Fenrir brings the AI of a Security Operations Center to your clients' servers, WordPress sites and endpoints. One multi-tenant console. The AI monitors, detects and responds 24/7 in graduated autonomy — you supervise and put your brand on it.
// 1 SOC, N sensors
Fenrir is an AI-driven Security Operations Center. One brain that analyzes, classifies and responds — fed by lightweight sensors on every surface of your clients.
Linux/macOS agent: SSH, nginx, auth, firewall, syslog monitored every second.
See the tiers →Plugin that brings clients' sites into the same SOC, with AI investigation.
Discover Fenrir for WordPress →// For MSPs
Tools built for those who deliver security as a service: unified console, white-label, AI Tier-1 24/7.
All clients in one console. Add a client in 15 minutes.
White-label: you deliver the SOC, under your name.
The AI handles Tier-1 24/7 — detection, triage, low-risk response. You step in only where needed.
Resell on subscription. Transparent tiers, no surprises.
Sovereign on-premise. NIS2, GDPR and ISO 27001 verified daily.
// How it works
Five stages, fully automated. Zero manual intervention.
6 real-time sources: SSH, web, auth, firewall, syslog, services
Advanced pattern matching identifies anomalies and known threats
AI evaluates the threat level with a confidence score
Automatic IP blocking, firewall updates, process quarantine
NIS2/GDPR/ISO 27001 reports ready to hand to your clients, under your brand.
// Automated compliance
The key differentiator: compliance not as a checklist, but as a continuous process integrated into operational security.
// Features
Nine integrated modules. One intelligent agent.
SSH, Nginx, auth, firewall, syslog and services monitored every second.
Artificial intelligence model that analyses and classifies every threat with a confidence score.
Graduated autonomy: automatic block, approval-based or log-only depending on confidence.
Over 20 commands to manage security directly from your phone. Wherever you are.
Automatic report every morning with detected threats, actions taken and compliance status.
Automatic infrastructure scanning with prioritised hardening recommendations.
Complete workflow for 72-hour notification: detection, impact analysis, communication.
Compliance documents ready for DPO and Board of Directors. Fully brandable.
Five revertible actions (kill process, file quarantine, stop service, network isolation, package rollback) gated by analyst confidence and one-click revertible from Telegram. Disabled by default, mandatory dry-run in first week.
// Protection in action
Real scenario: an SSH brute-force attack. You sleep. Fenrir doesn't.
458 login attempts from IP 203.0.113.42 in 30 seconds.
The SSH monitor identifies the attack pattern and generates an event.
Confidence score: 94%. Category: brute-force. Risk: critical.
Firewall rule added. The attacker can no longer reach the server.
Full notification with threat details, action taken and link to report.
You sleep. The server is protected.
Total response time: < 1 second// Automation levels
Fenrir acts autonomously only when confident. Otherwise, it asks for confirmation.
Immediate block without human intervention. The action is executed and notified.
Telegram alert with confirmation request. One tap to approve or dismiss.
The event is logged and included in the daily digest. No automatic action.
// Why Fenrir
It's an intelligent security agent, designed for European companies.
GDPR and ISO 27001 are not an add-on. They are integrated into the core of the system. Every action generates documentation.
Reports, alerts and interface designed for European regulatory requirements. GDPR-native from the ground up.
Professional documents ready for audits, regulatory inspections and Board of Directors presentations.
Manage all security from your phone. Approve actions, check reports, receive alerts. Wherever you are.
The AI model adapts to your server's normal behaviour, reducing false positives over time.
Installed on your servers. Your data stays yours. No external cloud. Full control over your infrastructure.
// Supported platforms
Compatible with all major enterprise Linux distributions and macOS Server. One agent, any infrastructure.
// Your Guardian
Fenrir protects your infrastructure 24/7 like an alpha wolf protects its pack.
// Pricing
All tiers include GDPR / NIS2 / ISO 27001 readiness, live dashboard, Telegram alerts, sovereign on-premise. The AI model and support tier are what change.
For the SMB that wants to be NIS2-ready without breaking the budget.
Stronger reasoning via frontier AI — fewer false positives, sharper investigations.
For organisations under NIS2 management liability (Art. 20) where a false negative is unacceptable.
One-time setup fee:: €1,500 Standard · €3,000 Premium · €5,000 Sovereign+ — covers install, baseline and playbook tuning.
AI API costs are billed to the customer. Typical range: €1–10/mo for Standard, €10–50 for Premium, €50–300 for Sovereign+ depending on HIGH/CRITICAL alert volume.
Yes. Fenrir automatically generates evidence for NIS2 obligations: immutable logs, incident management, a privileged-access register and asset classification. The reports are ready to be submitted to ACN within the 24- and 72-hour deadlines set by the directive.
Yes. Fenrir is a sovereign agent: it runs on-premise on your Ubuntu, Red Hat, SUSE, Debian or macOS servers. No data leaves your infrastructure, in line with GDPR and the national ACN cloud strategy. The AI analysis can also run entirely locally, on-premise.
Fenrir covers the Tier-1 level: detection, automated investigation and low-risk response. For complex scenarios (serious incidents, forensics, custom threat hunting) a human MSSP remains complementary. For most SMBs Fenrir is sufficient on its own.
Wazuh is powerful but requires significant SIEM expertise to make it truly useful. CrowdStrike and SentinelOne also cover servers, but they are enterprise EDR platforms: pricing and complexity out of scale for an SMB, telemetry on their cloud (not sovereign) and no application coverage such as WordPress. Fenrir is designed from day one for SMBs, agencies and system integrators: sensible defaults, deployment in 15 minutes, servers and WordPress sites in the same console, automatic NIS2 compliance, sovereign on-premise.
For essential entities up to 10 million euro or 2% of global turnover; for important entities up to 7 million or 1.4%. The directive (Legislative Decree 138/2024) also establishes personal liability for management bodies (Art. 20). For an average Italian SMB, a breach can translate into a 70-100k€ penalty.
Yes, especially if it is exposed to the Internet. Traditional antivirus is not enough: you need behavioral detection (brute force, baseline drift, known vulnerabilities) and centralized logs for GDPR compliance. Fenrir covers all of this natively, integrating with fail2ban, nginx, systemd and standard system logs.