Cybersecurity for small & mid-size teams

Enterprise-grade security.
Without the enterprise bill.

One cloud platform, seventeen products — and one risk score per person that no stack of point tools can compute. Mapped to NIST CSF 2.0, on one monthly subscription with every product included, and the tools you already own connect straight in. Not a SIEM, not a monitored SOC — what that means.

Deploys in days Cloud SaaS Works with your existing stack
app.forthound.com
Hound Security Tower · Dashboard
Illustration
Products in the suite
16
one subscription
Live connectors
2
the rest run on ours
Audit log
1
hash-chained, all products
Tenant isolation
Enforced
tested every release
Event volume · last 24h
Triage queue
Ransomware behaviorWS-FIN-01498
Impossible-travel loginsvc-analytics81
Phishing emailWS-HR-02264
Always on watch

The guard dog for your digital front door.

While attackers probe your perimeter, the Hound is already watching — detecting, containing, and reporting every attempt before it becomes a breach.

Put the Hound on watch →
One platform · seventeen products

Defend your systems and your people.

Attackers get in two ways: through your infrastructure, or through your people. FortHound covers both — plus the identity, access and asset controls auditors ask about — from one cloud console, one login and one audit trail.

Available

Hound Security Tower

AI security operations — ingest, triage, respond, and report from one window.

Open the live demo →
Available

Hound Phishing Simulator

Run realistic phishing tests across credential, malware & BEC attacks — see who clicked, who gave up credentials, and who keeps falling for it.

Open the simulator →
Available

Hound Cyber Training

Assign security courses with quizzes on a weekly, biweekly or monthly cadence — track completion % and flag anyone below 30%.

Open the LMS →
Available

Hound PAM

Privileged access management — vault admin credentials, grant just-in-time access with approvals, monitor live sessions and rotate secrets.

Open PAM →
Available

Hound Access Review

User access reviews — run certification campaigns, certify or revoke every entitlement, and auto-flag dormant, orphaned and toxic access.

Open Access Review →
Available

Hound Workflow

Routine forms and approvals — onboarding, access requests, policy exceptions and vendor reviews, routed through multi-step approval chains.

Open Workflow →
Available

Hound MFA

Push approvals, passkeys, TOTP and hardware tokens across your apps — with 30-day device trust and a complete authentication log.

Open MFA →
Available

Hound Offboard

Offboarding fails quietly — eleven tickets to eight teams, and the last three never close. One action revokes accounts, entitlements, privileged access, secrets, devices and factors, then issues a tamper-evident certificate of exactly what was done.

Open Offboard →
Available

Hound Signal

One risk score per person, computed across every other product — likelihood of compromise multiplied by what it would cost. No point tool can produce it, because no point tool can see the other thirteen.

Open Signal →
Available

Hound IR Planning

Draft a workable incident response plan and policy through a guided process: name the core team of legal and IT, agree a severity matrix, and set escalation rules so every incident is logged and the right ones reach the board and the regulator — by rule, not by memory at 3am.

Open IR Planning →
Available

Hound Command Center

When an incident happens, declare it and run it: alerts to the core team, a standing bridge, one-click core actions — reset passwords, warn all staff, preserve evidence — and a hash-chained log of everything done, ready for the forensics team.

Open Command Center →
Available

Hound Dormancy

Sign-in activity from AD, Entra, SAP and every app outside SSO, turned into a work queue. Third parties run on a tighter clock, every case goes to a named owner, and silence resolves to revoke rather than to nothing.

Open Dormancy →
Available

Hound Broadcast

Push security alerts, incident notices and policy updates straight to managed desktops through the agent you already have — and prove who actually saw them, machine by machine.

Open Broadcast →
Available

Hound Report

A “Report Suspicious” button in Outlook and Teams feeding one triage queue — matched against your own simulations automatically, promoted to a SOC alert when real, and the whole company warned in one click.

Open the queue →
Available

Hound Vault

Shared passwords, API keys, SSH keys and certificates — encrypted at rest, granted per vault rather than per role, and every single reveal recorded against a name.

Open Vault →
Available

Hound IT Assets

Agent-discovered hardware inventory, software licence compliance and lifecycle planning — know what you own, who has it and what it costs.

Open IT Assets →
Available

Hound Desk

The service desk the rest of the platform feeds. Requests, faults and work raised automatically by other products, on one queue — with separate clocks for answering and fixing, and a pause that has to say what it is waiting for.

Open Desk →
Roadmap

Hound Offensive

Continuous pentesting, external attack-surface mapping, API & secure-code review, and AI/LLM security testing.

Coming soon
Hound Signal

The risk your stack cannot see.

Not because your tools are bad. Because they cannot talk to each other.

Four vendors, four verdicts
Phishing vendorClicked 8 tests
LMS41% trained
PAM vendor1 privileged account
IGA12 entitlements
Four dashboards. Four amber lights. Nobody owns the sentence.
One platform, one answer
77
Jack Reed · Engineering
Clicked 8 simulated phishing emails — a repeat pattern, not a slip; entered credentials into the page; holds a privileged account; still has SAP access he has not used since May.
Likelihood 90 × Impact 66. Reduce the access and fix the behaviour. One name, one number, one decision.

Likelihood × impact, never a total

Adding risk factors together produces a league table of carelessness. Multiplying them puts a careful administrator above a careless intern — which is the honest ordering, and the one that tells you whether to trim access or run training.

Every number traces back

Each factor names the product that raised it and links straight to the record. A score nobody can explain is a score nobody acts on.

Impossible to buy piecemeal

CyberArk cannot see KnowBe4. Your IGA cannot see your endpoint. This exists only because seventeen products already share one identity model and one audit trail.

Connects to the tools you already run
Cisco DuoKnowBe4

Live today. Microsoft Entra ID, CrowdStrike, Defender and Proofpoint are next, built in the order customers ask for them — and any product can run on FortHound's own engine while you wait.

$0
Minimum — every product included
0
Products in one subscription
0
Hash-chained audit log across all of them
0
Third-party dependencies in the platform
Why FortHound

Security teams are outnumbered.
FortHound evens the odds.

You shouldn't need a seven-figure budget and a room full of analysts to defend your business. FortHound gives small and mid-size teams the seventeen controls they are actually asked for — identity, access, training, response and the record of all of it — at a price they can plan around.

SOC outcomes, SME budget

No stitching together five tools, five user lists and five bills. One platform, one predictable subscription, one audit trail across all of it.

Plugs into what you already own

Cisco Duo and KnowBe4 connect today, and every other product runs on FortHound’s own engine until its connector ships — so nothing waits on an integration. Entra ID, CrowdStrike, Defender and Proofpoint are next, built in the order customers ask for them. No rip-and-replace.

AI does the toil, not the deciding

Every alert scored and ranked; routine threats contained automatically by playbooks you control. Your people spend time on decisions, not on triaging noise.

100% ready to deploy

This isn't a slide deck. Spin up your cloud SaaS tenant — data flowing in minutes, tuned to your environment in days, not months.

The adversaries

Know them. Stop them. Prove it.

The crews that breach the Fortune 500 target small and mid-size businesses too — betting you're undefended. Hound Security Tower detects, contains, and documents every one of them.

Ransomware crews

Encrypt-and-extort operators moving fast across your fleet.

Host-isolation playbook

Nation-state APTs

Stealthy, long-dwell intrusions that hide in the noise.

Live MITRE ATT&CK mapping

Phishing & BEC

Credential harvesting and invoice-fraud lures aimed at your people.

AI analyst desk

Brute-force & bots

Automated login attacks and scanners probing your edge 24/7.

Auto-block at the firewall

Cloud intruders

Misconfigurations and stolen keys turning your cloud against you.

Posture & API monitoring

Insider & data exfil

Anomalous access and large egress from inside the perimeter.

Exfiltration containment
See it.Stop it.Prove it.
What you get

Seventeen products. One subscription.

Not a bundle of upsells — every one of these is included, and every one is a console you can open right now on the live demo.

Hound Signal

One risk score per person.

Computed across every other product — likelihood of compromise multiplied by what it would cost. No point tool can produce it, because no point tool can see the other thirteen.

Open the live demo →
Hound Security Tower

One window for your entire security operation.

Real-time posture, AI triage, automated response, investigations, and CISO-ready reporting — in a single console your team actually wants to use.

Command center

See every threat, ranked and in context.

A real-time dashboard with a live attack map, an AI-scored triage queue, and drill-downs from any metric straight to the underlying events.

  • Live global attack map
  • AI triage queue, highest-risk first
  • Click any KPI to see the records behind it
Live attack map · real-time inbound threat traffic
Respond

Incidents that fix themselves — or wait for your call.

Correlated incidents each reference a configurable response playbook with documented steps. Flip a playbook to auto and FortHound contains threats the moment they fire; keep it manual and every step waits for approval.

  • Configurable auto / manual playbooks
  • Graphical attack-path & MITRE ATT&CK views
  • One-window analyst desk: phishing, URL, IP, domain
Isolate host
Block source IP
Auto-contained
Playbook PB-07
Report

Answers for the board, not just the SOC.

One-click CISO briefings — biggest threats, posture, automation rate, risk — auto-compiled from live telemetry and exportable to PDF. Plus an external breach/CVE feed matched to your own inventory.

  • Executive report in one click
  • Threat-intel feed correlated to your assets
  • Admin console: team, roles & connectors
Exec report · PDF
Automation rate
SOC 2 · ISO · GDPR
Beyond the SOC

Four more ways the Hound has your back.

Attackers target your people and your privileged access. Phishing Simulator, Cyber Training, PAM and Access Review close those gaps — same platform, same login, one console.

Hound Phishing Simulator

Attack your people before the attacker does.

Launch realistic phishing campaigns across credential-capture, malware and BEC lures — then see exactly who clicked, who handed over credentials, and who keeps falling for it.

  • Credential · malware · BEC attack types
  • Per-user clicked / compromised tracking
  • Repeat-offender history & risk score
  • One click: enrol offenders into training
Open the simulator →
Phishing Simulator · Campaign
Sent
Clicked
18%
38 users
Gave credentials
7%
15 users
Delivered
214
all staff
Repeat offenders
3
≥2 fails
Who was compromised
M. ChenFinancecredentials
R. PatelOperationsmalware
J. OkaforExecutivewire / BEC
Hound Cyber Training

Turn every employee into a human firewall.

Assign bite-sized, FortHound-branded video courses with a quiz they must pass. Launch on a weekly, biweekly or monthly cadence and track completion to the percentage point.

  • AI-generated video courses + pass-to-complete quizzes
  • Weekly · biweekly · monthly cadence
  • Completion dashboard — sent / done / pending
  • Flags anyone below 30% over six months
Open the LMS →
Cyber Training · Completion
6 mo
Completion
74%
org-wide
Completed
59
of 80
Pending
21
assigned
At-risk <30%
1
follow up
Courses · completion
Phishing & Social Eng.monthly95%
Passwords & MFAmonthly95%
Ransomware Readinessweekly55%
Hound PAM

Control who holds the keys — and for how long.

Vault every privileged credential, grant just-in-time access behind approvals, watch live sessions with risk scoring, and rotate secrets before they go stale.

  • Privileged-account vault with rotation policy
  • Just-in-time access requests & approvals
  • Live session monitoring — terminate in one click
  • Full, time-stamped audit trail
Open PAM →
PAM · Privileged access
Live
Privileged accounts
8
3 high-privilege
Active sessions
1
monitored
Pending requests
3
awaiting approval
Stale credentials
2
past policy
Access requests
L. Obrien → root@prod-db-01JIT · 60 minpending
J. Reed → svc@jenkins-ciJIT · 120 minpending
Hound Access Review

Prove the right people have the right access.

Run periodic certification campaigns across every app and role, certify or revoke each entitlement in a click, and auto-surface dormant, orphaned and toxic access.

  • Certification campaigns across all apps & roles
  • One-click certify / revoke, with bulk actions
  • Auto-flags dormant, SoD-conflict & orphaned access
  • Audit-ready evidence for SOC 2 / ISO / SOX
Open Access Review →
Access Review · Q3 campaign
Live
Reviewed
62%
of entitlements
Revoked
17
access removed
Dormant
11
unused >90d
SoD conflicts
4
toxic combos
Flagged entitlements
A. Bello → AWS PowerUserdormant 140drevoke
S. Cruz → NetSuite ApproverSoD conflictrevoke
Hound Workflow

Routine requests, routed and approved.

Stop running onboarding and access requests through email threads. Structured forms route through multi-step approval chains with comments, SLA tracking and a complete audit trail.

  • Prebuilt forms — onboarding, access, exceptions, offboarding, vendor review
  • Multi-step approval chains with comments
  • SLA tracking flags anything overdue
  • Full timeline — who approved what, and when
Open Workflow →
Workflow · Approvals
Live
Open requests
4
awaiting approval
Approved
1
chain complete
Past SLA
3
escalate
Avg cycle
12h
submit → decision
Awaiting decision
Access Request · AWS PowerUserstep 2/3 · System Ownerpending
Policy Exception · MFA waiverstep 2/3 · Risk & ComplianceSLA
Total coverage

One hound. The whole attack surface.

Every capability radiates from a single platform — no bolt-ons, no extra logins. Here's what the Hound watches for you.

How it works

Live in three steps.

1

Connect your stack

Point FortHound at the tools you already run. Data flows in minutes; our team maps your environment.

2

FortHound takes over

The AI engine normalizes, scores, and correlates every event, opens incidents, and runs response playbooks — automatically or with approval.

3

You get one window

Your team works from a single console — real-time posture, an analyst desk, documented playbooks, and CISO-ready reports.

Deploy anywhere

Your data. Your network. Your choice.

Same platform, three ways to run it. Start on SaaS and move to self-hosted later without re-buying — the deployment model is a setting, not a different product.

SaaS FASTEST

We run it, you connect your tools. Fastest path to value, regional data residency, nothing for you to operate. Best for most teams.

Private cloud

Deployed into your own AWS / Azure / GCP tenant as containers on Kubernetes — your keys, your VPC, your control.

Isolated cloud tenant

Each customer runs in a logically isolated tenant, enforced in the platform and regression-tested on every release. Traffic is TLS end to end; secrets and credentials are sealed with AES-256-GCM.

Built to a standard

Mapped to the NIST Cybersecurity Framework 2.0

Every FortHound product declares the exact CSF 2.0 subcategories it satisfies — and names the capability that evidences each one, so your assessor can verify the claim instead of trusting a badge.

Also mapped to NIST SP 800-53 Rev 5 control families and NIST SP 800-63B authenticator assurance levels — Hound MFA operates at AAL2 by default and is AAL3-capable with phishing-resistant FIDO2 passkeys. FortHound's own control mapping. Not a NIST certification or endorsement.
HoundServices

The software finds it. People handle it.

FortHound is a platform, not a monitored service — it detects, records and proves, but it does not sit up at three in the morning. That is a person. HoundServices is where you buy the people: watching your estate, answering the phone at 2am, or filling the seat you have not hired yet. Professional-services work is billed at one published rate, $75 per hour.

Watched for you

Our people, on your estate, around the clock.

Hound SOC

24x7 monitoring by real analysts

Cybersecurity professionals watching your environment around the clock, triaging what fires and calling you when it matters. Runs on the SIEM you already own, or on Hound Security Tower if you would rather not own one.

  • Continuous monitoring and triage, not an inbox of alerts
  • Works with the SIEM you already run, or with Hound Security Tower
  • Escalation path agreed up front, so nobody wonders who to call
  • Every action lands in the same audit trail as the platform
How it is boughtMonthly, per estate. 24x7x365 with named analysts.

Hound Incident Response

Senior responders, on the bridge

A retainer that puts experienced responders on your incident inside the hour, and an emergency line if you are already in one. They work it in Hound Command Center, so the timeline and evidence register are defensible by the time it closes.

  • Retained hours that roll into readiness work if you never use them
  • Containment, forensics and the regulator-facing write-up
  • Runs inside Command Center — hash-chained log, evidence custody
  • Tabletop exercises, so the first real one is not the first one
How it is boughtAnnual retainer with a response SLA, or emergency engagement.

Expertise on tap

Senior security people, without a headcount.

Hound Security Consulting

Fixed hourly. No scoping games.

Senior security engineers by the hour at a published rate — architecture review, hardening, cloud and identity work, or a second opinion before you commit. Buy an hour or buy a hundred; the rate does not change.

  • $75 per hour — no discovery phase to price the discovery phase
  • Architecture, identity, cloud posture, hardening, migrations
  • Written findings you own, not a slide deck you rent
  • Unused hours never expire inside the term
How it is bought$75 per hour, billed in 30-minute increments.

Hound vCISO

Security leadership, fractionally

A named senior security leader who owns your roadmap, chairs the risk conversation and turns up to the board meeting — for a few days a month instead of a salary you cannot justify yet.

  • Owns the security roadmap and reports progress against it
  • Board and customer-assurance conversations handled
  • Vendor and insurer questionnaires answered properly
  • Builds the function until you are ready to hire it
How it is bought$75 per hour, by the day or the month. A named individual, not a pool.

Proof and readiness

Find the gaps before an auditor or an attacker does.

Hound Offensive Testing

Find it before they do

Penetration testing and red-team exercises against your estate, your applications and your people — with a report that ranks what to fix by what an attacker would actually reach, not by scanner severity.

  • External, internal, cloud, web and social engineering
  • Findings ranked by reachable impact, not scanner severity
  • Free retest of every finding you fix inside 90 days
  • Evidence lands in the platform, so the fix is provable
How it is boughtFixed price once scoped, built from $75 per hour.

Hound Compliance

Ready for the questionnaire

Get to NIST CSF 2.0, ISO 27001, SOC 2 or Cyber Essentials without a year of spreadsheets. The platform already maps its controls to NIST CSF 2.0, so the evidence is a report rather than an archaeology project.

  • Gap assessment against the framework you actually need
  • Evidence pulled from the platform, not rebuilt by hand
  • Policies written for your business, not templated boilerplate
  • Auditor liaison through to certification
How it is boughtFixed price per framework, built from $75 per hour. Readiness or the full journey.

Hound Deployment

From signed to running, with us

The Deployment Center walks you through it for free. This is the version where we do it with you — connectors wired, agent rolled out, roles assigned, and the readiness score green before we hand over.

  • Identity, endpoint and awareness sources connected and verified
  • The agent rolled out across the fleet
  • Roles, MFA and the audit trail set up correctly the first time
  • We leave when the readiness score is green, not when the hours run out
How it is boughtFixed price at $75 per hour. Included with annual subscriptions.
Pricing

One subscription. Every product.

No editions, no per-product SKUs, no upsell for the controls that matter. You get all seventeen products, and you keep the tools you already own.

FortHound Complete
$2,900 /mo + $28/user
A fixed platform fee, plus a flat rate per user. Everything, for everyone.
  • All seventeen products — detection & response, people security, identity & access, IT operations
  • Connect the tools you already own — Cisco Duo and KnowBe4 today, more as they ship, unlimited and at no extra charge
  • Endpoint agent and the Outlook/Teams add-in included
  • NIST CSF 2.0 evidence assessment and export
  • Unlimited administrators, auditors and API access
  • Every new product we ship, at no extra cost
Start a 30-day trial
What it costs
By headcount
Check the bill by hand — that is the point.
  • Platform fee — $2,900/month, whatever your headcount
  • Every user — $28/user/month, one flat rate
  • 100 people — $5,700/month
  • 250 people — $9,900/month
  • 1,000 people — $30,900/month
  • Billed monthly, cancel any time
Get a quote

Already run Duo, KnowBe4 or CyberArk? Keep them. Connect them and their data streams into the platform, so Hound Signal can still score every person across all seventeen products. Connecting is free and unlimited — charging you for integration work would be charging you to make our own product better.

A 250-person company pays $9,900/month — the $2,900 platform fee plus 250 × $28 — for all seventeen products and every connector. Two numbers, one multiplication: you can check the bill without calling us.

HoundServices is priced separately, at $75 per hour. Consulting, vCISO, offensive testing, compliance and incident-response work are billed against one published rate — no discovery phase to price the discovery phase. Hound SOC and the IR retainer are quoted per estate, because they run continuously rather than by the hour. See the services.

FAQ

Questions, answered.

Platform & products
Neither, and the distinction matters more than the label. A SIEM ingests logs from everything you run and lets you write correlation rules over them — FortHound has no such ingestion pipeline and does not claim one. A managed SOC puts human analysts in front of your alerts around the clock — FortHound is software, and the subscription does not include anyone watching it. What it is: seventeen security products a mid-size company is actually asked for, sharing one identity model, one role model and one tamper-evident audit trail, plus the two things only a platform can compute — a risk score per person across all seventeen, and a leaver revoked everywhere at once with a certificate to prove it. If you also want someone watching the queue outside your hours, 24×7 monitoring is available as a separate service, priced per engagement and not bundled into the subscription.
FortHound is one subscription — a $2,900 monthly platform fee plus $28 per user — with every product included and unlimited administrators, against five to eight point tools bought separately. To be precise about what it does not replace: it is not a SIEM and it does not put an analyst in front of your alerts at 3am. It replaces the tool sprawl, not the night shift. If you want the night shift, 24×7 monitoring is a separate service — ask us for it.
You don't buy them individually at all — there is one subscription and everything is in it. Switch on what you need today and leave the rest off; they share one login, one identity model and one audit trail, so turning one on later is a toggle, not a migration. Signal is the one that gets better with every product you enable, because it is a join over all of them.
No — connect them. In the Platform Control console every product can run in one of three modes: use ours, connect the tool you already own, or off. A connected tool streams its data in, so your dashboards and Hound Signal still see the whole picture — enrolment coverage from Duo, completion records from KnowBe4. Connecting is free and unlimited. Two connectors are built today: Cisco Duo and KnowBe4. Everything else runs on FortHound’s own engine until its connector ships, so no product is blocked waiting for one, and figures that have not come from a real integration are labelled simulated in the console and in the API. Tell us which tool you need next and it goes to the front of the queue.
The join. Signal scores every person by likelihood of compromise multiplied by blast radius, reading across all seventeen products — your Duo enrolment, your KnowBe4 completions, our phishing results, our privileged-access records — and no point tool can compute that because none of them can see the other fifteen. Offboard revokes across every one of those systems in a single action with a tamper-evident certificate. Command Center runs the incident across all of it. Those four capabilities are native-only for the same reason: they are joins, not products.
Yes. Because everything runs on one security core, the second product inherits your users, roles and audit history on day one. There is no second onboarding.
No. FortHound sits on top of what you already own and unifies them. As long as we can get the data, FortHound handles triage, correlation, response, and reporting. No rip-and-replace.
If your identity provider already covers every application, keep it. Hound MFA is for the gaps most teams have: legacy apps, infrastructure, and contractors outside the corporate IdP. It runs alongside an existing IdP rather than replacing it.
Deployment & the agent
Data starts flowing in minutes once a connector is pointed at FortHound. A typical tailored deployment completes in days, not months.
Not yet, and this answer used to say otherwise. Generic ingest — pointing any syslog, CEF, JSON/REST, webhook or S3 source at FortHound and having it parse like a built-in — is on the roadmap, not in the product. Today a connector is written against the vendor's API; Cisco Duo and KnowBe4 are done and the next ones are built in the order customers ask for them. Meanwhile every product runs on FortHound's own engine, so nothing is blocked waiting for an integration. Tell us which tool you need and we will tell you where it sits.
No — FortHound works from your existing tool data alone. The agent is optional and adds two things logs cannot give you: real hardware and installed-software inventory, and telemetry from endpoints your other tools do not cover.
Chassis make, model and serial; CPU, memory and disk; operating system and whether it is still vendor-supported; installed software titles; listening ports; running processes; local administrators. It does not read documents, keystrokes, browser history or file contents. Every payload is HMAC-signed, and the agent is a single file of readable JavaScript you can audit before deploying it.
One person part-time. That is the point of automated triage and configurable playbooks — the platform absorbs the volume so your people make decisions instead of clearing queues. Deployment and tuning are handled by our team as part of onboarding.
Security & compliance
Your data lives in a logically isolated tenant, and that isolation is regression-tested on every release across both the API and the live event stream. Traffic is TLS end to end. Secrets, connector credentials and second factors are sealed with AES-256-GCM under a master key that never leaves the server — the rest of your tenant's data is protected by the disk encryption of the environment it runs in, which is a real distinction and we would rather draw it than blur it. RBAC and tamper-evident audit logging are enforced platform-wide, and the NIST pack produces control-by-control evidence you can hand to a SOC 2, ISO 27001, GDPR, PCI or HIPAA audit. Single sign-on uses OpenID Connect — Entra ID, Okta, Google Workspace and anything else that speaks OIDC, with just-in-time provisioning if you want it. SAML is not built: verifying XML signatures safely needs canonicalisation, and we would rather ship one federation protocol we trust than two we half-trust. Without SSO, sign-in is a password plus a second factor.
Each product is mapped to the CSF 2.0 subcategories it supports, and the evidence pack assesses those controls against your live configuration rather than restating a claim. To be explicit: this is our own assessment and reporting tool. It is not a NIST certification — no such certification exists to hold.
Not yet, and we would rather tell you than imply otherwise. The controls a SOC 2 audit examines are built and enforced today — MFA, RBAC, tamper-evident audit logging, encrypted secrets, tenant isolation — and the NIST evidence pack gives an auditor a control-by-control starting point. Formal certification is on the roadmap; ask us where it stands.
Yes. The NIST CSF 2.0 evidence pack exports control-by-control as CSV or a printable report, showing which controls are satisfied, partial or gapped, with the measured evidence behind each. Partial and gapped findings are shown deliberately, so you remediate and re-evidence rather than discovering them mid-audit.
Nobody. There is no support-impersonation or break-glass path into a customer tenant — not one that is time-boxed and logged, none at all, because it has not been built. If that changes it will be opt-in and written to the same tamper-evident audit log you can read. Tenant isolation is enforced in the platform and regression-tested on every release — across the API and the live event stream.
Commercial
FortHound is delivered as cloud SaaS. Each customer gets a logically isolated tenant, with TLS in transit and secrets sealed under AES-256-GCM. A dedicated instance with data-residency controls is available on Enterprise. You're live in days — nothing to rack or maintain.
It is yours. Everything exports in open formats — CSV for records, JSON for raw events, PDF for reports — and we will run the export for you. No exit fee, no proprietary format, no hostage period.
Yes. We run a fixed-scope pilot against a slice of your real environment — typically one or two connectors and a subset of endpoints — so you evaluate FortHound on your own data rather than a canned demo.
Onboarding and tuning are included, in business hours, and you deal with the people who built the platform rather than a tier-one queue. 24×7 monitoring is not part of the subscription. It is a separate service with its own scope and price — someone watching your queue outside your hours and escalating to a named contact — and it is quoted per engagement rather than bundled into a plan, because pretending a subscription includes a night shift is how that promise gets broken.
Get in touch

See FortHound running on your stack.

Book a walkthrough or ask a question — we'll show Hound Security Tower live on your environment.

Book a demo
We'll reply within one business day. No spam, ever.
Thanks — your request has been logged. We'll be in touch shortly.
Xarrak Habib
Xarrak Habib
Founder · FortHound

Reach out directly to talk product, deployment, or a tailored pilot for your environment.

Connect on LinkedIn
Or email sales@forthound.com for a demo or pricing, info@forthound.com for anything else.
Founder: xarrak@forthound.com
Prefer to explore first? Launch the live console →
See it running

All seventeen. This is the actual product.

Not mockups — screenshots straight from the consoles you can open on the live demo. It scrolls itself; hover to stop it, or drag.

Hound Security Tower console Hound Security Tower Your whole operation in one window Alerts, incidents, playbooks and the live attack map — one console instead of five. Hound Signal console Hound Signal One risk score per person Likelihood of compromise multiplied by what it would cost. No point tool can compute it. Hound Offboard console Hound Offboard One action revokes everything Accounts, entitlements, privileged access, secrets, devices and factors — with a certificate proving it. Hound Phishing Simulator console Hound Phishing Simulator See exactly who clicks Credential, malware and BEC tests, per-user click tracking and repeat-offender history. Hound Cyber Training console Hound Cyber Training Training that gets finished Courses and quizzes on a set cadence, with completion tracked and stragglers flagged. Hound Report console Hound Report One button, one triage queue A Report Suspicious button in Outlook and Teams, scored and promoted to an alert when it is real. Hound PAM console Hound PAM Admin access only when it is needed Just-in-time elevation with approvals, live session monitoring and automatic secret rotation. Hound Access Review console Hound Access Review Certify or revoke, one by one Campaigns across every entitlement, with dormant, orphaned and toxic access flagged for you. Hound MFA console Hound MFA Push, passkeys, TOTP and hardware keys Strong authentication across your apps, with device trust and a complete authentication log. Hound Vault console Hound Vault Every secret, every reveal, on the record Passwords, API keys and certificates encrypted at rest, and every single decrypt named. Hound Workflow console Hound Workflow Approvals that route themselves Onboarding, access requests and policy exceptions moving through real approval chains. Hound Dormancy console Hound Dormancy Silence resolves to revoke Dormant accounts across AD, Entra, SAP and everything outside SSO, each with a named owner. Hound IR Planning console Hound IR Planning Decide it now, not at 3am A severity matrix and escalation rules, with a simulator showing exactly who gets told. Hound Command Center console Hound Command Center Run the incident, log every action A standing bridge, one-click containment and a hash-chained record ready for forensics. Hound Broadcast console Hound Broadcast Prove who actually saw it Alerts pushed to managed desktops, with a read receipt per machine. Hound IT Assets console Hound IT Assets Know what you own and what it costs Agent-discovered hardware, software licence compliance and lifecycle planning.

Ready to defend like a bigger team?

Open the live interactive demo, or book a walkthrough and we'll tailor it to your stack.

DEMO ENVIRONMENTAll data is fictional