Sell cybersecurity services — under your name
zcr handles everything end-to-end — present, demo, PoC, implementation, and managed 24×7. You focus on the customer relationship, then we share the revenue. No platform to build, no team to hire.
zcr is not new — national-scale organisations already trust us
We protect Thailand’s critical infrastructure — banks, energy, government, retail, and global manufacturers.
Founded 2023 · fast growth built on trust from Thailand’s critical infrastructure operators.
We do it all — under your name
From the first pitch to daily monitoring, zcr is the entire back-office team. The customer sees your brand — you focus on the relationship and closing deals.
Customers & contracts
Always under the partner’s name
Delivery & 24×7
zcr specialists (back-office)
Billing & reporting
Under the partner’s name
The customer is yours — zcr is just the back-office. The brand and relationship they see is yours (channel protection & deal registration are specified in the partner agreement).
Platform — software the customer runs themselves
End-to-end modular coverage: Visibility → Protection → Response. Sell modules individually or as a bundle.
Log Management
Centralised log retention under the Computer Act — the easiest deal to close.
SIEM
Detect, correlate and investigate threats across sources — with MITRE ATT&CK coverage.
SOAR
Automated playbooks that speed response and cut analyst manual work.
Exposure Management
See internet-exposed assets, vulnerabilities, and dark-web mentions from the attacker’s view.
Web / API Protection
Block OWASP Top 10, bots, and DDoS for customer web apps and APIs.
OT / ICS Security
Visibility and protection for industrial systems, passive — no impact on production lines.
Services — what our team does for you, under your name
Services are where the recurring margin is best, and where full white-label works — the customer sees your brand; our specialists do the work.
zcrSOC · zcrMDR — continuous monitoring & response, recurring revenue every month.
Assessment & Simulation
- ✓Pentest / VAPT
- ✓DDoS Simulation
- ✓Web Defacement
Risk Management · CSRM
- ✓Attack Surface (ASM)
- ✓Data Leak / Dark Web
- ✓Supply Chain Attack
Secure Development
- ✓Secure Coding (SC)
- ✓Awareness Training (SAT)
Advisory & Delivery
- ✓Consulting · PDPA / ISO / BoT
- ✓Implementation & Deploy
- ✓Incident Response / DFIR
Managed Monitoring
- ✓zcrManaged Grafana
- ✓zcrManaged Zabbix
zcrLog
Unified Log Monitoring & SIEM
Changing log to visible value
What it does
Centralized log management and SIEM for real-time visibility, search, alerts, reports, and Thai compliance-ready retention.
Key capabilities
- ↳Computer Crime Act and PDPA log retention
- ↳Real-time dashboard and attack map
- ↳High-speed search and filtering
- ↳MITRE ATT&CK mapping
- ↳Firewall, AD, endpoint, M365, Entra ID, and network integration
- ↳Executive PDF reports and RBAC
Use it for
zcrLog collects, stores, searches, and visualizes logs with real-time dashboards, attack maps, alerts, executive PDF reports, and RBAC.
Best For
IT admins · SOC teams · Compliance teams · Government
zcrSIEM
AI-Powered SIEM & SOAR
Intelligence That Drives Response | SOAR
What it does
AI-powered SIEM and SOAR capability for faster detection, investigation, threat hunting, incident response, and MDR-ready reporting.
Key capabilities
- ↳AI-powered threat detection and correlation
- ↳Built-in SIEM and SOAR capability
- ↳Threat hunting and investigation workspace
- ↳MITRE ATT&CK-aligned intelligence
- ↳Real-time dashboards, alerts, and response visibility
- ↳AI MDR and executive reporting
Use it for
zcrSIEM combines multi-source collection, correlation, AI-assisted analysis, threat hunting, MITRE ATT&CK context, and response visibility in one platform.
Best For
SOC teams · MDR teams · MSSPs · CISOs

zcrSOAR
Security Orchestration, Automation & Response
Automate the SOC. Cut the Toil.
What it does
zcrSOAR turns analyst workflows into repeatable playbooks. Case management, alert triage, approvals, and integrations for firewall, endpoint, identity, and SIEM.
Key capabilities
- ↳Incident and case management
- ↳Alert triage workflow with playbook automation
- ↳Manual and advanced approval steps
- ↳Email and Microsoft Teams notifications
- ↳Firewall, endpoint, identity, and SIEM integrations
- ↳Basic and executive dashboards with monthly reporting
Use it for
zcrSOAR orchestrates the tools your SOC already uses, runs alert triage and response playbooks, tracks every case with SLA visibility, and gives teams a clear approval workflow.
Best For
SOC teams · MDR providers · MSSPs · IT security operations
zcrOT
OT Security
Visibility and Protection for Industrial Environments
What it does
zcrOT helps organizations improve OT environments with safe passive visibility into industrial environments, OT assets, telemetry, risk exposure, behavior baselines, and dashboard-driven findings.
Key capabilities
- ↳Passive OT visibility
- ↳OT asset and relationship discovery
- ↳Telemetry-based monitoring
- ↳Risk exposure assessment
- ↳Behavior baseline foundation
- ↳Dashboard and findings visualization
Use it for
The platform combines focused security capability with flexible deployment, operational dashboards, and controls suitable for small teams through enterprise environments.
Best For
SMEs · Enterprise · Government · MSSPs
zcrWAF
Web Application Firewall
Web application firewall for websites and APIs
What it does
zcrWAF brings Thai-developed web application firewall protection into the zcr suite. It screens traffic before it reaches the origin server.
Key capabilities
- ↳OWASP Top 10 and common web attack protection
- ↳Rate limiting and abnormal traffic control
- ↳Bot and automated script traffic protection
- ↳CAPTCHA and authentication challenges
- ↳Dynamic HTML/JavaScript protection
- ↳Real-time monitoring, security logs, and virtual patch rule updates
Use it for
zcrWAF inspects traffic, applies rate limits and challenges, reduces exposed page structure, monitors attacks in real time, and updates WAF rules as virtual patches.
Best For
Thai organizations · Public websites · E-commerce teams · API owners
zcrCTEM
Continuous Threat Exposure Management
The Hacker View
What it does
EASM + CAASM + DRP + Compliance on one platform. One risk score. Zero tool sprawl.
Key capabilities
- ↳EASM — find every external asset and surface you expose
- ↳CAASM — unify your internal asset inventory across cloud, SaaS, on-prem, OT, IAM
- ↳DRP — watch the internet beyond your perimeter (dark web, paste sites, brand impersonation)
- ↳TI — turn raw CVSS into real risk using CISA KEV + FIRST EPSS + AI
- ↳Compliance — PDPA, CII, ISO 27001 evidence collection
Use it for
External + internal + brand + compliance exposure, on one platform.
Best for
Security & risk teams · Banks · Energy · Healthcare · Government · MSPs and MSSPs (multi-tenant) · CISOs
zcrX
SAST & Code Scanning
Find Risk Early. Build Securely.
What it does
Application security for finding code and design risk earlier in the software lifecycle.
Key capabilities
- ↳SAST
- ↳Code scanning
- ↳Risk prioritization
- ↳Secure development reporting
- ↳Developer workflow support
- ↳Executive visibility
Use it for
zcrX is planned as a code scanning and secure development platform for finding issues early and improving release confidence.
Best For
Development teams · AppSec teams · DevSecOps · Product teams