ThreatNexaris

Deployment

Where it runs, and what touches your network.

Three models, chosen by what your policy allows rather than by what we would prefer to sell. The differences that matter are where your telemetry sits and who carries the operational burden.

Hosted

Default

We run the platform. You connect the sources you want and nothing needs to be installed in your environment. The fastest way to get to a working answer, and the right choice for most teams.

  • No infrastructure for you to run or patch
  • Sources connected outbound from your side
  • Suitable where telemetry can leave your network

Hosted with a customer-side connector

Regulated estates

The platform is hosted, but the component that answers questions about your environment runs inside it. Your telemetry is queried locally and only the answer is returned, not the data behind it.

  • Runs inside your network, polls outbound only
  • No inbound port and no firewall change
  • Each question declares in advance what its answer may contain

Private deployment

By agreement

The platform deployed into infrastructure you control, for organisations whose policy or regulator does not permit the hosted model. Scoped case by case, because the operational burden moves to you and that has to be worth it.

  • Runs in your cloud account or data centre
  • Update and patch cadence agreed with you
  • Requires a named technical owner on your side

Onboarding

Useful in a day. Fitted in a month.

Intelligence coverage works from the first login. Everything after that is about making the answers specific to you, and the order below is deliberate: each step makes the next one worth more.

  1. Day 1

    Access and coverage

    Accounts created, single sign-on connected if you use it, and intelligence coverage live. There is nothing to configure for this part to start working.

  2. Week 1

    Your estate

    Asset inventory imported or discovered, so exposure stops being generic and starts naming your systems. This is the step that determines how useful everything downstream is.

  3. Week 2

    Detection and workflow

    Detection platforms connected with your index and field names, alert routing pointed at the channels your team already watches, and case workflow matched to how you actually triage.

  4. Week 3

    Monitoring and reporting

    Domains, people and suppliers added to monitoring. Reporting configured for the audiences that need it, including any regulator.

Support

What happens when something is wrong.

The honest version: this is an early platform, and the compensation for that is unusually direct access to the people building it. If you need a twenty-four hour follow-the-sun desk today, we are not that yet.

Support model
Access to engineering
The platform is early, so questions reach the people who can change it rather than a tier-one script.
Response commitments
Agreed in the contract at Enterprise, with a named contact. Best effort on the lower tiers, stated honestly rather than dressed up as an SLA.
Security issues
Reported to security@threatnexaris.com and treated as a priority over feature work.
Status and change
Material changes announced before they ship, not discovered afterwards.

Tell us what your policy allows.

Whether telemetry can leave your network usually decides the model in one sentence. Start there and the rest of the conversation is short.