v2.0 — AI-Enhanced Detection is live

Endpoint Security Built for MSPs
Not Megacorps

OmniProtect delivers world-class threat detection and response at a fraction of the cost. Full data sovereignty. Deploy anywhere in under 30 minutes.

OmniProtect MSP — dashboard
Dashboard
Clients
Alerts
Enrollment
Audit Log

24

Clients

1,847

Agents

3

Open Incidents

1

Critical

Recent AlertsLast 24h
CRITICALAcme CorpLSASS Memory DumpWIN-DC012m ago
HIGHTechStart IncSuspicious PowerShellDESKTOP-44X18m ago
MEDIUMBuildCo LLCLateral Movement IOCSRV-FILE011h ago

48

Detection Rules

12

MITRE Tactics Covered

4

Supported Platforms

<1s

Alert Latency

100%

Open Source

Platform Capabilities

Everything your security team needs

Purpose-built for Managed Security Service Providers delivering EDR to multiple clients from a single pane of glass.

AI-Powered Correlation

LangGraph multi-agent correlation engine connects disparate events across endpoints to surface attack campaigns that rule-based systems miss.

Lightweight Rust Agent

≤4% CPU and ≤80 MB RAM steady-state. eBPF collectors on Linux, ESF on macOS, ETW on Windows — deep visibility without the performance tax.

Multi-Tenant MSP Architecture

Schema-per-tenant PostgreSQL isolation. Provision clients in seconds, drill into any tenant console from the MSP portal, generate enrollment tokens on demand.

Live Threat Intelligence

Automated IOC ingestion from CISA KEV, MalwareBazaar, AlienVault OTX, and MISP. LMDB-backed local store delivers sub-millisecond IOC lookups.

MITRE ATT&CK Coverage

Interactive heatmap shows exactly which ATT&CK techniques are covered per tenant. Identify detection gaps and prioritize rule development with data.

Zero Vendor Lock-in

Apache 2.0 licensed — use it, fork it, sell it. Full Helm chart for RKE2/K3s, a typed Python integration SDK, and sovereign CI via Forgejo Actions.

Getting Started

From zero to protected in minutes

No 6-week onboarding, no professional services engagement. Self-hosted, self-managed, fully yours.

01

Deploy the stack

Run `make dev-up` or apply the Helm chart to your K3s/RKE2 cluster. The full platform — API, Kafka, Keycloak, PostgreSQL, Redis — is up in under 5 minutes.

helm install omniprotect helm/omniprotect/ \
  --set keycloak.enabled=true \
  --set kafka.enabled=true
02

Provision clients & enroll agents

Create tenants in the MSP portal, generate enrollment tokens, and deploy the Rust agent to endpoints. One command installs and enrolls automatically.

curl -fsSL https://get.omniprotect.io/agent \
  | ENROLLMENT_TOKEN="tok_xxx" bash
03

Detect, correlate & respond

Live threat intelligence populates the IOC store. Behavioral rules fire. The AI correlation engine links events into campaigns. Respond with one-click isolation.

POST /api/v1/agents/{id}/isolate
POST /api/v1/correlation/analyze

Technology

No half-measures. Best-in-class stack.

Every component chosen for performance, security, and long-term maintainability.

Rust 1.77

Agent runtime

FastAPI

Platform API

Next.js 14

Console

PostgreSQL 16

Schema-per-tenant

Kafka 3.8

Event streaming

Keycloak 26

Identity & SSO

Redis 7

Cache layer

Claude Opus 4.6

AI correlation

Helm / K3s

Deployment

Why OmniProtect

The enterprise alternative that you actually own

Compare against leading enterprise EDR vendors on the market.

Feature
OmniProtect
Enterprise EDR vendors
Deployment model
Self-hosted or cloud
Cloud-only / SaaS
Data sovereignty
Full — your infrastructure
Vendor-held telemetry
Per-seat licensing
None — open source
$15–$60 per endpoint/mo
Multi-tenant MSP portal
Built-in
Limited / separate product
Agent resource usage
≤4% CPU, ≤80 MB RAM
5–15% CPU typical
AI correlation
Claude Opus + LangGraph
Proprietary, opaque
Source code access
Apache 2.0 — fully open
Closed source

Get Started Today

Ready to secure your clients' endpoints?

Deploy in under 30 minutes. No sales call, no contract negotiation, no per-seat fees. Full source code included.

Apache 2.0 Licensed · Full source at github.com/OCSGroup101/Business_AIProtector