Strategy & Governance

Managed Security

Cyber Defense

Governance, Risk & Compliance

Operations & People

Talk to us
Aphelion Cyber
AphelioNYX

One platform for compliance, detection and the identity paths nobody maps.

Three modules, one sign-on: Compliance Hub for the evidence, MDR for the watch, and AD Pen-Test for the identity graph. The last of those was built for a requirement most identity tools quietly assume away: a working internet connection.

Where egress is forbidden (defence programmes, OT plants, classified environments), AD Pen-Test runs sensor, graph engine and command centre entirely inside your perimeter, and nothing phones home because there is nothing to phone. Where it is not, the same graph runs alongside Compliance Hub and MDR.

Platform capabilities

DetectPosture rules and a real-time detection engine running on your own hardware.
ManageFindings with an owner, a severity and a service-level target, not a dashboard.
RespondAttack paths ranked by what breaking one link actually removes.
MonitorRound the clock, and inside the boundary, where the data already is.

AD Pen-Test outbound calls: 0, by design, not by firewall rule

Module 01

01 / 03

Compliance Hub: enterprise compliance, automated.

One platform for every framework you are asked for. Map controls once, collect the evidence automatically, and stay audit-ready all year instead of for the six weeks before an assessor arrives.

The cost of fragmented compliance is rarely the audit fee. It is the enterprise deal that stalls at procurement because a security questionnaire cannot be answered inside the quarter.

8Frameworks out of the box, plus your own custom set
4Steps: connect, map, monitor, audit
5Integrations named today: AWS, Azure, GCP, GitHub, Okta
6 wksTypical onboarding to a monitored baseline
  • Frameworks Hub: SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, ISO 27701 and the DPDP Act, in one control set
  • Automated evidence: collected from the systems of record on a schedule, not screenshotted the night before
  • Continuous monitoring: a control that drifts raises a finding the day it drifts
  • Audit-ready reports: exportable, with the evidence attached to the control it answers
  • Also ships: policy management, risk register, access reviews, awareness training, phishing simulation, tabletop exercises, vendor risk assessment, multi-tenant

The consulting side of this

AphelioNYX / Compliance Hub / Frameworks On-premises
Framework coverageSample tenant
ISO 27001:202278%
93 controls72 evidenced21 open
SOC 284%
61 controls51 evidenced10 open
DPDP Act 202361%
42 controls26 evidenced16 open
GDPR69%
59 controls41 evidenced18 open
Evidence collected in the last hour
oktaQuarterly access review export · 412 accountsMapped ×7
awsEncryption-at-rest configuration, 38 bucketsMapped ×4
githubBranch protection and review policyMapped ×3
azureConditional access policy snapshotMapped ×5
Illustrative interface · sample tenant dataEvidence collected once, mapped to every framework that asks for it

Module 02

02 / 03

MDR: someone is watching, and they can act.

Managed detection and response, around the clock, combining SIEM correlation with analysts who are allowed to do something about what they see. A detection nobody acts on is a log line.

The difference between a monitored organisation and an unmonitored one is not the number of alerts produced. It is how many were triaged, by a person, before the shift ended.

  • Twenty-four-hour monitoring, with real-time analysis rather than a morning report
  • SIEM correlation across endpoint, identity, network and cloud telemetry
  • Triage by an analyst, with a documented disposition on every alert that closes
  • Containment actions agreed in advance, so the first response does not wait for a meeting
  • Handover into incident response the moment an alert becomes an incident

The managed SOC service

AphelioNYX / MDR / Live queue Shift B · 3 analysts
1,284Events / min
17Alerts today
3Open
4mMedian triage
Queue
02:14CRITImpossible travel: finance account, Ahmedabad → Lisbon in 22 minutesContained
02:09HIGHKerberoast pattern against three service accountsTriage
01:52MEDNew scheduled task on a domain controllerAssigned
01:31MEDOutbound volume spike from a build agentClosed · benign
00:58LOWPassword spray, 4 attempts, blocked at the edgeClosed
Illustrative interface · sample tenant dataEvery closed alert carries a disposition and a name

Module 03

03 / 03

AD Pen-Test: offline by design, zero cloud dependency.

Active Directory posture analysis, transitive attack-path graphing and a real-time detection engine, running entirely inside your perimeter, for the environments where a collector calling a vendor endpoint would be a finding of its own.

350+Active Directory posture rules on the appliance
5Hops to Tier-0 on an average graphed path
7OT protocols fingerprinted passively
8Sigma-style real-time detection rules
  • Posture analysis across the directory, with hybrid on-premises and cloud identity in one view
  • Transitive attack-path graphing: the chain, not the isolated misconfiguration
  • OT and ICS discovery with Purdue modelling: Modbus, OPC-UA, EtherNet/IP, DNP3, S7, BACnet, IEC 60870-5-104
  • Multi-dimensional risk scoring, and finding lifecycle with SLA and ITSM integration
  • Three tiers: sensor appliance → Node.js backend and graph engine → React command centre

Identity & access management    OT / IoT security

AphelioNYX / AD Pen-Test / Posture Air-gapped · rules v. offline bundle
62
Delegation and Kerberos11
Certificate services (ADCS)6
Privileged group hygiene19
Stale and orphaned objects47
Findings against service level
3Critical · 7d
14High · 30d
38Medium · 60d
91Low · 90d
Illustrative interface · sample tenant dataNo outbound connection is made at any point

Who runs it

Fit

Built for the environments that cannot call out.

  • Defence contractors
  • Regulated banks
  • Hospitals & healthcare
  • OT / ICS plants
  • Government tenants
  • MSSPs

If your environment has a working outbound path and nobody objects to telemetry leaving it, a cloud identity platform is very probably the better purchase, and we will say so on the call. AphelioNYX exists for the other case, where egress is prohibited, where a tenant boundary has to be absolute, and where the alternative to an offline tool is a spreadsheet.

We wrote about why that gap exists, including what you give up by running offline. It is a real trade, and it is worth understanding before you buy either kind.

Security & trust

Trust

The platform holds your data, so here is how it holds it.

  • EncryptionTLS 1.2 or later in transit; AES-256 at rest. In an air-gapped deployment there is no transit beyond your own network.
  • AccessSingle sign-on with SAML, role-based access control, and audit logging of every administrative action.
  • IsolationComplete tenant isolation. An MSSP running many tenants shares no data path between them.
  • ResilienceHardened infrastructure, automated backups, geographic redundancy, and recovery objectives that are tested rather than assumed.

AphelioNYX is SOC 2, ISO and GDPR compliant. Attestations are available on request under NDA. We would rather hand you the report than print a badge, and you will find no certificate imagery anywhere on this site for that reason.

Getting started

Onboarding

Six weeks to a monitored baseline.

  1. 01

    Kick off and connect

    Scope the tenancy, deploy the sensor, and connect the systems of record. In an air-gapped deployment this is where the offline rule bundle is staged and verified.

    Week 1
  2. 02

    Map and assign

    Map your existing controls onto every framework you are asked for, and give each one an owner. The overlap between frameworks is the work you only do once.

    Weeks 2-3
  3. 03

    Close the gaps

    Work the open findings in priority order, with evidence collected automatically as each one closes rather than gathered again at audit time.

    Weeks 4-6
  4. 04

    Monitor and audit

    Continuous monitoring from then on: a control that drifts raises a finding the day it drifts, and the audit export is always current.

    Ongoing

Illustrative benchmarks, stated as such in the source deck and stated as such here: teams commonly report 1,000+ hours spent per audit, three to six months to a first certification, 40%+ overlap between control sets, up to 80% less manual effort once evidence is automated, and two to three times faster audit preparation. These are indicative of the category, not measurements of your organisation or promises about it.

Forty-five minutes, a personalised demo, and a free readiness assessment.

We will run AphelioNYX against a scenario that looks like your environment, not a scripted one, and if a cloud platform would serve you better, we will tell you that instead.