NetSenX is a Network Detection and Response (NDR) platform for EU mid-market organisations that detects attacks from network behaviour, explains every alert in plain language and keeps customer data in the EU. This post explains why we built it and what it does today.
Updated 24 September 2026: the post was revised so that every statement matches the product as it ships today. The original version listed roadmap items and certification dates that are not current.
Why we built NetSenX
Attackers rarely stay on the machine they first compromise. They beacon out to command-and-control servers, scan the network and move laterally before they take data. Those steps show up in network traffic, including traffic that is encrypted.
Mid-market security teams tell us about three problems with existing tools:
- Alerts without reasons. An alert that cannot say why it fired gets ignored.
- Data leaving the EU. Many tools process telemetry outside the EU, which complicates GDPR and NIS2 conversations.
- Prices only on request. Enterprise NDR is usually quoted per deployment, which is a long process for a team of three.
What NetSenX does today
Behaviour, not signatures
The engine scores how each host behaves on the network — timing, volume, fan-out and protocol use — so a new malware variant without a signature still leaves a trail. It looks for command-and-control beaconing, scanning and lateral movement, and unusual outbound data volume.
Every alert explains itself
Each alert lists, in plain language, the network features that drove its score (SHAP values). This is included on every plan, the Free plan too.
A false-positive bound you can check
A split-conformal layer derives a verifiable false-positive bound among engine-surfaced alerts from benign traffic your analysts label on your own network. The dashboard shows the bound only once your calibration data supports it, and says so until then. We call this the NetSenX Math Guarantee; the pricing page explains what it does and does not promise.
Encrypted traffic, never decrypted
NetSenX works from flow metadata and a few protocol fields such as the TLS handshake. It never decrypts traffic.
Reporting deadlines, tracked
Incidents are tracked against the NIS2 Article 23 deadlines — early warning within 24 hours, notification within 72 hours, final report within one month — and a GDPR Article 33 breach notification is prepared for your DPO. Submitting it stays with you.
Data in the EU
The customer database runs in Ireland (AWS eu-west-1) and the API in Frankfurt, Germany.
What NetSenX is not
NetSenX is not an EDR, an antivirus, a SIEM or a managed detection service. It adds the network view alongside those tools. SOC 2 Type I and ISO/IEC 42001 are in preparation; we do not claim either before it is awarded.
Get started
Start on the Free plan, read how NetSenX compares with other NDR vendors, or book a 20-minute demo.
Written by the NetSenX Team at TriStiX S.L., the company behind NetSenX. Questions: [email protected].