Nine real-time monitors, autonomous Tier-1 AI analyst, revertible autonomous response, integrated compliance. All running on a single Linux host — no data ever leaves your perimeter.
Three numbers that explain why a SOC is no longer optional for organizations under NIS2 (Directive (EU) 2022/2555) or GDPR.
The average SMB has no SOC. It relies on logs no one reads — until the day damage is done. Fenrir changes that equation without requiring a dedicated security team.
From log line to verdict in less than a second. From verdict to (revertible) action in one second more.
real-time tail + periodic snapshotters
deterministic classification, no LLM
playbook + tool loop + structured verdict
5 revertible autonomous actions
DB, dashboard, Telegram
PostgreSQL or SQLite. OpenRouter (cloud) or Ollama (local). Cloudflare Tunnel for exposure. No inbound ports required.
SSH login, sudo, brute-force, user anomalies.
Hits on fake admin paths, scanners, exploit kits.
Bans, unbans, repeat offenders tracked cross-jail.
Suspicious patterns in production traffic.
Firewall drops, port scans, egress anomalies.
USB, OOM, segfault, AppArmor denials.
Ports, services, users, setuid: new entries alerted.
Install/upgrade/remove tracked for audit.
Pending security updates, prioritized by criticality.
When the verdict is confirmed_threat with confidence ≥85%, the agent runs the suggested action. Every action is persisted with the metadata needed to undo it.
SIGTERM 3s + SIGKILL fallback
mv + chmod 000 in isolated dir
systemctl stop with whitelist
iptables egress block per IP
apt remove + reinstall on revert
When an event is HIGH or CRITICAL, an investigation kicks off. The analyst loads the playbook for that category, runs tools (shell, geoip, threat intel, log search) in a max-5-round loop, and produces a structured verdict.
Output: verdict, confidence, summary, IOC list, recommended actions, full transcript for audit.
Latency: 10-60s per investigation. API cost: €0.01-0.05 per investigation.
Daily automated audit against GDPR, NIS2, ISO 27001. Each control passes or fails with attached evidence (log, command, output).
GDPR Art. 33 workflow built in: 72h timer, escalation, DPO notification, PDF report generation for the supervisory authority.
NIS2 mapping: incident handling, notification, technical and organizational measures.
Fenrir runs on your server (or your EU cloud). No centralized SaaS, no shared data lake, no vendor lock-in.
Source open: git clone, read every line, fix without calling the vendor.
Storage: your own PostgreSQL, configurable retention (default 90 days — GDPR Art. 5).
When an alert is routed to a cloud LLM (OpenRouter), the PII anonymizer replaces every personal identifier with an opaque token before the prompt leaves your server.
The cloud model reasons about <PRIVATE_PERSON_1>. Real values are restored in the final report on your side.
Alternative: local Ollama (Qwen, Llama). Zero cloud traffic.
Per server, per month, VAT excluded. LLM API costs at your charge (or use Ollama: zero cloud cost).
One-off setup fee: €1,500 Standard · €3,000 Premium · €5,000 Sovereign+. Covers installation, baseline, and playbook tuning.
Fenrir is a P3 Consulting product. HQ in Italy. Source on GitHub.