Skip to main content
INTEGRATION

Connect your SIEM / SOAR

Security operations centers run on SIEM/SOAR platforms — alerts, detections, correlation rules, incident workups. TruSecure's SIEM connector pulls this operational reality directly into the governance record, so control testing and incident evidence draw from the systems already running your security program.

What the connector pulls

SIEM / SOAR data pulled into TruSecure
Source systemWhat TruSecure pullsFeeds governance
SIEM alertsAlert stream, severity, classification, assigned ownerEvidence Automation · control test triggers
Detection rulesCorrelation rules, threshold configurationsControl Library · NIS2 Art. 21(2)(d) measures
Incident casesCase timeline, response actions, resolutionIncident and Resilience Workflows · NIS2 Art. 23 reporting
SOAR playbooksPlaybook execution logs, run historyEvidence of documented processes

Evidence produced from SIEM / SOAR data

One control test pulled from live SIEM / SOAR state — not a manual export, not a screenshot, but a verified query result with provenance:

Control test · SIEM-2026-089 alert coverageSample data
Control tested
NIS2 Art. 21(2)(d) — incident detection procedures
SIEM source
Splunk · correlation rule ID: CORR-0042
Test
re-perform · rule existence and configuration
Sample
1/1 rules · active, last modified 2026-08-14
Result
pass · configuration matches documented procedure
Evidence
SIEM query · timestamped 2026-08-22T09:31:17Z
Export
sealed · sha256:a4f7...2c1b

Setup and scope model

  1. Read-only, scoped permission

    Connector requires read-only access to alert streams, detection rules, and incident cases. No write permissions, no ability to modify configurations or execute responses.

  2. Data filtered by entity

    Pull is scoped to the TruSecure entity context — no cross-tenant data leakage, no irrelevant alerts. What you see in governance matches what the SOC sees for your organization.

  3. Continuous sync

    Evidence pulls incrementally, not bulk re-imports. A control test re-queries the SIEM live; incident evidence timestamps the exact moment of extraction. No stale exports.

Commercial packaging

SIEM / SOAR connectors are part of the paid TruSecure Fabric subscription. The connector itself, the continuous sync, the evidence provenance tracking, and the mapping to NIS2, DORA, ISO 27001, SOC 2 and other frameworks are all included — no per-connector fees, no usage tiers. Pricing is scoped in the conversation, not a price list.

How integration works

A demo with your actual SIEM / SOAR environment shown in preview mode — your data pulling into governance, feeding controls and evidence. Then a Resilience Sprint that configures the connector for production, scopes the entity context, and validates the first evidence pull. No self-serve checkout, no per-connector pricing.

TruSecure helps operationalize requirements and prepare evidence. Legal interpretation should be validated by qualified counsel.