Four focused surfaces. One evidence chain.
Sotiras separates day-to-day customer operations, collector qualification, authorized active validation, and public threat intelligence so each task has a clear workflow, audience, and privacy boundary.
Choose the work in front of you
Each product makes a different promise.
The status on each surface reflects how the current implementation is delivered today. Public availability does not imply that support-assisted validation or lab qualification has become unrestricted self-service.
Customer security operations
Sotiras AI
Sotiras AI is the customer operating layer for assets, collectors, threats, response, and verification. It keeps routine control activity quiet while bringing serious concerns into focus.
Authorized active validation
ProtectTheBox
ProtectTheBox runs bounded, authorized security validation against a customer-controlled target. It connects preflight, execution, detection, enforcement, rollback, and customer-readable proof.
Collector qualification and honeypot proof
Collector Lab
Collector Lab is the passive test harness for Sotiras collectors. It combines deterministic parser replay, controlled fixtures, live collector installation, and honeypot observations into repeatable qualification evidence.
Public-safe threat intelligence
Public CTI
Public CTI is the open intelligence surface for approved IP indicators, observation trends, classifications, and source context. It is deliberately separated from private tenant operations and controlled validation.
Operating model
Connected by proof, separated by purpose.
Evidence can support another workflow without erasing where it came from or why it was created.
- Operate01
Sotiras AI
Customer assets, collectors, threats, response, and verification stay in one focused operating layer.
- Qualify02
Collector Lab
Replay and controlled targets prove collection, parsing, classification, enforcement, and release evidence.
- Validate03
ProtectTheBox
Authorized active assessments prove defensive behavior and recovery on a customer-controlled target.
- Share04
Public CTI
Only approved public-safe indicators cross into the open intelligence surface.
The publication boundary is categorical.
ProtectTheBox runner IPs, customer targets, and controlled attack traffic never seed Public CTI. Collector Lab can contribute only qualifying unsolicited hostile observations under publication policy; synthetic and replay traffic remain excluded.
Roadmap
See major product themes and what is being built next.
Release notes
Review what shipped. Latest: 0.3.1.
Product feedback
Request a feature, collector, integration, or workflow improvement.
Coming next: July 28 customer-ready lab validation release
Version 0.4.0