TIGR | Threat Intelligence Guard & Response

Custom threats demand
custom eyes

Autonomous threat detection, AI-driven analysis, and automated endpoint isolation — capabilities typically found only in enterprise platforms costing $60,000–$120,000 annually. Built for K-12 schools — and every lean team that has to defend a network without an enterprise budget.

Real detection prowls in the shadows — not on flashy dashboards

You're a target.
The tools don't fit. The budgets don't scale.

K-12 school districts are among the most targeted sectors for cyberattacks in the United States — and the same pressures hit local governments, healthcare clinics, churches, nonprofits, and small businesses. They operate large, heterogeneous networks with thousands of endpoints, hold sensitive PII, fall under strict regulatory frameworks — and are chronically underfunded for cybersecurity.

1,600+
Publicly disclosed cyber incidents affecting U.S. school districts since 2016
827%
Increase in ransomware attacks against educational institutions, 2019–2023
$1.4M
Average recovery cost per incident — downtime, legal, remediation, credit monitoring
$0
Dedicated cybersecurity staff at most districts this size — security falls to general IT
TIGR
Threat Intelligence Guard & Response

Don't just pay.
Prowl.

TigerNDR is a custom-designed, AI-powered Network Detection and Response platform. It provides autonomous 24/7 threat detection, real-time network flow analysis, syslog event correlation, and automated endpoint isolation — running entirely on your own hardware, on your local network, and fully internet-independent.

Designed and built by TigerNDR LLC using AI-assisted development — delivering capabilities that traditionally demand a dedicated security engineering team and a multi-month build cycle.

27
AI Agents
4
Node Mesh
48K+
Lines of Code
99.5%
Uptime

Four nodes. One purpose each.
Fault-isolated by design.

A distributed, purpose-built architecture where each node serves a single primary function. Separation of concerns provides fault isolation, enables independent scaling, and simplifies security hardening.

Control Node
Web UI, AI coordination, operational agents, API gateway
On-premises
TIGR Node
Security monitoring, threat detection, CHOMP isolation, squad agents
On-premises
Inference Node
Local AI inference, CHOMP-isolated, no internet access by default
On-premises
Vector Database
Qdrant RAG pipeline, threat knowledge retention, queryable intelligence
On-premises

Data Sovereignty

All security-relevant processing occurs on your own hardware within your local network. No telemetry, logs, or analysis results leave the premises.

Autonomous Operation

Continuous detection and containment without human intervention. Oversight required only for releasing contained endpoints and reviewing alerts.

Defense in Depth

Security controls layered across network (firewall policies), host (UFW, SSH key auth), application (agent guardrails, I/O classification), and process (CHOMP isolation).

The Continuous Pipeline

1
Collect
Network packet capture via tcpdump. Syslog ingestion from 50+ devices via rsyslog.
Mr-Wire • Mr-Log
2
Aggregate
Raw captures into structured flow summaries. Events categorized by type, severity, source.
Mr-Summary • Mr-Log
3
Analyze
Flow patterns correlated against behavioral rules and anomaly thresholds. AI-powered contextual analysis.
Mr-Detect • Local AI inference
4
Respond
Findings exceeding thresholds trigger autonomous isolation via firewall API. All findings generate alerts.
CHOMP • Mr-Report
5
Retain
Threat findings, flow summaries, and analysis pushed to vector database for persistent intelligence.
Mr-Sync • Qdrant

Everything an enterprise NDR does.
Nothing an enterprise NDR costs.

🛡
TIGR Prowl Engine
Continuous network surveillance analyzing firewall syslogs, LDAP/AD auth events, VPN sessions, SNMP traps, and flow statistics. Every 30 minutes, 24/7. AI scores every cycle.
Detection • DE.CM
🫀
CHOMP Protocol
Containment and Hardened Operational Mitigation Protocol. Autonomous endpoint isolation via firewall User-ID API in seconds. One target, one action, humans release.
Response • RS.MI
🤖
27 AI Agents
Two operational squads — security detection pipeline and operational intelligence — each with single-responsibility design, runtime guardrails, and I/O classification.
Automation • 48K+ Lines
🔍
Asset Intelligence
Full integration with wireless management, MDM, ticketing, NAC, and monitoring platforms. FDB trace locates any device down to the switch port.
Visibility • ID.AM
📊
Threat Intelligence RAG
Qdrant-powered vector database for persistent, queryable threat intelligence. Every finding, flow summary, and analysis builds your network's institutional memory.
Intelligence • RS.AN
📧
Natural Language Interface
Local AI assistant with on-device model routing, automatic failover, and tool integration. Query your entire stack in plain English — via web or email.
Interface • On-Prem AI
💰
$0 Monthly Cost
No per-seat licenses, no per-event metering, no per-GB SaaS bills. Local inference, local storage, local everything — pay once for hardware, run it forever.
Economics • Local-First
🏢
Cloud Independent
All inference, storage, and processing run on your hardware inside your network. No SaaS dependency, no vendor outages, no data egress. If a cloud provider has a bad day, TIGR doesn't notice.
Resilience • On-Prem
🧩
Additive by Design
Read-only access to every integrated system — TigerNDR observes, never modifies. Zero-risk adoption: shut the platform off and your users won't notice a thing. Silent-failure mode means nothing TigerNDR does can break what's already working.
Non-Disruptive • Read-Only

Containment and Hardened
Operational Mitigation Protocol

CHOMP transforms TigerNDR from a passive monitoring system into an active defense platform capable of containing threats faster than any human operator. Mean time to contain: under 10 seconds.

When a host crosses threat thresholds, CHOMP registers a quarantine tag on the firewall in seconds — blocking the endpoint and emailing your team the details. It runs with hard safety limits: one target per event, a Never-Isolate list protecting all critical infrastructure, a one-way valve (TIGR can isolate, but only a human can release), and a scoped key that can do nothing but quarantine. Aligns with NIST CSF RS.MI-1.

27 purpose-built AI agents.
Two operational squads.

Each agent performs one well-defined function, has access only to the data required for that function, and communicates through shared data stores — not direct coupling. Every agent is secured by local AI I/O classification and Python-level runtime guardrails.

TIGR Squad — Security Operations
Mr-Wire
Packet capture & flow collection
Mr-Summary
Traffic summarization & aggregation
Mr-Log
Syslog ingestion & event parsing
Mr-Detect
Threat detection & CHOMP trigger
Mr-Policy
Detection policy & enforcement
Mr-Report
Security report generation & email
Mr-Sync
Threat-intel sync to vector DB
Varya Squad — Operational Intelligence
Mr-Cache
Device & network inventory cache
Mr-Clone
Local intent classifier & tool router
Mr-CVE
NVD & CISA KEV vulnerability lookups
Mr-Correlate
Cross-agent compound-threat correlation
Mr-Debug
Real-time code debugger & auto-fixer
Mr-Email
Email gateway for the entire stack
Mr-Library
Integration API reference library
Mr-Mythos
Defensive recon & exploit dry-run analysis
Mr-Observer
Read-only platform auditor & gap analysis
Mr-Privilege
Security posture & privilege-escalation audit
Mr-Pulse
Service health & heartbeat monitoring
Mr-Scribe
Daily operations chronicle
Mr-Teacher
Knowledge ingestion & corrections
Mr-Ticket
Ticketing search, lookup & resolution
Mr-Todo
Task tracking & sync
Mr-Tracker
Work-session history & summaries
Mr-Trainer
Local-model training data generation
Mr-Update
Firmware & software update tracking
Mr-Windows
Windows event-log anomaly detection
Mrs-Critic
Weekly autonomous platform audit (1–100)

Total platform: ~38,300 lines of Python across 77 source files and ~10,400 lines of PHP — ~48,700 lines combined, the figure cited above. Plus 86 supporting shell scripts (not included in the line count). Built entirely with AI-assisted development.

5 AI Principles
of the Architect

After years in the trenches, these are the non-negotiables when adding AI to critical systems.

01
Additive, never invasive.
Build the AI as a pure observer that layers on top of what you already own. It should never modify, replace, or become a single point of failure. If you can't turn it off tomorrow with zero disruption, you built it wrong.
02
Human-taught, human-governed.
Interview the engineers who actually run your network and encode their judgment. Every consequential action stays behind human approval. AI proposes. Humans dispose.
03
Local-first.
Data stays home. Run inference on your own hardware. No staff data leaves your control and no surprise per-query costs. It's both a privacy posture and a budget posture.
04
Least privilege by construction.
Give each agent a verified identity and the absolute minimum permissions needed — no write access to production, no deleting logs, no self-modification of privileges. Bound the blast radius in the code.
05
Build to a standard, stay honest about the gaps.
Design against recognized frameworks (like Five Eyes joint guidance on agentic AI). Audit row-by-row. Clearly document what's verified, what's partial, and what's still a gap. Honesty about limitations is what makes your strengths credible.

These aren't theory — they're how we ship secure AI systems.

// Principle 5 in practice
Five Eyes Alignment Audit
Reference: "Careful Adoption of Agentic AI Services" — Five Eyes joint cybersecurity guidance, published 1 May 2026.
87%
Alignment
<24h
From Release to Audit
100%
Controls Reviewed

On 1 May 2026, the Five Eyes intelligence alliance jointly published the first major government framework governing AI systems that take autonomous actions. We treated it as a deadline, not a suggestion: TigerNDR was audited row-by-row against every published control within 24 hours of release, and the platform demonstrated substantial alignment across the standard. Where the framework calls for more, we've named the owners and the remediation work — because the only audit worth doing is the one you publish honestly.

Co-authored byCISA · NSA · ASD ACSC · Cyber Centre Canada · NCSC-NZ · NCSC-UK
📄 Read the Guidance (PDF)
// How this compares
TigerNDR
87% row-by-row alignment, audited within 24 hours of guidance release. Published on this page.
Forrester
Positions the Five Eyes guidance as the "de facto procurement floor" for agentic AI in regulated sectors. Source
Big-vendor SOC tools
CrowdStrike, Cisco, and Palo Alto Networks all shipped agentic SOC tools at RSAC 2026; VentureBeat reports a common "agent behavioral baseline gap" across all three, and no public control-by-control alignment audit has been published by any of them at the time of writing. Source
Cloud Security Alliance
Launched the CSAI Foundation in March 2026 to develop an agentic-AI certification framework; certification work is still in progress. Source
Industry status
As of publication, no major commercial NDR, XDR, or SIEM vendor has released a public row-by-row alignment audit against the Five Eyes guidance. See CISA's official guidance page and reporting in The Register and CyberScoop.
Sources reviewed on 4 June 2026. Comparative claims reflect publicly disclosed positions only; absence of a public alignment audit does not imply non-alignment. We update this section as vendors publish their own assessments.

NIST. MITRE. FERPA.
Not just checkboxes.

TigerNDR directly addresses the DETECT and RESPOND functions that NIST identifies as the areas where K-12 organizations most commonly have capability gaps.

NIST CSF 2.0

  • DE.CM — Continuous Monitoring
  • DE.AE — Adverse Event Analysis
  • RS.MI — Response Mitigation
  • RS.AN — Response Analysis
  • RC.RP — Recovery Planning
  • ID.AM — Asset Management
  • PR.AC — Access Control

MITRE ATT&CK Coverage

  • T1021 — Remote Services (SSH, RDP, VNC)
  • T1046 — Network Service Discovery
  • T1110 — Brute Force Detection
  • T1071 — Application Layer Protocol
  • T1570 — Lateral Tool Transfer
  • T1078 — Valid Accounts

Data Privacy

  • FERPA & COPPA compliant by architecture
  • No data leaves your local network
  • No third-party data sharing for security
  • Flow metadata only — no deep packet inspection
  • Local AI inference for sensitive queries
  • State student-data privacy laws & HIPAA aligned

Built Under Anthropic's Cybersecurity Verification Program

TigerNDR is built with Claude under Anthropic's Cybersecurity Verification Program (CVP) — a vetting process that authorizes approved organizations for legitimate dual-use security development while keeping prohibited uses blocked. CVP verifies the development context, not the product itself: it affirms what TigerNDR is being built for — defensive threat detection and response.

Enterprise capability.
Streaming-subscription cost.

Commercial Alternatives
NDR (Darktrace, Vectra)$80,000 – $150,000/yr
XDR (CrowdStrike, SentinelOne)$60,000 – $120,000/yr
Managed SOC service$100,000 – $300,000/yr
SOC analyst salary (SE US)$85,000 – $110,000/yr
TigerNDR
Total hardware investment~$2,000 (one-time)
Monthly recurring cost$0
Annual platform cost~$2,000 (amortized)
Cost per student per year$0.33
Cost per device per year~$0.20
50+
Syslog Sources Monitored
<30m
Mean Time to Detect
<10s
Mean Time to Contain
~1,000
Connections per Cycle
86/100
Self-Audit Score
99.5%+
Platform Uptime

Real security for
real-world budgets

No vendor lock-in

Open architecture built on standard protocols. Your data stays yours. No per-seat licensing, no annual renewals that double in year two. Runs on existing infrastructure — three of four nodes use hardware you already own.

No SOC required

Designed for one-person or small IT security teams. TIGR handles the monitoring, scoring, and alerting autonomously. You handle the decisions. AI-assisted development keeps the entire platform buildable and maintainable by a lean team.

Privacy by architecture

All processing happens locally on your own hardware. No sensitive data, network telemetry, or authentication logs leave your local network. Regulatory compliance (FERPA, COPPA, HIPAA) is structural, not contractual.

Deployable package

TigerNDR is being packaged as a deployable appliance for K-12 districts and other lean organizations. Multi-tenant management plane on the roadmap. Currently optimized for Palo Alto NGFW environments, with broader vendor support coming as the platform matures.

Most organizations fall into two categories: those who've experienced a ransomware attack, and those who haven't yet. Enterprise tools exist — but they're designed for SOCs, six-figure budgets, and analyst teams. TigerNDR was conceived to resolve all three of these constraints simultaneously: enterprise-grade detection and response capabilities, at a fraction of commercial cost, with all data processing performed entirely within your own network.
The problem TigerNDR was built to solve

Plays well with your stack

TigerNDR speaks to the platforms you already run — pulling asset, identity, and telemetry context from each into one queryable intelligence layer. Known compatible integrations:

Meet Varya

A secure, on-prem conversational assistant sits on top of the platform behind an SSO login gate. Ask your network questions in plain English — device lookups, ticket status, threat context — with answers generated entirely by local inference. No data leaves your network.

// Featurette — we asked Varya to introduce herself

Reach out today

Your information is used only to respond to your inquiry. We don't sell, share, or pass it to third parties — privacy by architecture, same as the platform.

Let's talk

Whether you're a one-person IT security shop or an organization-wide team, we'd love to show you what TIGR can do. Request a demo, ask about deployment, or just say hello.

We typically respond within 24 hours.