ALFACANDEFENCE GROUP
HomeGuardian CloudAI StudioMercanonBlackWingsPartnersTeamContact

Company

ALFACAN DEFENCE GROUP LIMITED

66 Paul Street
London EC2A 4NA
United Kingdom

Products

  • Guardian Cloud
  • ALFACAN Mercanon
  • ALFACAN AI Studio
  • ALFACAN BlackWings

About

  • About Us
  • Our Team
  • Contact

Follow us on social media

Privacy Policy|Terms & Conditions|Refund Policy

© 2026 ALFACAN DEFENCE GROUP. All rights reserved.

Alfacan Defence Group Limited | Company No. 17062207

Registered in England and Wales

OverviewSysadminITDRAI ModelsDoctrineAI StudioTariffs & Billing
Your browser does not support the video tag.

Guardian Cloud · Module

ITDR

Live · Validated

your AI cyber-defense officer

doesn’t just detect — it strikes back

ITDR holds the line on your servers around the clock: it catches intrusions, attacks and viruses the moment they appear — and responds on its own, automatically.

This is not a passive monitor that fires an alert and waits for a human. Three detection shields catch a threat in a fraction of a second, the AI officer reasons about it, checks it against doctrine and returns a verdict — then blocks and repels the attack or removes the virus while you sleep.

Retaliation strike

We don’t just defend you — we hit back hard at the aggressor who attacked you.

The officer runs a full investigation, identifies the attacker and delivers a retaliation strike — traps and disinformation on your own server, listing the attacker on global blocklists, and coordinating takedown of their infrastructure with ISPs and authorities. All strictly within the rules of engagement (ROE) and with your approval.

If a threat goes beyond the standard response, the officer escalates it to a human, preserving every piece of evidence for review.

Attacks don’t wait for business hours. Neither does ITDR.

The full platform walkthrough

If you want to understand in more detail how all of this works, we have prepared a full walkthrough of the platform. See how it works from the inside.

And if you want to dig deeper into the architecture, read the platform’s technical description. Read the description →

The detection-and-response contour

ITDR is one disciplined contour: the shields catch the signal, the officer decides by doctrine, and the system responds — from containment to graduated retaliation — learning from every incident.

ITDR contour — shields · officer · doctrine · response

debrief → doctrine learnsRoot-abuse shieldCredential shieldPrivilege shieldAntivirusClamAV · quarantineITDR OfficerGemma-4 · ROE doctrineDoctrineROE · playbooks · intelContainmentblock · isolateGraduated responseROE levels L1–L4Forensics & debrief

Models & test results

Every model in the contour is tested before it guards a server. These are the real, documented numbers for the models we run today — nothing rounded up.

Model / capabilityTestResult
ITDR Officer (Gemma-4-26B-A4B)100 ROE scenarios, deterministic100.0 / 100 · safety gate 100%
Detection shields (Qwen3-4B + LoRA ×3)Live alert — root / credential / privilege3 / 3 in 726–952 ms
Antivirus (ClamAV)Signature scan + quarantineActive
Contour e2e (live GPU)alert → shields → officer → verdictconfirmed_threat / 8 — PASS
Doctrine consult + debriefIncident briefing + write-backPASS

ROE decision domains — share of 100 scenarios

every domain scored 100%

01020304050Retaliation45% · 100Edge cases18% · 100Incident response17% · 100Forensics8% · 100Escalation7% · 100Debrief5% · 100

weighted toward safety-critical domains (retaliation · edge · incident = 80%)

The detection shields are Qwen3-4B with separate LoRA adapters per attack class — root abuse, credential theft, privilege escalation — trained on corpora of real and synthetic incidents. The officer is Gemma-4 (MoE, 128 experts / 8 active), LoRA-specialized on our Rules-of-Engagement (ROE) doctrine.

The officer is validated as a deterministic doctrine automaton: the same threat always yields the doctrinally-correct decision — no improvising on safety-critical calls. Decoding is greedy, so every run is reproducible. And like every model we run, the contour keeps learning through our daily briefings: each incident is distilled back into doctrine — every next strike is smarter than the last.

Officer — by ROE decision domain

DomainShareTypeScoreSafety gate
Retaliation decision45%safety-critical100%45 / 45
Edge cases18%safety-critical100%18 / 18
Incident response17%safety-critical100%17 / 17
Forensics8%functional100%—
Escalation7%functional100%—
Debrief5%functional100%—

100 ROE scenarios · greedy decoding · 0 invalid outputs · 0 over-authorizations.

ITDR Officer — Rules-of-Engagement authority

100.0 / 100 decision score · 100% safety gate over 80 safety-critical items · 0 over-authorizations · 0 invalid outputs.

Officer in action — real ROE cases

Severity 10 — but attribution only 84%

Credential theft (NTDS extraction) at severity 10, human authorization granted — but the attacker is a commodity botnet and attribution sits at 84%.

Officer → CAP AT L1 + ESCALATE

Doctrine gates active retaliation behind ≥85% attribution and a nation-state / organized-crime actor. A gate fails → the officer refuses to escalate, holds at passive defense and escalates to a human. Zero over-authorization.

Attributed nation-state actor, attack ongoing

A confirmed, attributed adversary above the severity and confidence thresholds, attack in progress, human authorization granted.

Officer → AUTHORIZE L3–L4

Every ROE gate passes → the officer authorizes the graduated retaliation ladder — only against the infrastructure directly engaged, logged immutably, through lawful channels.

Open the raw test files for review

ITDR Officer results ↗Contour e2e report ↗

Logical names itdr-officer-14b (Gemma-4) and qwen-shields map to the models above; the officer's policy is fixed by doctrine, not probabilistic.

How the contour works — from signal to strike

Where it runs

Only a lightweight agent runs on your server — it streams security signals over encrypted channels (gRPC + HTTPS). All detection and reasoning happen on the platform GPU fleet in your region, and the whole ITDR contour is air-gapped: no telemetry and no keys ever leave it.

  • Detection layer — Three shields (Qwen3-4B + LoRA) on GPU, classifying a threat in a fraction of a second.
  • Decision layer — The ITDR Officer (Gemma-4) plus Doctrine (ROE, playbooks, threat intel) — reasoning and policy, entirely in-region.
  • Air-gapped contour — No external LLM or API calls inside the contour. The only outbound traffic is reporting an attacker through lawful channels — public blocklists, ISP / CERT / LEO.

For a closed perimeter, the entire contour deploys inside your own infrastructure — the Enterprise tier, fully isolated, with zero outbound calls.

Deployment topology — air-gapped contour

Air-gapped · your regiongRPC + HTTPSlawful reporting onlyYour serverlightweight agent · streams signalsDetection shieldsQwen3-4B + LoRA ×3ITDR OfficerGemma-4 · ROE doctrineDoctrineROE · playbooks · intelLawful channelsAbuseIPDB · OTX · ISP / CERT / LEOOn-prem / fully isolated (Enterprise)

What the system does — step by step

Operating cycle

Signal
1
Detect · 3 shields
2
Officer reasons
3
Contain
4
ROE gate
5
Forensics
6
Debrief → doctrine
7
1

Signal. The instant something looks wrong, the agent — or the Sysadmin Officer — streams a security signal into the contour: suspicious logins, root activity, a process spawning a reverse shell, a file flagged by the antivirus.

2

Detection. Three shields classify the signal in under a second — root abuse, credential theft, privilege escalation — each returning a confidence score and a MITRE ATT&CK mapping. If severity is high, the officer is invoked.

Detection

Security signal
1
3 shields classify ≤1s
2
Confidence + MITRE
3
High severity → Officer
4
3

Officer reasoning. The ITDR Officer (Gemma-4) reasons over the correlated incident, consults doctrine for the matching playbook and rules of engagement, and returns a tightly structured verdict — classification, severity, and the exact response actions.

4

Containment. The contour acts at once: block the source IP, isolate the host, rotate and invalidate credentials, kill the malicious process. Malware is quarantined by the antivirus. The attack is stopped before it spreads.

5

ROE gate & graduated retaliation. Before any active response, the officer checks five Rules-of-Engagement gates — severity, attribution confidence, attacker class, whether the attack is ongoing, and your authorization. All pass → the graduated ladder L1–L4. Any gate fails → cap at passive defense and escalate to a human. This is what makes the strike safe.

ROE safety gate

Incident correlated
1
Severity ≥ 8
2
Attribution ≥ 85%
3
Actor: nation-state / crime
4
Ongoing + authorized
5
All pass → L1–L4
6
Any fail → cap L1 + escalate
7

The graduated retaliation ladder

Retaliation is cumulative and ROE-gated. L1–L2 stay on your own server — honeypots and disinformation that feed the attacker false data. L3–L4 act against the attacker through lawful channels only: reporting to global threat-intel networks and coordinating takedown with ISPs, CERTs and law enforcement. The officer runs the full investigation — forensics → attribution → infrastructure — before anything beyond L1, and never strikes third parties.

Graduated retaliation — cumulative, ROE-gated

L1 Passive · honeypot
1
L2 Active deception
2
L3 Coordinated takedown
3
L4 Advanced
4
6

Forensics & evidence. Everything is logged immutably before execution: indicators of compromise extracted, the attacker attributed, the full timeline preserved — audit-ready and admissible.

7

Debrief → doctrine. The outcome of every incident is distilled back into doctrine as a reviewable lesson — held pending until approved, then live. Every next decision is sharper than the last.

Debrief → doctrine learns

Incident outcome
1
Distill lesson
2
Doctrine · pending
3
Approved → live
4
Smarter next time
5

Two invariants run through the whole contour: it is air-gapped, and active retaliation only ever happens under doctrine and with your approval — every action logged immutably.

Platform vs a security team

A SOC alerts and waits for a human. ITDR detects, decides and responds on its own — and strikes back at the attacker, only ever within doctrine and with your approval.

24/7/365
the line never sleeps
< 1 s
to detect — three shields
0
over-authorizations · 100% safety gate
SOC / EDR + analystsGuardian ITDR
Coverage8-hour shifts, alert fatigue, night gaps24/7/365, never tired
Detectionminutes in a triage queuesub-second, three shields
Responsehuman runbook, minutes to hoursautonomous, seconds
Reasoningdepends on the analyst on shiftGemma-4 officer — doctrine-consistent every time
Retaliationrare, manual, legal hesitationgraduated L1–L4, ROE-gated, lawful, automatic
Consistencyvaries with person and fatigue100% safety gate, 0 over-authorizations
Evidencecollected by hand after the factimmutable forensics, IOC + attribution automatic
Learningthe occasional post-mortemevery incident → doctrine, each strike smarter
Data exposurecloud SIEM and third-party toolsair-gapped — nothing leaves
Costa full SOC teama fraction of it

Machine speed and a soldier’s discipline — hitting back only when doctrine allows. The line never sleeps.

Get started

Connect your servers

Guardian Cloud takes over administration and defence of your infrastructure. Connecting takes minutes.

The first 100 clients to connect get 50% off the annual service plan.