IstroSec builds and runs its own AI: self-hosted, explainable, and verified against the underlying evidence.
Local LLMs and an air-gapped knowledge base for investigations
- A fully self-hosted, model-agnostic large-language-model platform, with no dependency on third-party, AI clouds or APIs.
- Designed for closed, air-gapped and on-premises environments handling sensitive data.
- A hybrid cybersecurity knowledge base: semantic and keyword retrieval, reranking and knowledge-graph traversal across CVEs, threat actors, malware families and MITRE ATT&CK techniques.
- Local-LLM forensic analysis: a multi-stage review pipeline (triage → analysis → validation) that works through large evidence sets and re-verifies every finding verbatim against the source. No hallucinated evidence.
- Guardrails against fabricating CVE IDs, CVSS scores, threat-actor attributions or indicators of compromise.
Sovereign AI SOC IN DEVELOPMENT
- An AI triage-and-investigation layer built on GRYPHON sensors: AI investigates each alert, and analysts approve every consequential action (human-in-the-loop by design).
- Built for EU sovereignty: deployable EU-hosted, on-premises or air-gapped, running local models.
- Every AI claim is evidence-cited; every metric is computed deterministically, not generated by a model.
- Hard per-tenant isolation and a tamper-evident, hash-chained audit trail for every step.
Built and run on IstroSec’s own infrastructure
IstroSec builds, trains and runs these models on its own compute infrastructure, under IstroSec’s own control, with no dependency on third-party AI clouds.
Backed by EU research: see our EU-funded projects, including GRYPHON-EWS — Early Warning System against advanced cyber threats.