Fenrir SOCFenrir MDRGARM · gratisFenrir WP BridgeFenrir WP Central How it works Pricing Compliance Blog
ON-PREMISE · SOVEREIGN · 24/7
Fenrir

You sleep. Fenrir doesn’t.

An AI-driven SOC that detects and responds to attacks on its own, on your servers. On-premise, sovereign, in plain language, at a public price. Set up in 48 hours.

fenrir-soc · srv-prod-01 live
SSH
1,204
events / 24h
Web · Nginx
38,902
requests / 24h
Auth
312
logins / 24h
Firewall
47
blocks / 24h
Syslog
OK
no anomalies
Services
9/9
active
Recent events 1 CRITICAL
02:01 SSH brute-force blocked
203.0.113.42 · conf 94%
BLOCKED
01:46 Port-scan · approval
198.51.100.9 · conf 72%
APPROVE
00:12 Admin login · MFA ok
10.0.4.21
OK
yesterday Nginx anomaly · log only
203.0.113.7 · conf 41%
LOG
01 · The family

One AI brain, all your sensors.

Five products, one SOC. The wolf covers your servers; GARM, the hound, stands at the WordPress gate. Same AI, same console, same calm.

02 · How it works

From threat to protection, in milliseconds.

Five steps, always the same. Show, don’t tell: the product working, not a description of it.

01 Observe 9 monitors read access, traffic and processes in real time. always
02 Detect Patterns, signatures and anomalies: the suspect event emerges from the noise. < 15 min
03 Classify The AI assigns a confidence score and maps to MITRE ATT&CK. ~1 s
04 Respond Above 90% it blocks or isolates on its own. Below, it asks or logs. < 1 s
05 Notify A calm notification: what happened, and the action already taken. instantly
03 · Live monitoring

9 monitors, in real time.

Fenrir watches access, traffic, processes, files and backups on your servers and brings them into a single view.

SSH
1,204
events / 24h
Web · Nginx
38,902
requests / 24h
Auth
312
logins / 24h
Firewall
47
blocks / 24h
Syslog
OK
no anomalies
Services
9/9
active
File integrity
OK
hashes verified
Processes
184
monitored
Backup
OK
verified · 02:00
04 · Graduated autonomy

It acts on its own only when it’s sure.

We always state what it does automatically and what it doesn’t. Honesty about autonomy is a strength, not a weakness.

> 90%

Automatic

Immediate block. Action executed and notified.

brute-force, known scanners
60–89%

Approval

Alert on Telegram, confirm with a tap.

suspect IPs, new patterns
< 60%

Log only

Recorded in the digest. No action.

low-level anomalies
05 · Protection in action

SSH brute-force, at 2 a.m.

You sleep. The server defends itself. You hear about it afterwards, calmly.

SSH brute-force · at 2am CRITICAL · 94%
02:00
The attack begins

458 attempts from IP 203.0.113.42 in 30 seconds.

02:01
The AI classifies · 94%

SSH brute-force. Critical risk.

02:01
IP blocked

Firewall rule added. Attacker out.

02:01
Alert on Telegram

Notification with the details and the action taken.

You sleep. The server is protected. Response: < 1 second
06 · Capabilities

Six modules, one discipline.

Every module speaks the same language: detection, confidence, action taken. No frills, no screaming alarms.

Monitoring
9 sensors across access, traffic, processes, files and backups. A single view.
Detection
Signatures, patterns and anomalies correlated. MTTD < 15 min on known attacks.
AI Analyst
Classifies with a confidence score and maps to MITRE ATT&CK.
Auto-response
Blocks, isolates, contains. Only when it’s safe: graduated autonomy.
Compliance
NIS2 art. 21, GDPR, ISO 27001. Audit pack for the DPO, always ready.
Telegram alert
Calm, numbers, action taken. Confirm with a tap, from your phone.
07 · Compliance

NIS2, GDPR, ISO 27001. Auditor-ready.

Compliance isn’t a PDF: it’s a state of health, measured and always current. The audit pack for the DPO is one click away.

GDPR 98%
NIS2 92%
ISO 27001 86%
SOC 2 78%
Checks · audit pack
Data-at-rest encryption Compliant
Log retention policy Compliant
Backup integrity Attention
MFA on privileged access Non-compliant
Network segmentation Compliant
Incident response plan Compliant
08 · Pricing

Public price list. No “request a quote”.

An IT manager can buy it without a tender and without a salesperson. €49, €99 or €199 per server per month. Security shouldn’t be a privilege.

Standard
€49
/server · month · excl. VAT
For the SME that wants to be NIS2-ready without breaking the budget.
  • 9 monitors + AI analyst on-premise
  • Up to 10 servers
  • Live dashboard + Telegram alerts
  • GDPR / NIS2 / ISO 27001
  • Email support within 48h
Most chosen
Premium
€99
/server · month · excl. VAT
Frontier AI: superior reasoning, fewer false positives, precise investigations.
  • Everything in Standard, plus:
  • Frontier AI analyst
  • Autonomous response · 5 reversible actions
  • Up to 30 servers
  • Multi-client dashboard
  • Email support within 24h
Sovereign+
€199
/server · month · excl. VAT
For those carrying NIS2 criminal liability (art. 20) who cannot afford a false negative.
  • Everything in Premium, plus:
  • Audit-grade AI, top tier
  • Unlimited servers
  • DPIA + audit docs from the P3 DPO
  • Direct phone line within 4h
09 · Your guardian

The numbers from any ordinary night.

We don’t promise the impossible. We promise calm, numbers and action taken.

0
attempts blocked last night, on a single server.
< 0 min
average MTTD on known attacks. MTTR under a minute.
0h
from contract to first active monitor. Setup, not a project.
0/9
monitors active on every server, from day one.
10 · Questions

The honest questions.

Fenrir acts on its own only when it’s safe. Above 90% confidence it blocks or isolates and notifies you. Between 60% and 90% it asks for confirmation with a tap on Telegram. Below 60% it simply logs. We always state what it does automatically and what it doesn’t.
No. Fenrir runs on-premise, on your servers. The analysis AI is local; nothing leaves the perimeter unless you decide otherwise. It’s a sovereign product, built for those under NIS2.
No. Fenrir SOC is self-service: you install it and within 48 hours the monitors are active. If you’d rather delegate, Fenrir MDR adds a 24/7 human analyst with an SLA on Italian business hours.
Yes. €49, €99 or €199 per server per month. An IT manager can buy it without a tender and without a sales rep. Security shouldn’t be a privilege for those who can afford an in-house SOC.
The WordPress line lives in the same SOC. GARM is the free malware scanner to start from; WP Bridge is the plugin that brings your site’s events into the SOC with plain-language AI investigation; WP Central is the console for those managing a fleet of sites.
Every action is logged, reversible and notified. Below the confidence threshold it doesn’t act: it writes to the digest. No random blocks, no false alarms shouted out loud. Calm is competence.

You sleep. Fenrir doesn’t.

Book a 30-minute demo, or start free with the hound at the gate.

Install GARM · free