Skip to content

A UK-based AI SOC, with UK/EU data residency

OwlSOC is a UK-based, founder-led AI SOC that investigates alerts from Microsoft Sentinel, Microsoft Defender and AWS. Data stays in the UK or EU, access is read-only by default, and we do not train models on your data. If your security or procurement team cares where alerts are processed and by whom, here is exactly how OwlSOC handles it.

Why residency and location matter

For a UK organisation, where security data is processed is not a detail — it shows up in your UK GDPR obligations, your procurement questionnaires, and often your own customers' requirements. Many of the AI SOC tools on the market are US-based and process data in US regions by default, which can turn a quick evaluation into a data-transfer and due-diligence exercise.

OwlSOC is built to make that part boring. UK-based team, UK/EU data residency, and a data-handling posture designed to answer a procurement questionnaire honestly rather than around it.

Where your data lives

OwlSOC processes your alert data in the UK or EU, encrypted in transit and at rest. It connects to your Microsoft and AWS tooling read-only by default, reading only the security signal needed to investigate an alert — the alert, the surrounding logs, and the identity, device and network context — and nothing outside that scope.

There are no agents to install and nothing sits in your traffic path. What OwlSOC can access is exactly what you grant when you onboard, and it is auditable from your side.

  • UK / EU data residency
  • Encrypted in transit and at rest
  • Read-only by default; write access is a separate, explicit grant
  • Access scoped to the security signal, auditable from your side

We do not train models on your data

OwlSOC does not train any model on customer data — ours or a third party's — and that is a contractual commitment that extends to every sub-processor in our pipeline. Investigation happens against your data without learning from it. This is the question that most often trips up AI tooling in procurement, and the answer here is a plain no.

We are happy to walk your security or procurement team through the architecture, the sub-processor list, and the data-processing agreement before you sign anything.

How this maps to UK GDPR and procurement

Residency, read-only access, a no-training commitment, and a DPA cover most of what a UK data-protection review asks about a processor. If your organisation works to frameworks like Cyber Essentials, or falls under regimes such as NIS2 or DORA, OwlSOC's posture is designed to slot into that evidence rather than complicate it.

To be clear about what those frameworks are: they are your obligations and your context, not certifications OwlSOC is claiming on your behalf. We will support your evidence-gathering, and we are straight about our own certification status below.

What OwlSOC is, and is not, certified for

Honesty matters more than a badge here. OwlSOC is not yet SOC 2 or ISO 27001 certified, and we will not imply otherwise. What we can do today is share our current security posture, our sub-processor list, and our data-processing agreement, and answer your questionnaire directly.

On the Compliance tier, OwlSOC also produces exportable case reports and audit-log exports you can fold into your own SOC 2, ISO 27001 or GDPR evidence — helping you meet your obligations, on the tools you already run.

Frequently asked

Is OwlSOC UK-based?

Yes. OwlSOC is a UK-based, founder-led team, and it processes alert data in the UK or EU. It investigates alerts from Microsoft Sentinel, Microsoft Defender and AWS Security Hub for UK and EU organisations.

Where is my data stored?

In the UK or EU, encrypted in transit and at rest. OwlSOC connects read-only by default and reads only the security signal needed to investigate an alert. Access is scoped to what you grant at onboarding and is auditable from your side.

Do you train AI models on our data?

No. OwlSOC does not train any model on customer data, ours or a third party's, and that is a contractual commitment across every sub-processor in our pipeline. Your data is investigated, not learned from.

Is OwlSOC SOC 2 or ISO 27001 certified?

Not yet, and we say so plainly rather than imply otherwise. We are glad to share our current security posture, sub-processor list and data-processing agreement before you sign. On the Compliance tier, OwlSOC also exports case reports and audit logs to support your own SOC 2, ISO 27001 or GDPR evidence.

Can you sign a DPA?

Yes. A data-processing agreement is available on request, and we will walk your security or procurement team through it, along with the architecture and sub-processor list, before any paid pilot begins.

See it on your alerts.

Start with a 30-day refundable pilot. £495, one environment, every alert investigated, a full report at week four. Read-only, live within 48 hours of access.