AI-assisted security operations for SMBs

Know what is exposed. Take the next safe action.

Sotiras helps small businesses verify assets, detect real attack behavior, and turn evidence into reviewed security work without hiring a full security team.

What problem does Sotiras solve?

Know what is exposed, what is attacking it, and what action is safe to take next.

Can it act for me?

Sotiras can take low-impact actions under policy while high-impact decisions stay reviewed.

How is this different from WAF?

Sotiras tracks actor intent, assets, evidence, and time, not only single request rules.

How do I start?

Start with one asset the business cares about, then build the evidence trail.

1 assetFast first proof
10 minInitial graduated ban
ReviewedHigh-impact actions

The problem

Attackers do not wait for office hours. Small teams still need safe decisions.

SMBs see brute force, credential stuffing, route probes, and exposed-service scans, but most do not have a security team to interpret every signal or babysit another dashboard.

Sotiras starts with one system you care about, builds an evidence trail, and helps decide whether to block, watch, assign, escalate, or ask support for help.

Attacks compound over time

A scanner, a brute-force run, and a later successful login should not look like unrelated events.

Noise burns attention

Every alert should explain what happened, why it matters, and what action is safe.

Tools are fragmented

WAFs, plugins, host logs, PBX logs, and firewalls need one customer-readable decision trail.

AI needs evidence

AI should summarize and recommend from known facts, not replace review, policy, or approval.

Safe action model

Let Sotiras help quickly, without hiding decisions from you.

The product is designed for graduated response. Low-impact actions can happen when confidence is high and delay increases risk. High-impact changes stay visible, reversible, and approved by the right person.

That means the first temporary ban can be safe and short, while credential changes, broad network blocks, incident communications, and recovery steps remain reviewed.

Low-risk action can be fast

High-intent probes and known bad behavior can trigger short graduated bans under tenant policy.

High-impact action stays reviewed

User lockouts, broad firewall changes, vendor access, and recovery decisions require approval and audit history.

Every action needs a trail

Sotiras records evidence, confidence, target, decision owner, rollback notes, and review status.

Beyond WAF rules

Blocking a request is not the same as understanding the threat.

A WAF can stop a pattern. Sotiras is built to understand the actor, the target, the evidence over time, and the customer decision that should follow.

1

Traditional WAF rule

Blocks or allows a request based on a pattern, often without explaining actor history or business impact.

2

Sotiras actor review

Looks at source behavior over time, asset context, authentication signals, probes, scans, and tenant policy.

3

Customer outcome

The user sees why something matters, what Sotiras did, what needs approval, and what should be watched next.

Customer outcomes

Security work a lean team can actually use.

Sotiras turns exposure, attack behavior, AI review, and support context into actions that can be approved, assigned, escalated, or watched.

Know what is exposed

Start with one system the business cares about. Sotiras verifies ownership, scans safely, and explains what is reachable.

See real attack behavior

Route probes, brute force pressure, suspicious logins, and scanner patterns become evidence instead of raw noise.

Understand what matters

AI reviews explain the source, target, evidence, confidence, business impact, and the next safe action.

Act without guessing

Turn evidence into a risk, incident, owner task, support request, temporary block, or watch decision.

Keep actions tied to assets

Every finding attaches to a system, owner, IP, hostname, service, criticality, and follow-up record.

Use safe automation

Low-impact actions can run under policy. High-impact changes stay reviewed, reversible, and auditable.

Know the actor context

Separate a noisy scanner, likely bot, shared network, known bad actor, and suspicious authenticated user.

Look for breach clues

Auth outcomes, known-bad IP matches, unusual access time, and host context help surface possible compromise.

Report progress clearly

Weekly proof turns observations, actions, risks, support work, and unresolved questions into one customer-readable record.

Getting started

From one asset to reviewed action.

01

Prove what matters

Pick one IP, server, PBX, WordPress site, or application. Sotiras verifies ownership and creates an asset record.

02

Watch for intent

Run a safe scan or connect a lightweight source. Sotiras looks for exposure, probes, auth pressure, and missing evidence.

03

Approve the next action

Review what Sotiras found, what it did, and what still needs approval, support, assignment, or escalation.

Practical first signal

WordPress sites can start with observe-only evidence.

If a customer only has wp-admin access, the plugin gives Sotiras a low-friction first signal: login failures, XML-RPC activity, route probes, and WordPress inventory. It starts in observe mode; a connected Free or Premium account can enable automatic application-layer enforcement after the owner opts in. If the customer controls the host, pair it with web or host collection later.

Safe observe-only start

The plugin can first watch suspicious activity without changing users, roles, files, caching, firewall rules, or login behavior.

Automatic WAF enforcement

Connected Free and Premium accounts can apply Sotiras block decisions before WordPress loads, after the site owner explicitly enables enforcement.

Useful attack signals

Track login failures, successful logins, XML-RPC activity, REST auth failures, route probes, and top observed paths.

Inventory context

Report WordPress core, PHP, active theme, installed plugins, and versions when the site owner connects cloud history.

Recently shipped

The evidence trail now follows you further.

Coverage keeps expanding across the stack you actually run, and the review loop now reaches your phone, not just the portal.

Mobile app for iPhone and Android

Get alerts, notifications, and auto-ban activity on your phone, and lift a ban yourself when a token allows it — no laptop required.

Kubernetes and container workloads

Kubernetes audit log collection and Falco runtime detection cover clusters alongside your existing host and web telemetry.

Azure and Google Cloud

Microsoft Entra ID sign-in monitoring, plus GCP Cloud Logging and Cloud Functions collection for serverless workloads.

Application groups

Group the hosts, VMs, and services that make up one real system, so evidence and actions stay tied to the business system, not a single box.

Simple pricing

Start small. Scale when you're ready.

Start with the smallest useful scope, then expand coverage when device count, telemetry volume, AI review, or response needs grow.

For one person managing their own protection — including independent IT professionals using Sotiras for client or business systems.

Free

$0forever

One connected WordPress site with a working WAF, email alerts, and community intelligence contribution.

  • One connected WordPress WAF
  • Owner-enabled automatic blocking
  • Early request guard before WordPress loads
  • Threat and enforcement email alerts
  • Community intelligence protection and contribution
  • 7-day cloud evidence window
  • ×Human support response commitment
  • ×AI threat analysis
  • ×Hands-on site recovery

Premium

$19.95per month

Deeper protection and evidence for one WordPress or nginx HTTP surface, with supported WordPress enforcement.

  • Everything in Free
  • Expanded Sotiras intelligence and evidence
  • WordPress or nginx protected surface
  • Limited AI threat analysis
  • 30-day evidence retention
  • Email support — initial response within 24 hours
  • ×Hands-on site recovery
  • ×Assisted-response hours
  • ×Managed observability workspace

Usage-based overages never count attack traffic — brute force, honeypot, and high-severity surge are excluded from automatic billing.

Optional WordPress recovery

$499 per incident for one standard WordPress installation

Includes bounded site cleanup, access review, re-scan, and recovery validation. Host compromise, multisite spread, custom-code repair, data restoration, forensics, and emergency response commitments require a separate scope.

Request recovery

Trial length

Starter periods can be offered for early customer onboarding. The portal shows the active plan, limits, and billing status for each workspace.

When billing starts

Recurring billing starts only when the workspace has an active paid plan. You can request plan changes from the portal before expanding coverage.

No surprise overages

Attack surge traffic is visible in reports but excluded from automatic overage billing.

Get started today

Verify one asset. Build the evidence trail.

Start with a guided scan-to-action flow, connect the right telemetry, and use Sotiras to review what happened across assets before deciding what to change.