CyberDragon Core is live — indigenous SIEM/SOAR with Edge protocol capture. Start a 7-day free trial on your own traffic →
Proof of Value

Try it free, prove it on your plant, then scale.

Self-serve cloud plans cover Free trial, Standard, and Premium. This page covers guided evaluation, enterprise licensing ranges, the deployment timeline, and SLA commitments.

6/6
Attack scenarios detected
lab validation
8–21s
Mean time to detect
MTTD range
15,093
Live IOCs in TI corpus
continuously enriched
0
False incidents
22.4h baseline run
L0–L5
Purdue coverage model
Industry 4.0 ready
Lab-validated metrics. PoV results may vary.
What operators say

Feedback from Proof of Value engagements.

Quotes from controlled PoV environments — evidence, safety, and passive OT visibility without PLC agents.

"First platform that showed us an OT write command without asking us to put an agent on the PLC."
OT Security Lead · Energy PoV
"The evidence export saved our audit team a full week of manual log correlation."
CISO · Manufacturing PoV
"The Safety Gate concept is what got our plant engineers comfortable signing off."
Plant Engineering Manager · PoV

Edge

Kit at the mirrored port

  • Software-mode collector or hardware SPAN.
  • Validate Modbus/DNP3/OPC-UA parsing per site.
  • No PLC agents in the safety review.
Edge collector
Evaluation tiers

7-day free trial → sandbox → PoV → pilot.

Guided Demo

1 hour

Axix screen-share, synthetic tenant

7-Day Free Trial

7 days

Self-serve CyberDragon tenant — no credit card

Hands-on Sandbox

5 business days

Dedicated demo-{company} tenant

Proof of Value (PoV)

30 days

Tenant + 1 Edge kit

Pilot

90 days

Production-like SLA

Enterprise (USD ranges)

Platform + Edge + optional packs.

ComponentModelStarting from
Platform basePer tenant / year$48,000 – $180,000
Edge nodePer collector / year$3,000 – $12,000
Incidents volumeTiered EPS / incidentsIncluded band + overage
PQC / compliance packAdd-on+15–25%
Professional servicesDay rate$1,200 – $2,500/day
Authorized assessment (CAAP)Per engagement$15,000 – $80,000

MSSP: per managed tenant / month, annual tenant packs (25, 100), example revenue share 70/30 MSSP/Axix. Become an MSSP partner →

Timeline

Typical go-live in seven weeks.

W0

MSA + DPA signed

W1–2

Infrastructure provisioned, tenant created

W3–4

Edge install, ingest validation

W5–6

UAT

W7

Go-live + 30-day hypercare

SLA

Uptime and response by tier.

TierUptimeP1Support
Standard99.5%4 hoursBusiness hours
Enterprise99.9%1 hour24×5
Critical Infrastructure99.95%30 min24×7
FAQ

Frequently asked questions.

What is CyberDragon?
CyberDragon combines passive Edge industrial protocol capture with an indigenous Kafka-powered SIEM and SOAR control plane — hybrid post-quantum identity, kill-chain detection, Threat Atlas enrichment, and tamper-evident evidence for enterprise, OT, IoT, and IIoT estates.
How is CyberDragon different from CrowdStrike?
Endpoint-first platforms excel where agents can run. CyberDragon is OT-native: passive SPAN capture of Modbus, DNP3, OPC-UA, and MQTT at the industrial DMZ, Enterprise→OT kill-chain correlation, Purdue L0–L5 / Industry 4.0 zone policy, and OT safety guardrails — without agents on PLCs. Many buyers run both: endpoint stack for corporate enterprise, CyberDragon for the corridor to the plant floor.
How is CyberDragon different from Tanium?
Inventory and patch platforms answer what is installed. CyberDragon answers what is happening on the industrial wire and how it ties to the enterprise kill chain — with indigenous SIEM/SOAR, evidence-grade audit, and hybrid post-quantum identity.
Do I need to replace my existing SIEM?
No. CyberDragon includes its own SIEM/SOAR plane and also augments your stack via syslog, Splunk HEC, STIX/TAXII, and webhooks — so you can start with OT depth and keep existing investments.
Can CyberDragon work in air-gapped OT?
Yes. Edge runs on-prem with offline SQLite buffering (~5,000 events). Core can deploy fully on-premises (Mode B), including Helm air-gap paths.
Is post-quantum cryptography real or roadmap?
Live today. Every session JWT is hybrid-signed with ML-DSA-65 + Ed25519 — crypto agility in production, not a 2030 slide.
Will CyberDragon automate changes on my PLCs?
No. Telemetry flows up only. OT-affecting actions require human approval AND independent OPA policy. The Safety Gate can deny actions even after analyst approval. We automate up to the plant floor — not against it.
What OT protocols are supported?
Modbus TCP/RTU, DNP3, OPC-UA, and MQTT at the Edge, deployed at IEC 62443 Level 3 / industrial DMZ.
What compliance frameworks are supported?
IEC 62443-3-3, NERC CIP, NIST CSF 2.0, ISO 27001:2022, and SOC 2 — with auto-mapping from live events into the evidence vault.
How long does deployment take?
Typical go-live in 7 weeks: provision (1–2), Edge install (3–4), UAT (5–6), hypercare (7+). A 7-day free trial can start the same day.
Is there a free trial?
Yes. Start a 7-day free trial with no credit card. We also offer a 1-hour guided demo, 5-day sandbox, and 30-day Proof of Value with an Edge kit.
Who is CyberDragon for?
CISOs, SOC teams, OT security engineers, Industry 4.0 plant operators, MSSPs, and auditors in energy, manufacturing, banking, healthcare, and critical infrastructure worldwide.
What is Threat Atlas?
Threat Atlas is CyberDragon’s live IoT/ICS threat, malware, and advisory board — aggregating public sources so operators can contextualize plant-floor risk alongside the indigenous SIEM/SOAR plane.

Start your 7-day free trial.

A dedicated CyberDragon tenant on your own traffic — not a slide deck. See kill-chain cyber defense on your network.