Cybersecurity company
Audit Detection Response Compliance
Security capability you own. 100% open-source infrastructure, deployed inside your perimeter. Your data does not leave it, your keys stay yours, and the code is open to inspection.
Our teams work from initial assessment through to day-to-day operation, then hand over to yours.
Five service poles
Audit & offensive security
Network, web and API penetration testing. Red team. Social engineering. Configuration and architecture audit. Deliverables your teams can act on immediately.
Learn more →Managed SOC
Continuous detection, investigation and incident response. Two deployment models: managed on CyberAar infrastructure, or fully sovereign within your own environment.
Learn more →Security integration
Deployment and configuration of network, endpoint, application and access security solutions. Operational documentation and handover to internal teams.
Learn more →Advisory
Security programme management, infrastructure redesign, secure development, remediation, SOC and CERT projects. Advisory role, not execution.
Learn more →Governance & compliance
Maturity assessment, compliance, cyber strategy, business impact analysis and shared CISO. ISMS aligned with ISO/IEC 27001:2022, certification underway.
Learn more →What sets us apart
Expertise
A team of specialists trained on critical environments, capable of intervening at every stage of your security - from detection to response.
Our technical publications →Sovereignty
Your data stays within your perimeter. No dependency on a foreign vendor or hyperscaler. You keep control.
What we host, and with whom →Distributed team
Present across four time zones, from our Dakar headquarters to Montreal. Operated 24/7 from general availability; during the pilot, 06:00-24:00 WAT on business days with on-call for critical alerts.
The pilot programme →Publications
Research
What we measure while building and running our own platform.
Our failover had never worked, and every dashboard was green
A VRRP pair that never moved its floating IP for two months, and the two other controls we found lying the same day.
CIS and Docker contradict each other, so decide in writing
CIS says disable IP forwarding. Docker depends on it. Applying the control breaks the platform; skipping it quietly makes the compliance report lie.
fail2ban locked us out of the whole estate, and it was right
An SSH agent holding several keys exhausts MaxAuthTries before offering the right one. Run in parallel, every node bans you at the same moment.
Pilot program open
Test our Managed SOC (AarSOC) with no commitment
Five organisations receive full access to the platform for six months, at no charge, with guided deployment and priority support.
Closes on Jan 2, 2027
Apply for the pilot program