Your alerts deserve
a real workflow.
A self-hosted incident response platform that turns security alerts into structured investigations: enriched by nine intelligence sources, escalated into incidents with a regulatory clock, and closed with a report. Entirely on your own infrastructure.
From alert to resolution
ir.mlab.sh structures the full incident response lifecycle into five clear stages.
Ingest
One endpoint that reads your SIEM's own field names, deduplicates on a key you choose, and classifies the observables in the payload.
Triage
Every alert arrives with its merged enrichment verdict. Decide explicitly: true positive, false positive, benign, or escalate.
Investigate
Cases with tasks, an append-only timeline, hashed evidence and correlation against every past investigation.
Respond
An incident with a commander, the five NIST phases, and the DORA, NIS2 or RGPD notification clock started automatically.
Close & review
A printable dossier, a post-incident review scored per phase, and action items carrying a due date and a change reference.
Everything your SOC needs
Built by security professionals, for security professionals. No bloat, no noise - just the tools that matter.
Alert ingestion
One endpoint takes an alert from a SIEM, an EDR or a script. The sender keeps its own field names.
- Splunk, Elastic and Sentinel field mapping
- Deduplication on a key you control
- 1 000 alerts a minute, batches of 200
Cases and incidents
A case is one investigation. An incident is what the organisation has to answer for, with its own lifecycle.
- Tasks, templates, notes, custom fields
- Incident commander and NIST phases
- SLA deadlines that recompute on escalation
Enrichment catalog
Nine sources asked at once, merged into one verdict, cached for six hours per organisation.
- VirusTotal, AbuseIPDB, GreyNoise, MISP and more
- Routing per observable type
- Declare your own REST source, no rebuild
Regulatory compliance
Assign a framework and every notification it requires appears with its deadline already calculated.
- DORA Art. 19, NIS2 Art. 23, RGPD Art. 33
- ICT incident and RGPD violation registers
- Post-incident reviews with action items
Automation
A visual DAG editor for the mechanical work, and webhooks for everything downstream.
- HTTP, condition, transform and delay nodes
- Slack, Discord, Teams or a signed endpoint
- Per-node execution history
Access control
Twelve permission bits per member, checked on every route, plus optional TLP enforcement.
- TOTP and WebAuthn passkeys
- Account keys and app tokens, scoped apart
- Append-only audit trail in ClickHouse
Self-hosted, private, yours
Your data never leaves your infrastructure. Deploy with Docker Compose in under 5 minutes. No SaaS dependency, no vendor lock-in.
Docker Compose
Single docker compose up to deploy the full stack. App, executor, MySQL & ClickHouse included.
Minimal requirements
2 GB RAM, 10 GB disk. Runs on any Linux server, VPS or local machine.
Auto-migrations
Database schema updates run automatically on startup. Just pull and restart.
48h grace period
License checks every hour via HMAC. If your server goes offline, ir.mlab.sh keeps running for 48 hours.
No hidden features behind paywalls
Self-hosted deployment
Run on your own infrastructure. Your data stays with you.
Granular permissions
Twelve permission bits per member, checked on every route, plus optional TLP enforcement.
Complete audit timeline
Append-only in ClickHouse, two-year default retention, configurable from 30 to 3 650 days.
REST API and webhooks
Every entity over a documented API, plus outbound webhooks to Slack, Discord, Teams or your own endpoint.
Free upgrades
Every release includes new features and fixes at no extra cost.
48-hour license resilience
Grace period ensures continuity if license server is temporarily unreachable.
Automatic database migrations
Schema updates apply on startup. No manual SQL needed.
Two-factor authentication
TOTP and WebAuthn passkeys on every tier, with an option to force enrolment workspace-wide.
Stop using spreadsheets for incidents
Most teams still manage incidents with shared docs, Slack threads and email chains. ir.mlab.sh gives you a proper platform without the enterprise price tag.
| Spreadsheets & Emails |
Enterprise SOAR |
Open-source IR tools |
ir.mlab.sh | |
|---|---|---|---|---|
| Self-hosted | ||||
| Deploy in <5 min | ||||
| Case management | ||||
| Alert triage workflow | ||||
| Observable correlation | ||||
| REST API | ||||
| Multi-source enrichment | ||||
| DORA / NIS2 / RGPD deadlines | ||||
| Visual playbooks | ||||
| Enterprise SSO | ||||
| Free tier available | ||||
| Professional support | ||||
| No vendor lock-in |
Who is it for?
SOC Analysts
Triage alerts faster, investigate with context, and stop drowning in false positives.
Incident Responders
Coordinate response across teams with structured cases, evidence and timelines.
Blue Teams
Build detection context, track indicators, and feed findings back into your defenses.
CISOs & Managers
Get visibility into your team's workload, response times and investigation outcomes.
Ready to fix your incident workflow?
Deploy ir.mlab.sh in under 5 minutes. Free tier included, no credit card required.