‹For your company◆
> technical view · engine room _

Threats already move
at AI speed.

Now you too.|

You’re in the engine room. An AI that actually operates your fleet (typed tools, human permission and a log of every step), not a chatbot handing you one more alert to look at. Look inside.

+7 years in IT and security Real fleet, every day Self-hosted
01 In three lines

The engine room,
without opening the blueprint.

✓One light agent per machine.

Zero-touch enrolment by domain policy: a new machine boots and joins the fleet on its own, with protection, telemetry and inventory already running.

✓Not one port exposed.

An encrypted, outbound-only channel to the server. From outside there is nothing to scan; from inside, everything is governed and logged.

✓AI with typed tools.

No free shell: the AI works through defined actions, validated and isolated per client. Anything sensitive waits for human sign-off.

02 See it

I won’t describe it. Stop it yourself.

This is the SySauron console. Press the button, watch a simulated threat come in and approve the response yourself. No sign-up, nothing to install.

response: on hold simulation// fictional data · none of this touches a real network
War Room Nordia · Central Branch ✦Ask a question or run an action⌘K LIVE
Fleet posture
0/100
11 Win10 EOL
Active threats
0
fleet quiet
Fleet operational
0/40
2 with no channel
Support queue
0
0 unassigned
Incident roomAI priorityRecent1 open
CRIT

Malicious attachment opened

WS-0312 · j.moreno · “invoice_2026.pdf.exe”
✦ AI verdict

This is not an invoice. It’s a program that is trying to encrypt the files on the machine. Response ready. Waiting for your sign-off.

⛔ Isolate machine ✕ Terminate process ✦ Investigate with AI
Malicious process terminated
Machine isolated from the network
Rest of the fleet checked
Your sign-off, recorded in the history
▶ Another attack ›↺ Replay
now
risk 96
MED

Defender in passive mode

WS-0188 · third-party EDR active
✦ AI verdict

Expected. This is not a fault. With a third-party antivirus present, Defender goes passive by design.

✓ Accept as expected
22 min ago
risk 31
Copilotwatching 38 machinesClaude
● Threat detected

“invoice_2026.pdf.exe” is trying to encrypt files on WS-0312. I have the response ready: isolate the machine and terminate the process. Press the gold buttons to approve it.

● Threat contained

Contained on ··· with your sign-off. The rest of the fleet is checked and the report is already written. The person who opened the attachment is still working.

● Quiet watch · 24 h

I contained 0 without your sign-off. I dismissed 1 false brute-force alert. All of it on the record.

✦What changed in the fleet last night?▍
// demo view · example data · the product UI as it runs in production
03 Capabilities

What SySauron does today,
on a real fleet.

No smoke and no roadmap dressed up as the present: everything on this list is running right now on real machines.

Detection and response

Deep telemetry per machine

Processes, connections and relevant changes, reconstructable as a complete execution chain and mapped to attacker techniques (MITRE ATT&CK).

Response at machine speed

Graded containment: terminate the process, isolate the machine, check the rest of the fleet. Anything irreversible waits for sign-off.

False-positive hunting

Multi-source correlation with memory: known noise is learned once and never rings again. Your inbox stops lying to you.

Fleet operations

Zero-touch enrolment

A new machine powers on and joins by itself: protection, inventory and support live without anyone touching it.

Employee lifecycle

Directory onboarding and offboarding, access and assigned machine: from ticket to done, with every step on the record.

Patching and end of life

Out-of-hours windows, end-of-support tracking and a batched replacement plan with compatibility checked.

Network and access

Zero exposure to the internet

The machines don’t open a single port. An encrypted outbound channel to your server: from outside there is nothing to scan.

Live map of the network

Topology per client: segments, dependencies and context for each entity. The same map the AI reasons over.

Governed remote access

Remote desktop and remote execution with fine-grained permissions, enabled per machine and always audited.

The intelligence layer

Knowledge per client

A context layer per organisation (network, history, its own rules) feeds every decision the AI makes. Isolated between clients.

Graded autonomy

From suggest-only to act-on-routine: each client sets the level. Anything sensitive, always with a human in front of it.

Verified offensive use

Analysis of your attack surface the way an attacker would, with frontier AI and a verified use case (Anthropic CVP).

// This is what it does. How it’s put together inside we go through with you on a technical call, whenever you want the detail.

04 The difference

A copilot that doesn’t chat.
It operates, with permission.

Most tools hand you one more alert to look at. SySauron has an intelligence inside it that understands your fleet, investigates on its own and prepares the action. You approve; it executes.

Ask in plain language

You talk to it like you’d talk to an engineer. It answers with facts.

From any screen, you press ⌘K and ask. The copilot knows the context of what you’re looking at: the machine, the threat, the client. It doesn’t improvise: it queries the real fleet data and shows you every step it takes.

  • Investigates a threat and reconstructs the full chain.
  • Proposes the response; anything with impact always needs human sign-off.
  • Every action is logged and can be looked up.
typed tools, not a shell isolation per client fleet data ≠ instructions every call, logged

// Today, with a human in the loop on every action. The autonomy widens with you, at your pace.

✦Investigate the WS-0312 incident and give me the full chain▍
To your intelligence
✦ Investigate the WS-0312 incident and give me the full chain
✦ Summarise the security posture for the client
Quick action · signed off by a human
⛔ Isolate a machineA
⚡ Run a sweep across the fleetQ
Go to
▦ Fleet · 40 machines
05 Your hand on the wheel

You decide how much rope
you give it.

Autonomy isn’t a yes or a no. It’s a dial you set according to what you’re comfortable with. You start with stabilisers; they come off when you say so. And never the other way round unless you say so.

Day to day

Reversible everyday actions. The AI proposes, you confirm. For starting without surprises.

Operations

Fleet management and guided rollouts. Anything critical, always with your go-ahead.

Advanced

Almost the whole operating panel in your hands. The AI does the muscle; you do the steering.

// Sensitive security isn’t delegated at any level. That one stays with me.

06 Architecture

Five strokes. No secrets
given away, no magic.

01

Light agent

On every machine. Minimal, quiet, no strange profiles.

02

Encrypted channel

Outbound only. Not one port open to the internet.

03

Your server

The brain. On your infrastructure or managed by us: your data lives there.

04

AI layer

Analyses, correlates and proposes through typed tools. Never an open console.

05

Human

Signs off on anything sensitive. Every action, theirs or the AI’s, is logged.

// the order matters: the AI sits BEHIND the server, not in front of your data.

07 The product from the inside

I’m not listing features.
I’m showing you the control room.

This isn’t a website with catalogue screenshots. It’s the same interface that operates real fleets every day. What you see, exists.

War Room

The whole state of your company, on one screen.

Security posture, active threats, fleet status and the support queue. Issues arrive already prioritised by the AI, with a verdict that separates the urgent from the known noise before you lose a minute.

  • One place to look, not ten scattered dashboards.
  • Every threat arrives with its diagnosis, not just an alarm.
Incident · AI priorityObfuscated PowerShell, spawned by Word
✦ analysed
✦ AI verdict

Chain Office → PS encoded → beacon. Pattern of a macro-dropper with 3 signature matches. I recommend isolating and capturing evidence.

⛔ Isolate WS-0312 ✕ Kill PID 7344 ✦ Investigate with AI
// the action in gold is signed off by a human · example data
74/100
Security posture4 exposure points found
✦ watched continuously
Machines behind on patches
11 machines · Windows 10 end of support
highAI plan
Remote desktop exposed
Remote access open on 6 machines
mediumFix
Anomalous trust certificate
Unrecognised authority on 1 machine
mediumReview
Domain account never rotated
Old service credential
lowSchedule
Security posture

The doors you left open without knowing.

SySauron audits the fleet continuously and tells you, in plain English, where someone could get in: unpatched machines, open remote access, odd certificates, old credentials. Every finding comes with its fix plan.

  • A security note anyone can understand, not an 80-page report.
  • We fix it, or we tell you how to.
08 How it’s built

Two colours on this panel.
Neither acts alone.

This isn’t decoration. It’s the contract for how SySauron works, and you’ll see it on every screen of the product.

✦

GREEN · THE INTELLIGENCEWatches, correlates and proposes

A layer of AI watches the fleet without a break, tells a real threat apart from the usual noise and prepares the response. What a security analyst would think, at the speed of a machine.

●

GOLD · THE HUMAN JUDGEMENTDecides, and answers for what happens

Every sensitive or irreversible action is signed off by a human before it runs. The AI speeds up the work; the judgement and the responsibility stay human.

The intelligence proposes. The human decides. And all of it goes on the record.

Anthropic · verified use · 2026

Frontier AI, unrestricted for security work.

We passed Anthropic’s verification to use their artificial intelligence for offensive security analysis, within a controlled framework. We look at your defences the way an attacker would, and find the hole before they do.

09 Straight answers

What you’d want to ask
before handing me your network.

How is this different from my usual IT guy?
The usual one turns up when you call. SySauron is already inside, watching, before you call, and the repetitive work gets done by an AI instantly instead of by a person in three days. You stop paying for firefighting. You pay for the fires not starting.
Doesn’t it slow the machines down, or pry?
A light agent nobody notices, and nothing is exposed to the internet: it all runs over a closed channel. This is not watching your people: it’s knowing whether the machines are healthy, protected and up to date.
What if I want something built for my company?
That’s the whole point. Once I’m inside I know the context of your business, and on top of that I build you automations or reports made to measure. The base is the same; what sits on top I build for you.
What if the intelligence gets it wrong?
That’s what the human judgement is for. Nothing sensitive runs without sign-off, everything goes on the record and the last word is yours. Worst case, it stops and I sort it out myself, and the log says exactly what happened.
What happens to my data?
It lives on a server under your control. I don’t sell it and I don’t train anything on it, and the AI only receives what its task needs, logged. We sign a data processing agreement before I touch a single machine.
Is there a minimum term?
No. If I add no value in a given month, you leave with no penalty. My aim is for renewing to be obvious, not compulsory.
Does it work with what I already have?
Yes. It adapts to practically any system and sits alongside whatever you already run. Today it’s most refined on Windows; if your infrastructure is something else, we build it around that. We’ll see it in the X-ray, no strings.
What does it cost?
A flat monthly fee based on the size of your fleet, a fraction of what building your own IT and security team would cost, without the payroll or the managing. We look at your case together and I tell you straight, no fine print and no merry-go-round of meetings.
Will you show me the stack?
On a technical call, yes: we go into all the detail you need to evaluate us properly. On the website we’d rather show what it does than how it’s built inside.
Am I dependent on you being available?
For the day to day, no: the platform watches and protects your fleet automatically around the clock, whether I’m online or not. For anything that takes judgement, I answer, and all of it is documented and logged, not kept in my head. As the service grows, that backup gets stronger.
Free · no strings

An X-ray of your IT,
before you decide anything.

In 48 hours I show you the real state of your IT. No jargon, and no arguing with anyone.

  • Real security posture: where they could get in.
  • Machines at risk or out of support that nobody is watching.
  • Three fixes you can apply now, whether you hire me or not.
Your data on your server Every action logged No lock-in Verified AI use (CVP)
Request my free IT X-ray
10 Who’s behind it

One face, not a call centre.

Álvaro Borges
Álvaro Borges · sole operator
2020
Trust & Safety at Google. Three years seeing how the giants defend themselves, from the inside. And learning the price of it: the data travels.
later
Back in Spain, running IT for companies. And I find the same old model: firefighting. Most of the issues were small, repetitive, avoidable.
2025
I build SySauron. My own platform, not somebody else’s software with a logo on it. If something breaks I know exactly where, because I wrote it.
hoy
It runs on a real fleet, every day. And I’m the one on the other end: if you write, I answer; if something breaks, I fix it.

Let’s talk about your fleet.

Tell me how your IT is put together and I’ll tell you straight how this would fit. Starting with a free X-ray. If you want the technical detail, we go through it on a call. And if the company decides to bring me all the way in, I don’t just protect a fleet. I make it run better.

or write to me directly: alvaro.borges@sysauron.com

SySauron · managed IT and security services · remote, from Spain

// destination · business version
Does someone else sign this off?
Forward this page to whoever holds the budget in your company.
Free IT X-rayLet’s talk