Flow monitoring, data retention, threat intelligence, vulnerability scanning and NIS2 reporting run on a single platform. Stop an attack at your upstream with RTBH, and have the regulator's report pre-filled before you start writing it.
A typical ISP runs five separate tools, five licences and five places to look for context. Every additional system adds complexity, integration cost and the risk that something falls between them.
Its own collector, its own database, its own licence.
A legal obligation handled by yet another system and yet another storage tier.
Feeds downloaded somewhere and evaluated somewhere else — not where the flows are.
Another tool, another console, another report nobody connects to network operations.
Spreadsheets, shared documents and deadlines tracked by hand.
All five areas run on the same data. When a flow record shows a suspicious address, its reputation, ASN, attack history and any link to an open incident are on the same screen.
The recording from a live system follows the path from a flow record to a blocked address and a pre-filled report. A video is fine, but deciding on someone else's data is not — which is why we offer a demo on your own traffic.
We deploy the system into your network and let it run on real traffic. You see your own flows, your own attacks and your own vulnerabilities — not a prepared showcase.
The video is in Czech with Czech subtitles. An English walkthrough is available live.
Request a demo on my dataFor internet service providers and network infrastructure operators — not a general security tool that discovered ISPs later.
Providers running their own network infrastructure across a region.
Operators of municipal networks and metropolitan fibre infrastructure.
Telecommunications operators with complex backbone infrastructure.
Colocation and cloud infrastructure operators.
Connectivity providers for critical government and industrial networks.
Fewer licences, fewer servers, fewer integrations. One platform instead of five tools with separate licence fees.
One system instead of several disconnected ones. The team focuses on security, not on maintaining tools.
Investigate an incident in minutes. The context — flows, threats, vulnerabilities — is in one place.
Records and reporting in one place, with all five reporting stages and the time remaining on each.
Deep traffic analysis, threat detection, mitigation and regulatory support over a single data set.
Every IP flow analysed in real time. IPFIX, NetFlow v9 and native interface mirroring.
22 predefined rules in three families: floods against your addresses, floods from one of your hosts, and scans and sweeps. UDP and TCP SYN floods, reflection attacks over DNS, NTP, LDAP, SSDP, memcached and chargen, port scans and address sweeps. From a mirrored interface the system names an attack within seconds.
Every flow is enriched with source reputation from eight feeds — FireHOL, abuse.ch Feodo and ThreatFox, AlienVault OTX, Emerging Threats Open and MISP. You recognise traffic to infrastructure known from botnets and malware campaigns without reading the payload.
The module covers NIS2 obligations and implements the Czech transposition in detail (Act 264/2025 Coll. and decrees 409/2025 and 410/2025 Coll.). It determines your regime, decides what counts as a reportable incident and tracks all five reporting stages including time remaining. We adapt the module to other national transpositions.
Continuous comparison of what is actually announced in global routing against what prefix holders authorised by signing a ROA. A divergence is a strong signal of a prefix hijack, a route leak or a misconfiguration.
Active and passive scanning, CVE and CVSS enriched with EPSS and KEV — prioritised by what is actually being exploited.
You do not just see the attack — the system cuts it off at the upstream peer via RTBH or FlowSpec.
Hundreds of thousands of scan records become one aggregated entry. Smaller database, faster investigation.
FireHOL, abuse.ch Feodo and ThreatFox, OTX, ET Open and MISP — including a link to your own MISP server.
Data straight from the RIR registries, with RPKI validation, BCP-38, MANRS and CAIDA rank.
10,542 tracked divergences between what is announced and what is authorised.
CSV, JSON and PDF in every section — flows, attacks, ASNs, incidents and forensic analyses.
The system collects data over NetFlow v9, IPFIX, packet mirroring and TCPdump — from multiple collectors, sites and data centres at the same time. Collection methods can be combined and the distributed architecture extended without limits as the network grows.

Conventional systems store every connection attempt separately. During a scan or a DDoS that produces hundreds of thousands to millions of records, loading the database and driving up storage cost. The system recognises port scanning, brute force, DDoS traffic and one-way connection attempts and converts them into aggregated records.

Every detected attack can be taken apart in depth — by its identifier, or by examining a specific IP address in a given time window. Analyses are stored, so you can come back to them a month later when writing the final report.

For any IP address you immediately know who owns it, what its ASN reputation is, how traffic reaches it and what relationships that network has. Data is populated from RIPE NCC (5.0 m records), APNIC (1.2 m), LACNIC, AFRINIC and ARIN over RDAP.

The system continuously compares what is actually announced in global routing against what prefix holders authorised by signing a ROA. A route covered by a ROA that does not authorise the announcing AS is a strong signal of a prefix hijack, a route leak or a configuration error.
There are currently 10,542 such divergences in the database — each showing the announcing AS, the authorised AS and the affected prefix, with export to PDF and JSON.

The built-in scanner checks devices on the network in two modes: a quick scan at most once an hour per subnet and a full scan once a day, both in parallel blocks, so a large network does not extend scan time linearly.

The system does not only detect. It can stop an attack at your upstream peer — before it saturates your uplink.

For every action you set the severity at which it triggers and how it should treat late detections from exporters. A blackhole can also be announced manually for a specific prefix, with an expiry or until revoked — and any active announcement withdrawn with one click.
The platform is designed to slot into an operator's existing infrastructure. Integration runs over a REST API and webhooks — into practically any CRM, billing or operations system an ISP uses.

When you are handling an incident at three in the morning, you are not jumping between three windows and two SSH sessions. The context you need is on the same screen as the flow record that brought you there.

The system handles traffic up to 100 Gbps. Collection can be split across multiple collectors and probes, so the architecture grows with your network — across sites and data centres.
We run the platform, you connect to it. The fastest route to first data, with no hardware to buy and no changes to your infrastructure.
You deploy the software into your own virtualisation. Data never leaves your network — for data retention, and for operators with their own policy on traffic data, usually the only acceptable option.
A certified device on lease, including replacement on failure, firmware, monitoring, remote management and SLA. Timing depends on hardware availability.
The module goes beyond the general wording of the directive. It implements the Czech transposition — Act 264/2025 Coll. and decrees 409/2025 and 410/2025 Coll. — in detail. The framework of obligations is the same across the EU; we adapt the module to other national transpositions.
A provider of a public communications network or service is regulated regardless of size — the small-enterprise exemption does not apply to you. The regime is decided by company size or reach: higher obligations from 350,000 active SIMs or 100,000 fixed connections, otherwise lower obligations. One organisation means one regime.
A reportable incident has three characteristics at once: it occurred within the scope of security management you defined, it originates in cyberspace, and a deliberate cause cannot be ruled out within 24 hours. The system knows these tests and shows you why one outage must be reported and another must not.
Initial report ≤ 24 h · Notification ≤ 72 h (trust services 24 h) · Interim report on the regulator's request · Status report after 30 days if the incident is still open · Final report ≤ 30 days after resolution. For each stage you see how much time is left — or by how much it is overdue.
Notifying the authority, contact details, security measures within the statutory period, and responding to warnings and reactive countermeasures without delay. Authority contacts, including emergency numbers, sit inside the system, split by your regime.
| Situation | Outcome |
|---|---|
| A user clicked a phishing link and entered credentials | Incident — reportable |
| Phishing arrived but nobody clicked | Event — not reportable |
| Outage during planned maintenance | Not an incident — intent ruled out |

Failing to report — late, not at all, or omitting follow-up reports — is an offence. Reporting an incident does not itself trigger an inspection; incidents happen to well-secured organisations too.
Health Monitor watches service availability and groups outages into candidate NIS2 incidents on its own — with calculated impact and an assessment of whether the cause looks like a cyber attack.
You then simply decide. Dismiss an operational outage. Promote a real incident into a report that is already pre-filled and carries the evidence: which attacks, from which addresses, at what severity.
The statutory clock starts with your decision — until then the system only flags that there is something to assess. We keep that boundary deliberately: what counts as an incident is decided by your responsible officer, not by software.

| Capability | Protectione | Conventional NetFlow | SIEM |
|---|---|---|---|
| Flow monitoring | ✓ | ✓ | ~ |
| Data retention | ✓ | ~ | ✕ |
| Threat intelligence | ✓ | ✕ | ✓ |
| Vulnerability management | ✓ | ✕ | ~ |
| Mitigation via RTBH / FlowSpec | ✓ | ✕ | ✕ |
| NIS2 to national law | ✓ | ✕ | ~ |
| RPKI and ASN intelligence | ✓ | ✕ | ✕ |
| ISP specialisation | ✓ | ~ | ✕ |
| Single platform | ✓ | ✕ | ✕ |
Price follows the number of ISP subscribers. No hidden fees. Prices exclude VAT and apply to the 500–1,000 subscriber band; larger networks are priced by band.
Cancel at any time.
Discount on the total price for a two-year term.
Discount on the total price for a three-year term.
Discount when paying a year in advance.
A certified device on lease: hardware, replacement on failure, firmware, monitoring, remote management and an SLA guarantee. After the term, a service fee of CZK 1,000 per month or purchase for a nominal sum.
| ISP subscribers | Start | Advanced | Complete |
|---|---|---|---|
| 500–1 000 | 5 000 | 7 000 | 10 000 |
| 1 001–2 000 | 7 000 | 9 000 | 13 000 |
| 2 001–5 000 | 9 000 | 12 000 | 16 000 |
| 5 001–10 000 | 12 000 | 16 000 | 20 000 |
| 10 001–20 000 | 15 000 | 20 000 | 25 000 |
| 20 001+ | on request | on request | on request |
Per month in CZK, excl. VAT.
Prices are shown in CZK; a euro quotation is available on request. For more than 20,000 subscribers we prepare an individual offer. A guaranteed response time (SLA) is a separate service on top of the plan.
The cloud and virtual editions are deployed within 48 hours. The hardware appliance within a week, depending on device availability. For the virtual edition we need resources in your virtualisation and access to a mirrored interface, or NetFlow / IPFIX export configured on your routers.
Up to 100 Gbps. Collection can be split across multiple probes and collectors, across sites and data centres — the architecture grows with the network, so you do not have to size it up front.
From a mirrored interface, within seconds. Records from IPFIX and NetFlow v9 exporters arrive 15 to 60 seconds after a connection ends, depending on your router configuration — the system evaluates those too and marks them as late, so you can tell what is happening now from what happened a moment ago.
Sensitivity is set with a single control across four levels — from high for quiet networks to very low for backbone and transit, where only a genuinely large attack should raise an alert. Each individual threshold can be tuned separately, and addresses that must never trigger a response go on a whitelist.
For every response you set the severity at which it triggers. The whitelist also works granularly — per IP, port or protocol, and separately for the LAN and WAN side. Active blackholes sit in one table and any of them can be withdrawn with a single click.
With the virtual and hardware appliance, yes — the system runs inside your network and the data does not leave it. The cloud edition is for operators who want a fast start without their own hardware; you can move between the options.
Yes — SNMP trap, syslog and URL callback are among the detector's responses. There is also a REST API for CRM, billing, customer portal or ticketing integration.
Beyond CVSS, the system pulls EPSS (probability of exploitation) and CISA's KEV catalogue of vulnerabilities known to be exploited. You patch by what actually threatens you.
The system has a stability test mode that identifies exactly those devices, and subnets or individual addresses can be excluded from scanning.
The data is yours and export is always available. It is charged by data volume according to the current price list — for large historical archives the transfer and processing are not trivial. We calculate the figure for you in advance, not on your way out.
Standard support in English and Czech is included. A guaranteed response time (SLA) is a separate monthly subscription on top of the plan.
Forty-five minutes, online, no commitment. We go through what the platform would look like at your organisation — how many systems it would replace, how NIS2 reporting would work for you, and what it would mean for your team. Walkthroughs are one-to-one, so the answers are specific rather than generic.
| Length | 45 minutes |
| Format | Online video call |
| Attendees | Your team, as many as you need |
| For | ISP owners, CTOs, network and security teams |
| Price | Free, no commitment |
After you send the form we get back to you within one business day to agree a time that suits you.
Interested in a demo, a pilot, or simply want to know more? Get in touch directly. We usually reply within 24 hours on business days.
One platform. One database. One dashboard.