Skip to content
CyberendX

ENTERPRISE · AGENTIC AI PLATFORM

From endpoint to SOC, one platform.

One agent, fifteen technologies, six operating systems. Detection on the device, triage in Matrix, cases and compliance in Praxes, every AI call through Nexus. Designed for tens of thousands of endpoints and hundreds of groups.

  • SaaS · behind Cloudflare
  • A domain per tenant
  • Google SSO
example-corp.cyberendx.com · Incidents
  • Scenario Phishing
  • Triage Titus
  • Status Closed

Case timeline · sample scenario

  1. Phishing attachment opened CyberendX · EDR
  2. Script interpreter process blocked CyberendX · AV
  3. Titus: mapped T1566 · T1059, playbook executed Matrix
  4. Case opened, risk register updated Praxes
  5. Closed · no human intervention needed

CyberendX module · 15 technologies

One agent does the work of fifteen products.

Each technology is licensed separately and switched on in the same agent. Policies roll out to tens of thousands of machines by group; every list is paginated server-side.

  • Antivirus Signatures + ML, pre-scan, quarantine
  • EDR Process lineage, LOLBins, ransomware
  • NDR Beacon detection, flow fusion, SNI
  • URL/DNS Security Categories, IoCs, cloud verdicts
  • DLP Endpoint + web; copy, upload, print
  • Data Classification Labels, discovery, tied to DLP
  • AI Prompt Security Leak and injection gate in the browser
  • ZTNA Broker, device posture, fail-closed
  • Host Firewall Per-application rules, group policy
  • Remote Desktop Secure sessions from the console, audit trail
  • Device Management Inventory, CVEs, USB and peripherals
  • Application Management Allow / block lists, version tracking
  • PAM Privileged access, just-in-time elevation
  • LLM Security Scanning Model and prompt security testing
  • Log Stream Management Structured streams to Matrix and your SIEM

Platform · 5 modules

Every module has its own agent; all of them share one governance.

Matrix

SOC · SIEM · SOAR

Titus, the autonomous triage agent, reduces signals to cases, maps them to MITRE ATT&CK and runs playbooks. Analysts see only the exceptions.

Explore Matrix

Praxes

GRC · Cases · War room

Security assessment, compliance and risk register, case management and war room. The path from incident to audit evidence builds itself.

Explore Praxes

Xplore

Assets · Observability

Asset intelligence and full-stack observability: OpenTelemetry, logs, metrics, traces, profiles, Kubernetes monitoring, synthetic tests and cloud cost.

Explore Xplore

Nexus

AI gateway · Licensing

Every module’s LLM calls pass through here: routing, guardrails, cost ledger and licence authority. You know from one place which model saw what.

Explore Nexus

The fifth module is CyberendX: the endpoint agent that carries the fifteen technologies above. CyberendX module All modules

Architecture

Data flow

Endpoint CyberendX agent Windows · macOS · Linux · iOS · iPadOS · Android
Triage Matrix SIEM · MITRE · SOAR
GRC Praxes Cases · Risk · Compliance
AI gateway Nexus Every LLM call from the three modules; guardrails, ledger, licensing Xplore: asset and telemetry layer

Scale, isolation and evidence trail

Scale

Designed for tens of thousands of machines and hundreds of groups.

Every list is paginated, searched and sorted server-side; the console never pulls every record to the client.

Isolation

A domain and data per tenant.

Each organisation runs at its own address; enterprise and personal infrastructure are physically separate.

Evidence trail

Every decision is written to the audit trail.

Policy, exception, licence and agent actions are written to the audit log, ready for the auditor.

Licensing

Per module, per endpoint. Only what you use.

Enterprise packages are not sold online or in app stores. Contact us for a quote and to purchase; we will scope the licence with you.

Endpoint

CyberendX module

Pick technologies, pay by device count. Pricing is quoted on the technologies you choose and the number of endpoints.

Get a quote

Full stack

All five modules, Xplore included

The whole platform including observability; a dedicated tenant for your organisation. Pricing by conversation.

Talk to sales

Frequently asked questions

Does it run alongside our existing antivirus?

Yes. During migration you can enable only EDR and NDR and hand over antivirus later. The agent does not load an engine until that technology is enabled in the licence.

What does the endpoint do if the internet goes down?

Decisions are made on the device. If the cloud verdict endpoint is unreachable the agent allows and records; policy enforcement and local signatures keep working.

How is the agent deployed?

The enterprise agent is deployed from the console and via MDM; there is no public download page. Installer packages are served from your console.

Can we use our own model for AI calls?

Yes. Nexus routes to your provider key or your self-hosted model; guardrails and the ledger stay the same.

A live demo in your own environment.

Follow a sample attack from detection to the case record; put your questions to our engineers.