10 Products ยท 1 Platform

The CyMesh portfolio.

Eight products, each best-in-class at its security layer. Buy them together as one platform โ€” replace 5-7 vendors and cut TCO by 62%.

๐Ÿ—๏ธ
Layer 1 ยท Infrastructure

CyForge

Hyperconverged infrastructure for the zero-knowledge era.

CyForge is HCI by Gartner's definition โ€” compute + storage + network + management converged on commodity hardware. Built on KubeVirt, Longhorn, and OVN. No proprietary appliances. No phone-home. No per-socket licensing. Replaces Nutanix and VMware VCF at half to one-third the TCO.

Use Cases

VMware refugees (Broadcom shock)

150-1,500% VCF renewal hikes have reopened every 2-year HCI plan. CyForge migrates VMs from vSphere via cross-provider migration with automatic rollback.

Cisco HyperFlex EOL migration

HX hit end-of-sale Sept 2024. Customers being pushed into Nutanix economics. CyForge runs on the same x86 hardware they already have.

Sovereign cloud for government

India DPDPA, EU NIS2, GCC nation-state requirements need air-gappable infrastructure. CyForge is sovereign by construction โ€” zero phone-home, source-code escrow.

Datacenter OEM partnerships

Yotta, CtrlS, NxtGen layer CyForge on existing capacity. They become sovereign cloud providers overnight. 70/30 revenue share.

Key Features

โšก

30-minute install

Single Helm chart. Bare metal to first VDI session in under 30 minutes.

๐ŸŒ

9 hypervisors unified

KubeVirt, libvirt, VMware, AWS, Azure, GCP, Proxmox, Nutanix, Hyper-V โ€” one API.

๐Ÿ”“

No per-socket licensing

OSS foundation. Add nodes without compounding vendor cost.

๐Ÿ›ก๏ธ

Sovereign by construction

Verified zero phone-home telemetry. Source-code escrow available.

vs Nutanix NC2: Up to 61% savings at 100 nodes / 1,000 VMs. vs VMware VCF: Up to 51% savings.
Full comparison โ†’
โš™๏ธ
Layer 2 ยท Compute / Virtualization

CyAxis

Nine hypervisors. One API. Zero lock-in.

CyAxis provides a unified VmProvider SPI across every major hypervisor and cloud โ€” provision, migrate, snapshot, scale on KubeVirt, libvirt, VMware, AWS, Azure, GCP, Proxmox, Nutanix, and Hyper-V from one control plane. No competitor covers this many providers behind a single interface.

Use Cases

Multi-cloud burst capacity

On-prem KubeVirt for baseline, burst to AWS/Azure/GCP during peaks. Same API, same audit, same identity model.

Cross-cloud VM migration

Move a VM from VMware to KubeVirt, or AWS to Azure, with validation and automatic rollback. Verified in production.

Hypervisor-agnostic DR

Primary on Nutanix, DR on Proxmox or AWS. CyAxis replicates regardless of underlying virtualization.

Engineering / dev sandboxes

Provision dev environments on the cheapest available capacity. Devs see one Terraform provider; platform team optimizes the backend.

Key Features

๐Ÿ”„

Cross-provider migration

KubeVirt โ†” VMware live-verified. Snapshot+convert+import flow for cloud providers.

๐Ÿ“Š

Unified observability

Same metrics, same logs, same alerts across all 9 providers.

๐Ÿšฆ

Honest typed failures

Returns NOT_SUPPORTED / CLOUD_IMPOSSIBLE for ops AWS can't do โ€” no fake success.

๐Ÿ‘ป
Layer 5 ยท Identity & Access

CyDusk

Zero-knowledge VDI. The credential never reaches the user.

CyDusk is a passwordless VDI broker. When a user clicks "connect to db-prod-01", the credential is fetched server-side, injected into the RDP/SSH/VNC tunnel by the broker, and never crosses the user's network. Stolen laptops, browser extensions, keyloggers, and clipboard scrapers cannot obtain the credential. Ever.

Use Cases

Contractor & third-party access

Give 200 contractors access to internal apps without ever giving them passwords. Revoke in <60s via per-session CAE.

DBA / sysadmin privileged sessions

Replace CyberArk. DBA clicks "connect", sees the session, never sees the password. Full session recording with forensic watermarking.

Remote clinician / trader desktops

Browser-only access to clinical apps and trading terminals. No local install. No VPN. No PHI/PII on endpoint. HIPAA + RBI + SEBI compliant by architecture.

Cross-border GCC engineering teams

India engineering team accesses parent-company systems. Credentials stay in the parent's vault. India endpoints see only pixels. Data residency satisfied.

Citrix replacement (cost pressure)

Citrix per-CCU pricing + NetScaler + Director adds up fast. CyDusk delivers VDI at 1/10 the list price, including FIDO2 and session recording.

Key Features

๐Ÿ”

Server-side credential injection

Patent filings in progress. Verifiable property: stolen endpoints cannot exfiltrate the credential.

๐Ÿ”‘

FIDO2 + PIV / CAC native

Passwordless authentication built in. No paid add-on. Smart cards work via PKCS#11 redirection.

๐ŸŽฅ

Forensic-watermarked recording

Per-tenant DCT watermark. Every recording cryptographically attributable to the user session.

๐ŸŒ

Browser-only access

RDP, SSH, VNC, SPICE all rendered in browser via Guacamole. No client install, no VPN, no training.

๐Ÿชž
Layer 6 ยท Session / Browser

CyLens

Remote Browser Isolation. Pixels only. Nothing else.

CyLens runs Chromium in an isolated server-side container. Users get only an AES-256 pixel stream. Zero-days, phishing pages, malicious USB devices, and weaponized downloads never reach the endpoint. Includes hardware-accelerated WebRTC, H.264 fallback, CDP screencast, PKCS#11 smart-card redirection, USB/IP device forwarding, and CDR file sanitization.

Use Cases

High-risk web access

Analysts who must browse unknown URLs (threat intel, OSINT, customer support links) do so in CyLens. Zero endpoint exposure to drive-by malware.

SaaS app isolation

Sensitive SaaS (Salesforce, internal portals) opened only in CyLens. DLP + clipboard controls + screenshot blocking enforced at the pixel layer.

Defence contractor browsing

Engineering staff on classified networks browse via CyLens. Zero data ever lands on the workstation; export-control compliance enforced.

Citrix Secure Browser replacement

Citrix charges premium add-on rates/user for the equivalent capability. CyLens ships at the platform's bundled rate as part of the Enterprise tier.

CDR sanitization for downloads

Every file downloaded through CyLens is sanitized โ€” macros stripped from Office docs, exploits removed from PDFs, archives reconstructed clean.

Key Features

๐Ÿ“บ

5 streaming modes

WebRTC (<200ms), H.264 hardware-accelerated, CDP screencast โ€” works on any endpoint.

๐Ÿชช

PKCS#11 remote signing

Smart cards stay at HQ while sessions run in the cloud. WebAuthn / FIDO2 passkeys via redirection.

๐Ÿงผ

CDR pipeline

Content Disarm & Reconstruct on every download. Macros, scripts, embedded objects stripped.

๐Ÿท๏ธ

Forensic watermarking

Per-tenant DCT watermark on every pixel stream. Screen captures stay attributable.

๐Ÿ“œ
Layer 4 ยท Policy / Governance

CyMatrix

One policy hierarchy. From tenant to packet.

CyMatrix is a hierarchical, most-restrictive-merge policy engine. NetworkPolicy, RuntimePolicy, DevicePosturePolicy, GeolocationPolicy, and DLP (380+ patterns with real validators โ€” IBAN MOD-97, Aadhaar Verhoeff, Luhn) flow from SYSTEM โ†’ TENANT โ†’ NETWORK โ†’ VM. Translated to OVN ACLs in real-time and enforced at the logical switch layer.

Use Cases

Multi-tenant SaaS isolation

One tenant's policy can never expose another tenant's data. OVN address-set isolation enforces at the network layer; DLP enforces at the data layer.

India DPDP compliance

380+ DLP patterns include Aadhaar (Verhoeff-validated), PAN, GST, bank IFSC. Real validators, not regex approximations.

Geolocation-based access

Impossible-travel detection (Mumbai login + London login 10 minutes later = blocked). Country-of-origin enforcement for export controls.

Network microsegmentation

VM-level firewall rules synthesized from policy. Hot-reload, no agent. OVN translates declarative intent to flow rules.

Forcepoint DLP replacement

Forcepoint is moving to SaaS-only. CyMatrix DLP is on-prem and integrated into VDI/RBI/audit โ€” no separate scan agent on endpoints.

Key Features

๐Ÿ›๏ธ

Hierarchical merge

Higher-scope policy wins on conflict. SYSTEM > TENANT > NETWORK > VM.

๐Ÿ”

380+ DLP patterns

Real validators (IBAN MOD-97, Aadhaar Verhoeff, Luhn) โ€” not regex approximations.

โšก

Real-time OVN sync

Policy change to network ACL in <1s. Hot reload, no restart.

๐Ÿ“‹

365-day audit trail

Every policy change attributed, immutable, exportable to SIEM.

๐Ÿ”
Layer 7 ยท Data & Secrets

CyVault

Per-tenant key derivation. KEK never on disk. Sovereign by construction.

CyVault is a credential vault built on HashiCorp Vault Raft 3-node + Transit envelope encryption. Per-tenant keys are derived via HKDF, so a leak of one tenant's derived key never compromises another tenant. The Key Encryption Key (KEK) lives only in Vault Transit โ€” never on disk, never in environment variables, never in memory longer than needed.

Use Cases

Multi-tenant credential isolation

Each tenant gets HKDF-derived keys. A compromise of one tenant cannot decrypt another. Master key stays in Vault Transit.

Provider credential encryption

Cloud provider passwords (AWS, Azure, GCP) encrypted at rest per-tenant. Vault Transit Phase 3 promoted in production.

VDI session ticket encryption

Every VDI ticket wrapped with AES-256-GCM before Redis persist. Closes the plaintext-credential vulnerability that most VDI brokers ship with.

Session recording envelope

Per-session DEK wrapped via Vault Transit. Recordings cryptographically tied to session metadata.

Key Features

๐Ÿงฌ

Per-tenant HKDF derivation

Tenant ID + master key โ†’ derived key. No cross-tenant blast radius.

๐Ÿ’Ž

Vault Transit envelope

KEK never on disk, never in env. Only Vault knows the master.

๐Ÿ”„

Zero-downtime key rotation

Rotate KEK; old DEKs still decrypt. Background re-encrypt without taking the system offline.

๐Ÿค–
Layer 8 ยท Intelligence

CyPilot

AI copilot grounded in your live cluster โ€” approval-first by design.

CyPilot is a conversational AI assistant for operations and troubleshooting. Powered by an on-prem LLM (phi3:medium-128k) + RAG over your knowledge base + real-time cluster state. Intent parser classifies risk (READ_ONLY / LOW_RISK / DESTRUCTIVE). LOW_RISK operations auto-execute; DESTRUCTIVE always requires explicit approval. No autonomous-execute path on mutating operations. Ever.

Use Cases

L1/L2 ticket resolution

"VM X is unreachable" โ†’ CyPilot runs diagnostics, suggests fix, runs LOW_RISK remediation if confidence >0.85. Operator approves anything risky.

New SRE onboarding

Junior SREs ask CyPilot how to do things. Grounded in your actual runbooks (RAG). No more "wait for the senior".

Compliance Q&A

"How are PHI records encrypted in this cluster?" โ†’ CyPilot answers with cluster-specific config + audit trail, not generic docs.

Incident war room

During incidents, CyPilot pulls correlated signals (CyOptics + Prometheus + logs) and proposes the most likely root cause. With citations.

Key Features

๐Ÿ 

On-prem LLM (Ollama)

phi3:medium-128k. No prompt data leaves your cluster. Sovereign AI.

๐Ÿ“š

RAG over your knowledge

90+ default knowledge entries; ingests your runbooks. nomic-embed-text embeddings, cosine similarity.

๐Ÿ›‘

Approval-first

DESTRUCTIVE actions never auto-execute. LOW_RISK allowlist is narrow + explicit.

๐Ÿฉบ
Layer 8 ยท Autonomous Response

CyGuru

Self-healing AI. Alert in, remediation out โ€” with audit, dedup, and approval gates.

CyGuru is the alert-driven self-heal pipeline. Two detection inputs (Alertmanager webhook + 60s SelfMonitorLoop probes), one dedup layer (60-minute window), one approval gate (default OFF for destructive), one executor. Handlers ship for pod crashloops, MongoDB rolling restarts, node memory pressure cordoning, and stale OVN chassis recovery. Every action audited; every action reversible.

Use Cases

Pod crashloop auto-recovery

Crashloop >3 restarts in 5min โ†’ CyGuru proposes pod-restart with audit. Admin approves; executor runs; success metric exported.

MongoDB rolling restart on outage

Mongo replica becomes unreachable โ†’ CyGuru proposes safe rolling restart. Avoids 3am pages for the SRE on-call.

Node memory pressure auto-cordon

Node >90% memory โ†’ cordon + drain non-critical pods. New schedules go elsewhere. Operator notified, not paged.

OVN stale chassis cleanup

OVN chassis registered by UUID instead of hostname โ†’ known production bug โ†’ CyGuru auto-fixes via node-agent restart.

Key Features

๐Ÿ”

Dedup window

60-minute dedup key prevents alert storms from generating remediation storms.

โœ‹

Approval-first

Default policy: human approves before execution. Trust earned over time.

๐Ÿ“ˆ

Full Prometheus metrics

proposed / deduped / approved / executed counters; duration histograms; auto-dashboards.

๐Ÿ“ก
Layer 3 ยท Network

CyOptics

AI network observability. Beautiful. Real-time. Sovereign.

CyOptics is a modern, AI-augmented network observability platform. Live flow telemetry, OVS bridge graphs, OVN ACL hit-counters, physical NIC throughput heatmaps, and AI-driven anomaly detection โ€” all in one beautiful UI. Replaces SolarWinds + ThousandEyes + parts of Datadog Network. Runs on your infrastructure. No flow data ever leaves your cluster.

Use Cases

OVN policy debugging

Which ACL rule dropped this packet? CyOptics shows the trace inline. No more ovn-trace via SSH.

VDI gateway saturation

Real-time bandwidth heatmap per gateway. AI flags when usage trends toward saturation 30 minutes ahead.

Cross-tenant leak detection

Anomaly: tenant A's pod is talking to tenant B's pod. CyOptics catches it; CyMatrix policy auto-enforces deny.

DDoS / scan detection

Sudden burst of new connections from a single source IP โ†’ AI flags as scan; CyMatrix policy can auto-block.

Compliance reporting

Where did this PHI flow go? CyOptics generates the answer in minutes, not the days a SOC team would take.

Key Features

๐ŸŽจ

Beautiful by design

Modern UI with WebGL flow graphs, heatmaps, and force-directed topology.

๐Ÿง 

AI anomaly detection

30-day baseline per flow / per service. Deviations score risk in real time.

๐Ÿ”ฌ

OVN-aware

Native understanding of OVN logical switches, ACLs, address sets. No mapping layer.

๐Ÿ“ค

SIEM forwarder

Flows + anomalies pushed to Splunk / Sentinel / QRadar in real time.

One Platform

Buy CyMesh, get all 10 products.

Enterprise tier Enterprise tier covers 1,500 users with every product included. No add-on licenses. No infrastructure surcharges. No hidden CALs.