OT Risk Visibility for Converged IT, OT & IIoT Environments
CyberDragon.ai correlates telemetry from enterprise IT and industrial OT into one compliance-ready operations loop — with hybrid post-quantum identity, OT policy compliance reporting, and multi-tenant architecture built for regulated enterprises.
A fully autonomous pipeline — ingesting OT packets and IT logs, correlating risk-chain stages, enriching with risk intelligence, and enforcing OT-safe automated workflows.
1
Edge Passive Collection
CyberDragon.ai Edge captures Modbus TCP, DNP3, and OPC-UA traffic at the plant — zero footprint, no agent on PLCs or RTUs. Events buffer offline and replay on reconnect.
2
TI Fusion & Normalize
Every event passes through 15,000+ live risk indicators (Abuse.ch, OTX, GreyNoise) and MITRE ATT&CK / ICS ATT&CK stage mapping — in-flight, before correlation runs.
3
Risk-Chain Correlation
Cascading window correlator (W15 → W60 → W24) reconstructs multi-stage campaigns including IT→OT pivots. One incident, not a thousand noise alerts.
4
OT-Safe Alert Dashboard
Temporal orchestrates approval-gated documentation playbooks and logs every step to the evidence vault. OPA independently checks every workflow against OT policy-compliance rules. Analyst Copilot documents next-step evidence with full risk-chain context.
Platform Capabilities
13 Built-In Capabilities. Zero Bolt-Ons.
Every module shares the same tenant boundary, asset inventory, evidence vault, and risk scoring — not a patchwork of integrations.
ML-DSA-65 + Ed25519 hybrid JWTs on every login, API call, and Edge→Core transport. Vault-backed signing. 7-tier RBAC via OPA. Live today, not roadmap.
ML-DSA-65Ed25519NIST FIPS 204
OT Policy Compliance Reporting
OPA independently evaluates every reporting workflow against asset-type policy allowlists, dual-approval documentation gates, and maintenance-window rules — logging the policy result for audit evidence even if a human already clicked approve.
OPADual-ApprovalPLC/HMI/RTU
Multi-Tenant MSSP Architecture
PostgreSQL row-level isolation — designed to prevent cross-tenant leakage at the database layer. MSSP Operator portal for portfolio-wide visibility, per-tenant IEC 62443 evidence mapping.
RLS IsolationMSSP PortalIsolation-First
Risk Intelligence Fusion
15,000+ live risk indicators enriching every event in-flight: Abuse.ch (10K+), MITRE TAXII, AlienVault OTX, GreyNoise internet noise filtering, and control-validation workflow integration.
Abuse.chOTXGreyNoise
OT Protocol-Native Edge
Passive Scapy/libpcap on SPAN port — zero active footprint. Native Modbus TCP + DNP3 parsing. 5,000-event SQLite offline buffer with auto store-and-forward.
Modbus TCPDNP3OPC-UA
Operations Analyst Copilot
Unified incident queue, MITRE ATT&CK timeline, Neo4j risk correlation graph, note-taking, playbook execution with Temporal approval gates, and evidence trail — all in one UI.
TemporalAutomated AlertsPlaybooks
Tamper-Evident Evidence Vault
SHA hash-chained audit trail per tenant. Every incident, playbook, compliance mapping, and policy-evaluation denial is cryptographically linked. On-demand verify API for auditors.
Hash ChainMinIOAudit-Ready
Risk Scoring & FAIR Matrix
Continuous per-asset and per-tenant FAIR-inspired risk scoring updated via Kafka delta events. MITRE technique breakdown. Asset Risk Map heatmap in Analyst Copilot.
FAIRKafkaReal-Time
Compliance Framework Management
IEC 62443-3-3, NIST CSF 2.0, ISO 27001:2022, NERC CIP — per-control evidence mapping, gap analysis, and audit-ready PDF export to support alignment with these frameworks. Not event tagging.
IEC 62443NERC CIPNIST CSF
Executive & Auditor Reporting
Template-driven PDFs in seconds: Board Summary, CISO Monthly, Auditor Packet, Gap Analysis. Live platform data — risk-chain stages, MTTD, compliance posture. MinIO-archived.
Board SummaryPDFMTTD
Analyst Copilot & Automated Alert Dashboard
LLM-guided incident triage, risk-chain visualization, and evidence-backed documentation playbooks. OPA policy checks evaluate every reporting workflow against OT safety policy and log the result before documentation is marked complete.
LLM CopilotTemporal WorkflowsOPA Policy Checks
Full-Stack Observability
Prometheus + Grafana across all 47 services. Custom cd_ metrics. Alertmanager rules for Kafka consumer lag, service health, and error rate thresholds. Platform Health dashboard.
PrometheusGrafanaAlertmanager
Deployment Options
Your Data. Your Rules. Your Deployment.
CyberDragon.ai deploys across four models — from Axix-hosted SaaS to fully air-gapped classified networks. Same platform, same capabilities, every model.
Best for: Mid-Market & MSSPs
SaaS — Axix Hosted
CyberDragon.ai Core runs in Axix's managed multi-tenant cloud. Tenant provisioned in days. Edge collectors deploy on-site and connect over PQC-secured transport. No infrastructure procurement needed.
Best for: Regulated Industries & Banking
Private Cloud — Customer VPC
Single-tenant Core in your AWS, Azure, GCP, or sovereign cloud VPC — managed by Axix. Your data never shares infrastructure with other customers. Contractual data residency without on-premises hardware.
Best for: National Utilities & Defense Contractors
On-Premises — Customer Data Center
Full CyberDragon.ai Core stack in your data center. All telemetry, evidence, and audit records remain within your physical boundary. Edge collectors connect over PQC-secured transport — data never leaves your network.
Best for: Classified Networks & Nuclear Facilities
Air-Gapped — No External Connectivity
Pre-built container image bundles + offline risk-intelligence feed packages. Edge collectors buffer events locally and sync during controlled transfer windows. Zero outbound internet required for any Core or Edge operation.
Platform Comparison
CyberDragon.ai vs Generic SIEMs & OT Monitoring Tools
Many platforms start from enterprise IT logging. CyberDragon.ai was architected OT-native from the first commit for converged IT and OT visibility.
Capability
CyberDragon.ai
Generic SIEM
OT Monitor Only
Native OT protocol parsing (Modbus, DNP3)
✔ Passive Edge
✗
✔
Hybrid post-quantum identity (ML-DSA-65)
✔ Live today
✗
✗
Risk-chain correlation (MITRE ATT&CK + ICS)
✔ Cascading W15/W60/W24
✔ Partial
✗
OT policy compliance reporting on automated workflows
Compliance is an operational outcome, not a checkbox. CyberDragon.ai maps platform-generated evidence — incidents, audit trail, playbook executions, policy-compliance evaluations — directly to specific control requirements across these frameworks. This supports evidence collection and gap analysis; it does not constitute a certification that your environment meets any framework.
IEC 62443-3-3
Maps evidence to system requirements & assurance levels for industrial automation and control systems — SR1.1 through SR7.x control families.
NIST CSF 2.0
Aligns collected evidence with Identify, Protect, Detect, Respond, and Recover functions for enterprise and converged IT/OT environments.
ISO/IEC 27001:2022
Supports evidence collection for information security management system controls and Annex A requirements with cryptographic chain-of-custody.
NERC CIP
Maps to bulk electric system control requirements. Gap analysis identifies unmet controls with evidence and gap-tracking workflows.
Why CyberDragon.ai
Built OT-Native. Not Retrofitted.
Every design decision was made for Purdue-segmented environments where incomplete policy documentation can leave safety instrumented systems without an auditable evidence trail.
Post-Quantum Identity — Today
RSA and ECDSA tokens will not withstand a cryptographically relevant quantum adversary. Every CyberDragon.ai session is signed with ML-DSA-65 + Ed25519 hybrid JWTs, Vault-backed and verifiable now — not promised in a future release.
Risk Chains, Not Alert Floods
Individual signature matches on Modbus function codes produce hundreds of disconnected alerts. CyberDragon.ai's cascading correlator (W15→W60→W24) reconstructs multi-stage campaigns into one incident with IT→OT pivot context.
OPA Policy Checks Independent of Approval
Unconstrained automated workflows that push config changes to PLCs without a policy check have caused real production outages. CyberDragon.ai's OPA policy engine evaluates every reporting workflow against OT safety rules independently — logging the result for audit evidence even after human approval.
MSSP-Native at Database Level
Single-org SIEMs force MSSPs to deploy separate instances per customer. CyberDragon.ai implements full PostgreSQL row-level tenant isolation — designed to prevent cross-tenant data leakage, with isolation checks covered in regression testing.
Proof of Integrity, Not Just Existence
Standard audit logs can be altered by anyone with database admin access. CyberDragon.ai's hash-chained evidence vault cryptographically links every entry to its predecessor — with on-demand chain verification for auditor handoff.
Detection + Validation in One Platform
Organizations run annual manual reviews with findings in spreadsheets while their SIEM generates unrelated alerts year-round. CyberDragon.ai unifies detection, risk scoring, and compliance evidence in one FAIR-aligned platform and vault.
Customer Stories
Trusted by Operations Teams Who Cannot Afford Downtime
From tier-1 energy utilities to MSSP operators managing multi-industrial portfolios.
★★★★★
“We evaluated three SIEM vendors and two OT-specific platforms before selecting CyberDragon.ai. The difference was immediate: our first OT anomaly scenario was correlated into a six-stage risk-chain incident in under fifteen seconds, with MITRE ICS techniques mapped on the timeline. The OPA policy checks gave our plant managers confidence that every reporting workflow is documented against OT safety policy before it is marked complete — that was the decision point for our board.”
CISO — Tier-1 Energy Utility
Oil & Gas · On-Premises Deployment
★★★★★
“Passive Edge collection was non-negotiable for us — we cannot install agents on safety instrumented systems. CyberDragon.ai Edge deployed in two days across three substations with zero network impact. When we lost WAN connectivity during a maintenance window, the SQLite buffer held five thousand events and replayed automatically. Our OT team finally has visibility without compromising safety.”
OT/ICS Operations Lead — Regional Electric Utility
Critical Infrastructure · SaaS Deployment
★★★★★
“Managing twelve industrial clients on separate SIEM instances was unsustainable. CyberDragon.ai's MSSP portal gives us cross-tenant incident visibility with database-level isolation we can demonstrate to auditors. Per-tenant compliance tracking against IEC 62443 means we deliver audit-ready reports without manual spreadsheet work. Our analysts handle three times the client portfolio with the same headcount.”
Director of Operations — Managed Service Provider
MSSP · Multi-Tenant SaaS
★★★★★
“Our compliance team used to spend weeks assembling IEC 62443 evidence from three different tools. CyberDragon.ai links every incident artifact to specific control IDs in the hash-chained vault — auditors get a verified chain export in minutes, not months. Detection, risk, and compliance finally share one source of truth.”
Compliance Director — Industrial Software Manufacturer
Manufacturing · Private Cloud
Pricing
Hybrid Asset-Based Pricing for Every IT/OT Deployment
CyberDragon.ai charges on value delivered: base platform fee + per-asset usage + low-cost Edge collectors to maximize telemetry coverage and reduce network blind spots.
Cancel anytime · ISA-62443-aligned · Save 17% on annual billing
Enterprise OT Continuity, Priced on Value Delivered — Not Just Hardware
Same category, transparent economics. See how CyberDragon.ai's asset-based pricing compares to platforms using per-site or opaque enterprise pricing.
Metric
CyberDragon.ai
Dragos
Claroty
MS Defender for IoT
Charging basis
Per monitored asset + platform fee
Per site / SiteStore
Per protected asset + modules
Per site or per device
Entry price
$980/mo (Standard)
~$10,000/yr entry tier
From ~$150,000/yr
$70–$400+/site/mo
300-asset example (annualized)
~$51,792–$110,160/yr
Not publicly disclosed at this scale
$150K–$1M+/yr
Requires M365 E5 / Defender P2
Native OT protocol parsing
✓
✓
✓
Partial
Post-quantum identity (ML-DSA-65)
✓Live today
✗
✗
✗
Air-gapped, no outbound internet
✓
Partial
Partial
✗
MSSP multi-tenant portal
Built-in
Partner program
Partner program
Varies by tenant
Deployment model
SaaS, Private Cloud, or Air-Gap
On-prem / hybrid
On-prem / hybrid / cloud
Cloud-connected deployment
Competitor information based on publicly available data as of July 2026; actual capabilities vary by vendor and deployment. All trademarks are property of their respective owners. Pricing figures reflect published entry tiers and industry estimates where per-asset rates are not disclosed; actual enterprise contract pricing varies by deployment size.
FAQ
Questions Operations Leaders Ask
A traditional SIEM aggregates logs and applies correlation rules — often producing high alert volume with limited OT context. CyberDragon.ai is a converged IT/OT/IoT continuity platform: passive Edge collectors parse industrial protocols natively, a risk-chain correlator reconstructs multi-stage campaigns across cascading time windows, TI fusion enriches every event in-flight, and OPA policy checks flag every reporting workflow for OT safety review. It is designed for Purdue-segmented environments, not retrofitted from enterprise log management.
No. CyberDragon.ai Edge operates as a passive collector using Scapy/libpcap packet capture on a SPAN/mirror port or network tap. It does not install software on PLCs, HMIs, RTUs, or safety instrumented systems. Edge parses Modbus TCP, DNP3, and OPC-UA from captured traffic and forwards normalized events to Core. This passive-first design is a core architectural principle.
CyberDragon.ai supports fully air-gapped deployment via pre-built container image bundles and offline risk-intelligence feed packages. Edge collectors buffer events in a local SQLite queue (5,000-event capacity) and synchronize with Core during controlled transfer windows. No outbound internet connectivity is required for detection, response, compliance, or evidence vault operation.
It means your authentication tokens are signed with both classical (Ed25519) and post-quantum (ML-DSA-65, NIST FIPS 204 / CRYSTALS-Dilithium) algorithms today — not in a future product release. Every analyst login, API call, and Edge-to-Core transport handshake uses hybrid PQC JWTs with Vault-backed key management. If a cryptographically relevant quantum computer emerges, your identity layer retains a quantum-resistant signature path. No migration project required — it is the default token format.
CyberDragon.ai supports evidence mapping for IEC 62443-3-3, NIST CSF 2.0, ISO/IEC 27001:2022, and NERC CIP — with per-control evidence linking, gap analysis, and audit-ready PDF export. Frameworks are installed per tenant via API. This helps teams align operations with framework controls; it is not a certification that your environment meets any framework. Evidence vault entries and incident artifacts are linked to specific control IDs with hash-chained integrity.
Yes. CyberDragon.ai's multi-tenant architecture is MSSP-native: PostgreSQL row-level isolation enforces tenant isolation at the database level, and the MSSP Operator role provides cross-tenant incident visibility, portfolio health dashboards, and read-only evidence access across managed customers. Your MSSP operates the service desk; you retain tenant-admin control over users, compliance frameworks, and data sovereignty. MSSP operators cannot write evidence cross-tenant — isolation is enforced by policy and tested in regression suites.
Free Trial is $0 for 7 days with 1 Edge collector. Standard is $980/mo platform fee (includes 25 assets + 2 collectors) with $12/asset/mo and $12/collector/mo overages. Premium is $1,980/mo (includes 100 assets + 5 collectors). A 300-asset deployment with 5 collectors runs about $51,792–$110,160/yr. Annual platform billing saves 17%. Online signup supports up to 50 Edge collectors; contact our solutions team for larger deployments.
SaaS tenants are provisioned in days with immediate analyst UI access. A proof-of-value deployment with one Edge collector typically completes within two to four weeks, including passive tap installation, Edge configuration, and Core tenant setup. Full on-premises or air-gapped deployments with multiple Edge sites require four to twelve weeks depending on infrastructure readiness and compliance review cycles. Contact Axix for deployment SLAs specific to your model.
Yes. You can cancel anytime from your account or by contacting support. There are no lock-in contracts or cancellation fees on self-serve plans. Access continues through the end of your current billing period.
We accept major credit and debit cards (Visa, Mastercard, Amex) through Paddle, our authorized payment provider and Merchant of Record where applicable. Card details are entered only in the secure Paddle checkout and are not stored on Axix servers.
Yes. After each successful payment you receive a receipt/invoice from Paddle for your records. Contact support if your organization needs a tax invoice or additional billing documentation.
Yes. Paid plans renew automatically at the end of each billing period (monthly or annual) until you cancel. Cancel or change your plan before the next renewal to avoid being charged for a new period.
One Platform. Every Layer of Your Continuity.
When your IT, OT, and IIoT environments share a converged risk surface, you need a continuity platform that speaks every protocol, correlates every stage, documents every exposure, and reports on every automated workflow — with cryptography built for the next decade, not the last one.