Starting point
softScheck Singapore tests, audits and certifies other companies' IT security — penetration testing, security audits, ISO 27001 consulting. Its own regulatory load is no side issue: the CSA's Cybersecurity Act and CCoP 2.0, the PDPA notification duties and the MAS requirements keep moving, and every client engagement produces findings, deadlines and escalations that have to be demonstrably worked. A firm that audits others cannot afford an attack surface of its own — client data does not leave the country.
Deployment
A dedicated Agentic360 installation on hardware in Singapore, serving its models locally: no request leaves the box, no cloud model sees client data. On it run five role-trained agents (CSA cybersecurity, PDPA, pentest & audit, ISO 27001, assistant), four live regulatory sources from CSA, PDPC and MAS, and both the IT security and the compliance scanner. ACOR, the platform’s operations resolver, brings channels, tickets, SLA clocks and escalations into one place. External pentest tooling submits findings straight into the tenant over the MCP gateway; anything at CVSS 9.0 or above waits in a review gate until a tenant admin has signed it off.
Outcome
The installation runs as the APAC pilot. Data residency and local inference are signed off, the regulatory sources are delivering, and findings from external tooling arrive in the tenant behind a review gate. Hard numbers on handling times are being collected in the pilot — they will stand here once softScheck has released them.