ITWISEOn-premises SIEM · ISO 27001 & TISAX evidence

Collect, protect and prove your logs at audit time.

SEC-WISE collects server, network and Microsoft 365 logs on your own server, stores them in an immutable archive, explains suspicious activity in plain language and prepares a signed evidence package for your auditor.

COLLECT · PROTECT · DETECT · RESPOND · PROVE

Product screen (Turkish UI) · fictional sample data

  • ISO/IEC 27001:2022Annex A evidence mapping
  • TISAX / VDA ISAcontrol evidence & auditor package
  • Data stays on-premisessupports KVKK-aligned retention
  • Tamper-evident logsWORM archive + signed hash chain
  • Turkish-firstUI and plain-language rule guidance

Features

From collection to evidence, one platform

Security team, IT and auditors look at the same screens; each role sees only what it is allowed to.

Log collection

Windows and Linux agent, syslog, SNMPv3, SNMP traps, Microsoft 365 and Acronis. Agents connect over mTLS; nothing is silently dropped.

Detection rules

122 built-in rules: match, threshold, sequence, absence and suppression. Maker-checker lifecycle and dry-run before publishing.

Plain-language alerts

Every alert answers: what happened, what should I do, could it be a false positive? Bulk decisions, expiring exceptions, noise policy.

Investigation

Start from an alert or entity: users, IPs, process tree, files; kill-chain stages, timeline and xlsx/HTML export.

Asset inventory & device 360

Automatic identity matching across Intune, Defender, agent, SNMP and DHCP; ports, LLDP topology, wireless and VPN context.

Microsoft 365 intelligence

Entra sign-ins, Defender alerts, inbound/outbound e-mail threats, new and look-alike domains with RDAP enrichment.

Evidence integrity

WORM raw archive, signed hash chain, continuous verification, retention and approved legal hold.

Compliance evidence

24 ISO/IEC 27001:2022 Annex A and 12 TISAX controls mapped; per-control evidence and a signed auditor package.

Operations & backup

Single-server install, encrypted nightly backups, NAS mirror, monthly isolated restore test, health dashboard.

Full feature list (Turkish) →

Product tour

Every alert comes with guidance

The alert drawer answers three questions — what happened, what to do, could it be a false positive — and every decision is recorded with its reason.

See the relationships, not just the rows

The investigation graph links users, addresses, devices, processes and files, groups similar entities and orders events by kill-chain stage.

Architecture

Single server, lossless bus, immutable archive

A record is acknowledged only after it is durably written. The raw copy goes to the immutable archive, the normalized copy to the event store. Everything runs inside your network.

SEC-WISE architectureLogs from sources flow over mTLS to the gateway, into the NATS JetStream bus, through the pipeline into the immutable MinIO archive and the ClickHouse event store; the detector runs rules and results appear in PostgreSQL and the web UI. Everything runs on a single on-premises server.SOURCESWindows serversSEC-WISE agent · event logs,Sysmon, SQL, IIS, DHCP, Hyper-VLinux serversSEC-WISE agent · journald, FIMFirewalls · switchessyslog (UDP/TCP/TLS) · CEF / KVUPS · printers · NAS · switchesSNMPv3 polling · SNMP trapsMicrosoft 365 · Entra IDDefender · Intune · e-mailAcronis Cyber Protectcloud API · backup statusON-PREMISES · SINGLE SERVER (Docker Compose, deploy/product package)Ingestion GatewaymTLS · ACK after durable writeback-pressure · DLQSNMP collectormTLS with agent identityCloud connectorsM365 · Acronis (pull)NATS JetStreamdurable bus16 partitions · sync alwaysraw-writerzstd segments + Merkleed25519-signed manifestnormalizer240 event types · dedupDetectorYAML rules · correlationthreshold · sequence · absenceswverifychain daily · full scan weeklyMinIO · WORM archiveObject Lock COMPLIANCEraw records immutableClickHouseevent store · fast searchPostgreSQLalerts, cases, evidence, audittenant isolation (RLS)Web UI + APIMFA · RBAC · four-eyesEncrypted nightly backupNAS mirror · monthly restore testUsersSOC · IT · auditorsmTLSsyslogSNMPv3APImTLSACK
  1. SourcesWindows/Linux agent, syslog, SNMPv3, Microsoft 365, Acronis
  2. Ingestion GatewaymTLS · ACK after durable write · back-pressure
  3. NATS JetStreamdurable bus · no silent loss
  4. Pipelineraw-writer (signed segments) · normalizer (240 event types)
  5. StoresMinIO WORM archive · ClickHouse event store · PostgreSQL
  6. DetectorYAML rules · correlation · exceptions
  7. Web UI + APIMFA · RBAC · four-eyes · auditor package
Simplified data flow.

Compliance

Evidence, not a “compliant” badge

Daily work — alert decisions, closed cases, backups, restore tests, integrity checks — turns into control evidence automatically. Missing evidence is explained with the period's numbers. The auditor package is ed25519-signed and independently verifiable.

Platform security

A security product protects itself first

Identity

argon2id passwords, mandatory TOTP MFA, step-up for sensitive actions, login throttling, CSRF origin checks.

Isolation

Server-side RBAC, PostgreSQL row-level security and ClickHouse row policies per tenant; read-only auditor role.

Agents & secrets

mTLS agents with your own CA, CA key isolated from the gateway, OpenBao secrets, AES-256 encrypted backups.

Audit trail

Every admin action is recorded immutably; high-impact changes need four-eyes approval.

Supply chain

Distroless, cosign-signed images with SBOM attestations, pinned by digest.

Small surface

Only 443 (UI) and 8443 (agents, mTLS) are exposed; data services live on an internal network.

Supported sources

Talks to the devices you already have

Windows (SEC-WISE agent)

  • Security loglogons, accounts, groups, policy
  • System & Application
  • Process creation4688 · command line
  • Sysmonprocess events
  • File access auditing4663 and related
  • Performance metricsCPU, memory, disk, services
  • Hyper-VVM state
  • SQL Serveraudit, backup, errors
  • IISW3C logs, sites/pools
  • DHCP serverscopes, leases, failover
  • Active DirectoryDC health, replication, dcdiag
  • WEFforwarded events

Linux (SEC-WISE agent)

  • journaldsystemd journal
  • sysloglocal files
  • FIMfile integrity monitoring
  • SSH / sudoidentity and privilege

Network & security (syslog · SNMP)

  • Sophos Firewallsyslog
  • Fortinet FortiGatesyslog
  • RuijieRGOS syslog · switch SNMP
  • HuaweiVRP switches · wireless AC
  • VMware ESXisyslog
  • Synology DSMLog Center
  • Generic switchSNMPv3 · LLDP
  • UPSAPC · RFC 1628
  • Printers · NAS · LinuxSNMPv3
  • CEF / KVfirewall and VPN
  • SNMP trapsv2c/v3 · rate-limited
  • SNMP v2cper device, opt-in, read-only

Cloud & backup (API)

  • Microsoft 365unified audit
  • Entra IDsign-ins, audit, devices
  • Intunemanaged devices
  • Defender XDRalerts and incidents
  • E-mail threatsinbound and outbound
  • Acronis Cyber Protect Cloudbackups, jobs, alerts

Vendor and product names are trademarks of their respective owners and are mentioned only to indicate compatibility.

By the numbers

Content that ships on day one

Measured from the current product release (October 2026).

122
Built-in detection rules
10
Rule packs
240
Normalized event types
26
Source types · 14 parser families
36
Mapped controls (24 ISO 27001 + 12 TISAX)
122/122
Rules with plain-language guidance
90
Rules mapped to MITRE ATT&CK
11
Network device & protocol profiles

FAQ

Frequently asked questions

Is SEC-WISE a cloud service?

No. SEC-WISE is installed on your own server or VM; logs, the archive and evidence stay there. Microsoft 365 and Acronis connectors only pull data from those services.

Will SEC-WISE tell us we are “ISO 27001 compliant”?

No, by design. It shows which evidence exists for each control and what is missing (complete / partial / missing / not expected). The auditor decides; the signed auditor package can be verified independently.

How do you prove logs were not altered?

Raw records are written first to a MinIO bucket in Object Lock COMPLIANCE mode and chained with ed25519-signed manifests. The chain is verified daily and the full content weekly; a mismatch opens a critical case.

Does it respond automatically?

No. SEC-WISE does not lock accounts or shut down devices. Any high-impact action requires a second person's approval (four-eyes) and is written to the audit log.

Is the UI available in English?

Turkish is the default. English can be selected per user; translation coverage starts from the main screens and is expanding. The product screens on this page are shown in Turkish.

Keep your logs on-premises and your evidence audit-ready.

See SEC-WISE with a scenario close to your environment: installation, first alerts, device view and the auditor package. A demo takes about 45 minutes.