Seraxi
Integrated security products · Trace · Keep · Lens

Security infrastructure,
made operable.

Seraxi is the memory and immune system of your network and security infrastructure — it keeps the full state of everything you run so nothing is ever truly lost, continuously senses how exposed it is, and helps it recover the moment something drifts or breaks. Network forensics, configuration assurance, and attack-surface intelligence — three integrated products on one platform, on your own appliance.

Built for the teams that run critical infrastructure

Three products. One operating picture.

Each stands alone. Together they close the loop from the wire, to the device, to the internet edge.

trace · sensor-01 live

Live capture

last 24h
9.4 Gbps
Throughput
30 d
Full retention
2.1 M
Active sessions
0.00 %
Packet drops
Throughput peak 12.0 Gbps
Trace
The forensic black box for your network

Trace records every packet that crosses your SPAN — full-fidelity, not just logs — so after a leak, a targeted attack, or any investigation you can pull the exact raw traffic to the minute. ML-driven NDR catches what static rules miss, and a self-hosted AI analyst answers in plain language, all on your own hardware.

  • Full-fidelity black box
  • Live & real-time capture
  • AI-powered NDR
  • Asset & IoT/OT visibility
  • Local GPU malware analysis
  • Self-hosted AI analyst
Learn more
keep · 512 devices live

Fleet posture

last 24h
99.4 %
Backed up
512
Devices
3
Config drift
2 m
Last run
509 / 512 in policy
3 awaiting tonight's window · 0 failed
Keep
The configuration vault — backup, compliance & vulnerability

Keep is the vault for your security and network device configs: agentless, vendor-native backups across 50+ vendors, tested and integrity-verified so a restore actually works. It remediates vulnerabilities and pushes firmware upgrades centrally, audits configs against ISO 27001, BDDK and PCI DSS, and surfaces the CVEs on every device.

  • Agentless, vendor-native vault
  • Tested & verified backups
  • Automated remediation
  • Compliance reporting
  • Vulnerability intelligence
Learn more
lens · live live

Attack surface

last 24h
1,284
Assets
37
Exposed
4
Critical
82
Risk score
Exposure by severity
Critical
High
Medium
Low
Lens
External + internal attack surface, on one graph

Lens shows how an open port the internet can see reaches the exact internal application behind it — the full outside-in path on one live security graph. A complete EASM platform with its own external scanner built in, it unifies the scanners you already run, scores everything with one Lens Risk Score, and surfaces shadow AI no one registered.

  • Outside-in path mapping
  • Complete EASM, built-in scanner
  • Unifies your scanners
  • AI & shadow-AI exposure
  • Lens Risk Score (LRS)
Learn more
See it in action

The screens your team actually lives in.

Not a stock dashboard — the real operating surface. Keep proves every backup, Lens maps every exposure, Trace turns packets into evidence — all feeding one operating picture.

keep · backups Backup fleet 142 devices · all vendors · last sweep 2m ago Verified 128 Drifted 3 Running 11 DEVICE VENDOR / MODEL LAST BACKUP SIZE STATUS edge-fw-01 backup · cfg + system Palo Alto PA-5410 2m ago 4.8 MB Verified core-fw-02 backup · cfg + system Fortinet FortiGate 600F 11m ago 2.1 MB Verified dmz-fw-03 backup · cfg + system Check Point 16000 Quantum running Running wan-rtr-07 backup · cfg + system Cisco Catalyst 8500 1h ago 318 KB Drifted adc-lb-04 backup · cfg + system F5 BIG-IP i5800 1h ago 12.4 MB Verified 5-step verification connect capture size hash restore-test
Keep — backup fleet, verified and drift-aware
lens · asset graph External attack surface 1,284 assets · 37 exposed services · live AI exposure shadow model server · unauthenticated Internet 0.0.0.0/0 edge-gw-02 203.0.113.7 · :443 vpn-01 203.0.113.9 · :500 app-tier 10.2.0.0/24 · :8443 ml-host-04 Ollama · :11434 db-edge 10.2.4.11 · :5432 CVE-2024-37032 RCE · Ollama path internet-reachable LENS RISK SCORE 82 Critical CVSS 9.4 EPSS 0.91 Reachability Internet Blast radius 7 assets KEV listed AI triage ready
Lens — live attack surface with AI exposure flagged
trace · capture Live capture eth4 · span port · 0 drops · indexed retention 14d THROUGHPUT 9.4 Gbps CAPTURED 42.7 TB PACKETS/S 1.31 M CAPTURE VOLUME · packets/s now anomaly +3.2σ PROTO SOURCE DESTINATION BYTES ML CLASS TLS 1.3 10.4.2.18 edge-gw-02:443 1.8 MB web · benign open › DNS 10.4.2.51 8.8.8.8:53 12 KB tunnel-like open › TLS 1.2 10.6.9.7 185.x.x.44:443 640 KB C2 beacon open › SMB 10.4.5.30 10.4.5.31:445 94 MB lateral · scan open › QUIC 10.4.2.18 fcdn-04:443 3.2 MB media · benign open ›
Trace — line-rate capture with a self-hosted AI analyst

Illustrative data shown. Your deployment runs entirely on your own appliance.

Deploy in a day. Operate for years.

Seraxi is built to be stood up fast and lived in — not a six-month integration project.

01

Land

Deploy the appliance on-prem or air-gapped. No agents to roll out, no data leaving your perimeter.

02

Connect

Point Seraxi at your fleet and surface. Vendor-native connectors do the rest — backup, capture, discovery.

03

Operate

One identity model, one audit trail, one asset graph. A finding in one product is context in the others.

Platform architecture

Three ingress lanes, one operating core.

Trace taps the wire, Keep speaks to your devices, and Lens watches the internet edge — all flowing into one core that shares identity, audit, and a single asset graph.

Trace · the wire Line-rate packet capture & sensor fusion Keep · the device Vendor-native config backup & posture Lens · the edge External attack-surface discovery Seraxi Core One identity model, one signed audit trail, one live asset graph — shared across every product.

Runs entirely on your appliance. Nothing leaves the perimeter unless you export it.

Integration breadth

Vendor-native, across the stack you already run.

Seraxi speaks each platform's own backup and telemetry paths — no fragile scraping, no brittle screen-scraping. A representative slice of what it connects to:

Firewalls & NGFW

4
Palo Alto Fortinet Check Point Cisco ASA / FTD

Routing & switching

4
Cisco IOS / NX-OS Juniper Junos Arista EOS MikroTik

SIEM & SOAR

4
Splunk QRadar Sentinel Cortex XSOAR

Load balancers & ADC

4
F5 BIG-IP Citrix ADC HAProxy NGINX

Network sensors

4
SPAN / TAP NetFlow / IPFIX Zeek Suricata

Attack surface

4
Public DNS Certificate transparency WHOIS / RDAP Port & service scans

Don't see your vendor? Native connectors are added continuously — the integration model is built to extend.

Built for the way operators actually work.

No agents to roll out, no data to surrender, no six-month integration.

100%
On-prem & air-gap capable
3-in-1
Capture · config · exposure
0
Agents to deploy
1
Asset graph across products
1 day
Typical time to stand up
100%
Privileged actions audited

One platform, not three point tools.

Seraxi shares one identity model, one audit trail, and one asset graph across capture, configuration, and exposure — so a finding in one product is context in the others.

Explore the platform →

Air-gap friendly

Runs fully on-prem with zero outbound internet — license, threat feeds, and AI all resolve inside your perimeter. No data leaves the appliance unless you say so.

Vendor-native

Speaks each device's own backup & telemetry — no fragile scraping.

Audit-first

Every privileged action is logged, signed, and exportable.

Operator-grade

Built for security ops: fast, scriptable, and honest about state.

Frequently asked

Does Seraxi run on-prem? +

Yes — fully. The platform is designed to run on your own appliance, including air-gapped environments. No backup, capture, or discovery data leaves your perimeter unless you explicitly export it.

Does Seraxi use AI — and where does it run? +

Yes, and on your terms. Lens uses AI to discover and assess exposed AI services and to triage vulnerabilities; Trace can answer plain-language investigation questions. Critically, the language model runs self-hosted on your own appliance — prompts and data never leave your perimeter.

Do I have to buy all three products? +

No. Trace, Keep, and Lens are standalone. Run one, two, or all three — they share one platform, so adding a product later just enriches the picture you already have.

How does it handle our existing vendors? +

Natively. Keep speaks each device's own backup path; Trace ingests your sensors; Lens maps your real external footprint. No fragile scraping or brittle screen-scraping.

How long does deployment take? +

Days, not a six-month integration project. The appliance stands up on-prem or air-gapped, vendor-native connectors do the discovery, and there are no agents to roll out across your fleet.

Does it integrate with our SIEM, SOAR, and ticketing? +

Yes. Seraxi is built to feed the stack you already run — findings, audit events, and correlated incidents are exportable into your SIEM/SOAR and ticketing workflows.

How is Seraxi licensed? +

Per product, by the scale you actually run — fleet size for Keep, capture throughput for Trace, attack surface for Lens — standalone or bundled. Talk to sales for a quote scoped to your environment.

Is it built for regulated environments? +

It's built for exactly that. Every privileged action is logged, signed, and exportable for audit — the rigor enterprise and banking environments require.

Built by operators, for operators.

Seraxi is an independent security-infrastructure company. We build the unglamorous, load-bearing tooling that security teams actually run their day on — with the rigor that enterprise and banking environments demand.

See Seraxi on your environment.

Book a technical walkthrough. We'll map Trace, Keep, and Lens to your fleet and show you a real backup, capture, and exposure picture — not a slide deck.