Built for regulated sectors, wherever they operate
Ten sector deep dives — utilities and critical infrastructure, healthcare, finance, public administration, defense, manufacturing and enterprise, plus three written for the United States: the defense industrial base under CMMC, financial services under NYDFS Part 500 and GLBA, and healthcare under HIPAA — for organizations in the EU, the United States, the United Kingdom, the Middle East, Asia-Pacific and beyond. Each maps the autonomous AI red team to the regulation, attack profile and procurement reality of that sector, and explains why it has to run on-premise, on private AI.
- Energy · Water · Telco
Utilities & critical infrastructure — NIS2, NIST, UK CAF
Continuous offensive validation, traffic-side intrusion detection and regulator-ready evidence for energy, water and telecom operators — mapped to NIS2, the UK CAF, NIST CSF and the Gulf national frameworks, on one on-premise appliance.
- Hospitals · Insurers · Pharma
Healthcare — ransomware target #1
Catch ransomware mid-encryption, validate exploitation paths before the next campaign, and keep breach-notification clocks — GDPR Art. 33, HIPAA — manageable.
- Health systems · Health plans · Health tech
US healthcare — HIPAA Security Rule, PHI kept on-premise
For hospitals, health systems, health plans and health-tech business associates: continuous, technical evidence for the risk analysis the HIPAA Security Rule already requires, a testing cadence ready for the one HHS has proposed, and PHI and exploit evidence that never leave the hospital network.
- Banks · Insurers · Payment
Finance — DORA, CBEST, NYDFS, MAS TRM
Continuous testing and threat-led validation for DORA and TIBER-EU, CBEST, NYDFS Part 500, MAS TRM and APRA CPS 234 — with ICT-incident evidence mapped in the same appliance.
- Banks · Insurers · Lenders · Fintech
US financial services — NYDFS Part 500, GLBA, SEC
Penetration testing from inside and outside the boundary, risk-based scanning and signed evidence for NYDFS Part 500, the FTC Safeguards Rule and SEC disclosure, run continuously on an on-premise appliance so nonpublic information never reaches a vendor cloud.
- Government · Local · Agencies
Government & public administration — sovereign by design
For governments and public administrations: sovereign, on-premise and evidence-backed — built first for the Italian PA (decree 138/2024, national cyber perimeter) and mapped to NIST 800-53, the UK CAF and the Gulf national frameworks.
- Classified · Air-gap · NSPI
Defense supply chain — air-gap ready, CMMC-mapped
For defense prime contractors, classified-data handlers and any organization where vendor-cloud touchpoints are disqualifying — from CMMC suppliers in the US to cleared contractors in Europe and the Gulf.
- DoD primes · Subcontractors · CUI
US defense industrial base — CMMC 2.0 and DFARS 7012
For DoD prime contractors and subcontractors that handle CUI: continuous testing of the NIST SP 800-171 requirements a C3PAO will assess, with pentest data and evidence kept inside your enclave on an on-premise appliance running private AI.
- Automotive · Machinery · Food · Chemicals
Manufacturing & industrial — supply-chain target
For manufacturers and industrial operators — automotive, machinery, food, chemicals, electronics — in the NIS2 perimeter, the US defense supply chain, or anywhere a ransomware-stopped line costs more than years of security tooling.
- Retail · Logistics · Pharma R&D · Professional Services
Enterprise & corporate — mid-large general business
For mid-to-large general enterprises outside the heavily-regulated verticals — retail, logistics, pharma R&D, professional services — that no longer fit the "too small to be targeted" excuse and want continuous validation without paying for a CISO seat at the table that does not yet exist.
Compliance, worldwide
34 frameworks across 8 regions, mapped automatically
Every finding, piece of evidence and remediation is mapped to the frameworks your auditors, regulators and customers use — in the EU, the United States, the United Kingdom, Canada, Asia-Pacific, the Middle East, Latin America and Africa. The appliance runs on-premise wherever you operate; the evidence never leaves your jurisdiction.
- Global / cross-industry
- ISO/IEC 27001:2022
- SOC 2
- NIST Cybersecurity Framework
- CIS Critical Security Controls v8
- PCI DSS
- SWIFT Customer Security Programme
- OWASP ASVS
- CSA STAR
- European Union
- NIS2 Directive
- DORA
- TIBER-EU
- United States
- NIST SP 800-53
- CMMC
- HIPAA Security Rule
- NYDFS Part 500
- GLBA / FTC Safeguards Rule
- SOX IT controls
- SEC cybersecurity disclosure rules
- CCPA / CPRA cybersecurity audit
- United Kingdom
- CBEST / STAR-FS
- NCSC Cyber Assessment Framework
- Canada
- OSFI Guideline B-13
- Asia-Pacific
- APRA CPS 234
- MAS Technology Risk Management
- Singapore Cybersecurity Act / PDPA
- RBI Cybersecurity Framework
- FISC Security Guidelines
- Korea ISMS-P
- Middle East
- Saudi NCA ECC / SAMA CSF
- UAE Information Assurance (NESA)
- Qatar NCSA framework
- Bank of Israel Directive 361
- Latin America
- Brazil LGPD
- Africa
- South Africa POPIA