The questions
we are working on.
Labs is where we test what actually holds up on constrained hardware. Nothing here is published yet — this is an honest list of what we are investigating and why it matters to the product.
Active themes
Each of these exists because a product decision depends on the answer.
Intrusion detection on edge hardware
How much detection can you actually run on a fanless module?
Benchmarking gradient-boosted and neural classifiers on Jetson-class hardware against public IoT and flow datasets, measuring accuracy against latency and thermal headroom rather than accuracy alone.
Behavioural baselining without labels
Can a model learn one network well enough to flag the unfamiliar?
Most environments have no labelled attack data. We are working on unsupervised baselining that adapts to a single network's shape and holds a low false-positive rate as that shape drifts.
Correlating network and physical events
Does joining camera and traffic signals reduce false positives?
Testing whether pairing video analytics with network anomalies produces higher-confidence findings than either source alone — particularly for restricted-area access and after-hours activity.
Summarizing incidents in plain language
Can a small local model explain an alert usefully?
Investigating compact language models running on the appliance to turn correlated events into a paragraph an IT generalist can act on, without sending any of it to a hosted API.
Write-up queue
What we intend to publish, in rough order. We would rather post a method others can reproduce than a number without one.
Detection latency on edge modules
Method and benchmark harness
On-device federated learning for privacy
Early exploration
Baselining drift over a twelve-month window
Needs longer-running deployments
Working with us
We are interested in collaborating with universities and with organizations willing to host a longer-running deployment. Real traffic over real time is the part we cannot synthesise.
Start a conversation →Found a vulnerability?
We run a responsible disclosure process and aim to acknowledge reports within two business days. The full terms are in the Trust Center.
Read the disclosure policy →