CyberCLI

Mission

Arm the rebels.

The big cyber vendors charge $36,000 a year and ask you to ship your alerts to their cloud. The SMBs, MSPs, and homelab operators they price out of reach deserve the same agentic, sovereign, auditable security operations capability — without the invoice and without the data egress.

Three commitments

Sovereign by default
Your alerts never leave your environment. Local AI runs on your hardware. BYOK frontier models stay routed through your keys. The license verifier is fully offline. We never see what your network sees.
OSS-extending, not OSS-locked
We build ON the OSS substrate the security community already trusts — Wazuh, Suricata, ClamAV, Falco, Keycloak. We don't ask you to throw it out and we don't try to lock you in. If you walk away, your OSS keeps running.
Auditable autonomy
Every AI decision is hash-chained, signed, and replayable. The Trust Ladder caps the AI's authority per action class — we visualize the leash. "Human-in-the-loop" is not a marketing word; it's a per-template ceiling you can audit.

Founder

Chris — the operator who built this because nobody else would.

Ten years running BladeOne — an independent cybersecurity firm — after more than a decade in U.S. government cyber operations and a tour with the U.S. Secret Service. The pattern across every one of those years: small teams who needed enterprise security capability without the enterprise invoice, and were left choosing between an MDR retainer that owns their data and a half-working OSS stack that nobody has time to maintain.

CyberCLI is the product I kept wishing existed for those teams: agentic security operations on your hardware, your data, your audit chain. The open-source community already builds the world-class detection substrate — CyberCLI orchestrates it, layers an agentic AI on top with a visible Trust Ladder, and ships it as a single binary. Same kind of work my team has been doing for a decade, made buyable.

I've been working with AI since college at Rice University's A.L.I.C.E. Foundation, well before the LLM era. The shift Karpathy and Altman keep pointing at — one operator plus modern AI doing what used to take a hundred-person company — is real. CyberCLI is what that looks like in security.