All 11 defense modules are included in every tier, on every server. You only pay for SLA, priority support and professional services.
Eleven defense layers, one binary, zero YAML. These are the four scenarios we obsess over.
Protect thousands of tenant sites against webshells, miners, brute-force and defaced pages. One agent per node; central panel for multi-tenancy.
See modules →Stop card-skimmers, Magento exploits, Laravel CVEs, API abuse. WAF + behavioral baseline. PCI-DSS-ready audit logs.
WAF details →152-ФЗ, 44-ФЗ, 223-ФЗ compatibility. Russian Software Registry application submitted. Air-gapped install for classified fleets.
Compliance →CI/CD safe. systemd-hardened agents. Metrics to Prometheus, logs to Syslog/CEF/SIEM. Runbooks for every event kind.
API →PHOENIX: honey-files, entropy spike detection, SIGSTOP + network quarantine. Safe by default.
PHOENIX →MIRAGE: decoy users, canary SSH keys, bait files, fake port listeners. Touch = 100% attack.
MIRAGE →SENTINEL: self-learning per-process baseline. Catches zero-days without signatures, without ML models.
SENTINEL →Every module can be turned on/off and switched between off / monitor / enforce / learning modes independently — from the panel or via ENV.
Anti-ransomware, multi-layer. Honey-files + entropy + kill-STOP. 30+ backup tools whitelisted out of the box.
4-layer active deception: decoy users, bait SSH keys, canary files, fake Redis/MySQL port listeners.
Behavioral baseline per-process. 24h learning → zero-signature anomaly detection, without ML.
Tail auth.log, ban >10 failed logins / 5 min, exponential re-ban on recidivism.
Listen on 2222/8088/etc. Any connection = permanent ban. Zero false positives.
/proc scanner every 60s: xmrig, kinsing, tsunami, cobaltstrike. Deleted-exec fileless detection.
SHA-256 baseline of /etc/*, /usr/bin, /usr/sbin. Catches rootkit hooks.
Detect phone-home to C2, mining pools, IRC botnets, Tor. Per-process attribution.
Signed Ed25519 rule-packs. Webshells, miners, backdoors. Extensible with community rules.
OWASP CRS-lite. 130+ rules: SQLi, XSS, LFI/RCE, SSRF, Log4Shell, Spring4Shell, Ivanti, Citrix.
SSH closed by default. On-demand grants per IP + TTL. Never locks out your current session.
Live blacklist from all SaiCore-defended servers. IP banned elsewhere = already blocked on yours.
ООО «САЙКО» is a Russian cybersecurity company incorporated in the Republic of Tatarstan. We ship SaiCore and a handful of other security tools.
April 2025. One year from first commit to public beta.
ООО «САЙКО» · ОГРН 1251600018933 · ИНН 1683027173
420099, Республика Татарстан, с. Семиозёрка, ул. Зиганшина, 39
ООО «САЙКО» registered. First commits to the SaiCore agent in Go.
Linux agent + control-plane MVP. First 20 design partners onboarded.
PHOENIX, MIRAGE, SENTINEL released. 11 modules total.
Open signup, public pricing, submission to the Russian Software Registry.
Active/standby control-plane, fully-supported Windows and macOS agents.
Kernel-level syscall policy enforcement for PHOENIX and SENTINEL.
The fastest way to reach a human is Telegram. For contracts, procurement paperwork and bug bounty — e-mail.
PoC welcome. First reply within 24 h. See disclosure policy.
+7 (939) 744-20-58
пн–пт 10:00–19:00 МСК
420099, Республика Татарстан,
с. Семиозёрка, ул. Зиганшина, 39
We're cooking deep-dive posts on PHOENIX internals, MIRAGE deception war-stories, and SENTINEL anomaly research. For now — follow @saicore_support on Telegram for updates.