SIEM, XDR, SOAR, threat intelligence, vulnerability management and penetration testing in one multi-tenant platform. Built in the EU, isolated per organization by design, aligned with NIS2 and the Cyber Resilience Act.
Own SIEM engine on raw events (OCSF, Sigma), connectors to Wazuh and other SIEMs, UEBA, CTI from MISP, OpenCTI and public feeds.
19 scan runners, Kubernetes and cloud posture, API assessment, safe exploitability validation, offline scanner for isolated networks, attack paths to critical assets.
Incidents with MTTA/MTTR, branching playbooks, containment through EDR, firewalls and identity with four-eyes approval, on-call paging, NIS2 reporting.
Immutable audit chains, executive and compliance reports, signed SBOM, public trust page, SSO and passkeys.