Services · five managed SOC offerings, three tiers
Five managed SOC offerings — 24/7 monitoring, threat detection & response, compliance evidence, phishing defense, and vulnerability management — packaged into three tiers (Watch / Defend / Command) sized for the regulated SMB in healthcare, legal, financial, defense, and SaaS.
stwp.offerings / five pillars
24/7 Monitoring
Always-on named-analyst coverage
Threat Detection & Response
AI surfaces the top 1% · a named engineer closes the loop
Compliance Evidence
Audit-ready artifact library per framework
Phishing Defense
Named-analyst inbox triage + user-reported review
Vulnerability Management
Continuous scan + a named engineer behind every reading
The five managed SOC offerings · named deliverables + cadence
Every offering has a named set of operators on the rotation. The role roster does not change between offerings — the SOC Director, the detection engineers, the IR Lead, the Compliance Lead all stay on shift across the five.
Always-on named-analyst coverage
Pure-always-on coverage across the telemetry you already ship — EDR, identity, network, cloud, and email. Named shift analysts on every escalation, a Monday customer-facing note, and a documented escalation contact — so the SOC stays attributable at handoff instead of dropping into an auto-only overnight window.
Named deliverables
AI surfaces the top 1% · a named engineer closes the loop
AI triages the top ~1% of inbound signals; a named detection engineer validates, escalates, or closes each one. Containment decisions, the detection-to-containment timeline, and the after-action review ship in writing — every step attributable to a named engineer, including the lessons-learned entries the auditor will sample against.
Named deliverables
Audit-ready artifact library per framework
Detection logs, incident records, access evidence, and response timelines translated into the artifact format each framework asks for — CMMC, HIPAA, PCI DSS 4.0, ISO 27001, US state privacy. Your named engagement lead signs the quarterly evidence pull and stays accountable for the life of the contract.
Named deliverables
Named-analyst inbox triage + user-reported review
Mail-gateway detections, reported-message triage, and the after-action note that lands in your customer-facing inbox on Monday morning — wrapped around a named analyst on rotation. AI surfaces the patterns; humans write the note a phishing victim actually reads before the next quarterly awareness round.
Named deliverables
Continuous scan + a named engineer behind every reading
Continuous external + authenticated scans, weekly prioritization reviews, and a named detection engineer writing the disposition note behind every accepted risk. Findings are scored against the framework list your auditor will sample against — not a CVSS-only ledger — and written into the after-action evidence on /compliance.
Named deliverables
Three tiers · Watch · Defend · Command
Every plan ships with US-based analysts, named escalation contacts, and full audit trails. The capacity numbers below are the most you can run, not the minimum you have to pay for — even the smallest tenants get the same named-SOC coverage as Defense.
For small teams that need a managed SOC without standing one up themselves. Pure 24/7 monitoring across EDR, identity, network, cloud, and email telemetry.
Includes
For organizations under a few hundred seats running under HIPAA, PCI DSS, SOC 2, or ISO 27001. Named engineer on the rotation, weekly hunts, and a quarterly evidence pull written in your framework.
Includes
For defense contractors, federal suppliers, and regulated financial institutions operating under CMMC 2.0 or NIST 800-171. Named engagement lead, custom use-case tuning, and audit-ready artifacts on demand.
Includes
Every plan ships with US-based analysts, named escalation contacts, and full audit trails. Pricing for larger organizations is custom — we’ll scope to your estate, not a slider.
If the offering list above matches what you need and the tier grid is the right shape, the fastest route is the one below — a thirty-minute call with a SOC engineer. We’ll scope Straitwatch against your actual estate before you sign.