ClearSkies iISOC for MSSPs
Integrate Everything.Automate the Rest.
Stop losing margins to custom API builds and manual onboarding. Deploy new tenants instantly, connect their existing tools natively, and automate your managed response workflows.

Architecture
Three layers, and what each contributes
| Layer | What sits there | What it contributes |
|---|---|---|
| Below the engine | iCollector, the six native add-ons, Marketplace connectors and open ingestion | Telemetry normalized into the shared context-aware model at collection, so no translation step is needed later |
| The engine | Centric-AI Fabric, Detection Factory, the TDIR engine, risk scoring, alert routing, the agentic layer, SOAR and playbooks | Entity resolution, correlation into incidents, one explainable score, and governed action back through connected controls |
| Above the engine | Operator console, per-tenant client portals, ChatOps, service catalog, reporting and cost-to-serve analytics | What you operate from and what each client sees under your brand |
Core functions
On every tenant, at its assigned tier
Independent of which add-ons are licensed.
Each core function is documented in its own brief.
See core functionalitiesInteroperability
Open at the edges, one model in the middle
On portability the position is stated commercially rather than technically: what may be exported, in what format, over what period and at what cost.
Displacement and assurance
Changing the correlation core, not the client's infrastructure
Migration and coexistence
ContentDetection migrated through Sigma where portable, rewritten where it is notHistoryRetained in place for the rest of its retention period or exported, so the evidence chain holdsParityA parallel run establishes detection parity before the incumbent retires, measured rather than assertedScopeThe platform ingests from tools the client already ownsFrameworks and assurance
DetectionMITRE ATT&CK, with MITRE Engenuity evaluations for independent validationReportingNIST Cybersecurity Framework 2.0 outcome language for board reportingControlsISO/IEC 27001 and 27002 mapping and audit evidenceSubprocessorSOC 2 Type II or ISAE 3402, which you pass to your own clientsEuropeNIS2, DORA and GDPR reporting, resilience and privacy obligationsAIEU AI Act governance of the generative and agentic layer