Securing businesses since 1998.

Clone Systems is a global Managed Security Service Provider and PCI SSC Approved Scanning Vendor. We protect more than a thousand organizations with 24/7 Security Operations Centers, proprietary SIEM, and AI-assisted operations.

1998
Securing businesses since
1,000+
Organizations protected worldwide
24/7
SOC coverage across US and EU
PCI ASV
Approved Scanning Vendor since 2007
Our Story

Nearly three decades of security leadership.

Clone Systems was founded in Philadelphia in 1998 as a security technology company. From the beginning our mandate was simple: build technology businesses can use to defend a security posture they actually own, and stand behind it with real people and round-the-clock support.

In 2001 we formalized as a niche Managed Security Service Provider, and in 2004 we activated our first 24/7 PCI-certified data center and US Security Operations Center. In 2007 the PCI Security Standards Council certified us as a global Approved Scanning Vendor, and we have been running quarterly ASV scans for merchants and service providers worldwide ever since.

Today we combine that heritage with a modern platform: proprietary SIEM aligned to MITRE ATT&CK, a unified scanning portal, mobile apps, an AI assistant, and AI-powered SOAR playbooks. Same people. Same standards. Faster, sharper, always-on.

  • Compliance you can prove
    Every scan, playbook, and portal is built around evidence a QSA or auditor can actually use.
  • AI with a human in the loop
    Our AI assistant accelerates triage and remediation, but a senior analyst signs off on outcomes.
  • Straight to the experts
    Talk to a certified engineer on the first call. No scripted qualifying rounds, no multi-year lock-in.
Milestones

A quarter century of shipping security that works.

Every era below is drawn from the actual Clone Systems roadmap. Scroll through the story and each era opens as you reach it.

  1. 1998 — 2007
    Founding Era

    Founded as a security technology company in Philadelphia, then formalized as a niche MSSP with a dedicated CISSP team, a PCI-certified data center, a 24/7 US-based Security Operations Center, and became a Global PCI SSC Approved Scanning Vendor.

    • 1998
      Clone Systems, Inc. is established
      Building security technology businesses could use to strengthen their posture.
    • 2001
      Formal MSSP launch
      Managed firewall and IDS/IPS services for retailers and banks, run on our own platform.
    • 2003
      CISSP team formed
      A dedicated Certified Information Systems Security Professionals team with a whatever-it-takes attitude.
    • 2004
      PCI-certified data center & US SOC
      Self-contained infrastructure and 24/7/365 monitoring go live.
    • 2007
      Global PCI ASV certification
      Certified by the PCI SSC to perform vulnerability scans for merchants and service providers worldwide.
    • 2007
      Recognized IDS/IPS expertise
      Industry recognition for managed detection delivered on our own proprietary platform.
  2. 2008 — 2013
    Scale & Global Reach

    Launched the CloneGuard security suite, opened offices in New York and London, and activated the European Security Operations Center.

    • 2008
      CloneGuard suite launched
      New wave of security products addressing fast-changing customer needs.
    • 2009
      Reseller program
      White-label and reseller program for VARs, QSAs, and other service providers.
    • 2010
      London office opens
      International expansion to serve European customers and resellers.
    • 2012
      Gartner Magic Quadrant recognition
      Recognized as a niche pure-play MSSP with strong customer marks for delivery.
    • 2013
      European SOC activated
      24/7/365 monitoring extended across the EU with regional response coverage.
  3. 2014 — 2019
    Platform Modernization

    Built proprietary SIEM and Log Management, consolidated all scanning services into a single portal, released mobile apps and the Incident Response Platform, and expanded white-label REST APIs.

    • 2014
      Proprietary SIEM & Log Management
      Purpose-built with customers for speed, search, and analyst usability.
    • 2017
      REST APIs for scanning
      White-label resellers can fully embed our scanning platform into their own products.
    • 2017
      NextGen SIEMv1
      Cloud API integrations, two-phase alerting, and STIX/TAXII custom threat intel.
    • 2018
      Unified scanning portal
      PCI ASV, vulnerability management, and pentesting consolidated into one interface.
    • 2018
      Mobile scanning apps
      iOS and Android apps for managing scans from anywhere.
    • 2019
      Incident Response Platform
      Direct customer view into the SOC for real-time incident review and response.
  4. 2020 — 2022
    XDR, SOAR & Cloud

    Integrated SOAR into the IRP, launched CloneGuard ONE for SMB XDR coverage, released the EDR agent, added automated dark web scanning, and re-engineered the scanning stack for PCI DSS 4.0.

    • 2020
      SOAR integrated into IRP
      Interactive customer-facing playbooks streamline SOC investigations.
    • 2020
      SIEM v2.0 released
      Events aligned to the MITRE ATT&CK framework and multiple compliance standards.
    • 2020
      EDR agent general availability
      Multi-platform endpoint threat protection integrated with our SIEM.
    • 2021
      Automated dark web scanning
      New add-on lets clients confirm their data is not being sold on the dark web.
    • 2021
      Multi-tenant SIEM with XDR
      Enterprise-grade SIEM for SMBs, aligned to the most stringent compliance frameworks.
    • 2022
      ASV 4.0 ready architecture
      Distributed scan workers, authenticated app checks, smarter throttling, and delta rescans.
  5. 2023 — Today
    AI-Assisted Security

    Stood up a dedicated AI Lab, launched AI Remediation and AI SOC Analyst, shipped AI-powered SOAR with a full audit trail, and relaunched CloneGuard with a rebuilt scanning portal and online checkout.

    • 2023
      Pentest Reporting 2.0
      Findings mapped to MITRE ATT&CK and CWE, with prioritized remediation and one-click retest.
    • 2023
      AI Lab established
      Safe, private AI projects for log summarization, remediation plans, and analyst assistance.
    • 2024
      SAQs on PCI DSS 4.0.1
      Aligned to the Council's October 2024 refresh and January 2025 SAQ A updates.
    • 2024
      Correlation packs & playbooks
      New detections for AD enumeration, EDR tampering, DNS zone transfers, and DB password spraying.
    • 2024
      AI Remediation & AI SOC Analyst (beta)
      Internal AI platform converts vulnerability data into step-by-step fix guidance.
    • 2025
      AI-powered SOAR (GA)
      AI runbooks enrich alerts, propose actions with evidence, and execute low-risk containment with human approval.
    • 2025
      PCI DSS 4.x future-dated controls complete
      Full platform support for requirements effective March 31, 2025.
    • 2026
      CloneGuard portal relaunch
      Rebuilt scanning portal with 4x the vulnerability detection library, authenticated web app testing, endpoint agents for remote hosts, and a privately hosted AI assistant.
How We Protect You

Four things every Clone Systems customer gets.

Written in 2006. Still true today. Modernized with AI-assisted operations, XDR coverage, and PCI DSS 4.0.1 tooling.

24/7 Security Operations

Our United States and European Security Operations Centers identify vulnerabilities, monitor threats, and respond in real time, every hour of every day.

Proprietary Technology

Every platform we run is proprietary Clone Systems technology, built and maintained in-house and delivered as a fixed-cost service so there is no capital expense to your team.

Certified Senior Engineers

CISSP-led engineers integrate with your team, strengthen your posture, and stay accountable through every incident, exception, and audit cycle.

Global Security Experience

Insight gathered from securing customers across regulated industries on multiple continents shapes the guidance we bring back to every client.

Global Footprint

Two SOCs. One incident response platform.

Clone Systems runs Security Operations Centers in the United States and the European Union, both staffed 24/7/365 by CISSP-led analysts. They share tooling, playbooks, and case history through a single incident response platform, so nothing falls between shifts or between regions.

  • Philadelphia, USA — HQ & SOC
  • Cyprus, EU — European SOC
  • PCI SSC ASV since 2007
  • AI-powered SOAR (GA 2025)
SOC
24/7/365
Coverage
US + EU
SIEM
Proprietary
Framework
MITRE ATT&CK
Standards
PCI, HIPAA, SOC 2, GDPR
AI
Human-in-the-loop

Trusted by Leading Organizations

From Fortune 500 enterprises to global retailers, financial institutions, airlines, manufacturers, and healthcare organizations, organizations have trusted Clone Systems to strengthen their security posture since 1998.

Intel — Clone Systems technology alliance
IBM — Clone Systems technology alliance
BMW — Clone Systems technology alliance
Chevron — Clone Systems technology alliance
Coca-Cola — Clone Systems technology alliance
Vodafone — Clone Systems technology alliance
Lufthansa — Clone Systems technology alliance
Hertz — Clone Systems technology alliance
FIS — Clone Systems technology alliance
Fiserv — Clone Systems technology alliance
Envato — Clone Systems technology alliance
American Airlines — Clone Systems technology alliance
7-Eleven — Clone Systems technology alliance
American Express — Clone Systems technology alliance
Pizza Hut — Clone Systems technology alliance
Best Western — Clone Systems technology alliance
Beauty & Hair — Clone Systems technology alliance
Associated Press — Clone Systems technology alliance
Burlington — Clone Systems technology alliance
3M — Clone Systems technology alliance
Brooks Brothers — Clone Systems technology alliance
Thales — Clone Systems technology alliance
Henry's — Clone Systems technology alliance
Free Press — Clone Systems technology alliance
Berkshire Hathaway HomeServices — Clone Systems technology alliance
Arby's — Clone Systems technology alliance
Austrian Airlines — Clone Systems technology alliance
Carrefour — Clone Systems technology alliance
Bitcoin.com — Clone Systems technology alliance
Mitsubishi Electric — Clone Systems technology alliance
Intel — Clone Systems technology alliance
IBM — Clone Systems technology alliance
BMW — Clone Systems technology alliance
Chevron — Clone Systems technology alliance
Coca-Cola — Clone Systems technology alliance
Vodafone — Clone Systems technology alliance
Lufthansa — Clone Systems technology alliance
Hertz — Clone Systems technology alliance
FIS — Clone Systems technology alliance
Fiserv — Clone Systems technology alliance
Envato — Clone Systems technology alliance
American Airlines — Clone Systems technology alliance
7-Eleven — Clone Systems technology alliance
American Express — Clone Systems technology alliance
Pizza Hut — Clone Systems technology alliance
Best Western — Clone Systems technology alliance
Beauty & Hair — Clone Systems technology alliance
Associated Press — Clone Systems technology alliance
Burlington — Clone Systems technology alliance
3M — Clone Systems technology alliance
Brooks Brothers — Clone Systems technology alliance
Thales — Clone Systems technology alliance
Henry's — Clone Systems technology alliance
Free Press — Clone Systems technology alliance
Berkshire Hathaway HomeServices — Clone Systems technology alliance
Arby's — Clone Systems technology alliance
Austrian Airlines — Clone Systems technology alliance
Carrefour — Clone Systems technology alliance
Bitcoin.com — Clone Systems technology alliance
Mitsubishi Electric — Clone Systems technology alliance
Talk To Clone Systems

Have a question about our company?

Tell us what you are working on. A certified engineer will get back to you with straight answers and no long-term lock-in.

COMPANY INQUIRY

Ask us anything

Straight answers from a certified engineer. All fields required.

No spam, ever.

About Clone Systems FAQ

Common questions about the company.