We got tired of
renting our own data.

Legacy SIEMs charge by the gigabyte. Network monitoring tools charge by the sensor. They hold your data hostage behind metered APIs.

We built the Npro Platform to run on your infrastructure. You hold the keys. You own the data.

Data Sovereignty

Your logs stay in your VPC. Whether it's HIPAA, PCI-DSS, or GDPR, data never leaves your premise. Air-gap friendly by design.

Hyper-Efficiency

Written in Rust and Go. Our backend sips CPU while processing thousands of events per second. No Java bloat.

Total Convergence

Npro (Security) and NRTG (Network) share one database. Correlate a firewall breach with a bandwidth spike instantly.

The Pipeline

How we ingest, process, and store your data without the "Index Tax".

1
Ingestion Sources
Npro Agents SNMP
2
Normalization Engine
JSON parsing & Threat Intel tagging.
3
ClickHouse OLAP
Columnar storage. 70% compression. Millisecond queries.

Why ClickHouse?

Standard databases (PostgreSQL/MySQL) choke on logs. Elasticsearch is RAM-hungry. ClickHouse allows us to store billions of rows on standard hardware with instant retrieval.

API-First Design

Every chart in our dashboard is powered by the same REST API available to you. Automate your SOC, build custom reports, or integrate with ticketing systems programmatically.

The "Rent vs Own" Reality

Feature
Npro Platform
SaaS Giants
Data Retention
Unlimited (Your Disk)
Expensive (7-30 Days)
Pricing Model
Flat Agent License
Metered Ingestion (GBs)
Privacy / Air-Gap
100% On-Premise
Shared Public Cloud
Deployment
Ubuntu / Debian
Proprietary Black Box
New Advanced Detection

Risk-Based Alerting & Offense Correlation

Raw alerts generate noise. Offense correlation cuts through it. nPro's correlation engine groups related security events from the same agent into a single Offense — a ranked, MITRE ATT&CK‑tagged threat cluster your SOC team can triage in one place.

Event Correlation

Related alerts from the same agent are grouped into a single offense. One investigation card replaces thousands of raw log lines.

MITRE ATT&CK Mapping

Each offense surfaces the ATT&CK tactics involved — Defense Evasion, Lateral Movement, Privilege Escalation — mapped to the kill chain automatically.

Risk Scoring

Every offense is scored 0–100. Analysts see Critical, High, Medium, and Low priorities at a glance — no manual triage of thousands of raw events required.

SOC Workflow

  • Mark offense as Investigating to claim ownership
  • Add Analyst Notes at the offense level for shift handover
  • Close as Resolved or flag as False Positive
  • Full first_seen / last_seen timestamps for incident timelines

What an Offense Captures

  • Agent ID and device hostname
  • Threat Intelligence IOC match indicator
  • Event volume over 24 h — distinguishes sustained attacks from noise
  • Source and destination IPs involved
Threat Intelligence

STIX 2.1 / TAXII 2.1 Threat Intelligence

nPro connects to any STIX 2.1 / TAXII 2.1 feed and automatically matches ingested indicators of compromise against your live log traffic — entirely on-premise, with no data leaving your perimeter.

Connect Any Feed

Your internal MISP instance, commercial providers, or open feeds like AlienVault OTX. Configured from the dashboard — no config files.

Real-Time IOC Matching

Indicators are matched against incoming log traffic in real time. Offenses from IOC-matching agents are flagged with a Threat Intel badge.

Air-Gap Compatible

Pull feeds manually or via scheduled sync on air-gapped networks. The matching engine runs locally — no outbound calls during detection.

Offense Integration

IOC hits surface directly inside the Offense Monitoring view — analysts see which offenses involve known malicious indicators without switching tools.

Our Mission: Security Without Compromise

nPro was built on a simple belief: every organisation, regardless of size or geography, deserves enterprise-grade security visibility without being forced to send sensitive data to a third-party cloud. We founded nPro to give DevOps teams, security engineers, and IT administrators the tools they need to defend their infrastructure while keeping full control of their data.

Why We Built nPro

The SIEM market has long been dominated by expensive cloud-based platforms that charge per GB, require lengthy professional services engagements, and store your most sensitive security telemetry on infrastructure you do not control. For organisations in Southeast Asia, the Middle East, and emerging markets, this creates both a financial barrier and a regulatory compliance risk. nPro removes both obstacles with a self-hosted, open-architecture platform that deploys in minutes.

Compliance-First Architecture

nPro is designed for regulated industries. Healthcare organisations managing patient data, financial institutions under central bank supervision, and government agencies operating classified networks all require that security logs remain within their sovereign perimeter. nPro's on-premise architecture satisfies GDPR, PDPA, ISO 27001, PCI-DSS, and sector-specific data residency mandates without requiring any architectural compromise.

Built by Security Engineers

Our team combines deep experience in threat detection, network engineering, and large-scale distributed systems. We have operated SOC environments, deployed SIEM platforms at scale, and seen firsthand how fragmented tooling creates gaps that attackers exploit. nPro integrates XDR, SIEM, and network monitoring into a unified platform specifically because we know the cost of silos in a real incident response scenario.

A Platform That Grows With You

Whether you are a 10-person startup monitoring a handful of servers or a 10,000-node enterprise with distributed sites across multiple countries, nPro scales to match your environment. Our ClickHouse-powered backend handles billions of log events with sub-second query performance. Distributed probes enable monitoring of remote sites without centralising all network traffic through a single location.

Trusted Across Industries

nPro is deployed by organisations in healthcare, financial services, telecommunications, manufacturing, and government. Our managed security service provider (MSSP) partners use nPro to deliver white-labelled security operations services to their clients across Southeast Asia and beyond. If you are evaluating a SIEM platform for your organisation or building a managed security offering, our team is ready to help you assess whether nPro is the right fit.

nPro AI

Online

Hi! I'm the nPro assistant. How can I help you learn about our SIEM & monitoring tools today?

Powered by nPro AI