Security Operations Center · as a Service
Open-source core. Compliance-first positioning (nDSG, FINMA-light, ISO 27001). Bundled with the same fractional IT leadership your team already has on retainer.
Architecture
A hardened sensor VM sits on the client's network and tunnels back to MIXEL over WireGuard. All detection, correlation, and case work runs centrally so the client carries minimal infrastructure.
Wazuh agents (+ optional MS Defender for Business)
Hosted on mixel-vps-01 (Hetzner CCX33 · 32 GB · co-located with Supabase migration target)
Open-source stack
Every component is industry-standard open source we can audit, tune, and migrate. The only commercial lines we add are ones the client probably already pays for (Microsoft Defender) or pay-as-you-go cheap (VirusTotal API).
Endpoint security monitoring, log ingest, file integrity, FIM, vulnerability scoring. Indexer doubles as our central log store.
Runs on the on-site sensor. Suricata for signature-based IDS, Zeek for protocol-aware metadata and anomaly hunting. ET Open + custom Sigma rules.
Tickets, observables, tasks, attachments, MITRE ATT&CK tagging. Auto-creates a case when n8n promotes a Wazuh alert.
Auto-enriches IPs, hashes, URLs against VirusTotal, AbuseIPDB, MISP, Shodan, etc. Plugged into TheHive so analysts don't context-switch.
CTI sharing platform. Pulls AlienVault OTX, abuse.ch, ENISA feeds. Feeds IoCs to Wazuh and Cortex automatically.
Visual playbooks: enrichment, case creation, Slack/Teams notify, SLA timers, customer portal updates. Already in our stack — same instance pattern.
Pricing
Pricing aligns with our existing CHF 2,500–7,500/mo fractional IT leadership tiers. SOC bolts on as a single recurring add-on with one shared MSA.
For under-25 endpoint shops
For 25–100 endpoint orgs
Regulated / 24×7-required clients
Why MIXEL
Specialist security for organizations under 250 employees — the same open-source stack enterprise SOCs use, sized and priced for the businesses Sophos and Arctic Wolf won't quote.
Headquartered in Buchs ZH. Reports and case work in German, French, or English. nDSG-aligned by default — your auditors don't need to translate.
Every alert is an auditable Sigma rule. Every log lives in your tenant. Walk away anytime — your data goes with you.
Already on retainer with us? SOC bolts on as a single MSA, single invoice, single accountable contact. No new vendor to onboard.
Monthly PDFs in your language. ISO 27001-friendly evidence trail. FINMA-light controls mapped to your environment. Hand the package to your auditor as-is.
Your contact is a named person you can call. Not a ticket queue, not a Tier-1 chatbot. P1 incidents reach the founder within 15 minutes on Premium MDR.
Wazuh, TheHive, Cortex, MISP, n8n — the same OSS components running inside Fortune 500 SOCs. Maintained, tuned, and made boringly understandable.
30-minute call · no slide deck · just a frank look at your current stack and what we'd change.