Product portfolio
Current implementation

Four focused surfaces. One evidence chain.

Sotiras separates day-to-day customer operations, collector qualification, authorized active validation, and public threat intelligence so each task has a clear workflow, audience, and privacy boundary.

Choose the work in front of you

Each product makes a different promise.

The status on each surface reflects how the current implementation is delivered today. Public availability does not imply that support-assisted validation or lab qualification has become unrestricted self-service.

Available now

Customer security operations

Sotiras AI

Sotiras AI is the customer operating layer for assets, collectors, threats, response, and verification. It keeps routine control activity quiet while bringing serious concerns into focus.

Use it for: Owners, operators, IT teams, and security reviewers protecting customer systems.
Explore Sotiras AI
Support-assisted

Authorized active validation

ProtectTheBox

ProtectTheBox runs bounded, authorized security validation against a customer-controlled target. It connects preflight, execution, detection, enforcement, rollback, and customer-readable proof.

Use it for: Customers and Sotiras operators validating a collector and defensive controls in an approved scope.
Explore ProtectTheBox
Lab capability

Collector qualification and honeypot proof

Collector Lab

Collector Lab is the passive test harness for Sotiras collectors. It combines deterministic parser replay, controlled fixtures, live collector installation, and honeypot observations into repeatable qualification evidence.

Use it for: Sotiras operators, developers, and reviewers qualifying collector behavior and release claims.
Explore Collector Lab
Public

Public-safe threat intelligence

Public CTI

Public CTI is the open intelligence surface for approved IP indicators, observation trends, classifications, and source context. It is deliberately separated from private tenant operations and controlled validation.

Use it for: Customers, analysts, operators, and community users investigating a public IP or activity pattern.
Explore Public CTI

Operating model

Connected by proof, separated by purpose.

Evidence can support another workflow without erasing where it came from or why it was created.

  1. Operate01

    Sotiras AI

    Customer assets, collectors, threats, response, and verification stay in one focused operating layer.

  2. Qualify02

    Collector Lab

    Replay and controlled targets prove collection, parsing, classification, enforcement, and release evidence.

  3. Validate03

    ProtectTheBox

    Authorized active assessments prove defensive behavior and recovery on a customer-controlled target.

  4. Share04

    Public CTI

    Only approved public-safe indicators cross into the open intelligence surface.

The publication boundary is categorical.

ProtectTheBox runner IPs, customer targets, and controlled attack traffic never seed Public CTI. Collector Lab can contribute only qualifying unsolicited hostile observations under publication policy; synthetic and replay traffic remain excluded.

Roadmap

See major product themes and what is being built next.

Release notes

Review what shipped. Latest: 0.3.1.

Product feedback

Request a feature, collector, integration, or workflow improvement.

Coming next: July 28 customer-ready lab validation release

Version 0.4.0

Preview release