AphelioNYX
One platform for compliance, detection and the identity paths nobody maps.
Three modules, one sign-on: Compliance Hub for the evidence, MDR for the watch, and AD Pen-Test for the identity graph. The last of those was built for a requirement most identity tools quietly assume away: a working internet connection.
Where egress is forbidden (defence programmes, OT plants, classified environments), AD Pen-Test runs sensor, graph engine and command centre entirely inside your perimeter, and nothing phones home because there is nothing to phone. Where it is not, the same graph runs alongside Compliance Hub and MDR.
Platform capabilities
AD Pen-Test outbound calls: 0, by design, not by firewall rule
Module 01
01 / 03Compliance Hub: enterprise compliance, automated.
One platform for every framework you are asked for. Map controls once, collect the evidence automatically, and stay audit-ready all year instead of for the six weeks before an assessor arrives.
The cost of fragmented compliance is rarely the audit fee. It is the enterprise deal that stalls at procurement because a security questionnaire cannot be answered inside the quarter.
- Frameworks Hub: SOC 2, ISO 27001, GDPR, HIPAA, PCI DSS, ISO 27701 and the DPDP Act, in one control set
- Automated evidence: collected from the systems of record on a schedule, not screenshotted the night before
- Continuous monitoring: a control that drifts raises a finding the day it drifts
- Audit-ready reports: exportable, with the evidence attached to the control it answers
- Also ships: policy management, risk register, access reviews, awareness training, phishing simulation, tabletop exercises, vendor risk assessment, multi-tenant
Module 02
02 / 03MDR: someone is watching, and they can act.
Managed detection and response, around the clock, combining SIEM correlation with analysts who are allowed to do something about what they see. A detection nobody acts on is a log line.
The difference between a monitored organisation and an unmonitored one is not the number of alerts produced. It is how many were triaged, by a person, before the shift ended.
- Twenty-four-hour monitoring, with real-time analysis rather than a morning report
- SIEM correlation across endpoint, identity, network and cloud telemetry
- Triage by an analyst, with a documented disposition on every alert that closes
- Containment actions agreed in advance, so the first response does not wait for a meeting
- Handover into incident response the moment an alert becomes an incident
Module 03
03 / 03AD Pen-Test: offline by design, zero cloud dependency.
Active Directory posture analysis, transitive attack-path graphing and a real-time detection engine, running entirely inside your perimeter, for the environments where a collector calling a vendor endpoint would be a finding of its own.
- Posture analysis across the directory, with hybrid on-premises and cloud identity in one view
- Transitive attack-path graphing: the chain, not the isolated misconfiguration
- OT and ICS discovery with Purdue modelling: Modbus, OPC-UA, EtherNet/IP, DNP3, S7, BACnet, IEC 60870-5-104
- Multi-dimensional risk scoring, and finding lifecycle with SLA and ITSM integration
- Three tiers: sensor appliance → Node.js backend and graph engine → React command centre
Who runs it
FitBuilt for the environments that cannot call out.
- Defence contractors
- Regulated banks
- Hospitals & healthcare
- OT / ICS plants
- Government tenants
- MSSPs
If your environment has a working outbound path and nobody objects to telemetry leaving it, a cloud identity platform is very probably the better purchase, and we will say so on the call. AphelioNYX exists for the other case, where egress is prohibited, where a tenant boundary has to be absolute, and where the alternative to an offline tool is a spreadsheet.
We wrote about why that gap exists, including what you give up by running offline. It is a real trade, and it is worth understanding before you buy either kind.
Security & trust
TrustThe platform holds your data, so here is how it holds it.
- EncryptionTLS 1.2 or later in transit; AES-256 at rest. In an air-gapped deployment there is no transit beyond your own network.
- AccessSingle sign-on with SAML, role-based access control, and audit logging of every administrative action.
- IsolationComplete tenant isolation. An MSSP running many tenants shares no data path between them.
- ResilienceHardened infrastructure, automated backups, geographic redundancy, and recovery objectives that are tested rather than assumed.
AphelioNYX is SOC 2, ISO and GDPR compliant. Attestations are available on request under NDA. We would rather hand you the report than print a badge, and you will find no certificate imagery anywhere on this site for that reason.
Getting started
OnboardingSix weeks to a monitored baseline.
- 01
Kick off and connect
Scope the tenancy, deploy the sensor, and connect the systems of record. In an air-gapped deployment this is where the offline rule bundle is staged and verified.
Week 1 - 02
Map and assign
Map your existing controls onto every framework you are asked for, and give each one an owner. The overlap between frameworks is the work you only do once.
Weeks 2-3 - 03
Close the gaps
Work the open findings in priority order, with evidence collected automatically as each one closes rather than gathered again at audit time.
Weeks 4-6 - 04
Monitor and audit
Continuous monitoring from then on: a control that drifts raises a finding the day it drifts, and the audit export is always current.
Ongoing
Illustrative benchmarks, stated as such in the source deck and stated as such here: teams commonly report 1,000+ hours spent per audit, three to six months to a first certification, 40%+ overlap between control sets, up to 80% less manual effort once evidence is automated, and two to three times faster audit preparation. These are indicative of the category, not measurements of your organisation or promises about it.
Forty-five minutes, a personalised demo, and a free readiness assessment.
We will run AphelioNYX against a scenario that looks like your environment, not a scripted one, and if a cloud platform would serve you better, we will tell you that instead.