Know what is exposed
Start with one system the business cares about. Sotiras verifies ownership, scans safely, and explains what is reachable.
Sotiras helps small businesses verify assets, detect real attack behavior, and turn evidence into reviewed security work without hiring a full security team.
Know what is exposed, what is attacking it, and what action is safe to take next.
Sotiras can take low-impact actions under policy while high-impact decisions stay reviewed.
Sotiras tracks actor intent, assets, evidence, and time, not only single request rules.
Start with one asset the business cares about, then build the evidence trail.
The Sotiras product system
Customer operations, collector qualification, authorized active validation, and public intelligence have different jobs and different trust boundaries.
The focused customer workspace for assets, collectors, threats, response, and verification.
ExploreAuthorized active validation with preflight, controlled execution, rollback, and customer proof.
ExploreParser replay, live collector qualification, honeypot observations, and independent proof review.
ExploreApproved public-safe IP intelligence, deliberately separated from customer tests and private evidence.
ExploreThe problem
SMBs see brute force, credential stuffing, route probes, and exposed-service scans, but most do not have a security team to interpret every signal or babysit another dashboard.
Sotiras starts with one system you care about, builds an evidence trail, and helps decide whether to block, watch, assign, escalate, or ask support for help.
Attacks compound over time
A scanner, a brute-force run, and a later successful login should not look like unrelated events.
Noise burns attention
Every alert should explain what happened, why it matters, and what action is safe.
Tools are fragmented
WAFs, plugins, host logs, PBX logs, and firewalls need one customer-readable decision trail.
AI needs evidence
AI should summarize and recommend from known facts, not replace review, policy, or approval.
Safe action model
The product is designed for graduated response. Low-impact actions can happen when confidence is high and delay increases risk. High-impact changes stay visible, reversible, and approved by the right person.
That means the first temporary ban can be safe and short, while credential changes, broad network blocks, incident communications, and recovery steps remain reviewed.
Low-risk action can be fast
High-intent probes and known bad behavior can trigger short graduated bans under tenant policy.
High-impact action stays reviewed
User lockouts, broad firewall changes, vendor access, and recovery decisions require approval and audit history.
Every action needs a trail
Sotiras records evidence, confidence, target, decision owner, rollback notes, and review status.
Beyond WAF rules
A WAF can stop a pattern. Sotiras is built to understand the actor, the target, the evidence over time, and the customer decision that should follow.
Blocks or allows a request based on a pattern, often without explaining actor history or business impact.
Looks at source behavior over time, asset context, authentication signals, probes, scans, and tenant policy.
The user sees why something matters, what Sotiras did, what needs approval, and what should be watched next.
Customer outcomes
Sotiras turns exposure, attack behavior, AI review, and support context into actions that can be approved, assigned, escalated, or watched.
Start with one system the business cares about. Sotiras verifies ownership, scans safely, and explains what is reachable.
Route probes, brute force pressure, suspicious logins, and scanner patterns become evidence instead of raw noise.
AI reviews explain the source, target, evidence, confidence, business impact, and the next safe action.
Turn evidence into a risk, incident, owner task, support request, temporary block, or watch decision.
Every finding attaches to a system, owner, IP, hostname, service, criticality, and follow-up record.
Low-impact actions can run under policy. High-impact changes stay reviewed, reversible, and auditable.
Separate a noisy scanner, likely bot, shared network, known bad actor, and suspicious authenticated user.
Auth outcomes, known-bad IP matches, unusual access time, and host context help surface possible compromise.
Weekly proof turns observations, actions, risks, support work, and unresolved questions into one customer-readable record.
Getting started
Pick one IP, server, PBX, WordPress site, or application. Sotiras verifies ownership and creates an asset record.
Run a safe scan or connect a lightweight source. Sotiras looks for exposure, probes, auth pressure, and missing evidence.
Review what Sotiras found, what it did, and what still needs approval, support, assignment, or escalation.
Practical first signal
If a customer only has wp-admin access, the plugin gives Sotiras a low-friction first signal: login failures, XML-RPC activity, route probes, and WordPress inventory. It starts in observe mode; a connected Free or Premium account can enable automatic application-layer enforcement after the owner opts in. If the customer controls the host, pair it with web or host collection later.
Safe observe-only start
The plugin can first watch suspicious activity without changing users, roles, files, caching, firewall rules, or login behavior.
Automatic WAF enforcement
Connected Free and Premium accounts can apply Sotiras block decisions before WordPress loads, after the site owner explicitly enables enforcement.
Useful attack signals
Track login failures, successful logins, XML-RPC activity, REST auth failures, route probes, and top observed paths.
Inventory context
Report WordPress core, PHP, active theme, installed plugins, and versions when the site owner connects cloud history.
Coverage keeps expanding across the stack you actually run, and the review loop now reaches your phone, not just the portal.
Get alerts, notifications, and auto-ban activity on your phone, and lift a ban yourself when a token allows it — no laptop required.
Kubernetes audit log collection and Falco runtime detection cover clusters alongside your existing host and web telemetry.
Microsoft Entra ID sign-in monitoring, plus GCP Cloud Logging and Cloud Functions collection for serverless workloads.
Group the hosts, VMs, and services that make up one real system, so evidence and actions stay tied to the business system, not a single box.
Simple pricing
Start with the smallest useful scope, then expand coverage when device count, telemetry volume, AI review, or response needs grow.
For one person managing their own protection — including independent IT professionals using Sotiras for client or business systems.
Free
One connected WordPress site with a working WAF, email alerts, and community intelligence contribution.
Premium
Deeper protection and evidence for one WordPress or nginx HTTP surface, with supported WordPress enforcement.
Usage-based overages never count attack traffic — brute force, honeypot, and high-severity surge are excluded from automatic billing.
Optional WordPress recovery
$499 per incident for one standard WordPress installation
Includes bounded site cleanup, access review, re-scan, and recovery validation. Host compromise, multisite spread, custom-code repair, data restoration, forensics, and emergency response commitments require a separate scope.
Trial length
Starter periods can be offered for early customer onboarding. The portal shows the active plan, limits, and billing status for each workspace.
When billing starts
Recurring billing starts only when the workspace has an active paid plan. You can request plan changes from the portal before expanding coverage.
No surprise overages
Attack surge traffic is visible in reports but excluded from automatic overage billing.
Explore the product
Product roadmap
See how scan-to-action, telemetry, audit, and response are evolving.
Plan comparison
Compare Free, Premium, Business, Business Operations, and Enterprise features.
Public IP lookup
Check whether an IP has active Sotiras threat intelligence — no account needed.
Downloads
Get public plugin packages while guided host setup runs through the portal.
Documentation
Setup, security operations, and incident response guides.
Feature wishlist
Request the agent, integration, workflow, or UI improvement you need.
Existing customers looking for upgrade details can still review release notes at /product/releases.
Get started today
Start with a guided scan-to-action flow, connect the right telemetry, and use Sotiras to review what happened across assets before deciding what to change.