On-premise security monitoring

See everything.
Keep it yours.

Tranzify Watch brings server posture, log search, threat detection and incident response together — without sending telemetry to someone else’s cloud.

Linux
agent available
S3 / API
agentless sources
365 days
flexible retention
Tranzify Watch monitoring consoleWatch controlLIVE INFRASTRUCTURE
operational
CONNECTED24agents
EVENTS / MIN8.4k+12.8%
OPEN SIGNALS031 critical
RECENT EVENT STREAMSEVERITY
AUTHssh.login.failed8
NETfirewall.rule.changed6
SYSpackage.update.available3
AVdefinitions.status2
!
Detection matchedBrute force attempt · 4s ago
8
agent connectedip-10-24-8-16
SERVER POSTUREEVENT PIPELINEDETECTION ENGINEINCIDENT WORKFLOWAVAILABILITYSERVER POSTUREEVENT PIPELINE
From signal to resolution

One operational loop
instead of scattered panels

Data follows a predictable path: collect, normalize, explore, detect and investigate. Every stage is observable and versioned.

01Collect

Unified telemetry

System journals, metrics, inventory, updates, antivirus and firewall posture arrive in one normalized model.

02Explore

Search without compromise

ClickHouse, nested JSON fields, AND/OR groups, comparisons, regular expressions and filtering by any key.

03Detect

Detection engineering

Versioned parsers and rules turn raw events into actionable signals without executing user-provided code.

04Respond

Incident workflow

Statuses, owners, comments, attachments and resolution history preserve the full investigation context.

Architecture

Data keeps moving.
Control stays with you.

Components are separated by responsibility and can scale independently.

Sources
LLinux agentS3Object storageHTTP API
Tranzify Watch Core
Tranzify Watch Core
Normalize · Detect · Route
Storage
ClickHouseevents · analyticsPostgreSQLstate · workflow
01

Policy-driven collection. Every telemetry interval is delivered through the agent policy.

02

Protected delivery. The agent validates configuration signatures and server trust.

03

Purpose-built storage. Events and operational state use the engines that fit them.

Security by design

Your perimeter.
Your rules.

Tranzify Watch is designed as a self-contained system with no mandatory cloud account, hidden data channels or remote command execution on monitored hosts.

Read the security model
01

Data control

The platform and its events remain inside the organization’s infrastructure.

02

Protected agent

One-time enrollment, mTLS and signed JSON policies.

03

Verifiable releases

Packages and manifests are signed with an AWS KMS key.

04

Complete audit trail

User actions are recorded in an append-only activity log.

Quick start

From clean Ubuntu
to the first event.

The installer validates resources, prepares both databases, creates the system account and opens the first-run setup wizard.

Ubuntu 22.04 / 24.042 vCPU minimum8 GB RAM minimum
ubuntu — bash
# Install Tranzify Watch
$ curl -fsS https://packages.tranzify.watch/install.sh | sudo bash
System requirements Release signature Core services Setup ready on port 443
A practical security operations platform

Infrastructure monitoring, log analytics and incident response in one system

Built for organizations that need security visibility without transferring operational data to a third-party SaaS.

01

On-premise infrastructure monitoring

Monitor Linux servers, operating-system health, available updates, antivirus status, firewall rules and listening ports from a centrally managed policy.

Collection intervals are configurable from one second to hours, so critical telemetry can remain fast while expensive inventory checks run less often.

server monitoringLinux security agentinfrastructure visibility
02

Fast log search at scale

ClickHouse stores high-volume events and supports nested JSON fields, exact values, ranges, AND/OR groups, regular expressions and full-text candidates.

Raw events remain available for investigation while normalized records provide stable fields for dashboards, filters and versioned detection rules.

log managementClickHouse SIEMJSON log search
03

Security detection and incident response

Safe parsers transform text and JSON logs without executing arbitrary user code. Detection rules can be tested against historical data before publication.

Alerts can be promoted to incidents with owners, statuses, comments, files, evidence, decisions and an append-only activity history.

threat detectionincident managementsecurity operations
04

Tranzify Watch Linux agent and server posture

The Tranzify Watch Linux agent collects server posture through a signed, versioned JSON policy. Administrators choose which inventory, resource, update, antivirus, firewall, listening-port, service, and log-file checks run on each policy. Collection intervals can range from near-real-time heartbeat checks to slower inventory scans, keeping monitoring useful without wasting server capacity.

Agent enrollment uses an expiring, one-time token and a trusted TLS connection. The central platform can disable an agent or deliver a new signed configuration, while endpoint activity remains read-only. This model supports private networks, VPN environments, cloud VPCs, and public domains without requiring telemetry to be sent to an external SaaS provider.

Linux agentserver posturesigned policy
05

Security event pipeline, detection, and log search

Security events can arrive from Linux agents, Amazon S3 objects, or scheduled HTTP API sources. Versioned parsers turn JSON records and line-oriented text logs into consistent datasets while preserving raw evidence. ClickHouse stores high-volume event data for time-range analysis, and PostgreSQL keeps users, policies, rules, alert state, and operational workflow data.

The event explorer supports exact text, regular expressions, nested JSON paths, numeric comparisons, sorting, and grouped AND or OR conditions. Detection rules target a selected dataset, can be tested against historical events, and are published as controlled versions. Retention and capacity views help operators understand how long searchable data can remain inside their own infrastructure.

security eventslog searchdetection rules
06

Incident workflow and auditable security response

A detection can create an alert, and an analyst can promote that alert into a managed security incident. The incident workspace records status, severity, owners, participants, comments, attachments, decisions, and the final resolution in one timeline. This gives responders a clear operational history instead of distributing evidence across chat messages and unrelated task systems.

Append-only activity records support reviews and internal control processes aligned with ISO 27001, ISO 27007, and PCI DSS practices. The platform does not itself certify an organization: customers define their controls, access model, retention, evidence handling, and response procedures. Tranzify Watch provides the monitoring and incident-response records needed to operate and demonstrate those processes.

incident workflowaudit trailsecurity response
Open architecture · predictable operations

Your infrastructure speaks.
It is time to listen.

Deploy Tranzify Watch in a test perimeter and connect your first Linux server.