Kyberen
AI proposes. You keep the helm.
Detection, response and AI triage in one platform built for small security teams. The AI sorts and explains; a human confirms, corrects, and stays in charge of every critical decision.
See it in action
From raw logs to a qualified ticket, AI triage under human control, and access control with four-eyes approval.
Recorded on the pre-release build (working name: Mini SOAR). Showcase segments use synthetic data only.
What it does
One product, three layers.
Detect & respond
Logs from Linux, Windows, network and mail are normalised into one format and turned into prioritised tickets.
- auditd, EVTX, syslog, PCAP, Snort, CSV, Elastic
- Sigma-style detection, MITRE ATT&CK mapping
- Process trees and automated response playbooks
Supervised AI triage
The AI proposes a verdict with its confidence. The analyst confirms or corrects, and that decision is what the model learns from.
- Autonomy ceiling set by an admin
- Never closes a critical ticket on its own
- One-click kill switch
Secure by construction
A security tool must hold up to the attacks it watches for.
- Roles, MFA (authenticator app or hardware key)
- Four-eyes approval on sensitive actions
- Encryption at rest, full audit log
Why "Kyberen"
Two meanings, one stance.
Kybernētēs
Greek for the helmsman, the root of "cybernetics". The AI can row; a human holds the tiller.
Kyber
The original name of ML-KEM, the post-quantum key-exchange standard. Where the product is heading.
Roadmap
Planned work. Nothing below is shipped yet.
AI agent activity monitoring
Ingest agent traces (OpenTelemetry GenAI, JSONL logs), detections mapped to OWASP LLM Top 10 and MITRE ATLAS, export to a larger SOC in OCSF.
Post-quantum readiness
Crypto-agility in the product, hybrid ML-KEM TLS once the stack supports it, crypto discovery from network captures exported as a CycloneDX CBOM.
Incident grouping
One attack, one incident: tickets linked by host, time window and process lineage.
Compliance evidence
The reports an auditor asks for, mapped to NIS2 and ISO/IEC 27001 logging and incident controls.
Where we are
Early stage, working product. Kyberen runs end to end today. We are now talking with SMBs and managed security providers, and looking for a first handful of pilot users.