Onnex
Your business has the answer.
Let Onnex find it.
LOADING
. . .
Completed
0

Products

Onnex Bastion

They Unify Your Bills. We Delete Them.

Stop stitching a dozen dashboards by hand. Deliver enterprise-grade on-prem security and operations, managed from a single multi-tenant pane of glass.

Onnex Bastion is Huntress, but broader and unified. We integrate mature, proven open-source security engines behind a single control-plane, a single identity provider, and a single correlated timeline. Higher margins for the MSP, lower total cost of ownership for the client, and one throat to choke.

12
Security and operations capabilities collapsed into one platform
5
Open-source engines live and operating today
7
Compliance frameworks mapped from the on-premises audit trail
1
Control plane, one identity model, one correlated timeline
Twelve security and operations capabilities converging into a single platform, with each row marked live, backbone or sequenced.
Twelve capabilities, each separately bought and separately billed today, collapsing into one control plane. Five engines are integrated and operating, one is the identity backbone, and six are sequenced roadmap rather than shipping.

The Sprawl You Pay For Today

A typical small business needs roughly ten to twelve distinct security and operations capabilities to be secure and well-run today. Under the status quo, every single one is a separate SaaS subscription, separately billed, separately configured, poorly integrated, and collectively expensive. The managed service provider spends its hard-earned margin stitching a dozen disconnected consoles together by hand.

CapabilityThe Onnex Bastion unified solution
Intrusion detection and preventionSuricata (integrated today)
SIEM, log management and XDRWazuh (integrated today)
Edge IP reputation and auto-banCrowdSec (integrated today)
DNS filtering and web securityAdGuard Home (integrated today)
Digital forensics and threat huntingVelociraptor (integrated today)
Identity, SSO and MFAAuthentik (identity backbone)
Next-gen firewall and segmentationOPNsense (sequenced roadmap)
Web-application firewallCoraza / ModSecurity (sequenced roadmap)
Zero-trust remote accessWireGuard / Headscale (sequenced roadmap)
Vulnerability scanningOpenVAS / Greenbone and Trivy (sequenced roadmap)
Backup and disaster recoveryRestic / BorgBackup (sequenced roadmap)
Monitoring and uptimePrometheus / Grafana / Uptime Kuma (roadmap)

The result: instead of 10–12 logins, bills, and expired contracts, Onnex Bastion collapses the entire stack into one control-plane, one identity model, and one correlated event timeline.

The Three Pillars

Enforcement, not just alerts. “Response is execution, not a ticket”

Traditional managed-detection overlays sell a human-run Security Operations Center that ingests telemetry and returns a recommendation. But a “containment begins within 60 minutes” promise is a human number. It cannot scale to seconds. Onnex Bastion owns the entire on-premises observation and enforcement plane, so response is direct, machine-speed execution: block at the firewall, sinkhole at DNS, disable a session at the identity layer, isolate a host, or kill a process. Reversible Tier-1 containment executes autonomously in seconds with no human click required.

Sovereignty, weaponized. “Your data never leaves the building, not even to reach the AI”

In cloud-centric security stacks, all your sensitive network and endpoint telemetry must leave your premises to reside in a vendor’s cloud. For residency-sensitive verticals bound by HIPAA, CMMC or ITAR, this is a legal and regulatory non-starter. Onnex Bastion runs entirely locally at your premises, and the AI Operator’s transport is fully injected, so on a data-residency-bound site you can point it at a sovereign on-box model running on the appliance. Your data and your AI reasoning stay inside your physical walls.

Pure-margin economics. “They unify your bills, we delete them”

SaaS security overlays attempt to simplify your life by bundling multiple products into a single invoice, but you still pay the underlying per-seat license fees. Because Onnex Bastion’s core is built on mature open-source engines rather than proprietary vendor forks, per-seat software license fees disappear inside the box. The MSP’s marginal cost is pure compute, and the gap between low compute costs and your managed-service price becomes your resale margin.

Built-In Trust: the Compartmentalize Safety Valve

We answer the single biggest objection to autonomous machine-speed response: “what if the AI blocks my CEO or takes down production?” The trust mechanism is not “trust the algorithm”. It is an explicit, reviewable, human-gated set of controls called Compartmentalize.

1 · Blast-radius computation

When a high-severity threat is detected, the platform automatically computes its lateral-spread neighbourhood based on real observed network topology.

2 · Operator-editable boundary

The proposed blast radius is drawn on a live, animated attack map. Before any enforcement occurs, the operator can manually toggle hosts in or out of the containment plan.

3 · Audit chain of record

Only when approved does the action execute, writing every step, decision and rationale to an append-only, cryptographically verifiable, hash-chained audit log owned by the client.

Two Adoption Paths

You do not need to force a painful rip-and-replace on day one. We support two distinct on-ramps to fit your clients’ renewal cycles:

Overlay to land

Keep your client’s existing security stack. Ship its telemetry into Onnex Bastion’s unified timeline and AI operator via bring-your-own-telemetry push ingest. Immediately deliver correlated root-cause triage, the 12-playbook NIST incident-response library, and the client-owned audit trail, with zero footprint changes.

Replace to expand

As third-party SaaS contracts expire, absorb those capabilities into Bastion’s bundled open-source engines. This is where your economics scale, deleting per-seat line items and unlocking active machine-speed L2 containment.

Questions, and Our Honest Boundaries

What is Onnex Bastion, in plain English?

A unified physical or virtual appliance that collapses a dozen disconnected security and operations subscriptions into one platform. It correlates logs from network, endpoint, DNS and identity layers into a single event timeline, triaged 24/7 by an embedded AI operator.

What is actually live today, and what is planned?

Shipped and operating: the integration backbone, meaning one control-plane, Authentik SSO and the unified timeline; the five live open-source engines, CrowdSec, AdGuard Home, Suricata, Wazuh and Velociraptor; the MSP Fleet Plane operating live across two real client boxes with a live animated map; and the closed containment loop operating autonomously on our SDN test range, including real measured MTTR clocks, ebtables L2 isolation and the sovereign on-box model. Planned and sequenced: production-scale validation of the remaining engines (firewall, WAF, zero-trust, backups, secrets) and the cross-tenant threat-intel sharing network effect, which is mechanism-complete but awaits real external indicators across a broader client estate.

Are you certified (SOC 2, HIPAA)?

Onnex Bastion ships with a defendable seven-framework platform compliance control-mapping: SOC 2, ISO 27001, NIST CSF 2.0, NIST SP 800-53, PCI-DSS 4.0, HIPAA and GDPR. Four of these are automatically scored directly from your live, hash-chained on-premises audit trail. However, this is a compliance mapping built to accelerate an audit. It is explicitly not a vendor-issued certification, and we do not represent it as one.

Is the sub-minute containment guarantee a legal contract?

The physical capability to contain threats autonomously in under a minute is thoroughly measured and verified on our SDN range. Turning this into a commercial “or it’s free” warranty is a draft commercial claim pending final legal and governance sign-off. We represent the technical capability as real, but we do not make contractual promises until fully signed.

See the MSP Fleet Plane and the on-prem AI Operator in action.