Own the security line item
One platform price per client — not five per-seat SKUs stapled together. The margin, the renewal, and the client relationship stay yours.
24/7 detection and response across endpoints, identities, and email — the tier-1 and tier-2 work automated, the judgment and the policy yours. One platform price per client, response modes per tenant, and reporting your account managers forward as-is.
One platform price per client — not five per-seat SKUs stapled together. The margin, the renewal, and the client relationship stay yours.
True multi-tenancy: every client on one screen with per-tenant response policy, bulk actions with rollback, and no swivel-chairing between five vendor portals.
The AI is cost-governed by design — deep reasoning runs only where a case is genuinely ambiguous, so the price you quote a client is the price you pay.
API connections to Microsoft 365 / Google Workspace plus a light agent through your RMM — ConnectWise, Autotask, and NinjaOne integrations meet the workflow you already run. Every tenant starts in watch-only mode; response arms when you say so.
The platform executes the routine within the policy you set. Decisions that need a human arrive as staged approvals with the evidence attached — routed to the role you designate, answerable from a phone.
A per-client digest of what was caught, what was done, and the evidence behind every claim. Your account managers forward it as-is.
The same afternoon, with and without correlation — drawn from the client’s own tenant, not a stock slide. This is the evidence your QBR has been missing.
MSSPs run Centeye as operating infrastructure, not another portal: multi-tenant from birth, with the architecture facts your own customers’ security reviews will ask about.
Every tenant on one console with per-tenant engagement modes, bulk actions with rollback, and cross-tenant visibility of the same campaign hitting multiple clients — one investigation, not ten.
Tenant-isolated data, role-based access, and a tamper-evident audit log on every action — who, what, why, reversible where the platform allows. The evidence your post-incident reviews and client security questionnaires actually ask for.
Kavach does the tier-1/tier-2 work across the whole tenant base and stages decisions with evidence attached — so each of your analysts commands more clients instead of triaging more queues.
Per-tenant digests, incident timelines, and cyber-insurance readiness reporting your clients can hand to a carrier or an auditor — generated from the audit trail, not written after the fact.
Co-managed, by design. Engagement modes are set per action and per tenant — pre-authorize containment for clear threat classes, route approvals to the client’s IT director or your analyst for the rest, or run advise-only against their own tooling. The client’s team gets the same evidence view your analysts have.
No — and if you have them, they stay in command. Kavach does the tier-1/tier-2 work: triage, correlation, staged response, post-action verification. Your team sets policy per action and per client, and takes the approvals. Providers with analysts point the approvals at them; providers without route them to the account lead.
Functionally, yes — managed detection and response across endpoints, identities, and email, operating 24/7. The difference from a classic MDR service: the tier-1/2 work is automated inside your policy, and the human judgment stays on your bench — the managed detection and response outcome, without handing the client relationship to someone else’s SOC.
Whatever your policy says — that’s the point of the modes. Pre-authorize containment for the clear-cut threat classes so nights are covered at machine speed; everything else stages with its evidence and holds. Nothing acts outside the modes you set, and nothing silently expires.
Every action is policy-scoped, attributable (who, what, why), written to a tamper-evident audit log, and reversible where the platform allows. Destructive steps default to human approval. You can show any client — or insurer — exactly what happened and who authorized it.
It can consolidate them, or run alongside during evaluation. Centeye connects via API behind existing filters and can run next to your incumbent EDR in watch-only mode — compare the findings, then decide what to consolidate.
Underwriters increasingly require EDR/MDR, MFA enforcement, 24/7 monitoring, and documented incident response. Centeye continuously operates those controls and documents them — Argus keeps a per-client readiness report your clients can hand to their carrier.
Per client, one platform price — talk to us and we’ll price your book. No published per-seat menu, no AI metering.
A 30-minute walkthrough of the multi-tenant console on real data — then we price your client list, per client, no metering.