About TriStiX

Built in Alicante for the EU mid-market.

TriStiX S.L. is a cybersecurity company in Alicante, Spain, that builds NetSenX. NetSenX is a Network Detection and Response (NDR) platform for EU mid-market organisations that detects attacks from network behaviour, explains every alert in plain language and keeps customer data in the EU. We exist because EU mid-market security teams deserve enterprise-grade NDR without enterprise-grade complexity or cost.

Mission

Cyber-resilient EU companies, without the alert factory.

Make EU companies cyber-resilient through mathematically bounded detection, AI-augmented response, and audit-proof compliance — without sacrificing privacy, sovereignty, or budgets.

We do this by treating three things as non-negotiable: a conformal layer that states the false-positive bound a tenant's own calibration data supports and withholds a figure when it supports none (the NetSenX Math Guarantee), an EU data and regulatory perimeter, and a price point that a mid-market CFO recognises as defensible. Everything else in the product is in service of those three.

TriStiX S.L.

Who builds NetSenX

TriStiX S.L.

The Spanish company that builds and operates NetSenX, from Alicante.

  • ISO/IEC 42001 lead implementer on our teamA personal credential for implementing an AI management system. TriStiX S.L. itself holds no ISO/IEC 42001 certificate; that is a Q3 2026 target.
  • Company research on arXivTriStiX S.L. research preprint arXiv:2603.28558v1 — multi-valued logic for compliance applications
  • Built in-houseDetection engine, agent, dashboard and this site are written and reviewed by TriStiX S.L. — no white-labelled third-party engine
  • EU companyTriStiX S.L. — Av. Maisonnave 41, 3º, 03003 Alicante, España · NIF B-26925016

NetSenX was started by a practitioner who spent a decade in EU mid-market security teams watching the same pattern repeat. The detection stack gets louder every quarter, the budget gets tighter every fiscal year, and the alert backlog grows on a schedule no human SOC can sustain. Vendors call this “coverage.” The teams living with it call it an alert factory.

NetSenX exists because more alerts do not buy more security. The mathematical work behind our proprietary LGGT+ engine — published as arXiv:2603.28558v1 — gives us an upper bound on false positives that is derived, not tuned. That bound is not a marketing claim. It is an inequality, and anyone with a copy of the paper can check the derivation. How tight it binds on your network depends on how much labelled benign traffic has been calibrated — which is why the product tells you the bound your own data supports, and tells you plainly when it does not yet support one.

The rest of NetSenX exists to make that guarantee operational: an AI Analyst Core that writes the analyst notes, an audit log that survives the auditor, an AI management system being built to ISO/IEC 42001 so it survives the regulator. EU mid-market security teams deserve enterprise-grade NDR without enterprise-grade complexity or cost. That is the company.

What we are building next

  • Triple Crown finish — SOC 2 Type II + ISO 42001 + ISO 27001 by 2027-Q2.
  • EIC Accelerator application in Q4 2026 to scale the EU mid-market go-to-market.
  • First engineering and customer-success hires in Q3-Q4 2026 — Alicante and remote-EU.

Company facts

The boring details, on the record.

Vendor-onboarding teams ask the same questions every time. Here are the answers, plainly.

Founded
2024
HQ
Alicante, Spain (EU)
Legal form
TriStiX S.L. — Sociedad Limitada
Funding
Bootstrap · EIC Accelerator application Q4 2026
Compliance
SOC 2 Type II + ISO 42001 + ISO 27001 by 2027-Q2
Team
1 founder · hiring Q3-Q4 2026

Operating principles

Three rules. No exceptions.

01

Math before marketing

Every detection claim has a mathematical foundation. If we cannot prove a bound, we will not put a number on a slide.

02

Sovereign by design

EU data, EU regulations, EU language fluency. No data leaves eu-west-1. No US sub-processor touches customer payloads.

03

Audit-first

Compliance is a feature, not a friction. The evidence pack is built before the marketing site is built.

Talk to the founder

We answer our own email.

No SDR funnel, no junior gatekeeper. The founder reads every message sent to this address and replies within one EU business day. If your question is technical, it will be answered by the person who wrote the code.

[email protected] · Alicante, EU · CET (UTC+1)