Seraxi

AI-assisted threat detection · OT security · configuration assurance · attack surface

Security infrastructure,
made operable.

Network memory and threat detection, configuration assurance, and attack-surface intelligence — three products on one platform, running entirely on your own appliance. Built for the teams that run banks, utilities and critical infrastructure.

  • 100% on-prem · air-gap
  • 50+ vendors, agentless
  • IT + OT on one sensor
  • London · İstanbul

What it answers

The questions that arrive at the worst possible time.

Three products. One operating picture.

Each stands alone. Together they close the loop from the wire, to the device, to the internet edge.

Chapter 01 — Seraxi Keep

Seraxi Keep

Configuration assurance for network & security devices

Keep connects to every firewall, router, switch and load balancer you run and keeps a verified baseline of each one. From that baseline it answers the questions that matter: which devices does last night's advisory hit, which configs drift from corporate policy, which certificates expire this quarter, what goes end-of-support next year — and whether the backup would actually restore.

Capabilities

  • Advisory-to-device matching
  • Configuration baseline & policy controls
  • Compliance checks
  • Lifecycle: EOL / EOS check
Product page
Seraxi Keep — Checks: config posture, licences, certificates, lifecycle and security baseline across the fleet

What it answers

A FortiOS advisory was published last night. Which of our devices are affected?
Keep matches the advisory to model and firmware across the inventory and lists them — with the recommended fix.
Does every firewall comply with our security policy?
Policy controls run against each baseline continuously; every deviation is listed by device and control.
Seraxi Keep — fleet dashboard with backup activity and vendor distribution

Chapter 02 — Seraxi Trace

Seraxi Trace

Network memory and threat detection — one sensor, modular

Trace records the raw traffic on your network so an investigation never depends on a firewall's accept/deny log, detects threats with machine learning and a real, self-hosted AI, and brings the same visibility to OT networks — Modbus, DNP3, IEC 104, OPC UA and the PLCs behind them. Underneath, a live asset inventory built from the wire. One appliance; Analysis, TDS and Assets as modules — and Seraxi Relay for OT.

Modules

  • Trace Analysis Network memory
  • Trace TDS Threat Detection System
  • Seraxi Relay OT security · built on Trace
  • Trace Assets Inventory from the wire
Product page
Seraxi Trace TDS — threat detection stream with severity, source, destination and description

What it answers

We suspect an attack happened last night. What do we actually have?
The packets. Trace Analysis replays the raw traffic for that hour — not a firewall log that only says accept or deny.
Is something on the network talking to a domain nobody recognises?
Trace TDS flags the behaviour on live traffic with ML and a self-hosted AI, and shows the packets behind the verdict.
Seraxi Trace Analysis — session browser with sub-second search over recorded traffic

Chapter 03 — Seraxi Relay

Seraxi Relay

OT security that never touches the process

Seraxi Relay is OT security built on the Trace sensor. It listens passively to industrial networks, identifies PLCs, RTUs, HMIs and SCADA servers from the wire, places them on the Purdue model and watches the control traffic itself — Modbus, DNP3, IEC 104, IEC 61850, OPC UA, PROFINET, EtherNet/IP, S7comm — with a self-hosted AI that learns what normal looks like for your process.

Capabilities

  • Passive protocol decoding
  • Purdue asset map
  • Control-traffic baselining
  • IT / OT boundary monitoring
Product page
L3 eng-ws-12 · historian L2 scada-a · hmi-02 L1 PLC-07 · rtu-3 L0 pump-4 · valve-9 Purdue L0–L3 · passive COM NC · process NO · alarm trip · Modbus FC16 · outside window → operator · PCAP · ticket

What it answers

A PLC took a write from a workstation. Was that supposed to happen?
Relay knows the Purdue level, the protocol and the maintenance window; the write is flagged in seconds and the packets are kept.
What is actually on the plant network — every PLC, RTU, HMI?
Passive discovery from the wire: vendor, model, firmware and protocol for 50+ device types, placed on the Purdue model automatically.
relay · purdue map · plant-a Purdue map 47 assets · 9 protocols · passive · last packet 2 s ago PLC / RTU 18 HMI / SCADA 7 Alerts 2 IT / OT boundary · conduit fw-ot-01 L3 Operations / IT eng-ws-12 Windows 11 RDP · S7 historian AVEVA PI OPC UA jump-01 Linux SSH L2 Supervisory · SCADA / HMI scada-a Siemens WinCC S7comm hmi-02 Schneider Vijeo Modbus/TCP eng-srv Rockwell Studio CIP L1 Control · PLC / RTU PLC-07 Siemens S7-1500 S7comm · Modbus rtu-3 ABB RTU560 DNP3 · IEC 104 plc-03 Rockwell CompactLogix EtherNet/IP L0 Field pump-4 VFD · Danfoss PROFINET valve-9 Emerson HART / IP meter-2 Honeywell Modbus RTU/TCP Modbus FC16 write · L3 → L1 protocols: Modbus/TCP · DNP3 · IEC 104 · IEC 61850 · OPC UA · PROFINET · EtherNet/IP · S7comm · BACnet — passive, zero process impact

Chapter 04 — Seraxi Lens

Seraxi Lens

External + internal attack surface, on one graph

Lens shows how an open port the internet can see reaches the exact internal application behind it — the full outside-in path on one live security graph. A complete EASM platform with its own external scanner built in, it unifies the scanners you already run, scores everything with one Lens Risk Score, and surfaces shadow AI no one registered.

Capabilities

  • Outside-in path mapping
  • Complete EASM, built-in scanner
  • Unifies your scanners
  • AI & shadow-AI exposure
Product page
Seraxi Lens — security graph from internet-facing hostnames down to backends and CVEs

What it answers

The internet sees port 8443 open. Which internal application is behind it?
Lens draws the path from the exposed port to the exact service on one graph.
Someone stood up an LLM server. Is it exposed?
Lens discovers self-hosted model and MCP servers and flags the unauthenticated ones.
Seraxi Lens — risks stream with severity, KEV, EPSS and Lens Risk Score

Coverage

The vendors you run. The frameworks you answer to.

Vendor-native connectors, no screen-scraping. Controls map to the frameworks your auditors ask about — mapped, not certified.

Vendors & platforms

Firewalls & NGFW
Palo Alto · Fortinet · Check Point · Cisco ASA / FTD
Routing & switching
Cisco IOS / NX-OS · Juniper Junos · Arista EOS · MikroTik
SIEM & SOAR
Splunk · QRadar · Sentinel · Cortex XSOAR
Load balancers & ADC
F5 BIG-IP · Citrix ADC · HAProxy · NGINX
Network sensors
SPAN / TAP · ERSPAN / GRE · NetFlow / IPFIX · PCAP import
Attack surface
Public DNS · Certificate transparency · WHOIS / RDAP · Port & service scans

Frameworks & regulations

  • ISO 27001
  • PCI DSS
  • BDDK
  • KVKK
  • NIS2
  • DORA
  • NIST CSF
  • CIS Benchmarks
  • IEC 62443

Don't see your vendor? Native connectors are added continuously — the integration model is built to extend.

Platform architecture

One platform, not three point tools.

Seraxi shares one identity model, one audit trail, and one asset graph across capture, configuration, and exposure — so a finding in one product is context in the others.

Explore the platform

01

Air-gap friendly

Runs fully on-prem with zero outbound internet — license, threat feeds, and AI all resolve inside your perimeter. No data leaves the appliance unless you say so.

02

Vendor-native

Speaks each device's own backup & telemetry — no fragile scraping.

03

Audit-first

Every privileged action is logged, signed, and exportable.

04

Operator-grade

Built for security ops: fast, scriptable, and honest about state.

Seraxi is built to be stood up fast and lived in — not a six-month integration project.

Deploy in a day. Operate for years.

  1. 01

    Land

    Deploy the appliance on-prem or air-gapped. No agents to roll out, no data leaving your perimeter.

  2. 02

    Connect

    Point Seraxi at your fleet and surface. Vendor-native connectors do the rest — backup, capture, discovery.

  3. 03

    Operate

    One identity model, one audit trail, one asset graph. A finding in one product is context in the others.

Frequently asked

Seraxi is an independent security-infrastructure company. We build the unglamorous, load-bearing tooling that security teams actually run their day on — with the rigor that enterprise and banking environments demand.

Does Seraxi run on-prem? +

Yes — fully. The platform is designed to run on your own appliance, including air-gapped environments. No backup, capture, or discovery data leaves your perimeter unless you explicitly export it.

Does Seraxi use AI — and where does it run? +

Yes, and on your terms. Lens uses AI to discover and assess exposed AI services and to triage vulnerabilities; Trace can answer plain-language investigation questions. Critically, the language model runs self-hosted on your own appliance — prompts and data never leave your perimeter.

Do I have to buy all three products? +

No. Trace, Keep, and Lens are standalone. Run one, two, or all three — they share one platform, so adding a product later just enriches the picture you already have.

How does it handle our existing vendors? +

Natively. Keep speaks each device's own backup path; Trace ingests your sensors; Lens maps your real external footprint. No fragile scraping or brittle screen-scraping.

How long does deployment take? +

Days, not a six-month integration project. The appliance stands up on-prem or air-gapped, vendor-native connectors do the discovery, and there are no agents to roll out across your fleet.

Does it integrate with our SIEM, SOAR, and ticketing? +

Yes. Seraxi is built to feed the stack you already run — findings, audit events, and correlated incidents are exportable into your SIEM/SOAR and ticketing workflows.

How is Seraxi licensed? +

Per product, by the scale you actually run — fleet size for Keep, capture throughput for Trace, attack surface for Lens — standalone or bundled. Talk to sales for a quote scoped to your environment.

Is it built for regulated environments? +

It's built for exactly that. Every privileged action is logged, signed, and exportable for audit — the rigor enterprise and banking environments require.

Request a demo

See Seraxi on your environment.

Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.

Customers

Already running Seraxi?

The customer portal holds your product downloads, installation and administration guides, release notes and support.

  • Product downloads (OVA)
  • Installation & admin guides
  • Release notes
  • Support
Sign in to the portal

support@seraxi.com