Security we built, security we run.

Certificates for sale. Network and server protection as standard equipment — both running on tooling we wrote ourselves, both open source on GitHub.

SSL · TLS · code signing NetFlow + BGP blackhole WAF · BPF LSM · kernsec Open source · Go Included with every server
INCLUDED · NOT SOLD

What’s protecting your server, behind the scenes.

Δύο εργαλεία που γράψαμε εμείς, τρέχουν στη δική μας υποδομή, και κυκλοφορούν open source. Όχι products. Όχι upsells. Απλώς ό,τι ήδη προστατεύει το box όπου ζει το site σας.

BUILT IN-HOUSE

Argus

Network-layer protection

Real-time NetFlow / IPFIX enrichment + DDoS detection + automatic BGP blackholing. Runs on our edge, watches every flow that touches our AS, mitigates attacks at the routing layer before they reach individual servers.

  • NetFlow v9 / IPFIX collection
  • GeoIP + ASN + BGP path enrichment
  • Rule + ML-driven detection
  • Automatic eBGP blackhole announcement
BUILT IN-HOUSE

CFM

Server-layer protection

Five-layer defence: HTTP challenge engine, in-path WAF, log detectors, BPF LSM userspace enforcement, KSPP-grade kernel hardening. Installed on every server we operate — the reason brute-force, web shells, and post-exploit pivots have a short half-life on our infrastructure.

  • 66-rule WAF (SQLi · XSS · RCE · Log4Shell)
  • SSH / mail / FTP / MySQL detectors
  • BPF LSM behavioural enforcement
  • KSPP kernel-surface hardening
OUR STANCE

Four ideas behind the stack.

Τι κάνει την προσέγγισή μας στην ασφάλεια διαφορετική από τον ανταγωνισμό;

We write the tools we run

Argus and CFM are our own code, running on our own network, hardened by our own incident response. We dogfood every release in production before it touches a customer’s server.

Open source, by intent

Security tooling you can’t read isn’t security tooling. Both projects are public on GitHub. Audit the code. Fork it. Run it on a server we have nothing to do with. We’d rather be trusted than mysterious.

Defence-in-depth, by design

No single layer catches everything. Certificates pin identity. Argus catches network-layer abuse. CFM catches request-layer abuse. The stack works because each layer fails differently.

Always on, never sold

Argus and CFM aren’t paid add-ons — they run on every server we operate, included with whatever hosting plan you bought. The certificate page is the one with a price list.

Need a security review of your existing stack?

Send us your topology. We’ll spend an hour with you — what’s exposed, what’s tunable, what’s missing. No commitment, just an engineer’s eye.