CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Deployment

Cloud, sovereign, or somewhere in between.

Edge stays at the plant DMZ. Core can live in cloud, sovereign region, or fully on-prem — including air-gap.

Fastest start

Hybrid Cloud (Mode A)

Core hosted in cloud; Edge on-site.

Best for: Mid-market, fast PoV

Full control

Sovereign On-Prem (Mode B)

Core + Edge at customer site.

Best for: Air-gap, data sovereignty

Maximum isolation

Dedicated Single-Tenant

Isolated VPC and database per customer.

Best for: Banks, national utilities

Balanced

Hybrid Edge + Sovereign Cloud

Edge stays local; Core runs in a sovereign cloud region.

Best for: National utilities

Partner ready

MSSP BYOC

MSSP hosts the platform under an Axix license.

Best for: Service providers

Fleet

Edge kits at every plant

  • Mode A: Core in cloud, Edge on-site.
  • Mode B: Core + Edge sovereign / air-gap.
  • Certs and firmware tracked per node.
Edge fleet
How it works

Typical go-live in 7 weeks.

Week 0

MSA + DPA signed

Week 1–2

Infrastructure provisioned, tenant created

Week 3–4

Edge install, ingest validation

Week 5–6

UAT

Week 7

Go-live + 30-day hypercare

Collectors

Health during roll-out

  • Uptime, last event, degraded flags during week 3–4 install.
  • Protocol parsers validated per site.
  • Offline SQLite buffer if Core is unreachable.
CyberDragon Edge collector status board
SLA tiers

Standard, Enterprise, Critical Infrastructure.

TierUptimeP1 responseSupport
Standard99.5%4 hoursBusiness hours
Enterprise99.9%1 hour24×5
Critical Infrastructure99.95%30 min24×7

Config

Platform health for the tenant

  • Tenant-admin sees config without Super Admin.
  • Dedicated single-tenant option for banks and national utilities.
  • Typical go-live in 7 weeks.
Platform config
Prerequisites

What we need from you before week one.

Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Explore Now
Runtime path

What happens to a packet after go-live.

01

Capture

Edge mirrors traffic from a SPAN port or hardware TAP at the industrial DMZ and parses OT protocols locally.

02

Buffer

Events land in a SQLite WAL store-and-forward queue (~5,000 events) so a link outage never loses telemetry.

03

Transport

HMAC-SHA256 signed batches, optionally mTLS, are shipped to Core over the ingest network only.

04

Enrich

Threat-intel fusion adds OTX, Abuse.ch, ThreatFox, MITRE TAXII, and GreyNoise context in flight.

05

Correlate

Cascading W15 / W60 / W24 windows assemble events into kill chains and flag Enterprise→OT pivots explicitly.

06

Decide

Risk scoring, compliance auto-mapping, and Temporal playbooks with human approval and OPA guardrails.

07

Seal

Detections, approvals, and denials are hash-chained and Ed25519-signed into the evidence vault.

FAQ

Frequently asked questions.

Can CyberDragon run fully air-gapped?
Yes. Sovereign on-prem (Mode B) runs Core and Edge at your site, with a Helm air-gap installation path.
What happens if the link to Core drops?
Edge keeps capturing and buffers roughly 5,000 events in SQLite WAL, then forwards when the link returns.
How long does a deployment take?
Typical go-live is seven weeks: provisioning in weeks 1–2, Edge install in 3–4, UAT in 5–6, then go-live and 30-day hypercare.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.