meshSOAR
Contact
Security orchestration · case management · self-hosted

The SOAR I wanted to work in, built for managed security teams.

meshSOAR is a self-hosted, multi-tenant platform for security operations teams that look after many client organizations. It brings together the strongest ideas from today's SOAR products, alongside the features I've wanted after years of working inside one. It covers cases, automation, ticketing, client communication, scheduling and reporting.

Why it exists

One platform, assembled from the best of the category

Each SOAR product gets something right. One has clear incident layouts and playbooks. Another shows exactly why alerts were grouped together. Another makes HTTP integrations quick to build and lets you replay any automation step. meshSOAR puts those strengths into a single product and adds what operations teams usually work around: real ticketing, a governed channel to clients, shift-aware dispatch, and version control for every piece of content.

What it does

Capabilities

Cases and alerts

Alert grouping you can see and explain, a case wall, entities, evidence, and closure rules the team agrees on.

Playbook automation

Playbooks are stored as YAML graphs with a visual canvas. They run durably on Temporal, and every step can be replayed.

Integrations

Simple HTTP actions are templates. Complex ones are Python on a versioned SDK. Webhooks work in both directions.

Service desk

Requests and tickets sit beside cases, with SLAs that meshSOAR calculates itself instead of taking them from each source.

Client console

Clients sign in to one console to see their cases, answer questions and receive reports, limited to their own data.

Shifts and dispatch

Built in from day one, and fully configurable: rosters, on-shift assignment pools, workload rebalancing, and your own shift patterns and dispatch rules.

Reporting

Executive reports an MSSP is proud to send and a client's executive is impressed to receive. They're delivered per client as PDFs and dashboards.

Versioned content

Every definition you can edit in the UI keeps its history: playbooks, layouts, settings and guides.

How it's built

Principles

  1. Your choice of deployment. Run it fully local, with your data on your own infrastructure, or use the hosted SaaS version in the cloud.
  2. Tenant isolation is enforced by the database. Every tenant table has row-level security, and isolation is proven in CI.
  3. Configurable, not hardcoded. Settings live in a registry, down to the product name, so it can be white-labeled.
  4. AI where it helps, under your control. AI features are optional, and the operator decides whether to turn them on.
  5. Operable by a small team. It's designed for two or three engineers to run.
FastAPITemporalPostgreSQLNext.jsKeycloakOpenBaoMinIOk3s
Status

In active development

meshSOAR is an independent project with one founder. I build it with Claude Code, working alongside AI agents for implementation and review. A working self-hosted beta runs today, and a company will be formed around it ahead of the first release.

Founder

Meshari Alhazmi

I have 6+ years across SOC analysis, detection engineering, SOC engineering, and security automation and DevSecOps. meshSOAR is the platform I wanted in every one of those roles.

Stay tuned

Something great is being built

To follow progress or talk about meshSOAR, write to m.alhazmi@meshsoar.com.