Skip to content
defneo

LIVE

All-in-one security platform · on-premise

Company security, from one place.

Defneo puts prevention, monitoring, incident response and compliance (NIS2, DORA, GDPR, ISO 27001) into a single installation your IT team controls. No ten consoles, no external cloud.

  • Installed in hours, Docker Compose
  • Data stays in your infrastructure
  • Compliance evidence from real system state
defneo.local / cto-center
The Defneo interface — CTO Center, showing posture score and compliance state
modules in a single installation
50+
pillars: prevention, monitoring, response, compliance, evolution
5
compliance frameworks: NIS2, DORA, GDPR, ISO 27001, AI Act, CIS
6
controls proven automatically from infrastructure
13

Five pillars, one platform

Everything an IT manager does for security, end to end

Every Defneo module belongs to one of five pillars. They share the same inventory, agents and log, so every alert, CVE or compliance control has context.

01 · Prevention

19 modules

Block it before it happens

Perimeter, identity and attack surface managed from one place. What is exposed is visible, what is known is blocked.

  • Traefik reverse proxy
  • Automatic TLS
  • CrowdSec IDS/IPS
  • Virtual WAF
  • Rate limiting
  • Anti-scraper (bot protection)
  • Blocklists (IP, ASN, country)
  • IOC
  • Geo-blocking
  • Exposure Mgmt (CTEM)
  • Security scanner
  • Network scanner
  • Automated pentest
  • CVE on real software
  • HIBP
  • Email Auth (SPF/DKIM/DMARC)
  • Typosquat
  • Phishing Sim
  • OSINT

02 · Monitoring

18 modules

See everything on one screen

Servers, network, traffic, assets and software, with own agents and standard metrics. You get a morning briefing, not ten charts.

  • Overview
  • CTO Center
  • Daily briefing
  • Prometheus / Grafana
  • Server agents
  • Agents inventory
  • FIM (file integrity)
  • Network and assets
  • Geolocation (traffic & attacks)
  • Analytics
  • A/B Monitor
  • Error & A/B testing
  • Error pages vs. sitemap
  • Backends
  • Traffic reports
  • Domains (CT)
  • SEO audit
  • GitHub & Azure AD audit

03 · Response

11 modules

When it happens, you have a flow, not panic

Detection, triage, remediation and legal reporting in one place. Clocks start by themselves, forms are written from data.

  • CrowdSec decisions
  • AI Summary (incident digest)
  • Remedy Summary (remediation plan)
  • Remediation tasks
  • Risk scoring
  • Incident register
  • 24h / 72h / 30d clocks
  • Pre-filled DNSC forms
  • MITRE ATT&CK
  • Kali tools
  • SIEM export

04 · Compliance

13 modules

Proven from system state

A multi-framework compliance center that reads what the other modules do. A control mapped once is reused across all frameworks.

  • NIS2 Action Plan
  • DORA
  • GDPR
  • ISO 27001
  • CIS Benchmarks
  • AI Act / AI governance
  • ANAF scoping
  • DNSC route with clocks
  • Audit-ready PDF report
  • Legislation kept current
  • CREM (requirements & controls register)
  • Supplier inventory (supply chain)
  • HR & Inventory portal

05 · Evolution

7 modules

Keep pace with the cyber market and the law

Threats, standards and legislation change monthly. The platform updates; AI policies and benchmarks ship with it.

  • Updated CVE & IOC feed
  • AI Policies
  • In-product legislation (CRA, amendments)
  • Config versions
  • Proxy Nodes
  • Integration management
  • Updates included

All-in-one

One product, one vendor, one invoice

Over 50 modules replacing a stack of separate tools: reverse proxy, IDS/IPS, WAF, scanner, monitoring, inventory, phishing sim, GRC. All talking to each other.

For the IT manager

An ordinary day with Defneo

You have no time for ten dashboards. Defneo tells you in the morning what happened, what is urgent and what needs proving.

  1. The morning briefing

    What happened overnight: blocked IPs, new CVEs on your software, agents that failed to report, expiring deadlines.

    Briefing · CTO Center

  2. A critical CVE, but only where it matters

    Correlated with software installed on each host. Three servers affected, remediation task created, owner assigned.

    CVE · Exposure Management · Agents

  3. A colleague reports a suspicious email

    The domain is a typosquat of the company. You add it to the blocklist and check who clicked in the last phishing simulation.

    Typosquat · Blocklist · Phishing Sim

  4. The auditor asks for backup and MFA evidence

    You already have it: controls are ticked automatically from system state, source shown. Export the PDF report.

    Compliance center · PDF report

  5. A new server goes to production

    The agent inventories it, the CIS benchmark runs, TLS is issued automatically, CrowdSec covers it. No tickets.

    Agents · CIS · Traefik · CrowdSec

Defneo — infrastructure overview dashboard
Defneo — DORA compliance center

Incident response

From first signal to final report, without re-reading the law

Detection, triage and reporting are one flow. Legal clocks start at detection time; forms are filled from incident data.

  1. Detect

    crowdsec: ban 185.220.x.x · http-probing · 14:02:11

    CrowdSec detects and blocks automatically, with visible decisions and blocklists managed from the UI. Server agents flag file changes and abnormal network behaviour.

  2. Triage

    CVE-2026-1183 · openssh 9.6 · 3 hosts · CVSS 9.1

    CVEs are correlated with software actually installed on each host, not a generic list. Risk scoring, remediation task, owner.

  3. Respond

    incident #42 · 24h left 19:42:07 · 72h left 67:42:07

    A significant incident starts the DNSC clocks (24h / 72h / 30 days) and generates the three pre-filled forms, ready for PNRISC.

  4. Prove

    report.pdf · 59 controls · 13 auto · generated 18:11

    The compliance report is generated from live data: every control with status and evidence source. The document you meet the audit or inspection with.

Compliance

Compliance is the outcome of security, not a separate questionnaire

The compliance center reads system state and ticks what it can prove. A control mapped once is reused across all frameworks.

  • NIS2
  • DORA
  • GDPR
  • ISO/IEC 27001
  • AI Act
  • CIS Benchmarks
  • NIST CSF 2.0
  • auto:tls_activeTLS active
  • auto:backup_okRecent backup
  • auto:ids_ipsIDS/IPS (CrowdSec)
  • auto:mfaMFA / passkeys
  • auto:vuln_scanVulnerability scans
  • auto:fimFile integrity

Remaining controls are documented with owner, deadline and evidence; overdue items are visible. Every control links straight to the module that manages it.

Free check

Does NIS2 apply to you?

Same logic as the product: sector mapped to the annexes of GEO 155/2024, subject to size thresholds. You also get the result by email.

Main sector
Company size

We use your data only to send the result and contact you about Defneo. Never shared with third parties.

News and threats

What is happening in the cyber landscape right now

Threat radar: critical CVEs, active campaigns in Romania and the EU, DNSC alerts. Each entry also tells you where to see it in Defneo.

Updated 05 Sept 2026

  • Critical

    OpenSSH 9.6: pre-authentication code execution

    Affects Linux servers exposed on port 22. Patch available. Active exploitation reported by CERT-EU.

    In Defneo: CVE · Agents · Exposure Mgmt

  • High

    “e-Factura” phishing with ANAF typosquat domains

    Emails with HTML attachments stealing Microsoft 365 credentials. Domains are registered 48h before the campaign.

    In Defneo: Typosquat · Email Auth · Phishing Sim

  • High

    Qilin ransomware: initial access via VPN without MFA

    Repeated pattern: leaked credentials (HIBP), VPN without MFA, lateral movement in 6 hours. Online backups are encrypted first.

    In Defneo: HIBP · MFA · Backup · FIM

  • Info

    NIST publishes final post-quantum migration guide

    Recommends a cryptographic inventory, prioritising long-lived data and hybrid TLS (X25519 + ML-KEM).

    In Defneo: Quantum-ready · Traefik TLS

The feed updates from CVE / IOC sources and DNSC and CERT-EU alerts. Subscribe to the monthly briefing for the digest.

Post-quantum readiness

The transition to post-quantum cryptography starts with an inventory

Data encrypted today can be decrypted tomorrow (“harvest now, decrypt later”). NIST standardised PQC algorithms in 2024 and the EU roadmap asks critical infrastructures to start the transition by 2030. Defneo shows where you stand and what changes first.

  1. Inventory your cryptography

    Certificates, TLS suites, SSH keys, VPN, code signing. Which algorithm, which length, where used.

  2. Prioritise by data lifetime

    What must stay secret for 10+ years (medical records, IP, contracts) migrates first.

  3. Enable hybrid TLS at the edge

    Traefik with X25519 + ML-KEM: compatible with current clients, quantum-resistant key exchange.

  4. Ask suppliers for a PQC plan

    Contract clauses and evidence of crypto-agility, tracked across the supply chain.

  • ML-KEM (FIPS 203)
  • ML-DSA (FIPS 204)
  • SLH-DSA (FIPS 205)
  • X25519 + ML-KEM hybrid
  • RSA-2048 → deprecated 2030

Cryptographic inventory

What Defneo sees in your infrastructure

Agents and the scanner inventory certificates, TLS suites, SSH keys and algorithms in use, then flag them by quantum resistance.

  • TLS 1.3 · X25519 + ML-KEMPQC-ready
  • RSA-2048 certificates (14)to migrate
  • RSA-1024 SSH keys (3)critical
  • VPN IKEv2 · DH group 14to migrate
  • Code signing · ECDSA P-256planned
PQC readiness score (sample)38 / 100
Request a PQC assessment

Blog · best practices

Practical guides for the IT team

Technical articles, no marketing: how to configure, how to prove, how to prepare. Written by the team building Defneo.

All articles

Why all-in-one

A stack of separate tools vs. Defneo

  • Perimeter

    Separate stack

    proxy + IDS + WAF, three vendors

    Defneo

    Traefik + CrowdSec + WAF, one configuration

  • Vulnerabilities

    Separate stack

    separate scanner, generic CVE lists

    Defneo

    CVE correlated with actually installed software

  • Monitoring

    Separate stack

    Grafana somewhere, alerts by email

    Defneo

    daily briefing, agents, one screen

  • Compliance

    Separate stack

    consultant + Excel, once a year

    Defneo

    continuous, proven from system state

  • Incidents

    Separate stack

    panic + empty template

    Defneo

    automatic clocks + pre-filled forms

  • Cost

    Separate stack

    N licences, N contracts, N consoles

    Defneo

    one licence; the product stays and works

Honest positioning: Defneo does not replace your IT team and does not “make you compliant” by magic. Policies and decisions remain the organization’s. What it does: one picture, blocks what can be blocked, proves what can be proven, tracks every deadline.

Pricing

Annual licence, on-premise installation included

No per-user or per-deliverable cost. All modules of the chosen tier, updates included.

  • Start

    Essential security

    Up to 10 servers

    €4,900/ year

    • Prevention: Traefik, TLS, CrowdSec, WAF, blocklist
    • Monitoring: agents, FIM, briefing, CTO Center
    • Response: incident register, clocks, tasks
    • NIS2 compliance: scoping, DNSC route, PDF report
    Request a quote
  • Business

    Full platform

    Up to 50 servers

    €12,900/ year

    • Everything in Start
    • CTEM: inventory, CVE on real software, scoring
    • Identity: Phishing Sim, HIBP, Typosquat, OSINT
    • Multi-framework: DORA, GDPR, ISO 27001, CIS
    • SIEM export, GitHub & Azure AD audit
    Book a demo
  • Enterprise

    Group / multi-entity

    Over 50 servers or several entities

    Quote

    • Everything in Business
    • Multiple instances, proxy nodes
    • AI Act / AI governance
    • Dedicated integrations, SLA
    • NIS2 officer and management training
    Request a quote

Indicative prices, excl. VAT. Final quote depends on server count and compliance frameworks enabled.

PDF · Checklist

The NIS2 Art. 21 security checklist

All 59 controls across 12 domains, with ISO 27001 / NIST CSF mapping and what can be proven automatically. PDF, by email.

Monthly briefing

What changed in cyber and in law, once a month

Critical CVEs, active campaigns in Romania, DNSC orders, new deadlines. One email a month, no marketing.

Next step

A 30-minute demo, on your test infrastructure

No slides. We install, connect the first agents and show you what Defneo sees in your network.

  1. Day 1Installation, first agents connected, perimeter covered by Traefik + CrowdSec.
  2. Week 1Full inventory, correlated CVEs, daily briefing running, compliance checklist populated.
  3. Month 1Gaps closed or planned, compliance report up to date, the team works from one screen.
Pick a slot in the calendar

Or leave your details and we call you within 24h

Infrastructure

We use your data only to send the result and contact you about Defneo. Never shared with third parties.