For MSPs & MSSPs

The security platform that reads the whole attack. Your judgment in command.

Centeye runs the security shift for MSPs and MSSPs — around the clock. It correlates endpoint, identity, and email telemetry into one incident per attack, then contains it within the response policy you set, per action, per client.

One afternoon’s attack, end to end
Fake invoice1:02 PM · email
Stolen login used2:17 PM · identity
Ransomware staged4:01 PM · endpoint
One incidentsame user · one chain
Contained4:05 PM · verified
  • No MX change — Microsoft 365 & Google Workspace connected in minutes, watch-only to start
  • Behavior-based detections, mapped to MITRE ATT&CK
  • Every action audited — who, what, why — and reversible wherever the platform allows
  • Four response modes, set per action and per client
Microsoft 365 Google Workspace Windows macOS API-based deployment — nothing for end users to learn
The correlation gap

Attacks correlate across surfaces. Point tools can’t.

A phishing email, a suspicious sign-in, and an unfamiliar binary each clear their own tool’s threshold as “low severity.” Read together, they are one attack in progress. That read is the product — here is the same afternoon, with and without it:

Without Centeye

1:02 PMFake invoice delivered — filter scored it clean
2:17 PMStolen login used — “probably just travel”
4:01 PMRansomware staged — one alert in a queue
9:12 AM💥 Next morning: files encrypted, ransom note on every screen

With Centeye

1:02 PMInvoice flagged suspect — first-contact sender, pressure cues
2:17 PMSign-in tied to that email — takeover called, session revoke staged
4:01 PMPayload behavior → host isolated in seconds
4:05 PM✓ Contained & verified — you approved one action
The operating model

The platform works the incident. Your team commands it.

Kavach, the analyst on shift, and Argus, the advisor on record, carry the tier-1 and tier-2 load — triage, correlation, staged response, reporting. Yes, the engine behind them is AI — bounded like staff, not loosed like a chatbot: nothing acts outside policy, every step is attributable, and the judgment calls stay with your team. How Praxis™ orchestrates it →

Kavach

The analyst on shift — works the incident

Triages every alert, connects the clues across email, identity, and endpoints into one incident, proposes the fix with evidence — and executes within the policy you set, then verifies it worked. On shift 24/7, conversational at tenant and fleet scope, with every action reversible and written to a tamper-evident audit trail.

Argus

The advisor on record — tells the story

Turns incidents into plain-English, client-ready reporting — what was caught, what was fixed, and the evidence behind every claim — answers "was that safe?", and keeps the cyber-insurance readiness story current, in-app or over email, Slack, Teams, and SMS.

Level 0 — Watch Detection and full incident narrative only. Complete visibility, no action taken.
Level 1 — Advise Centeye proposes the exact remediation with evidence. Your team — or the client’s — executes.
Level 2 — Approve Centeye stages the action with the evidence attached; it executes on a one-tap approval from the role you designate.
Level 3 — Pre-authorized Containment pre-authorized per threat class — executed in minutes, verified against live state, and reported.

Response modes, not a black box: each action class carries its own mode, per client. Destructive actions default to approval, and every decision is logged — who, what, why.

Built for MSPs & MSSPs

Multi-tenant security operations, priced like a product line.

  • One incident per attack — Email, identity, and endpoint telemetry are correlated into a single incident — the full kill chain in one record, not fragments across three queues.
  • Policy-bound response in minutes — Containment runs pre-authorized where you allow it and routes to approval where you don’t. Every action is reversible, audited, and verified after execution.
  • Multi-tenant by design — One console across the client base — response policy per tenant, bulk actions with rollback, and client-ready reporting your account managers forward as-is.
  • Deployed in minutes, watch-only first — API connections to Microsoft 365 and Google Workspace plus a light agent through your RMM. Every tenant starts in watch-only mode; you change the response mode when the findings earn it.

Connect one tenant. Judge the findings.

A guided demo on real multi-tenant data — or connect a tenant in watch-only mode and evaluate the detections against your current stack. You change the response mode when the evidence earns it.