Watch it work before you let it act.

PROSENTRIQ attaches a kernel-level eBPF probe to your box in one command and starts scoring real traffic in under two minutes — in a mode that is structurally incapable of dropping a single packet. You decide when, or if, it's allowed to start blocking anything.

No credit card. No reboot. No Zeek installed until you say so.

~
$
Validating API key against api.prosentriq.com … ok
Attaching prosentriq_observe.o (xdp, observe-only) to eth0 … ok
Running 5-minute baseline … done
PROSENTRIQ trial agent is live in OBSERVATION mode on eth0.
Kernel-level XDP enforcement Fails open, never silently off SOC 2 · PCI DSS · HIPAA control mappings Self-hostable Detection API No AGPL, no open-core catch

Three steps, in order, nothing skipped

This is the entire path from a cold box to enforced, monitored infrastructure. Each step is real and independently testable.

01

Install in observation mode

One command validates your API key against the Detection API before touching your system, then live-attaches prosentriq_observe.o — a build of the probe with every drop and redirect code path removed, not merely disabled. It cannot block traffic even if instructed to.

02

Watch real findings accumulate

Behavioral baselining, GeoIP and reputation scoring, and threat correlation all run exactly as they would in production — you just see the output instead of the enforcement. The Threat Historian starts linking events across days immediately.

03

Flip to enforcement when you're ready

prosentriq-ctl enable-enforcement confirms your account and tier with the Detection API, swaps in the real enforcement probe, and logs the change to an audit trail. Reversible at any time with disable-enforcement.

Two planes, doing two different jobs

The kernel agent enforces locally and never needs to phone home to function. The Detection API scores, correlates, and evolves rules across your whole fleet. Neither one is a thin client for the other.

Kernel agent
(your host)
firewall_probe.o (XDP) profiler_probe.o Behavioral baseline Genetic algorithm Honeypot prosentriq-ctl
Detection API
(control plane)
Account & API keys Reputation engine Threat Hub Compliance reports Rate limiting

eBPF/XDP inspection

Inspects packets at the kernel boundary before they reach userspace — efficient enough to run on every packet, hard to fake with a userspace agent.

Behavioral baselining

Learns what "normal" looks like per host — process identity, memory legitimacy, connection patterns — instead of matching static signatures.

Genetic algorithm rule evolution

Scores and evolves firewall rules against real traffic automatically, without a human writing or approving each one.

Threat Historian

Correlates low-and-slow attack patterns across days — a day-1 scan linked to a day-9 login attempt, the kind of thing signature tools miss entirely.

Collective immunity

An attack detected on one node updates reputation data shared across your fleet through the Threat Hub, in minutes, not after a manual review.

Compliance evidence

Generates SOC 2, PCI DSS, and HIPAA control-mapped reports on demand — JSON, Markdown, or a signed-checksum PDF an auditor can verify.

Built to fail open, on purpose

A security tool that silently turns itself off during a network blip is worse than one that was never installed. PROSENTRIQ treats that as a design constraint, not an edge case.

  • If the Detection API is briefly unreachable, enforcement keeps running on the last confirmed state — it does not shut off.
  • A revoked or invalid API key is checked continuously by the running agent itself, not only the next time someone remembers to run a CLI command.
  • Every enable/disable of enforcement is written to a local audit log, independent of the Detection API's own records.
prosentriq-ctl
$ prosentriq-ctl status
Mode: production
Interface: eth0
API key: psq_live_uBrf...
Account: confirmed, tier production

Straightforward pricing

Free to try in observation mode for as long as you want. Pay when you turn on enforcement.

Full pricing details
Trial
$0
Single host, observation only, no time limit.
  • Full scoring & behavioral baselining
  • Structurally cannot block traffic
  • Upgrade to production anytime
Enterprise
Custom
Fleets, MSPs, and air-gapped deployments.
  • Volume pricing per node
  • Dedicated Threat Hub instance
  • On-prem / air-gapped install path
  • SLA & priority support

Get your key

An email and one command. The account exists before install.sh does anything to your system — not after.

$ get your api key