NetSenX product capabilities
Six capabilities, one audited detection stack.
Every NetSenX capability ships with an auditable model lineage and a plain-language explanation, and detection output passes through a conformal layer that states the confidence behind it. Below is what each one does — and why it changes the operating cost of NDR for EU mid-market teams.
Bounded false positives
NetSenX Math Guarantee
A split-conformal layer derives a finite-sample false-positive bound on the alerts the engine surfaces, at a configurable confidence level, from your own analyst-labelled benign traffic. The bound is a property of the construction, not a threshold tuned until the numbers looked good.
Each alert ships with a calibrated confidence interval, model version, and lineage. Your auditors see the same evidence your SOC sees.
Your dashboard reports the bound your calibration data currently supports — and reports that it supports none yet, naming what would close the gap, rather than showing a figure it cannot back.
Highlights
- Split-conformal bound at a stated confidence level
- Honest not-yet-supported state instead of a fabricated number
- ISO 42001 AIMS-governed model lineage
Lateral movement
NetSenX Layer 3 Graph Intelligence
Per-flow detection catches what happens on a wire. Graph detection catches what happens across a network — adversary playbooks rarely stop at one host.
Layer 3 correlates hosts, users, and processes into a behavioral graph, surfacing lateral movement, beacon clusters, and credential abuse patterns invisible to per-flow detection.
Every Layer 3 alert ships with the underlying subgraph as evidence, ready to drop into an incident write-up or a regulator filing.
Highlights
- Detects lateral movement and C2 clusters
- Subgraph evidence attached to every alert
- Hosts, users, and processes correlated together
Plain-language triage
NetSenX AI Analyst Core
Most NDR alerts arrive as JSON and leave as tickets. NetSenX ships every alert with a senior-analyst-quality note — what happened, why it matters, what to do next.
Notes are generated under the ISO 42001 AIMS with version-pinned models and full lineage. They are pre-tagged for CRA Art. 14 and NIS2 Art. 21 reporting, so your incident report drafts itself.
The analyst note never replaces your team. It removes the 15-minute warm-up every analyst does before they can act.
Highlights
- Plain-English explanation per alert
- Pre-tagged for CRA / NIS2 reporting
- Auditable model lineage on every note
Day-one detection
NetSenX FastStart
Traditional behavioral NDR needs 14–30 days to establish a baseline. NetSenX FastStart starts detecting on day one, drawing on anonymized cross-customer patterns rather than waiting for your own traffic to teach the model.
Patterns are shared as hardened intelligence, never as raw flows. Your data stays inside your perimeter; the patterns travel.
By week two, FastStart hands off to your tenant-local baseline. By week four, the system is calibrated to your environment with no learning gap and no detection vacuum.
Highlights
- Detection from day one, not day 30
- Privacy-preserving cross-customer intelligence
- Smooth handoff to tenant-local baseline
Pre-payload identification
NetSenX TLS Fingerprint Engine
Adversary tooling leaves a TLS-handshake signature long before it leaves a payload. NetSenX identifies malicious tooling at the handshake — before any DNS lookup, before any signature, before any IOC feed has caught up.
The engine fingerprints client behavior on encrypted channels without decrypting them. Privacy and detection in the same step.
Integrated into both Layer 1 and Layer 3, so a single handshake feeds both the behavioral score and the graph correlation.
Highlights
- Detection before payload or DNS lookup
- No TLS decryption required
- Feeds both behavioral and graph layers
Evidence packs included
Audit-Ready Compliance
Compliance is a feature, not a cost. NetSenX ships pre-built evidence packs for SOC 2, ISO 42001, ISO 27001, CRA Art. 13/14, NIS2 Art. 21, GDPR by design, and AI Act Art. 50.
Every alert, every model version, every configuration change is logged into an evidence trail your auditors can request directly. No screenshots, no last-minute scrambling.
Triple Crown attestations are in flight: SOC 2 Type I in Q2 2026, ISO 42001 in Q3 2026, ISO 27001 in Q4 2026. We publish progress, not vapor.
Highlights
- SOC 2 + ISO 42001 + ISO 27001 in flight
- CRA / NIS2 / GDPR / AI Act evidence built-in
- Direct auditor access to evidence trail
The proprietary LGGT+ engine
Behavioral analysis meets multi-valued logic.
NetSenX uses our proprietary LGGT+ engine combining behavioral analysis with multi-valued logic — detecting threats unknown to signatures, resilient to malware variants. The engine evaluates threats on a continuous risk spectrum rather than binary safe/unsafe, providing nuanced detection that mirrors real-world threat ambiguity.
Internal architecture details are proprietary. Customers receive an ISO 42001-aligned, AIMS-managed system with mathematical guarantees on false-alarm rate.
Continuous risk spectrum
Multi-valued evaluation, not binary thresholds.
- SafeEstablished baselines, peer-aligned behavior
- AmbiguousNovel, but not yet adversarial
- SuspiciousDiverging signals, recommended review
- MaliciousAdversarial pattern, math-bounded alert
Marker position is illustrative. Every NetSenX alert ships with a confidence interval and an analyst note explaining where on the spectrum the event landed and why.
Detection architecture
Two layers, one verdict you can defend in an audit.
NetSenX combines behavioral signal at the flow level with graph correlation at the network level. Both layers carry mathematical evidence and ISO 42001-governed model lineage.
Layer 1
Behavioral (LGGT+)
What it sees
- Per-flow features: timing, volume, periodicity
- Endpoint and host telemetry alignment
- Encrypted-traffic shape and TLS handshake fingerprints
What it catches
- Beaconing and command-and-control
- Tooling identifiable at the TLS handshake
- Behavioral drift indicating compromise
Math guarantee
Conformal false-positive bound on Layer 1 alerts, ISO 42001-governed
Layer 3
Graph Intelligence
What it sees
- Correlations across hosts, users, and processes
- Multi-hop network paths and asset relationships
- Temporal clusters of related events
What it catches
- Lateral movement across the network
- Coordinated activity invisible to per-host detection
- Insider misuse patterns spanning subnets
Math guarantee
Graph-level evidence chains, attached to every alert
Detection pipeline
Packets
Mirrored capture, EU-resident
Behavior
LGGT+ continuous risk score
Graph
Layer 3 host/user correlation
Alert
Bounded FAR + analyst note
NetSenX Math Guarantee
A false-positive bound you can check, not a number you have to believe.
Most NDR vendors quote false-alarm rates the same way restaurants quote portion sizes: with hope and a smile. NetSenX takes the opposite route. A split-conformal layer sits after detection and derives a false-positive bound on the alerts the engine surfaces, at a configurable confidence level, from your own analyst-labelled benign traffic. Your dashboard reports the bound that data currently supports — and reports that it supports none yet, rather than showing you a figure, when the calibration set is too small.
Split-conformal prediction
Every NetSenX alert carries a calibrated confidence interval. The false-positive bound among engine-surfaced alerts comes from the construction of the predictor at a stated confidence level — it is not a threshold tuned until the numbers looked good.
ISO 42001 AIMS governance
Models are version-pinned, datasheets are published, lineage is auditable. The Math Guarantee is governed under our AIMS, not a marketing footnote.
What we commit to
We commit to the mechanism and to the evidence: the bound your calibration data supports, the sample size behind it, and an honest not-yet-supported state when it does not. We do not publish a false-alarm figure we have not measured on your data.
Not yet calibrated
Too little analyst-labelled benign traffic to support any bound. The product says exactly that, and names what would close it — it does not show a zero.
Active — wider bound
Calibration data supports a bound, but a looser one than the configured target. The product states that it is standing behind the wider bound instead — and still shows no figure, because the tighter target it was aiming at was never reached.
Active — target bound
Calibration size supports the configured confidence level. This is the one state that carries a number — and it never arrives alone: the bound, the count of audited samples behind it and the window they were measured over are shown together.
Awaiting recalibration
The calibration behind the bound has aged out, or the traffic it was built on has drifted away from what the network looks like now. The bound is withdrawn until a fresh calibration replaces it — a stale number is not kept on screen because it used to be true.
Re-validating
A calibration update is being verified before it takes effect. The previous claim is withdrawn while that runs.
These are the states the product actually serves — no state reports a bound the calibration data does not support. We do not publish comparison figures for other vendors: we have not run those tests, and quoting someone else's benchmark as our own evidence is exactly the practice this page exists to reject.
NetSenX AI Analyst Core
Every alert reads like it came from a senior analyst.
Raw alert data is paired with a plain-language note: what happened, why it matters, and the recommended response — pre-tagged for your CRA Art. 14 and NIS2 Art. 21 reporting obligations.
- alert.id
- ALR-2026-0521-04183
- alert.timestamp
- 2026-05-21T09:14:22+02:00
- alert.severity
- high
- alert.layer
- L1 behavioral + L3 graph
- src.host
- finance-srv-04.corp.local
- src.ip
- 10.42.18.27
- dst.fqdn
- delta-cargo-track[.]xyz
- dst.ip
- 185.244.62.117
- dst.tld_registered
- 2026-05-21T03:11:00Z (6h ago)
- protocol
- TLS 1.3 / HTTPS
- bytes.up
- 2.4 KB / 90s
- bytes.down
- 182 B / 90s
- pattern
- low-volume periodic beacon, jitter 5%
- detection.confidence
- 0.94
- conformal.bound
- served at the tenant's calibrated confidence level
Beaconing detected from finance-srv-04 to a previously unseen domain (delta-cargo-track.xyz) registered 6 hours ago. Outbound payload is small, periodic, and low-jitter — a pattern consistent with initial-access tradecraft documented in recent ENISA threat reports.
The destination IP belongs to a hosting netblock that has been associated with short-lived adversary infrastructure in three prior incidents on the NetSenX cross-customer pattern bank (anonymized). The graph layer also observed two finance-subnet peers (finance-srv-02, finance-srv-09) issuing DNS lookups for the same domain within the last 90 minutes.
Recommended response
- Isolate finance-srv-04 from the production VLAN.
- Capture a memory image before reboot for forensic review.
- Sweep the finance subnet for peer hosts contacting the same FQDN or IP.
- Open a ticket against your IR runbook; this alert ships pre-tagged for CRA Art. 14 incident logging.
Privacy-preserving intelligence
Learn from the fleet. Share nothing of yourself.
NetSenX customers contribute anonymized behavioral patterns — never raw flows, never identifiable telemetry. Patterns are aggregated, hardened, and redistributed as cross-customer intelligence that powers FastStart and the Math Guarantee.
- Anonymized at the source — your data never leaves your tenant in raw form.
- GDPR-by-design data minimization, with a DPA published upfront.
- Patterns governed under the ISO 42001 AIMS, with opt-out at any time.
Book a 20-minute demo to see all six in action.
We will walk a live alert from packet capture to analyst note, with the audit evidence trail visible at every step. Bring your hardest question.