The team behind your SOC
We are the operator that runs security for your customers, under your brand. Buy the platform from zcr.ai, buy the people who operate it from us — or take both together and start selling managed security next month without hiring a single analyst.
Every partner is missing one of two things. Some are missing both.
zcr.ai solves the platform half. This is the other half — and the third one below needs them together.
You already look after their firewalls, AD and endpoints, and your team can work a case. Security keeps coming up and you have nothing recurring to sell against it.
→ Take the platform from zcr.ai and run it yourself.Your analysts are working cases on someone else's tooling, licensed per customer, so your unit cost never comes down no matter how many customers you add.
→ Take the platform from zcr.ai and keep your team.Every deal closes and the counter resets to zero. You want recurring revenue, but hiring a security team to get it is a two-year detour you never take.
→ Take both. You sell, we operate, your customer never meets us.Scoped, priced, and delivered under your name
Each line is a defined offering with a monthly unit — not a consulting engagement you have to scope with us first. You set your own end-customer price and keep the margin.
Managed SOC Operations
Our analysts monitor, triage and escalate on your tenant. Your customers call you; we sit behind you in the queue and never appear on the ticket.
Managed Exposure
Continuous external attack surface monitoring on zcrCTEM. Nothing installed, no credentials issued, so a customer can be live the same week you sell it.
Managed Leak Detection
Credential dumps and brand abuse monitored across dark web sources, verified by an analyst before anything reaches your inbox.
Managed Penetration Testing
Web, API and infrastructure testing against a documented methodology, senior-reviewed, written in your report template with your logo.
Managed Detection Engineering
Rules, parsers and tuning for the platform you run, delivered as reviewed code. Keeps your detection current without a dedicated engineer on your payroll.
Managed Onboarding
We stand the platform up for your customer and hand you a working tenant. For reseller partners who sell but would rather not operate.
Incident Response Retainer
A pre-agreed retainer so that when your customer is breached at 2am, you already have a forensics team and a signed scope instead of a procurement problem.
Managed OT Monitoring
Asset discovery and monitoring for industrial, solar and EV charging environments — where an IT-shaped SOC playbook does not apply.
We operate on a platform we own
Most white-label operators rent their tooling from a vendor, per customer, so their cost floor never drops and they pass it to you. We run on zcr — eight products our own engineers build — so nobody bills us per seat for the hours we work on your tenant, and no vendor territory clause stops us serving your customer in another country.
One detection rule runs a single query across every tenant, so onboarding your twentieth customer costs us almost nothing extra. That is the reason our monthly unit price can start where it does.
Explore the zcr platform ↗Being clear about what we are not is the whole offer
- An operator, not an adviser
- Engineers who run security day to day against a documented methodology, reviewed before anything leaves the building.
- Capacity you buy by the month
- A committed monthly unit, published as a price rather than quoted on request, so you can build your own service package and know your cost before you talk to us.
- Invisible to your customer
- Your brand on the report, your name on the ticket, your account manager on the call. We are not in the room.
- Not a direct seller
- Cyber Defense sells only through partners. Every deal closes through a partner — there is no direct sales team that could ever call your customer.
- Not a staffing agency
- We do not send CVs, we do not bill hours, and you do not line-manage our people. You buy delivered work.
- Not a consultancy
- We do not sell strategy or advisory. That is your margin and your relationship, and we have no team that could take it.
Three checks from outside, and one thing we say ourselves
Awarded to zcrLog by NCSA Thailand, VNU Asia Pacific, SCBX NextTech and Cybersec Asia at Business Matching Day.
Recognised in the APJ Partner Programme Awards, judged on partner-led delivery rather than licence volume.
NECTEC standard for computer traffic data retention systems under Thailand's Computer Crime Act.
A decade of running security operations for Thai organisations — the operating experience that the zcr platform was built out of.
Pick one customer. We will run it for 60 days.
Choose a customer you already serve. We deliver Managed Exposure on their domain for two months, in your template, at no cost — so you can see exactly what your customer would receive before you sign anything.
Apply as a partner- CRITICAL RDP exposed to the internet 203.0.113.44:3389 2m ago
- CRITICAL Staff credentials in a published combolist 3 accounts · verified 18m
- HIGH TLS certificate expires in 6 days vpn.example.com 1h
- HIGH Dangling subdomain points at an empty bucket old-cdn.example.com 3h