PersonalSOC

PersonalSOC

Personal Security Operations Center

PersonalSOC gathers this device's logs and the state of its defenses into a report that helps you spot anything unusual. It is a small security operations center (SOC) for people without a dedicated security team, so you can understand your device's situation, with evidence, and decide what to do next.

It ships with the RoamSwitch installer, but it is a separate app with its own icon. It works even where RoamSwitch is not installed.

Check status with one button

Press Check status and PersonalSOC reads this device's logs (depending on the OS: SSH authentication, auditd, web, DNS, macOS unified log), your MCP settings and RoamSwitch's detection history, all read-only. It never raises its privileges; logs it cannot read are reported as unreadable.

Dashboard

See the overall risk (an estimate), counts by severity, occurrences by category, the trend over time and MITRE ATT&CK techniques at a glance, in charts.

Report

Sources, findings by category and IOCs (defanged) are compiled into a Markdown report. Times are shown in this device's local time, in a readable form.

Autonomous investigation by an LLM (optional, off by default)

When enabled, after the check an LLM investigates on its own and writes the report as an auditor. PersonalSOC gives the LLM only permitted read-only tools, and hands it no shell or files.

Scheduled runs (optional)

Registered with launchd on Mac and systemd (user) on Linux, it notifies you only when there is a detection that was not there last time (the notification contains only the count). root is never used.

10 languages

Japanese, English, German, Spanish, French, Italian, Korean, Portuguese, and Simplified and Traditional Chinese. It follows your OS language automatically.

RoamSwitch MCP integration

If RoamSwitch is installed, PersonalSOC pulls unresolved detections and failed configuration diagnostics from RoamSwitch's MCP server (read-only) and folds them into the same report as the log findings. Identical detections are merged into one, with a count and the latest time. During an LLM investigation it can call only RoamSwitch's read-only tools; anything that acts, such as run_*, is refused. Without RoamSwitch this source is simply skipped, and it can be turned off in settings.

Screenshots

PersonalSOC dashboard: overall risk gauge, severity donut, occurrences by category, hourly trend and MITRE ATT&CK counts
PersonalSOC report tab: current status summary, status by category and trend tables
PersonalSOC settings: automatic status check sources, scheduled runs, LLM integration and display language

All data shown in these screens, such as IP addresses, is fictional.

Sample report

A sample of the report (with LLM integration on). You can copy it as Markdown and share it as is.

The IP addresses and logs shown are all fictional. Reports come out in the display language (10 languages).

How to launch it

Mac: open PersonalSOC in the Applications folder (it has its own icon, separate from RoamSwitch).

Linux: open PersonalSOC from your application menu (it has its own icon). From a terminal, run personalsoc-app.

Command line: personalsoc scan --report (report), personalsoc scan --llm <name> (LLM investigates on its own).

Privacy and scope

PersonalSOC analyzes logs entirely on this device. It opens no listening ports, and its window loads no external sites.

LLM integration is off by default. When enabled, PersonalSOC starts the LLM command you chose (opencode, claude, codex, agy, etc.) and passes it the details of detections and the log lines behind them (secrets such as keys and tokens are masked). Depending on that command's settings, the content may be sent to an external service. Where it goes and how it is handled follows the LLM you chose and its provider's terms.

RoamSwitch's "Zero-Telemetry" (it never sends your traffic or logs anywhere) describes RoamSwitch itself. Communication that occurs when you enable PersonalSOC's LLM integration is not covered by it. With LLM integration left off, PersonalSOC never sends the contents of your logs off the device.

License

PersonalSOC is licensed under the Apache License 2.0 and is not covered by the RoamSwitch license agreement (EULA). The license text, NOTICE and the list of bundled third-party software are inside the app on Mac (PersonalSOC.app/Contents/Resources) and in /usr/share/licenses/personalsoc/ on Linux.

Requirements and updates

macOS 12 or later. On Linux it needs WebKitGTK 4.1 (libwebkit2gtk-4.1), which the deb and rpm packages install automatically; on Arch (AUR) install webkit2gtk-4.1 as an optional dependency. On Mac you can update from Settings, under Updates. It connects only when you press the button, and the downloaded file is verified with a signature before it is installed. On Linux it is included in RoamSwitch package updates.