Products
Onnex Bastion
They Unify Your Bills. We Delete Them.
Stop stitching a dozen dashboards by hand. Deliver enterprise-grade on-prem security and operations, managed from a single multi-tenant pane of glass.
Onnex Bastion is Huntress, but broader and unified. We integrate mature, proven open-source security engines behind a single control-plane, a single identity provider, and a single correlated timeline. Higher margins for the MSP, lower total cost of ownership for the client, and one throat to choke.
- 12
- Security and operations capabilities collapsed into one platform
- 5
- Open-source engines live and operating today
- 7
- Compliance frameworks mapped from the on-premises audit trail
- 1
- Control plane, one identity model, one correlated timeline
The Sprawl You Pay For Today
A typical small business needs roughly ten to twelve distinct security and operations capabilities to be secure and well-run today. Under the status quo, every single one is a separate SaaS subscription, separately billed, separately configured, poorly integrated, and collectively expensive. The managed service provider spends its hard-earned margin stitching a dozen disconnected consoles together by hand.
| Capability | The Onnex Bastion unified solution |
|---|---|
| Intrusion detection and prevention | Suricata (integrated today) |
| SIEM, log management and XDR | Wazuh (integrated today) |
| Edge IP reputation and auto-ban | CrowdSec (integrated today) |
| DNS filtering and web security | AdGuard Home (integrated today) |
| Digital forensics and threat hunting | Velociraptor (integrated today) |
| Identity, SSO and MFA | Authentik (identity backbone) |
| Next-gen firewall and segmentation | OPNsense (sequenced roadmap) |
| Web-application firewall | Coraza / ModSecurity (sequenced roadmap) |
| Zero-trust remote access | WireGuard / Headscale (sequenced roadmap) |
| Vulnerability scanning | OpenVAS / Greenbone and Trivy (sequenced roadmap) |
| Backup and disaster recovery | Restic / BorgBackup (sequenced roadmap) |
| Monitoring and uptime | Prometheus / Grafana / Uptime Kuma (roadmap) |
The result: instead of 10–12 logins, bills, and expired contracts, Onnex Bastion collapses the entire stack into one control-plane, one identity model, and one correlated event timeline.
The Three Pillars
Enforcement, not just alerts. “Response is execution, not a ticket”
Traditional managed-detection overlays sell a human-run Security Operations Center that ingests telemetry and returns a recommendation. But a “containment begins within 60 minutes” promise is a human number. It cannot scale to seconds. Onnex Bastion owns the entire on-premises observation and enforcement plane, so response is direct, machine-speed execution: block at the firewall, sinkhole at DNS, disable a session at the identity layer, isolate a host, or kill a process. Reversible Tier-1 containment executes autonomously in seconds with no human click required.
Sovereignty, weaponized. “Your data never leaves the building, not even to reach the AI”
In cloud-centric security stacks, all your sensitive network and endpoint telemetry must leave your premises to reside in a vendor’s cloud. For residency-sensitive verticals bound by HIPAA, CMMC or ITAR, this is a legal and regulatory non-starter. Onnex Bastion runs entirely locally at your premises, and the AI Operator’s transport is fully injected, so on a data-residency-bound site you can point it at a sovereign on-box model running on the appliance. Your data and your AI reasoning stay inside your physical walls.
Pure-margin economics. “They unify your bills, we delete them”
SaaS security overlays attempt to simplify your life by bundling multiple products into a single invoice, but you still pay the underlying per-seat license fees. Because Onnex Bastion’s core is built on mature open-source engines rather than proprietary vendor forks, per-seat software license fees disappear inside the box. The MSP’s marginal cost is pure compute, and the gap between low compute costs and your managed-service price becomes your resale margin.
Built-In Trust: the Compartmentalize Safety Valve
We answer the single biggest objection to autonomous machine-speed response: “what if the AI blocks my CEO or takes down production?” The trust mechanism is not “trust the algorithm”. It is an explicit, reviewable, human-gated set of controls called Compartmentalize.
1 · Blast-radius computation
When a high-severity threat is detected, the platform automatically computes its lateral-spread neighbourhood based on real observed network topology.
2 · Operator-editable boundary
The proposed blast radius is drawn on a live, animated attack map. Before any enforcement occurs, the operator can manually toggle hosts in or out of the containment plan.
3 · Audit chain of record
Only when approved does the action execute, writing every step, decision and rationale to an append-only, cryptographically verifiable, hash-chained audit log owned by the client.
Two Adoption Paths
You do not need to force a painful rip-and-replace on day one. We support two distinct on-ramps to fit your clients’ renewal cycles:
Overlay to land
Keep your client’s existing security stack. Ship its telemetry into Onnex Bastion’s unified timeline and AI operator via bring-your-own-telemetry push ingest. Immediately deliver correlated root-cause triage, the 12-playbook NIST incident-response library, and the client-owned audit trail, with zero footprint changes.
Replace to expand
As third-party SaaS contracts expire, absorb those capabilities into Bastion’s bundled open-source engines. This is where your economics scale, deleting per-seat line items and unlocking active machine-speed L2 containment.
Questions, and Our Honest Boundaries
What is Onnex Bastion, in plain English?
A unified physical or virtual appliance that collapses a dozen disconnected security and operations subscriptions into one platform. It correlates logs from network, endpoint, DNS and identity layers into a single event timeline, triaged 24/7 by an embedded AI operator.
What is actually live today, and what is planned?
Shipped and operating: the integration backbone, meaning one control-plane, Authentik SSO and the unified timeline; the five live open-source engines, CrowdSec, AdGuard Home, Suricata, Wazuh and Velociraptor; the MSP Fleet Plane operating live across two real client boxes with a live animated map; and the closed containment loop operating autonomously on our SDN test range, including real measured MTTR clocks, ebtables L2 isolation and the sovereign on-box model. Planned and sequenced: production-scale validation of the remaining engines (firewall, WAF, zero-trust, backups, secrets) and the cross-tenant threat-intel sharing network effect, which is mechanism-complete but awaits real external indicators across a broader client estate.
Are you certified (SOC 2, HIPAA)?
Onnex Bastion ships with a defendable seven-framework platform compliance control-mapping: SOC 2, ISO 27001, NIST CSF 2.0, NIST SP 800-53, PCI-DSS 4.0, HIPAA and GDPR. Four of these are automatically scored directly from your live, hash-chained on-premises audit trail. However, this is a compliance mapping built to accelerate an audit. It is explicitly not a vendor-issued certification, and we do not represent it as one.
Is the sub-minute containment guarantee a legal contract?
The physical capability to contain threats autonomously in under a minute is thoroughly measured and verified on our SDN range. Turning this into a commercial “or it’s free” warranty is a draft commercial claim pending final legal and governance sign-off. We represent the technical capability as real, but we do not make contractual promises until fully signed.
See the MSP Fleet Plane and the on-prem AI Operator in action.