ACCEPTING Q3 · 2026 ENGAGEMENTS

Protecting the unseen layer.

Affordable SOC-as-a-Service for SMEs. Real-time threat detection, disciplined processes, and the dedicated expertise that closes the gap most organizations don't know they have.

SOC 2 TYPE II · ISO 27001WAZUH-NATIVE · OPEN-SOURCE FIRSTGCFA · CBL2 · CBL1 · SAL1EST. 2019 · AMSTERDAM
02 — Trust

Led by experience.
Driven by people.

Kalyx is small by design. Every engagement is led by senior practitioners — no SDR funnels, no offshored analysts, no checkbox reports. You work directly with the people doing the work.
Working with Kalyx has been exceptional. They uncovered hidden gaps in our security, provided proactive, tailored guidance, and elevated our operations with unmatched visibility and expertise.
MK
M. Karimi
Head of Infrastructure · Series B Fintech
Years of experience
20+

Delivering resilient, intelligent security through advanced technology, precise execution, and client-focused protection.

Client satisfaction
100%

Security excellence you can trust — reflected in the confidence and renewal rate of every client we serve.

03 — Capabilities

Advanced security.
Open-source strength.

Kalyx leverages open-source security technologies like Wazuh to deliver cutting-edge SOC services — enterprise-grade protection without enterprise-grade vendor lock-in or markup.
/ Coverage

Scalable protection. Minimal cost.

Robust coverage against known threats, risks, and attack vectors — scaling alongside your infrastructure rather than your invoice.

EDR · NDR · CLOUD412 NODES
/ Monitoring

Integrated monitoring, tuned for signal.

Kalyx enhances Wazuh with bespoke detection content and additional tooling — streamlining threat-detection workflows from log to evidence.

EVENTS · 24H14.2K / SEC PEAK
/ 24·7

Always watching. Always responding.

Senior analysts on shift around the clock. When something matters, you hear from a human — not a templated email.

edr.endpoints412 · UP
cloud.aws.guarddutySYNC
cloud.gcp.cspmSYNC
siem.wazuh.clusterHEALTHY
threat.intel.feeds3 NEW
on-call.tier1N. VEGA
mttd · trailing 30d6m 12s
04 — Services

Discover our
services.

A comprehensive range of defensive and offensive services tailored to businesses of every size. Each engagement is shaped around your risk profile, your stack, and the threats your industry actually faces.
01 / 06

Endpoint monitoring

Centralized visibility across every organizational endpoint to rapidly detect and respond to security threats.

Learn more
02 / 06

Detection engineering

Designing advanced detection mechanisms that identify malicious behavior across complex technology environments.

Learn more
03 / 06

Cloud security

Continuous monitoring and protection of cloud workloads, services, and data across AWS, GCP, and Azure environments.

Learn more
04 / 06

Threat intelligence

Actionable insights that help organizations detect, understand, and anticipate the threats specific to their sector and exposure.

Learn more
05 / 06

Threat hunting

Proactively identifying hidden threats through deep analysis of systems, networks, and security telemetry — MITRE ATT&CK aligned.

Learn more
06 / 06

Regulatory compliance

Aligning your cybersecurity program with NIST, ISO 27001, HIPAA, GDPR, and the frameworks that matter to your auditors and customers.

Learn more
05 — About

Security-driven
SOCaaS for
growing organizations.

Kalyx exists to make advanced security operations accessible to the organizations that need them most — not just the Fortune 500. We work with you to close the gap between the security you have and the security you need.

Built around you

Our solutions are fully customized to fit your organization's unique security requirements and operational needs — never a packaged template.

Team collaboration

We work shoulder-to-shoulder with your team to ensure seamless integration, shared context, and comprehensive protection across every system.

Your needs, our priority

Every decision we make focuses on addressing your specific challenges, priorities, and long-term security objectives — not vendor incentives.


06 — Principles

Our guiding
principles.

Serve with care. Empower security through transparency. The values we hold ourselves to — every day, every engagement.

We secure organizations with integrity, transparency, and a commitment to real client success. These six principles are not posters on a wall. They show up in scoping calls, in incident response, in the way we write reports.
P / 01

Integrity

We act with honesty, transparency, and accountability in everything we do. If we miss something, you'll know.

P / 02

Client-first

Our clients' safety, trust, and success guide every decision. Your incident is our priority — not a queue ticket.

P / 03

Excellence

We deliver high-quality security solutions with precision and expertise. Senior operators only.

P / 04

Fairness

We provide effective security without overcharging or unnecessary complexity. Honest scope, honest invoice.

P / 05

Innovation

We stay ahead of threats with forward-thinking solutions, continuous research, and a small library of internal tooling.

P / 06

Reliability

Clients can count on us to protect them consistently and proactively. The work is the same at 3am as it is at 3pm.

07 — Process

Milestones,
not surprises.

Working with Kalyx follows a structured, collaborative approach. From assessment and agreement to onboarding and ongoing partnership, each milestone ensures clarity, alignment, and measurable outcomes.
STEP / 01

Assessment

Evaluate current security posture and identify the gaps that matter most.

STEP / 02

Agreement

Define objectives, scope, and mutual expectations clearly — no surprises.

STEP / 03

Onboarding

Integrate systems, teams, and processes efficiently — usually in under 14 days.

STEP / 04

Partnership

Ongoing collaboration for continuous security improvement — for years, not months.

08 — Pricing

Security
at scale.

Kalyx believes security is a necessity, not a luxury. That's why we reject inflated pricing and offer accessible, scalable security for businesses of every size.

Two tiers, no upsells. Both include 24/7 SOC monitoring, dedicated analyst contact, and unlimited reporting. Pricing scales with endpoints, not features.
/ Tier 01

Foundational SOC

Best for smaller businesses who want to operate safely online — with senior-led monitoring from day one.

FROM€1,490/ MONTH
  • Endpoint detection & monitoring
  • 24/7 monitoring & analyst support
  • Monthly security reports
  • Security configuration assessment
  • Up to 100 endpoints

Compare plans

Identify the most suitable and reliable solution for your security needs.

ServiceFoundationalAdvanced
Endpoint detection & monitoringIncludedIncluded
24/7 monitoring & supportIncludedIncluded
Monthly security reportsIncludedIncluded
Security configuration assessmentIncludedIncluded
Threat huntingIncluded
Cloud & container securityIncluded
Compliance (NIST, HIPAA, GDPR)Included
Endpoints includedUp to 100Up to 300
09 — Credentials

Staff
certifications.

Our analysts and engineers hold the certifications that matter — and the operational experience that earns them. We invest in continuous education because the adversary doesn't stand still.
GIAC
SANS · GIAC

Certified Forensic Analyst (GCFA)

BTL2
Security Blue Team

Certified Blue Team Level 2

BTL1
Security Blue Team

Certified Blue Team Level 1

SAL1
TryHackMe

Security Analyst Level 1 (SAL1)

10 — FAQ

Frequently asked
questions.

Common questions about our SOC, our onboarding, and how we measure ourselves. Don't see yours? Ask the team directly.
Our SOC continuously monitors your endpoints, cloud workloads, and network telemetry for signs of malicious activity. When something matters, our analysts triage, investigate, and either remediate directly or hand off a clear, documented finding to your team — typically within minutes, not hours.
A two-week onboarding: kickoff and scoping, agent deployment and log integration, baseline detection tuning, and a tabletop walk-through of incident comms. You'll have a named onboarding lead from day one.
MTTD (mean time to detect), MTTR (mean time to respond), false-positive rate, and detection coverage against MITRE ATT&CK. We share these openly in monthly reports — including the trend lines you don't want to see, when they happen.
Triage starts immediately. For confirmed incidents, we contain via your EDR/cloud controls, preserve evidence, notify your on-call within the SLA window, and coordinate response through agreed comms channels. Every action is logged in your tenant.
A lightweight Wazuh agent on every endpoint and server streams telemetry into a hardened, dedicated cluster — process events, file integrity, authentication, network anomalies, and configuration drift. We layer Kalyx-authored detection rules and behavioral analytics on top.
11 — Blog

Recent
writing.

Notes, write-ups, and opinions from the Kalyx team. Field-tested, not theoretical.
JAN 5, 2026BY KALYX9 MIN READ

Managed or in-house? Choosing a SOC approach that fits.

A practical framework for SMEs trying to decide whether to build a security operations capability internally, outsource it, or run a hybrid model — without falling for the marketing on either side.

Read article
DEC 18, 2025BY KALYX4 MIN READ

Detection rules we're shipping this quarter.

A short tour of the Wazuh detection content Kalyx added to the platform between October and December — what they catch, and the telemetry they need to fire.

Read article
NOV 22, 2025BY KALYX6 MIN READ

The case for boring incident response.

Why repeatable, documented, slightly-dull incident response beats heroics. A short essay drawn from a year of post-incident reviews across our client base.

Read article
WRITING

Kalyx's blog.

Updates, opinions, and write-ups from the Kalyx team. Practical security thinking from the people doing the work.

CONNECT

Stay connected.

Follow Kalyx on LinkedIn for announcements, research drops, and field notes from the team.

Let's talk

Discover Kalyx.

Delivering advanced SOC services that detect, prevent, and respond to threats — with transparent, fair pricing. Book a 30-minute scoping call with the team.