An answer for any path
Every planProbes for WordPress, .git, Jenkins, cloud metadata or Kubernetes get a believable reply instead of a 404: chosen on the box in Trial, written by an LLM in Professional.
Enterprise · in development
Classified enclaves, plant networks and data that can't leave the country need security that works disconnected. RipTide Enterprise, now in development, is built for them: the decoys, the console and an optional local model, all on hardware you own.
The problem
Cloud-delivered detection needs an internet connection, a vendor tenant and your data leaving the building. For an air-gapped enclave, a regulated workload or a sovereign cloud, that's a nonstarter.
Those are the very networks attackers most want to reach, and the ones where an intruder can stay hidden the longest.
Enterprise is in development. Tell us what your network allows in, and help shape it.
How RipTide catches it
Today's builds download a few components the first time they start. Enterprise removes that step, so RipTide can cross the gap like any approved software.
Everything it needs in what you carry across the gap, ready for your usual software approval.
One binary on Linux or macOS hardware you already own, with its console beside it.
Decoys, verdicts and the console run on the sensor. An optional local model writes replies on the box, with nothing sent to an outside AI.
OCSF and STIX exports and a TAXII feed, served on your own network to the tools you run inside.
Enterprise, in development
Most of this ships today. Enterprise closes the last gap.
| The requirement | Where RipTide stands |
|---|---|
| No internet | Enterprise, in development. Today's builds download components on first start. Enterprise is being built to install and run with no connection at all. |
| No cloud tenant | Ships today. One binary on hardware you own, with its console beside it. |
| No third-party AI APIs | Ships today. Trial replies are chosen on the box, and RipTide can run a local GGUF model you supply. Turn replies off and the decoys keep working. |
| Data stays home | Ships today. Captured evidence stays on your sensor until you export it. |
| No new appliance | Ships today. Runs on Linux or macOS hardware you already own. |
The detections that do the work
Every decoy has zero legitimate users. So every touch is a finding.
Probes for WordPress, .git, Jenkins, cloud metadata or Kubernetes get a believable reply instead of a 404: chosen on the box in Trial, written by an LLM in Professional.
Speaks nginx, Apache, IIS, Go and uvicorn, down to header order and error pages.
A real sign-in form plus Basic and Bearer challenges. Every credential offered is fingerprinted and kept for investigation.
What lands in your SOC
The same sensor and the same decoys as every other plan, with exports served to the systems you run on the inside.
$ sudo ./riptide ✓ decoys live: www :8090 · api :8091 ✓ replies: local model · nothing leaves the box ✓ console ready: http://10.0.8.20:7103/ … watching for the first touch
Illustrative example of an Enterprise install, which is in development. RipTide detects and records; it never takes destructive action against anyone's infrastructure.
Questions
Detection itself runs entirely on the sensor. Today's builds still download a few components the first time they start, so a network with no connection at all needs Enterprise, which is in development. Tell us about your environment and we'll keep you posted.
Yes. Models only choose or write replies for requests the decoys have no script for. Turn replies off and the decoys, the console and the exports keep working.
Hardware you already own, running Linux or macOS. Today's build runs on a 512 MB cloud server; a local model needs more memory, and in a briefing we'll size it for your environment.
Tell us what your environment allows in. We'll show you how RipTide gets there.
Thirty minutes with the people who built it. Bring your hardest question.
Thanks. We'll reply to , usually within one business day.