Detection logic that runs in silicon.

Below the OS. At wire speed. Without CPU involvement.

Scroll

Network IPS has had the same three limits since the 1990s.

01

Single-indicator evasion

Boolean detection rules fail when any required indicator is removed from the attack. This is not a configuration problem. It is the language.

02

The CPU tax

PCRE-based content matching at 10 Gbps consumes 60–80% of available CPU. Operators prune rule sets. Known attack variants go undetected — not because rules do not exist, but because hardware cannot keep up.

03

The trust boundary

Detection runs in the same OS and memory space as the traffic it inspects. A sufficiently capable attacker can disable detection before it fires.

We built a new detection language.

Detection logic compiles to weighted-confidence functions evaluated directly in FPGA and ASIC bitstreams. Single-indicator evasion fails by construction. CPU overhead disappears.

Detection logic runs in silicon — in the same hardware pipeline as packet forwarding, including the VPN decryption path, covering encrypted traffic before plaintext reaches memory. The CPU, OS, and application stack are removed from the detection path entirely.

The same language runs in software today as a drop-in replacement for existing IPS engines, and generates production-quality signatures autonomously from CVE descriptions. Silicon is the destination, not the requirement.

Detection becomes a circuit. Evaluated in nanoseconds. Impossible to disable in software. Covering the full rule set in parallel — no pruning, no tradeoff between coverage and performance.

20+ patent-pending inventions.

Technology available for licensing to firewall manufacturers, NIC and ASIC vendors, and domain-specific security platforms.

Three products. One detection language.

Forge™

Autonomous IPS for network infrastructure

Forge™ generates production-quality detection logic autonomously from a vulnerability description — no human authoring, no purchased threat intelligence, no attack traffic required. A single detection definition compiles to three targets: PDL for existing IPS engines today, a native weighted-confidence software engine, and an FPGA/ASIC bitstream for silicon execution. Designed for firewall and IPS manufacturers.

Eigen™

Device-derived protection for critical infrastructure

Eigen™ reads a device's own firmware and documentation and derives complete protection from those artifacts alone — with no external input, no cloud dependency, and no software to compromise. Known vulnerabilities are covered. Novel attack patterns not yet assigned a CVE are blocked by structural enforcement. Designed for IoMT, ICS/OT, and critical infrastructure operators.

Core™

Silicon IP for NIC and ASIC manufacturers

Core™ is a licensable silicon architecture that integrates packet inspection detection logic directly into the NIC receive path — compiled to a hardware bitstream and loaded onto the programmable logic fabric of the network interface chip. Detection runs before the packet touches host memory. Designed for NIC and ASIC manufacturers whose silicon ships inside enterprise servers, firewalls, industrial control systems, and medical devices.

Thinking on network security.

White Paper · June 2026

The Perimeter Is the Wrong Place for IPS

Why perimeter-centric intrusion prevention is architecturally mismatched to modern threats, and what the TeamPCP supply chain attack reveals about the detection model we should be building instead.

Read on LinkedIn →

Building network security infrastructure?

If you want to understand what this technology means for your product, reach out directly.

Connect on LinkedIn instead