About Corxor

Independent. Calm. Long-term.

Corxor is an independent, founder-led security company. We build calm, AI-native tools — strong enough for teams running their own SOC, simple enough for teams that don't have one. Either way, you don't babysit the product.

Where we are going, and what we will not do to get there

Mission

Defend the machine without reading the person.

Security should not be something you buy by handing over your privacy. Corxor is built so that an organisation can be defended without its people being watched, and so that a customer keeps the thing every other vendor asks them to give up: independence over their own data.

  • Behaviour is the evidence. Content never is.

    Arkor decides on what a program does, not on what a person wrote. A detection travels as exactly what a verdict needs: a SHA-256 fingerprint, the process, its parent and the account it ran as, the command line, the MITRE technique it maps to, the decision and the confidence behind it — plus the machine's name, OS and agent version so the fleet can be managed at all.

  • The fingerprint leaves. The file stays.

    When Arkor needs something identified, it sends the hash, not the bytes. Even a false-positive report — the one place a customer is actively asking us to look at a file — carries the fingerprint and the file name, and nothing of the contents.

  • One exception, and we name it.

    A Critical incident produces a forensic snapshot scoped to that incident, so the investigation it opened can actually be carried out. It is size-capped, stored inside your own tenant, and deleted on a schedule you control — thirty days unless you say otherwise. Each one is hashed on arrival and sealed into an append-only chain, and the certificate that comes with it can be verified by your lawyers or a forensic authority without any access to us. A vendor who claims nothing ever leaves the endpoint is either not doing forensics or not telling you what they do.

  • The list, for cloud tenants, in full

    Your tenant holds the items above and nothing else. It never holds a document, a spreadsheet, source code, an email, a chat message, a browsing history, a keystroke, a screenshot, a clipboard, a microphone or camera capture, a stored credential, or the contents of any file. Two of the fields we do hold — the command line and the account a process ran as — can contain a person's name, which is why we describe what we take rather than claiming to take nothing personal. On-premise deployments keep all of it on your own infrastructure; there is no tenant on our side to hold anything.

  • A property of the protocol, not a promise.

    None of this rests on good intentions. It is what the agent is able to send, it is visible in the console, and it is the kind of commitment that can be written into a contract and checked by an auditor rather than believed.

Vision · 2030

Autonomous defence, on every platform where machines are trusted to act.

Cybersecurity is the first surface, not the last one. Wherever a machine is allowed to decide and act on its own — a factory line, a vehicle, a fleet of robots, an agent with authority over a system — something has to be accountable for that decision. We intend Arkor to be what teams reach for on each of them.

  • Wanted wherever robotics runs

    The robotics era does not need a different security idea; it needs the same one applied to machines that move. Detection, response, autonomy — the ladder we already climb on the endpoint is the ladder those platforms will need, and we are building to be the product they ask for by name.

  • A voice in what an autonomous system may decide

    The rules governing AI decisions should not be written by a handful of jurisdictions and handed to everyone else. Corxor works towards standards agreed between countries rather than imposed by one, and towards being one of the parties whose consent is part of setting them.

  • Human rights and human identity, by design

    We support every serious effort to keep identity in the hands of the person it belongs to, and we build to those standards ahead of the law requiring it. A defence system that erodes the people it defends has failed at its own job.

  • Shared ground for agents

    Agent platforms and their protocols are being defined right now, and they will decide whether autonomous systems can be inspected or only trusted. We contribute to that common ground — interoperable, inspectable, and safe to hand authority to.

  • Responsible to the world it runs in

    Efficiency is an environmental decision. Every verdict reached with less compute is energy not spent, and we treat that as part of the engineering, not as a statement at the end of a report. We are here to serve a better world, not only a defended one.

Detection → Response → Autonomy

From the founder

Built under one accountable hand.

Corxor is founder-led and independent, and the platform was designed and built that way on purpose: the architecture, the detection engines, the model pipeline and the console were held to a single standard rather than negotiated between teams. Dozens of subsystems, one idea running through them — that a decision this product makes must always trace back to a reason a person can read. Security software earns trust by being inspectable, not by being large, and independence is what makes it possible to keep saying no to the shortcuts that would make it less so.

— Founder, Corxor

How we build

Decisions you can audit — not claims you have to trust.

Corxor builds security the way safety-critical systems are built: defined inputs, bounded behaviour, and a record that outlives the incident. Every product we ship runs on AISOS — the intelligence layer that observes activity, decides under policy, explains the decision in plain language, and learns only from verified outcomes.

  1. 01

    Behaviour over signatures

    A file name proves nothing. We model what software does — execution chains, persistence, credential access, encryption patterns — and weigh behavioural, structural and reputation evidence together before a verdict is reached.

  2. 02

    Decisions on the device

    Inference runs on the endpoint, where attacks actually execute. Response does not wait for a cloud round trip, and raw telemetry does not have to leave your environment to be understood.

  3. 03

    Every action leaves a record

    Each decision carries what was observed, which signals mattered, which policy applied, and whether it can be reversed. The audit trail is written for reviewers and auditors — not for marketing.

  4. 04

    Bounded autonomy

    Autonomy is a level you set per action class, not a switch that is simply on. Destructive actions stop at a human countersign, and response is reversible wherever reversal is possible.

On evidence. Our endpoint product is currently under evaluation with independent anti-malware test laboratories. We publish results when there are results to publish. Where the product has a limit, we would rather state the limit than imply a certification we do not yet hold — the same standard we apply to every number on this site.

Technical questions, architecture reviews and security disclosures are welcome. Write to info@corxor.com — an engineer answers.

Where we are

Built independent. Incorporated globally.

Engineered for international customers from day one. The same product, the same response time, the same engineering depth — everywhere we ship.

Independent · Founder-Led

Built by an independent founding team.

Independent engineering team operating across time zones. We treat every customer geography as a first-class market — not a translation footnote. Same product surface, same SLA, every region we serve.

Incorporated globally

Built to serve teams everywhere.

Incorporated in the United States so that customers anywhere — from small SaaS teams in Berlin to MSPs in Singapore — can buy from us with familiar paperwork and standard terms.

Independent. Founder-led. Incorporated for global customers. The protection we run on our own laptops every day is the protection we ship to every endpoint.

How we work

Four things we hold onto.

01

Calm by default

Security software should not raise your blood pressure. We design for quiet by default, alerts only when they earn it.

02

No black boxes

We explain what the product does, including the parts that aren't impressive yet. Marketing doesn't get to wear engineering's clothes.

03

Independent

Founder-funded. We can take the time to build something we'd want on our own machines. No quarterly theater.

04

Long-term

We're building this for the next ten years, not the next funding round. The product compounds with every customer.

Want to talk?

We answer every message ourselves. No SDR, no sequence, no marketing list.