Key vendors

The vendors we build security architecture on

Nine leading platforms — from sovereign cloud and AI telemetry, through next-generation firewalls and privileged access management, to logically resilient backup.

Catalog

Nine key vendors

The technologies we implement and maintain every day. Expand a vendor to see the full list of products and modules. The other suppliers in our portfolio are in the Technology partners section.

Public Cloud Products

  • Virtual machines (VMs) and Spot instances — flexible compute instances
  • Managed Kubernetes — container automation and orchestration
  • Dedicated compute instances with graphics processors (GPU) — high performance for AI/ML
  • Storage — Object Storage S3, Block Storage, ephemeral storage, virtual machine storage
  • Network services and security — Load Balancing, Firewall
  • Management and identity tools — Customer Panel, Cloud Management Panel, API, Identity

Private & Hybrid Cloud

  • Private cloud — physically and logically isolated dedicated environments
  • White Label public clouds — ready-made cloud platforms for partners and MSP providers
  • Professional services and technical support for Kubernetes

Sovereign Earth observation data (EO Data & Tools)

  • EODATA repository and EO data catalog — more than 90 PB of sovereign satellite data
  • VHR satellite imagery (Very High Resolution) — very high resolution imaging
  • EO Traceability Service — tracking the provenance and integrity of satellite data and AI models
  • Dedicated national and sector platforms — CREODIAS, CDSE, CODE-DE, WEKEO, EOLAB, DEDL

Artificial intelligence and Sherlock (AI Services)

  • CloudFerro Sherlock (Managed Generative AI Service) — fully sovereign European GenAI in Poland
  • Search Agents & Knowledgebases — automated, sovereign RAG: OCR, chunking, embeddings
  • AI compute services — high-performance GPU instances for machine learning
  • Global AI embeddings in Earth observation — semantic vectorization of geospatial archives

Dedicated mobile container environments

  • BASTION — a mobile tactical cloud with a full Kubernetes architecture in a container; a Polish DUAL USE tactical cloud

Threat Exposure & Detection Posture Platform

  • Agentic Detection Engineering / Cardinal AI — automatic extraction of TTPs from threat intelligence
  • MITRE ATT&CK Coverage Mapping — continuous mapping of detection rules and identification of gaps
  • Broken Rule Remediation — automatic detection of logic, parsing and misconfiguration errors
  • Rule Health Monitoring — ongoing audit of the technical health of SIEM/EDR rules
  • Pre-tuned Rule Catalog — a base of more than 8,000 ready-made rules in the native syntax of leading SIEMs
  • Coverage Scoring — monthly, measurable reporting of detection maturity for the CISO
  • Continuous Threat Exposure Management (CTEM) — unification and correlation of preventive and detective controls

Telemetry Pipeline Products

  • Cribl Stream — intelligent filtering, volume reduction, masking and routing of logs and telemetry
  • Cribl Edge — collecting, processing and optimizing metrics at the network edge and on endpoints
  • Cribl Search — searching and analyzing distributed telemetry data in place
  • Cribl Lake — flexible, sovereign telemetry storage with no dependence on a single vendor

Cribl.Cloud

  • Telemetry as a Service — management and operation of telemetry pipelines in the cloud

Artificial intelligence and AI security (Cribl AI)

  • Cribl Guard (Background Detection) — detecting sensitive PII/PCI data in traffic using local NER and regex
  • Cribl Copilot / Copilot Editor — a generative assistant and editor for transformation pipelines in natural language
  • Cribl MCP Server & MCP Integrations — developer integration with external AI clients

Generative AI Security (FortiAI)

  • FortiAI-Protect — DLP for prompts, guardrails for GenAI models, Shadow AI, zero-day sandboxing
  • FortiAI-Assist — NOC/SOC automation, alert triage, threat hunting, Day 1 to Day N configuration
  • FortiAI-SecureAI / FortiAIGate — a secure LLM gateway protecting the runtime against prompt injection and DDoS

Secure Networking & Infrastructure

  • FortiGate NGFW — physical and virtual next-generation firewalls, network segmentation
  • FortiGuard Security Services — automated subscriptions and real-time protection signatures
  • Secure Switches & Wireless LAN — secure switches and Wi-Fi access points
  • Secure SD-WAN & Universal ZTNA — secure distributed connectivity and unconditional Zero Trust access

Cloud Security & Cloud-Native Protection

  • FortiCNAPP — an integrated cloud application protection platform from code to cloud
  • FortiWeb & FortiADC — web application and API protection (WAF) and Load Balancing

Security Operations (SecOps)

  • FortiSIEM / FortiSOAR / FortiAnalyzer / SOCaaS — SIEM systems, SOAR orchestration, analytics and SOC as a service
  • FortiEndpoint / FortiNDR / FortiDeceptor — endpoint protection, NDR, deception technology

Identity & Access Security

  • FortiPAM — privileged access management
  • FortiAuthenticator / FortiToken / FortiIdentity Cloud — identity servers and MFA authentication

Solutions for industrial environments (OT Security)

  • Ruggedized Products — a line of industrial network devices and firewalls (including the FortiGate Rugged series) for fail-safe operation in extreme temperatures, dust, humidity and strong vibration
  • OT Security Service — dedicated FortiGuard Labs signature, rule and protection profile databases for industrial protocols (Modbus, DNP3, BACnet) and automation systems
  • NAC for OT — identification, classification and unconditional access control of IoT and IIoT devices (PLC controllers, HMI panels, sensors) without installing agents
  • NDR for OT — traffic monitoring in OT environments (FortiNDR) and analysis of behavioral anomalies in machine communication
  • SOC Analytics for OT — integration of FortiAnalyzer and FortiSIEM with the specifics of industrial events, one console for IT and OT
  • OT Tech Alliance — confirmed operational compatibility with the systems of leading automation and SCADA software vendors

Platform modules

  • ISO/IEC 27001 — information security management system
  • ISO/IEC 42001 — artificial intelligence management system
  • ISO/IEC 27017 — security of cloud services
  • ISO/IEC 27018 — protection of personal data in the public cloud
  • CRA — Cyber Resilience Act
  • ISO 23001
  • AI Act — the EU artificial intelligence regulation
  • NIS2 — the directive on the cyber resilience of essential and important entities
  • UKSC — the Polish National Cybersecurity System Act

Characteristics

  • A dedicated GRC platform supporting resilience, with AI Security elements — both in managing AI security and in using AI to analyze data from the organization's security layers
  • One modular platform that helps meet the requirements of UKSC, NIS2, ISO 27001, ISO 42001, the AI Act and CRA — giving full insight into the organization's security level

Network Security (SNS)

  • Stormshield Network Security (SNS) Firewalls — a family of physical and virtual NGFW firewalls
  • Stormshield XDR — a system for correlating and detecting network and endpoint threats
  • SNS Industrial Firewalls (SNi10, SNi20, SNi40, SNi50) — hardened firewalls dedicated to OT/SCADA environments

Endpoint Protection (SES)

  • Stormshield Endpoint Security (SES) — advanced, proactive hardening and protection of workstations and servers

Data Protection (SDS)

  • Stormshield Data Security (SDS) — encryption of files, disks, e-mail messages and SharePoint spaces

Central management and tools

  • Stormshield Management Center (SMC) — central management of distributed SNS firewalls
  • Stormshield Log Supervisor (SLS) — central aggregation, analysis and supervision of device logs

Exposure Management Platform

  • Tenable One — an integrated platform for managing the organization's overall risk exposure
  • Tenable One AI Exposure — identification of Shadow AI, misconfigurations and vulnerabilities in ChatGPT, MS Copilot and similar

Vulnerability Management

  • Tenable Vulnerability Management — scanning and managing vulnerabilities in cloud and hybrid environments (formerly Tenable.io)
  • Tenable Security Center — enterprise-level on-premise vulnerability management (formerly Tenable.sc)
  • Nessus Professional / Nessus Essentials — the global standard for IT vulnerability scanning

OT & Identity Security

  • Tenable OT Security — protection and vulnerability identification for industrial automation and ICS systems (formerly Tenable.ot)
  • Tenable Identity Exposure — detecting gaps and attacks in Active Directory infrastructure and identities (formerly Tenable.ad)

Cloud & App Security

  • Tenable Cloud Security — securing containers and code, and a CNAPP platform
  • Tenable Attack Surface Management (ASM) — managing the external, internet-facing attack surface
  • Tenable Web App Scanning (WAS) — automatic security scanning of web applications and APIs

Privileged Access Management (PAM) — control of privileged accounts

  • WALLIX PAM — securing, managing and rotating credentials of privileged accounts, API keys, passwords and administrative access to critical IT systems, databases and AI environments (preventing model tampering)
  • WALLIX Remote Access — rigorous supervision, authentication and full recording of remote sessions of external developers, subcontractors and partners on sensitive IT/OT projects and AI implementations
  • WALLIX Web Session Manager — advanced recording, visualization and control of sessions carried out through web interfaces and applications

Identity and Access Management (IAM) — authentication and identity

  • WALLIX IDaaS (formerly Trustelem technology) — a cloud identity-as-a-service platform providing SSO and MFA, seamlessly securing access to applications and data from anywhere
  • WALLIX Authenticator (MFA Application) — an authentication app for iOS, Android and Windows: push notifications, TOTP codes, security keys and passkeys (FIDO); compatible with SAML, LDAP and RADIUS
  • WALLIX Enterprise Vault & AAPM — secure, centralized storage, rotation and programmatic management of secrets (passwords, API keys, certificates) used by applications, scripts and CI/CD pipelines, eliminating hardcoded credentials

Privilege Elevation and Delegation Management (PEDM)

  • WALLIX BestSafe — endpoint protection and hardening that enforces the principle of Least Privilege at the level of individual processes and applications; allows trusted administrative operations to run without granting users full administrator rights

Identity and Access Governance (IAG)

  • WALLIX IAG — continuous analysis of permissions, periodic and auditable access reviews and elimination of excessive privileges; key to demonstrating compliance with NIS2 and DORA

Security as a Service

  • WALLIX ONE — a centralized, flexible SaaS platform delivering the full range of identity and access services on demand in a Zero Trust model, including WALLIX ONE CONSOLE and WALLIX ONE PAM CORE

User Behavior Analytics (UBA)

  • Malizen (technology integrated into the WALLIX ecosystem) — an AI-algorithm-based tool for continuous, proactive behavioral analysis of human users and non-human identities (automated agents and AI processes); runtime anomaly detection, mitigation of insider risks and prevention of attacks before they escalate

SphereCyberX — spherical security architecture

  • Triple-I (Immutable, Indestructible, Immediate) — immutable point-in-time copies, logical resilience and immediate DR
  • xSAIR (Secure AirGap Immutable Repository) — logical, automatic network isolation of repositories in a Zero Trust model

Data protection software

  • Xopero ONE Backup & Recovery — backup of workstations, Windows/Linux servers, VMware, Hyper-V, Microsoft 365 and DevOps/Git

Dedicated appliances (Backup Appliance)

  • Xopero Unified Protection (XUP) — an all-in-one backup server, disk array and deduplication with no license limits on endpoints and virtual machines

Cloud services

  • Xopero Cloud Storage — a sovereign, EU-located cloud backup repository

We do not pick technology from a catalog. Every solution implemented in an organization is selected individually — taking into account the existing architecture, threat analysis, the organization's maturity level, risk profile and business goals.

We will match the solution to your architecture

Every implementation is designed individually — for your existing architecture, risk profile and business goals.