correlate

Weak signals across endpoint, identity and cloud assembled into one chain

Playbook workflow of AI agents
Summarize

Findings written up as 4Ws: who, what, when, where — with the evidence

Hypothesize

Verdict hypotheses with reasoning, impact and a reversible containment plan

Triage · In production

A billion events a week — only 10 incidents that matter

957MObservations / week

Real-time correlation against IoCs across the whole stack

683Investigations / week

AI and analysts research, correlate and build the blast radius

10Incidents / week

Confirmed, contained and handed over with next steps

Client case:· 2,500 Windows/macOS macines· 2,500 O365· 400 cloud servers (Win/Linux)· Massive Azure· Integration with MS Teams· Custom Salesforce logs ingestion
82%

alert noise reduction

2 min

alert triage · 10 min enrichment

15 min

to identify an intrusion — industry average is 206 days

99%

MITRE ATT&CK coverage

Trust

A platform your SLA can stand on

Isolated tenant per client

Every client’s data, users and AI context stay in their own tenant

Hosted anywhere

Wherever your clients' data needs to live — deployed in the region their regulator expects

Certified ourselves

UnderDefense is SOC 2 and ISO 27001 certified — on our own platform

No training on client data

Your clients’ data is never used to train AI models

Every AI step on record

Each enrichment, query and verdict is logged — a full audit trail

We depend on it too

Our own 24/7 SOC runs on MAXI — its uptime is our SLA as well

Triage · Playbooks

Your playbooks become your Intellectual Property

The problem

Every customer is unique. We give that flexibility to adjust Detections and Response with Playbooks

How MAXI solves it

How things are processed to make it work for your customer - is defined by You with our AI. Unique 26 versioned templates, rolled out to many clients, tuned per client.

Outcome
Key facts

Bulk upgrade in safe mode · Sandbox on a real alert · AI prompts per client · Grouping policies

Playbook Templates
Communicate · Voice

One click, and MAXI calls the client

The problem

At 3 a.m. an analyst dials contact after contact from a spreadsheet — and nobody logs who answered.

How MAXI solves it
Calls in orderWalks the client's escalation chain one contact at a time until someone confirms
A spoken briefingSeverity, incident number and what happened — the contact presses a key to confirm
Human decisionNothing is ever dialed automatically — your analyst presses the button
Voice escalation playbook
Communicate · Escalation

The right person hears it first — a human always makes the call

The problem

3 a.m., critical incident: the analyst hunts for a phone number.

How MAXI solves it

An ordered escalation chain per client: who is called first, over which channel, and what each contact opts out of.

Outcome

Clients hear exactly what they need, when they need it.

Key facts

30 notification types · Per-contact opt-out · Email · Jira · PagerDuty · Auto-close when the client stays silent · Great defaults — you override every one

Escalation contacts per tenant
Onboard · AI context

Tell the AI who your client is — once

The problem

Analysts investigate blind: they don't know the client's business or what normal looks like there.

How MAXI solves it
AI organization contextThe client's business, crown jewels and what normal looks like — read before every investigation
Your client's logoTheir brand on their workspace
Written onceEvery alert, case and report for this client uses it
Tenant AI organization context
Onboard

Launch a new client in one sitting

The problem

A new client means spreadsheets and shared logins

How MAXI solves it

One tenant card — plus a login for the client

Outcome

Your value is visible from day one

What your client sees

Every alert · case history · MTTD

Tenant card
Connect · Health

Broken connectors surface before the client notices

The problem

A connector breaks silently — and the client finds the gap before you do.

How MAXI solves it
Live statusEvery source per client: active or broken, with change logs
Per-source tuningCut noise per client source before it reaches your queue — every filter tested in a playground first
Early warningExpired credentials and deactivated connectors trigger an alert
Sources health per client
Triage · Views

A view for SOC managers, a view for analysts

The problem

Managers need the overview, analysts need the workflow — one screen rarely gives both.

How MAXI solves it
List — for SOC managersEvery alert across every client in one table: severity, client, source, status, assignee
Board — for analystsCases move through the stages, from waiting for triage to client replied
One queue, two lensesSwitch in one click — same data, same filters, nothing duplicated
Alert Triage list view
Triage · Case

A case with evidence, not a raw alert

Your clients' data is never used to train AI models
The problem

Analysts get a raw alert and spend the first hour just collecting context.

How MAXI solves it
4Ws + hypothesesWho, what, when, where — with the investigation steps behind them
IoCs with reputationEvery indicator checked before your analyst sees it
Verdict with confidenceTrue positive, false positive, legitimate or risk accepted
Case with 4Ws and alert details
Triage · Incident

An incident your client actually understands

The problem

Clients get raw SIEM dumps they can't act on.

How MAXI solves it

Every incident reads like a briefing — what happened, what it means, what to do next.

Outcome

Clients act in minutes instead of calling your SOC for a translation.

Key facts

When · What · Who · Where · What this means for you · What you should do next · IoCs & reputation

Incident details for the client
Report · QBR

Every QBR proves your value — in one click

The problem

Reports stitched by hand from five tools make thin QBRs.

How MAXI solves it

The monthly MDR report in one click — 17 sections, built from data the platform already has.

Outcome

The SLA you kept and the threats you stopped — the proof that drives renewal.

Key facts

640 alerts reviewed → 633 false → 7 confirmed · Response times vs SLA · Night-shift coverage · Top detections

MDR Impact Report — executive summary
Report · Builder

Pick the sections, MAXI writes the report

The problem

Monthly reports are assembled by hand from exports and screenshots — for every client.

How MAXI solves it
OperationalUsers at risk, response times, alerts over time, night-shift coverage, confirmed incidents
DetectionTop detections, SIEM license usage and warnings, 90-day analytics
StrategicLeaked credentials, communication summary, monitored assets, vulnerable hosts
New MDR report builder
Onboard · SLA

An SLA clock for every client

The problem

Every contract has different SLA terms, tracked in someone's head or a spreadsheet.

How MAXI solves it
Critical2 min to acknowledge · 15 min to inform · 45 min to a final verdict
Per severityCritical, High, Medium and Low — each with its own targets
Per clientDefaults out of the box, tuned to each contract
SLA values per tenant
Report · CISO Copilot

Find answers — SUPER FAST, in plain language with COPILOT

The problem

A client's question turns into hours of queries across Splunk, Sentinel and Defender.

How MAXI solves it
Questions, not queries“Which assets have unpatched critical vulnerabilities?” — answered from the client's own data
Hands on the stack33 tools: Splunk, Elastic and Sentinel searches, Defender hosts and users, incidents, assets, cases
Reports on demand7-day risk, 30-day impact, board summary, compliance gap — saved to the client's reports
CISO Copilot
Get started

Unlock new revenue streams for your MSP/MSSP

Add managed infrastructure and security services to your portfolio without building them from scratch. Bundle with your existing offerings, increase client lifetime value, and multiply your per-client margins.

  • Generate recurring revenue from every client with bundled services
  • Compete with larger players—offer enterprise-grade managed security at any scale
  • Onboarding in 2–3 weeks—sell faster, implement sooner
Grow · More service lines

More to sell on the tenant you already run

Every client you monitor is a ready-made opportunity for the next service — no new platform, no new onboarding.

Compliance

Turnkey programs per client — only the frameworks they need, Trust Center included.

Readiness per framework · autochecks · auditor access

External risks

Attack surface, leaked credentials and exposed services monitored continuously.

Subdomains · open ports · TLS · credential leaks

Assessments & pentest

Cloud CIS benchmarks, vulnerability scans and pentest reports in the client's workspace.

AWS · Azure · GCP · Kubernetes CIS · pentest

vCISO with Copilot

Board-ready answers and reports on demand for clients without a security leader.

Board summary · risk report · compliance gap

Bundles are set per client with presets — switch a service on the day the client says yes.
Grow · Packaging

Sell in tiers from day one — upgrade a client with one switch

A starting blueprint for your own price list — rename, reprice and regroup as you like. Each tier is a preset on the client’s tenant.

Tier 1

Standard

Confident protection 24/7/365

  • Endpoint detection & response 24/7
  • Dark web exposure & leaked passwords
  • Direct chat with on-duty analysts
  • Monthly reports & remediation guidance
Tier 2

Enhanced

Extends to cloud, SaaS and email

  • Everything in Standard
  • Cloud, SaaS & email detection & response
  • External attack surface & threat intelligence
  • Vulnerability assessment · IR retainer
Tier 3

Professional

360° protection and full visibility

  • Everything in Enhanced
  • Managed SIEM & XDR
  • Advanced threat hunting & automated response
  • Compliance reporting · tool fine-tuning
Grow · Compliance

Turnkey compliance — only the frameworks each client needs

The problem

Every client needs a different framework — spreadsheets don't scale past three.

How MAXI solves it

Switch frameworks on per client: NIS 2 + ISO 27001, SOC 2, the local regulator.

Outcome

Each client gets exactly its program — on the tenant you already run.

Key facts

ISO 27001 · SOC 2 · HIPAA · GDPR · PCI DSS 4.0.1 · NIST CSF 2.0 · DORA · NIS 2 · ISO 42001 · CIS v8 · CCPA · DPF · NBU 143 · All tenants × frameworks on one screen · Fix once — counted in every framework

Compliance progress dashboard
Grow · Compliance

Evidence that collects itself

The problem

Evidence is gathered by hand right before the audit — and it's outdated the day after.

How MAXI solves it
Every 24 hours214 autochecks re-verify the client's connected stack
Failed → taskGaps become tasks with an owner, not audit surprises
Passed → evidenceProof lands on the control automatically — audit-ready between audits
Autochecks
Onboard · Access

The right access for every client's team — in a minute

The problem

Client staff, auditors and your own analysts need different access — shared logins are an audit finding waiting to happen.

How MAXI solves it

Invite from the tenant card with a role per product: AI SOC, Compliance AI, CISO Copilot.

Outcome

Access is set during onboarding — every permission on one screen.

Key facts

Active / pending at a glance · Resend or remove in one click · Auditor access scoped to one client

Add user with role
Role permissions
Grow · Compliance

Audits without the scramble — and your own NIS 2 covered

The problem

Every audit means questionnaires, PDFs and weeks of back-and-forth with the client.

How MAXI solves it
Trust CenterA public page your client shares instead of a security PDF
Auditor accessScoped to one client — the auditor self-serves
Your own NIS 2MSSPs are in scope too — close yours on the same platform
Trust Center
Alternatives

Build it, stitch it — or run it on MAXI

BUILD IT YOURSELFSTITCH POINT TOOLSMAXI Time to first clientMonthsWeeksSame dayOne queue across every clientYou build itOften a console per tenantBuilt inAI Tier 1 investigationYou build itSeparate vendorBuilt inClient portal & monthly reportsYou build itPartialBuilt inCompliance as a second lineSeparate toolSeparate vendorSame tenantWho maintains itYour engineersYou integrateUnderDefense
Support

You are not doing this alone — we have your back

The UnderDefense SOC team
Partner success

One named contact from kickoff to renewal

Pilot plan agreed up front

SOC engineering

Integrations, detections and playbooks tuned with your team

The engineers who run our own SOC on MAXI

Escalation backup

Tier 3 and incident response when a case outgrows your bench

Support · Bench on demand

Backup when you need it — you stay the face of the service

Optional: the analysts who run UnderDefense’s 24/7 SOC on MAXI work behind your service — per shift, per tier or per incident. Your client only ever talks to you.

Night shift

Offload night shifts or alert triage — the hardest seats to staff.

Tier gaps

Fill Tier 1, Tier 2 or Tier 3 gaps without hiring.

Incident response

An IR retainer with remote forensics when a case outgrows your bench.

Detection engineering

Rule tuning, threat hunting and a library of 1,000+ correlation rules.

Automation handles the noise. Humans handle the nuance.

Manage security for your clients in a new way

UnderDefense Incident Response Platform helps MSPs to manage ensure 24×7 breach protection through active monitoring, detection, and respond to cyber attacks from a single console across all your clients

24×7 Breach detection and Incident Response

Our 24×7 SOC-as-a-Service ensures security is monitored around the clock by expert team of professionals.

Protect Your Organization

UnderDefense’s 24×7 security teams work around the clock to monitor, detect, and respond to cyber attacks before they have the chance to impact your business.

Tools your clients already have

We support industry-leading security solutions which your clients have or you sold them. Core platforms like: Sentinel One, CrowdStrike, Fortinet, Sophos, TrendMicro

Managed Risk & Compliance

You will get an automated Compliance monitoring, documentation and analytics to help your client meet standards like PCI, HIPAA, ISO27001, SOC2

Security that makes sense

UnderDefense’s 24×7 security teams work around the clock to monitor, detect, and respond to cyberattacks before they have the chance to impact your business.

Product Branding

  • Incorporate MSP brand with service offerings

MSP Service Reports

  • Customizable reports to illustrate client endpoint security posture & actions taken by MSP to respond to threats

Multi-Tenant Support

  • Manage multiple clients from one console with multiple dashboards

Bundled Functionality

  • Add on 24×7 SOC, SIEM, MDR, EDR, vulnerability, patch, compliance, as-a-Service
  • Reduced total cost of ownership

Cloud Security

  • Host your client tenant in your region in Amazon, Google or Azure and other cloud tech

MSP Service Licensing/Price

  • Simple Monthly subscription
  • Endpoint based pricing
  • Low cost per asset

Small, Medium, Large scale enterprises are at continuous risk

MSPs can help protect the end customers by adding (white label) UnderDefense 24×7 security-as-a-service offerings to their portfolio.

MAXI executive overview dashboard
  • Over 2,000 new attacks are being launched every day that exploits a weakness in software components
  • 43% of cyber-attacks target small businesses.
  • 60% of small businesses that are victims of a cyber-attack go out of business within six months.
  • There was a 424% increase in new small business cyber breaches last year
  • 40-60 new vulnerabilities are discovered every day, many are critical
  • Many companies take six months or longer to discover vulnerabilities, and several more months to mitigate risks
MSP & MSSP partner program

Launch your AI SOC service on MAXI

A named partner contact, a pilot plan agreed up front, and the engineers who run our own SOC on MAXI.