▸ FASTERUP AI AUTONOMOUS PLATFORM

Autonomous Cybersecurity
for Business & Public Administration

FasterUp detects, decides and responds to cyber threats in real time — seven complementary defense layers, from the wire to the workstation and the phone, orchestrated by MLEO into a single autonomous decision. Managed Security Operations Center and Vulnerability Assessment, deployed at your premises.

10ms–11sthreat to autonomous decision
24/7monitoring & response
7complementary defense layers, orchestrated by MLEO
0live threat indicators
SERVICES

Two services. One autonomous platform.

Managed detection & response and continuous vulnerability assessment — powered by the same AI engine and the same live threat intelligence.

MANAGED · 24/7

SOC — Security Operations Center

Fully managed, autonomous monitoring on seven complementary defense layers. FasterUp detects intrusions, network anomalies, command-and-control, data exfiltration and policy violations — the AI engine decides, and MLEO enforces on the right layer: block, notify or escalate, in seconds.

Cluster 1 IDS/IPSCluster 1 SIEMCYBER3 Context Fusion EngineMISP threat intel

Autonomous response in seconds — not hours. Alerts and reports reach your team by Telegram & email.

See details
  • 24/7 monitoring with no in-house security analysts required — the platform handles the routine, humans handle the exceptions.
  • Real-time detection on Cluster 1 IDS/IPS, event correlation through Cluster 1 SIEM.
  • Four-source context fusion on every alert: MISP + Cluster 1 IDS/IPS + SIEM + the CYBER3 Database.
  • Severity-driven autonomous action: silent log → automatic IP block → urgent alert → human escalation.
Competitive edge: one vendor owns the entire chain — from the network sensor to the decision — so response takes 2–11 seconds, not hours, with no SOC to staff, train or keep awake at 3 a.m.
CONTINUOUS
🎯

VAS — Vulnerability Assessment

Continuous, automated assessment of your assets for known vulnerabilities, misconfigurations and exposed services. You receive prioritized, actionable reports — so you fix what matters first, before attackers find it.

asset discoveryCVE detectionscheduled scansprioritized reporting

Know your exposure before attackers do. Scans run safely, on a schedule you control.

See details
  • Automatic asset discovery across your network — you cannot protect what you do not know you have.
  • Detection of known vulnerabilities (CVE) and insecure configurations.
  • Scheduled scans, run safely, on a calendar you control.
  • Prioritized reporting — remediate the highest-impact risks first.
Competitive edge: VAS and SOC work together — the SOC stops attacks in progress while VAS proactively shrinks your attack surface before attackers find the gap.
🤖

Autonomous Response

Every alert is scored by AI across all sources. By severity, FasterUp logs, blocks automatically, raises an urgent alert or escalates to a human — and MLEO executes the block on the right layer, from the firewall to a quarantine VLAN. No analyst required to act.

blocknotifyescalate

Severity-driven actions, 24/7 — even at 3 a.m.

See details
  • Suspect — ambiguous event, worth tracking → logged silently.
  • Confirmed — confirmed attack → automatic block of the source IP.
  • Severe — high-impact event → an urgent alert is raised.
  • Critical — critical compromise → escalation to a human analyst.
Competitive edge: the platform acts without waiting for a human. Your team is involved only when a critical decision genuinely needs it.
🧠

AI Context Fusion Engine

The CYBER3 Context Fusion Engine unifies four independent sources — threat intelligence, network telemetry, SIEM correlation and the CYBER3 Database — into one contextual risk decision.

multi-sourcecontextual risk2–11s

Fusion of four signals into a structured decision — proprietary FasterUp technology.

See details
  • Four independent signals scored together: MISP threat intel, Cluster 1 IDS/IPS network telemetry, Cluster 1 SIEM correlation, the CYBER3 Database.
  • One contextual risk decision per alert — in 2–11 seconds.
  • Proprietary technology, owned end-to-end by ROL PORTAL SERVICES.
Competitive edge: the same engine also powers the CYBER3 endpoint app (XDR) — network and workstations share one live threat intelligence, closing the loop between perimeter and endpoint detection.
🖥️

Network Sensors

Dedicated sensors at your sites — inline or passive — run the first network layers on the spot: Inline IPS at the wire, Active Response in the firewall and L2 Shield at Ethernet level, against ARP spoofing, rogue DHCP, scanning and exploits — without touching your workstations.

inline / passiveprivate VPNno endpoint agents

Connected back to the SOC over an encrypted private VPN.

See details
  • Installed inline or passive at each site — ~15 minutes per site, no agents on endpoints.
  • Watches for ARP spoofing, rogue DHCP, scanning, exploits and anomalous behaviour.
  • Your data stays on your premises — only metadata flows to the SOC, over an encrypted private VPN.
Competitive edge: privacy by design — built for GDPR and public-sector data handling, with full audit trail.
🔔

Clear, Human Alerts

When something matters, your team gets a concise, human-readable explanation — what happened, why it's a threat, and what FasterUp already did about it — by Telegram and email.

TelegramemailAI explanation

No noise. Only what needs your attention, explained plainly.

See details
  • Plain-language explanation: what happened, why it is a threat, and what the platform already did.
  • Delivered to your team by Telegram and email.
  • No raw log dumps, no alert storms.
Competitive edge: zero alert fatigue — your staff sees only what needs attention, already triaged and acted upon.
TECHNOLOGY

Cascade blocking. Seven complementary layers.

Every threat passes through a cascade of seven defense layers: from the wire to Ethernet, then the cloud and the endpoint. Whatever slips past one layer is caught by the next. The layers are complementary, not redundant: each covers an angle the others cannot see. MLEO orchestrates them as a single organism.

Capabilities Status

7 / 7 Active
1Network
Inline IPS
Activeresponse < 10 ms
2Host
Active Response
Activeresponse 2–11 s
3Ethernet
L2 Shield
Activeresponse < 1 ms
4AI
CYBER3 Context Fusion Engine
Activeresponse 2–11 s
5Cloud
CYBER3 Edge
Activeresponse < 50 ms
6Desktop
CYBER3 EDR/XDR for Desktop
Activeresponse real-time
7Mobile
CYBER3 Mobile Protection
Activeresponse real-time
Orchestrator
Multi Layer Enforcement Orchestrator
orchestrates 7 / 7 layersL2 ↔ L3
◤ Traffic + threats enter100% inspected
1
Inline IPSNetwork · L3–L7
inline inspection at the wire · signatures + anomalies · IOC indicators
Detects and stops the packet at the wire, in milliseconds, before it enters the client's network.
Active< 10 msresponse time
2
Active ResponseHost · L3
firewall DROP rule · escalation to a fleet-wide permanent block
Automatic response to an alert: a DROP rule in the firewall for the attacker's IP. Native fallback, independent of AI.
Active2–11 sresponse time
3
L2 ShieldEthernet · L2
native Ethernet · anti-ARP-spoof (gateway IP↔MAC pin) · anti-rogue-DHCP · dead-man anti-blackhole
The only Ethernet-level layer. Stops MITM, ARP poisoning and rogue DHCP — attacks the IP layers cannot see.
Active< 1 msresponse time
4
CYBER3 Context Fusion EngineAI · L3–L7
multi-source fusion: network + host + threat intel + CYBER3 DB
Autonomous decision from fused context; blocks even outbound connections to C2 (command and control).
Active2–11 sresponse time
5
CYBER3 EdgeCloud · anywhere
DNS-shield · edge IOC (2M+ indicators) · browser extension
Web and DNS protection anywhere, even off-network: dangerous domains and URLs are blocked before the connection is made.
Active< 50 msresponse time
6
CYBER3 EDR/XDR for DesktopDesktop · workstation
behavioral detection · XDR telemetry → SOC · quarantine
Covers threats that reach the workstation (USB, files, processes), beyond the network.
Activereal-timeresponse time
7
CYBER3 Mobile ProtectionMobile · device
anti-scam / anti-phishing · DNS filtering · VPN
Protects the user on the move: the last layer, on the personal device.
Activereal-timeresponse time
◣ Reaches the network / the usertraffic inspected across 7 layers

Proprietary orchestrator · 7 layers

Multi Layer Enforcement OrchestratorMLEO · THE CORE THAT LINKS THE 7 LAYERS

Without orchestration, each layer would detect and block on its own. MLEO is the core that correlates signals across layers and decides which layer enforces each threat, based on a unified device identity: the same machine seen as an IP at Layer 3 and as a MAC at Layer 2.

Layer 3 · layers 1 · 2 · 4

IP-based blocks

Inline IPS, Active Response and CYBER3 Context Fusion Engine: who attacked, on which port, when.

MLEO · unified identity

One source of truth

MAC ↔ IP ↔ VLAN ↔ port
↔ physical location ↔ criticality

Layer 2 · layer 3

MAC identity

L2 Shield: ARP table with history, Ethernet anomalies, the real device behind the IP.

Enforcement on the right layerdrop list on the sensor (L3)·VLAN quarantine on the switch (L2)·blocked once, not on every layer separately

What it solves

  • Evasion by changing IPAn attacker blocked on one IP takes another and carries on. At L3 it looks like a new actor; at L2 it is the same MAC — and MLEO recognizes it.
  • Correct isolation during ARP spoofingSpoofed traffic appears to come from the victim. Directional correlation isolates the attacker, not the machine the traffic seems to come from.
  • One picture, not fragmented blocksThe same device is no longer blocked separately on 3–4 layers with no link between them.
  • Tracing over timeStarting from an IP seen 24 hours ago, you find the MAC and the physical port where the device sits.

Safety principles

observe before enforceallowlist with absolute precedencetransactional rollbackVLAN quarantine, not shutdownfail-safe on every layer

The MLEO enforcement chain

  1. 0Continuous collection: ARP, MAC tables, blocks from every layervisibility
  2. 1Reconciliation table MAC ↔ IP ↔ VLAN ↔ port, with IP historyvisibility
  3. 2Every L3 block gains its L2 identity (MAC, VLAN, port, criticality)visibility
  4. 3Same MAC, different IPs within 15 min: IP-change evasion alertsteps 0–3 give full visibility without touching the client networkvisibility
  5. 4Enforcement: port moved to a quarantine VLAN, with allowlist and rollbackpreconditions: allowlist + tested rollbackenforcement
  6. 5New MAC on a port with block history; spoofed ARP + L3 block: port isolationenforcement
  7. 6Reverse direction L2 → L3: anomalous MAC resolved to IP and dropped preventivelyenforcement

Why a cascade?

No layer is perfect on its own. A packet stopped by the IPS never reaches Active Response; one that slips through is caught by the CYBER3 Context Fusion Engine; an L2 attack (ARP spoofing), invisible to the IP layers, is stopped by L2 Shield.

Autonomous, no human in the loop

Detection → context fusion → autonomous decision in 2–11 seconds → action: temporary block, escalation to a permanent block, notification. The allowlist protects legitimate equipment at every step.

One organism

MLEO is not a new layer. It is the orchestrator that links the existing layers, so seven layers that see separately become one organism that sees the same device at every level.

FasterUp NEXTGEN SOC · 7 layers · MLEO · defense in depth

Sense. Correlate. Decide. Act — autonomously.

The FasterUp AI Autonomous Platform turns raw network signal into a structured response in seconds, fusing four independent intelligence sources for every decision.

Network SensorsCluster 1 IDS/IPS · inline or passive
Dedicated sensors at each site capture and inspect traffic for ARP spoofing, rogue DHCP, scans and exploits — no agents on your endpoints. Only metadata leaves your network, over an encrypted private VPN.
SIEM CorrelationCluster 1 SIEM · events normalized & correlated
Raw packets become normalized events, then correlated across the whole estate so isolated signals turn into a single, meaningful incident — not thousands of disconnected logs.
CYBER3 Context Fusion Engineautonomous decision in 2–11s
The proprietary engine fuses four independent sources — MISP threat intel, Cluster 1 IDS/IPS telemetry, SIEM correlation and the CYBER3 Database — into one contextual risk decision in 2–11 seconds.
Responseblock · notify · escalate
By severity the platform acts on its own: silent log, automatic source-IP block, urgent alert, or escalation to a human analyst — end-to-end in seconds, 24/7.
AUTONOMOUS How the platform decides & acts on every alert
Each alert is scored by AI across four sources. Suspicious events are logged silently; a confirmed attack triggers an automatic IP block; severe events raise an urgent alert; a critical compromise escalates to a human analyst. End-to-end: 2–11 seconds.
HEALTH CHECK The platform that watches — and repairs — itself
The whole platform runs under an autonomous Health Check that continuously monitors, administers and self-repairs the entire sensor fleet — 24/7, without human intervention. It detects stalled packet capture, restarts stuck services, recovers dropped VPN tunnels, and validates the end-to-end pipeline with synthetic canary alerts. Every sensor heals itself; the fleet stays online.
Autonomous by defaultDecides and acts without waiting for an analyst — the platform handles the routine, humans handle the exceptions.
Multi-source context fusionMISP threat intel + Cluster 1 IDS/IPS telemetry + Cluster 1 SIEM correlation + CYBER3 Database — on every single decision.
Deployed at your premisesSensors live on your network; only metadata flows to the SOC over an encrypted private VPN.
Built for accountabilityFull audit trail, structured reporting and GDPR-aligned data handling — designed for public administration.
Open, proven stackBuilt on Cluster 1 IDS/IPS, SIEM correlation and MISP threat intelligence — hardened, orchestrated and decided by our AI engine.
Real-time pipelineRaw packet → normalized event → correlated alert → AI decision → response, end-to-end in seconds.
ENDPOINT XDR · CYBER3

The SOC, extended to every workstation — and every phone

Layers 6 and 7 of the cascade run on people's devices: CYBER3 EDR/XDR for Desktop on every Windows workstation and CYBER3 Mobile Protection on every phone. Both report to the same SOC, draw on the same threat database and are orchestrated by the same MLEO — one owner of the technology, from the network sensor to the app on the phone.

Layer 6 · Windows

CYBER3 EDR/XDR for Desktop

A native Windows app that turns every workstation into a detection and response point connected to the SOC. Digitally signed, updated automatically, managed per organization from the client console.

CYBER3 EDR/XDR for Desktop — Dashboard

Real-time protection

DNS-Shield on the whole workstation: dangerous domains are blocked at resolution, and DNS keeps working if the shield ever stops (fail-open). A local threat engine with 2.5M+ known indicators and a browser protection extension with 29,131 rules.

🔍

Computer scan

Checks the workstation's security posture — antivirus, firewall, UAC, updates — and scans Downloads, Temp and startup items for known malware. Score 0–100, one-click quarantine, automatic re-scan every 3 hours.

🛰️

CYBER3 Global Scan, built in

Discovers every device on the local network, checks 38 exposed ports and matches software versions against known CVEs — non-destructive, it only “looks at the doors”. Optional AI report saved to the organization's account.

🛑

Workstation isolation

At confirmed malware, or on a SOC command, the CYBER3 guardian cuts the workstation off the network while keeping the link to the SOC, so it can be reconnected remotely. It reconnects by itself after 30 minutes unless the SOC holds it; a kill-switch disarms it instantly.

🖥️

Client console + SOC

Organization mode starts with an activation code or silently at deployment. The desktopapp.cyber3.ai console shows the workstation inventory, status and events, and runs remote scan, isolation and reconnection — picked up by the workstation within 30 seconds. Each client sees only its own fleet.

📡

Security telemetry

Only security metadata leaves the workstation — heartbeat, scans, threats, isolation — through the local sensor or, off-site, through the CYBER3 cloud edge. In personal mode, nothing is sent.

🔒

CYBER3 VPN

Encrypted, no-logs WireGuard VPN: 400 MB free every day, unlimited by subscription, servers in 4 countries, choice of server on paid plans.

Instant checks + backup

Messages (AI verdict), links, phone numbers, email breaches and passwords (k-anonymity: only a hash prefix leaves the device). Backup of important files to the on-site server, with retention.

Layer 7 · Android

CYBER3 Mobile Protection

The Android app that stops scams, phishing and dangerous sites on every employee's phone — in real time, with on-device processing. The same threat database as the sensors and workstations, refreshed every 12 hours. Available on Google Play.

CYBER3 Mobile Protection — Home
Home
CYBER3 Mobile Protection — Call & message protection
Call & message protection
📞

Call protection

CYBER3 becomes the phone's Caller ID: every incoming number is checked against the threat database. Optional auto-reject for known scam numbers and a visual warning over the call screen.

💬

Message protection

Reads incoming notifications — SMS, WhatsApp and other apps — without SMS permissions, and warns only when a message is dangerous.

🤖

Message check

Paste or share a message from any app and get Safe, Suspect or Danger, with the reasons: imitated brand, risky domain, urgency or payment wording, URL tricks — explained by AI.

🌐

Web protection

A DNS filter on the phone, with no server in between: dangerous domains from the threat database, ads and trackers are blocked in every app.

📱

Phone scan

A 0–100 score: screen lock, USB debugging, developer options, security patch age; apps with admin or accessibility rights, sideloaded apps with risky permissions — and every installed app's hash checked against the threat database.

🪪

Identity & breaches

Email breach check with continuous monitoring every 12 hours and a notification on each new breach; password check with k-anonymity.

🔒

CYBER3 VPN

Encrypted, no-logs WireGuard VPN: 400 MB free every day, unlimited by subscription, 6 servers in 4 countries, split tunneling and a built-in speed test.

🔗

Number & link check + reporting

Check any number or link; unknown threats can be reported and, once validated by an analyst, join the shared threat database.

One ecosystem. One owner of the technology, end-to-end.

The seven layers are not products from different vendors glued together. They are one system, built, operated and supported by the same company — so there are no blind spots between products and one accountable owner for the whole chain.

1–4On the sensor, at your siteInline IPS · Active Response · L2 Shield · CYBER3 Context Fusion Engine
5In the cloud, anywhereCYBER3 Edge — DNS-shield and the threat database at the edge
6On every workstationCYBER3 EDR/XDR for Desktop
7On every phoneCYBER3 Mobile Protection

Shared by all seven layers

  • the same CYBER3 threat database (2.5M+ indicators, refreshed daily)
  • the same SOC, 24/7
  • the same MLEO orchestrator: a threat seen on one layer is enforced on the right one
  • a closed loop: our own sensors contribute their indicators to the database that protects workstations and phones

What we build and operate ourselves

network sensors and their rule setsL2 ShieldCYBER3 Context Fusion Engine and MLEOCYBER3 Edge and the threat databasethe sovereign security LLMthe Desktop and Mobile appsthe VPN networkthe client console and the SOC portal

Why it matters for an institution

  • It covers the dominant attack vector: the employee and the workstation — phishing, scams, malicious links and attachments, leaked passwords.
  • It protects staff working in the field or remotely, not only inside the physical perimeter.
  • Privacy by design: on-device processing and k-anonymity; no accounts required, no ads, no advertising SDKs.
  • Endpoint telemetry feeds the same SOC and MLEO, closing the loop between network detection and endpoint detection.
PACKAGES

Sized to your institution

Each package includes everything in the previous one and adds layers and capabilities. The exact configuration (sensors, sites, workstations, phones) is set after an initial assessment of your environment.

STANDARD

Standard

Includes

  • Managed 24/7 SOC · autonomous response in 2–11 s
  • Inline sensor at the main site
  • Layers 1–4: Inline IPS · Active Response · L2 Shield · CYBER3 Context Fusion Engine
  • MLEO: L3 ↔ L2 correlation and enforcement on the right layer
  • Monthly scheduled VAS
  • Plain-language alerts (Telegram, email) + client portal with NIS2 reports
  • Autonomous 24/7 sensor Health Check
Best for
Central office with concentrated IT infrastructure. Gets you autonomous 24/7 monitoring and a regular vulnerability picture without standing up a SOC of your own.
EXTENDED

Extended

Everything in Standard, plus

  • Inline sensors at every site
  • Layer 5 · CYBER3 Edge: DNS-shield and edge IOC for the whole organization
  • Layer 6 · CYBER3 EDR/XDR for Desktop on critical workstations
  • Client console: workstation isolation, remote scans, fleet status
  • CYBER3 Global Scan of the internal network
  • MLEO across all sites
  • Bi-weekly VAS
Best for
Multi-site institutions with elevated exposure. Network coverage everywhere plus endpoint XDR on the workstations that matter most.
RECOMMENDED

Complete

Everything in Extended, plus

  • CYBER3 EDR/XDR for Desktop on every workstation
  • Layer 7 · CYBER3 Mobile Protection on staff phones
  • MLEO across all 7 layers: network, cloud, workstation, phone
  • Continuous VAS
  • Breach and identity monitoring for the organization's accounts
  • Unified network + endpoint + mobile reporting (NIS2 Art. 21/23)
Best for
County level, sensitive citizen data, strict compliance. Full multi-layer defence — perimeter and every workstation — under one vendor and one unified report.

Pricing: this document presents the services and the technical solution. A detailed financial offer is prepared on request, based on the initial assessment (sites, sensors, endpoints) and the procurement method applicable to your institution.

GET STARTED

From assessment to autonomous defense

A simple onboarding for organizations of any size — from a single office to a distributed public institution.

🎯

1 · Assessment

We map your assets and exposure with a Vulnerability Assessment — a clear picture of where you stand.

▸ Request assessment No commitment · scoped to your environment
See details
We map the assets and exposure of your institution through a vulnerability assessment — the result is a clear picture of your current state. No commitment, scoped strictly to your environment, and it forms the basis for a correctly sized proposal.
🖥️

2 · Sensor deployment

We install network sensors at your sites — inline or passive — connected to the SOC over a private encrypted VPN.

▸ See the architecture ~15 min per site · no endpoint agents
See details
We install network sensors at each site, inline or passive, connected back to the SOC over an encrypted private VPN. About 15 minutes per site, with no agents on your endpoints. Optionally, we deploy the CYBER3 XDR app on workstations and mobile devices per your policy.

3 · Autonomous SOC

24/7 AI monitoring and response goes live. You receive alerts and reports — the platform handles the rest.

▸ Talk to us Managed · autonomous · always on
See details
24/7 AI monitoring and response goes live. You receive clear alerts and reports while the platform handles the rest — running under an autonomous Health Check that monitors, administers and self-repairs the whole fleet, with no human intervention.