Active defence · v4.7

Autonomous cyber defense agents that hunt, contain, and deceive.

Threxen is a fleet of AI agents that watch your telemetry every second, score it against attacker behaviour, and contain a compromise before a human ever sees the dashboard. One platform — many isolated tenants — built to operate inside the legal boundary of CFAA, NIS2, and DORA.

Tenants live
38
across 11 jurisdictions
MTT-contain
0.8s
median, last 30 days
Decoys served
1.4M
last 24 hours
threxen
  • 14:02:11[watchdog-04] lateral SMB enumeration detected → host seg-eu-12
  • 14:02:14[watchdog-04] isolating seg-eu-12 · revoking session 3e9a··
  • 14:02:15[deceiver-02] booby-trapping 6 honeyfiles (DCS, ForgeJWT, kubeconfig)
  • 14:02:19[profiler-01] actor cluster typed FIN-117 · toolchain overlap 0.74
  • 14:02:22[analyst-handoff] playbook P-44 pushed to Tier-2 queue · 4 hunts open
  • 14:02:26[watchdog-09] OAuth abuse: 3 refresh tokens replayed from exfil IP range
  • 14:02:28[watchdog-09] pausing 3 sessions · quarantining token vault
  • 14:02:33[deceiver-05] serving forged decoy to 198.51.100.0/24 · 11 paths hit
  • 14:02:38[profiler-01] actor cluster updated FIN-117 → 0.81 confidence
  • 14:02:41[analyst-handoff] attribution packet sealed · evidence hash 9c4f··
  • 14:02:11[watchdog-04] lateral SMB enumeration detected → host seg-eu-12
  • 14:02:14[watchdog-04] isolating seg-eu-12 · revoking session 3e9a··
  • 14:02:15[deceiver-02] booby-trapping 6 honeyfiles (DCS, ForgeJWT, kubeconfig)
  • 14:02:19[profiler-01] actor cluster typed FIN-117 · toolchain overlap 0.74
  • 14:02:22[analyst-handoff] playbook P-44 pushed to Tier-2 queue · 4 hunts open
  • 14:02:26[watchdog-09] OAuth abuse: 3 refresh tokens replayed from exfil IP range
  • 14:02:28[watchdog-09] pausing 3 sessions · quarantining token vault
  • 14:02:33[deceiver-05] serving forged decoy to 198.51.100.0/24 · 11 paths hit
  • 14:02:38[profiler-01] actor cluster updated FIN-117 → 0.81 confidence
  • 14:02:41[analyst-handoff] attribution packet sealed · evidence hash 9c4f··

Agents live

247

+6 last hour

Open hunts

4

−2 last hour

Containments (24h)

11

+3 last hour

▸ live stream from tenant:eu-west-1 · sample redaction applied

Operating boundary
CFAA — defensive only, inside-customer-perimeterNIS2 — essential-entity reporting timelinesDORA — ICT-risk + operational-resilienceGDPR — per-tenant isolation, BYOK

02 · Capabilities

Four agent families. One coordinated response.

Each agent family operates continuously on the same telemetry plane. They don't hand off and forget — they share verdicts, cross-corroborate, and only escalate when their confidence overlaps.

family 01
W

Always hunting, never idle.

Watchdog agents continuously score telemetry against attacker behaviours — adversarial-AI prompts, lateral movement, credential abuse, supply-chain tampering — and surface a verdict in seconds, not at end-of-shift.

agent.class = watchdogs

family 02
C

Quarantine in 800 ms, not 8 hours.

Confirmed compromises trigger immediate isolation: poisoned sessions revoked, tunnel interfaces shut, lateral pathways severed at the host. Every action is auditable and reversible by a human analyst.

agent.class = containment

family 03
D

The blue team that bites back.

Deceivers lay high-fidelity decoys — decoy documents, forged SaaS endpoints, fake kubeconfigs — and live-poison adversary tooling as it touches them. Attackers waste hours inside a perimeter that is already known.

agent.class = deceivers

family 04
P

Attribution your insurer can read.

Profilers fingerprint the actor — toolchain overlap, behavioural cadence, infrastructure history — and produce a sealed evidence packet a human reviewer (or regulator) can sign off on without re-running the analysis.

agent.class = profilers

03 · Kill chain

From the first probe to a sealed attribution packet — autonomous.

Threxen doesn't wait for a SOC analyst to triage. Detect → Contain → Deceive → Attribute runs without paging a human until a forensic packet is ready to review.

Autonomous
Auditable
Reversible
  1. 01

    Detect

    Telemetry is scored by behaviour, not signatures. Adversarial-AI prompt patterns, lateral Kerberos abuse, OAuth replay, supply-chain manifest drift.

  2. 02

    Contain

    Verdicts above threshold trigger autonomous host isolation, session revocation, and tunnel teardown. Mean time-to-contain: under one second.

  3. 03

    Deceive

    Compromised attackers are routed into a deception mesh with high-fidelity decoys. Their tooling is fingerprinted and live-poisoned.

  4. 04

    Attribute

    A sealed evidence packet — actor confidence, toolchain map, regulatory framing — lands on a Tier-2 analyst desk, ready for action.

04 · Tenancy

One platform. Many fully-isolated tenants. No leakage — by construction, not by policy.

Regulators don't trust shared multi-tenant SaaS. Threxen runs every customer — and every business unit, subsidiary, or jurisdiction inside each customer — as its own cryptographic enclave. Operators can't read tenant data, and a breach in one tenant can't reach another.

  • Per-tenant key envelope

    Every customer — and every BU, subsidiary, or jurisdiction inside it — gets its own cryptographic key envelope. Threxen operators cannot read tenant data.

  • Sector-pinned storage

    PHI stays in HIPAA-only data planes. Card data stays in PCI-isolated CDE views. EU operational data stays in EU-only jurisdictions.

  • End-to-end encryption

    At rest and in transit. Keys never leave the tenant envelope; rotation, escrow, and HSM-backed bring-your-own-key are first-class.

  • Forensic replay

    Every agent decision — every hunt, every containment — is sealed with a hash chain your auditor can re-verify months later.

Tenant lattice

logical view
eu-westeu-centralus-eastus-westapacmecaukThrexen

▸ each hexagon = one cryptographic key envelope · edges = signed audit lane · no shared egress

05 · Policy packs

Sector-specific control planes, not retrofitted bolt-ons.

Every regulated framework Threxen supports ships as a policy pack: a set of detections, containment rules, evidence formats, and reporting cadences the relevant regulator already recognises.

HIPAA

pack

PHI access boundaries, audit trails, BAA-grade isolation across covered-entity tenants.

status: pinned · audit: continuous

PCI-DSS 4.0

pack

CDE segmentation, card-data-flow whitelisting, key-evident forensic replay of every containment.

status: pinned · audit: continuous

FedRAMP Moderate

pack

US-only data egress, FIPS-validated key envelope, continuous-control reporting aligned to NIST 800-53.

status: pinned · audit: continuous

DORA

pack

ICT-risk register, third-party-provider incident timelines, and operational-resilience testing posture for EU financial entities.

status: pinned · audit: continuous

NIS2

pack

Essential-entity incident reporting timelines, supply-chain risk register, and sector-specific escalation policies.

status: pinned · audit: continuous

CFAA

pack

Active defence is bounded inside the customer perimeter — no offensive operations against third-party systems, ever.

status: pinned · audit: continuous

Brief a defence architect

See Threxen score your telemetry — live, in your sector.

Thirty minutes. A sample stream. Watchdog agents scoring it in front of you and a containment verdict landing in real time — no slides, no forward-deployed engineer. NDA available; procurement not required.

Quick request

form · ~60s

Tell us your sector, attackers, and regulators.

We'll come back with a tenant topology, the active policy packs, and a one-line mailto your auditor can read.

▸ 30-min session · NDA on request

Mission differentiator

Three traits that move a defender off the breach clock.

Watchdog, Deception, Containment — the three traits every Threxen tenant ships with on day one. They are how a SOC stops being its own bottleneck.

trait · watchdog

Telemetry scored by behaviour, not signatures.

Watchdog agents run continuously on every tenant stream — adversarial-AI prompt patterns, lateral SMB, OAuth replay, supply-chain drift — and surface a verdict in seconds, not at end-of-shift.

trait · deception

High-fidelity decoys that bite back.

Deceivers lay decoy documents, forged SaaS endpoints, and fake kubeconfigs — then live-poison adversary tooling the moment it touches them. Attackers waste hours in a perimeter they have already lost.

trait · containment

Quarantine in 800 ms, not 8 hours.

Confirmed compromises trigger immediate isolation: poisoned sessions revoked, tunnel interfaces shut, lateral pathways severed at the host. Every action is auditable and reversible by a human analyst.

Compliance

HIPAA
PCI-DSS
FedRAMP
DORA
NIS2

Every badge ships as a governed policy pack — detections, containment rules, evidence formats, and reporting cadences the relevant regulator already recognises.

06 · Pricing

Three plans. One defence posture.

Pick the entry point that matches your sector and the regulators you report to. Scale up without re-architecting tenants.

Starter

For platform teams getting a first defence posture live.

$499/mo
  • Watchdog event monitoring (1 region)
  • Basic decoy catalog — docs + SaaS endpoints
  • 1 compliance pack (choose HIPAA, PCI-DSS, DORA, or NIS2)
  • Email alerts · webhook digest
Start with Starter
Most chosen

Business

For regulated teams running containment in production.

$2,499/mo
  • Full decoy management · dynamic decoy generation
  • Autonomous containment actions · reversible
  • All compliance packs: HIPAA, PCI-DSS, DORA, NIS2
  • API key access · analyst handoff console
Start with Business

Enterprise

For multi-jurisdiction operators and US federal work.

Contact sales
  • FedRAMP Moderate policy pack
  • Multi-jurisdiction sub-tenants · sector-pinned storage
  • Dedicated key envelopes · HSM-backed BYOK
  • Custom SLA · named defence architect
Contact sales

▸ billed monthly · annual = 2 months free · procurement / PO accepted on Business and Enterprise

07 · For your analysts

Autonomy without opacity. Every action lands on a desk with context.

Threxen contains autonomously but never silently. Tier-2 analysts receive a sealed evidence packet for every hunt — actor confidence, toolchain overlap, the detections that triggered, and a one-click reversible trail. They approve, reverse, or escalate. The agent does not.

analyst inbox · queued
5 packets · sorted by severity
  • watchdog-04

    Lateral SMB enumeration on seg-eu-12

    0.8s ago
  • deceiver-02

    Honeyfile touched · toolchain fingerprint sealed

    4m ago
  • profiler-01

    Actor cluster typed FIN-117 (conf 0.81)

    11m ago
  • watchdog-09

    OAuth refresh-token replay from exfil IP range

    23m ago
  • deceiver-05

    Decoy decoy-svc hit 11 paths · 2 tooling fingerprints

    31m ago
reversible from this railevidence hash · 9c4f..d22a

▸ final channel · talk to a human

Stop watching the SOC work overnight. Give it a team.

Tell us your sector, your attackers, and your regulator. We'll send back a tenant topology, the active policy packs, and a one-line mailto for your auditor.

threxen@polsia.app

provisioning within 48h · SOC 2 audit pack bundled