Security operations for SMBs

Kyberen

AI proposes. You keep the helm.

Detection, response and AI triage in one platform built for small security teams. The AI sorts and explains; a human confirms, corrects, and stays in charge of every critical decision.

See it in action

From raw logs to a qualified ticket, AI triage under human control, and access control with four-eyes approval.

Recorded on the pre-release build (working name: Mini SOAR). Showcase segments use synthetic data only.

What it does

One product, three layers.

01

Detect & respond

Logs from Linux, Windows, network and mail are normalised into one format and turned into prioritised tickets.

  • auditd, EVTX, syslog, PCAP, Snort, CSV, Elastic
  • Sigma-style detection, MITRE ATT&CK mapping
  • Process trees and automated response playbooks
02

Supervised AI triage

The AI proposes a verdict with its confidence. The analyst confirms or corrects, and that decision is what the model learns from.

  • Autonomy ceiling set by an admin
  • Never closes a critical ticket on its own
  • One-click kill switch
03

Secure by construction

A security tool must hold up to the attacks it watches for.

  • Roles, MFA (authenticator app or hardware key)
  • Four-eyes approval on sensitive actions
  • Encryption at rest, full audit log

Why "Kyberen"

Two meanings, one stance.

Kybernētēs

Greek for the helmsman, the root of "cybernetics". The AI can row; a human holds the tiller.

Kyber

The original name of ML-KEM, the post-quantum key-exchange standard. Where the product is heading.

Roadmap

Planned work. Nothing below is shipped yet.

NEXT

AI agent activity monitoring

Ingest agent traces (OpenTelemetry GenAI, JSONL logs), detections mapped to OWASP LLM Top 10 and MITRE ATLAS, export to a larger SOC in OCSF.

PLANNED

Post-quantum readiness

Crypto-agility in the product, hybrid ML-KEM TLS once the stack supports it, crypto discovery from network captures exported as a CycloneDX CBOM.

PLANNED

Incident grouping

One attack, one incident: tickets linked by host, time window and process lineage.

PLANNED

Compliance evidence

The reports an auditor asks for, mapped to NIS2 and ISO/IEC 27001 logging and incident controls.

Where we are

Early stage, working product. Kyberen runs end to end today. We are now talking with SMBs and managed security providers, and looking for a first handful of pilot users.

Talk to us

Pilot, partnership or a question: one email is enough.

contact@kyberen.com