Four products in production/Canton, Michigan

We build the software that watches your data layer.

Database activity monitoring, managed databases, sovereign meetings, and managed Kubernetes, built for banks, government, and the service providers who serve them. Everything runs on infrastructure you control, under keys you hold.

10
Database engines
215
Security rules
21
Compliance frameworks
0
Agents on your databases

Vyrell, in production today.

01

The product, as it actually runs

Vyrell audit log showing system activity with expanded detail: log ID, user ID, auth method and user agent, alongside successful and failed login records.
Vyrell / Settings / Audit Logs, live deployment, not a mockup.Source addresses redacted for publication.
02

Four products, one discipline

Vyrell

Live
Database activity monitoring

Each connector authenticates as a low-privilege, read-only audit reader and polls the engine’s own audit trail across ten database engines.

Nothing is installed on the production database, so onboarding a target is a grant of read access rather than an agent rollout.

Detail →

Nothi

Live
Managed database platform

A Kubernetes-native control plane provisions databases as operator custom resources across twelve engines, inside tenant-isolated namespaces on the customer’s own cluster.

Managed-service operations, provisioning, backups, metering, and upgrades, without handing the data to a third-party cloud tenant.

Detail →

Dorbar

Live
Sovereign video meetings

Every room carries a classification fixed at scheduling: an Official room the in-cluster media server is trusted to record and transcribe, or a Sealed room that is end-to-end encrypted and the server cannot see at all.

Both trust models on one platform, air-gap capable, chosen per room rather than per product.

Detail →

Moncho

Live
Sovereign managed Kubernetes

Managed Kubernetes with a hosted control plane per tenant and three isolation tiers, up to a cluster that shares no API server or etcd with anyone else.

Sovereign clusters with a compliance pack attached: posture per framework, hash-chained snapshots, continuous CIS scanning.

Detail →

Each product names its own limits on the platform page.

03

How it works, and what that gets you

Agentless collection

Each connector signs in as a low-privilege, read-only audit reader and polls the database’s native audit trail.

Onboarding a database is a permission grant, not an agent rollout, so a new target takes days, not a change-management cycle.

Tamper-evident trail

Vyrell’s own audit log is SHA-256 hash-chained and insert-only, with a daily integrity verifier.

Tampered records, chain breaks, and sequence gaps are detectable, so the trail holds under an auditor’s scrutiny.

Behaviour analytics

Users, source hosts, client IPs, and applications are scored against their own baselines, with peer-group comparison.

Each alert carries a plain-English reason for the score, so an analyst triages instead of reverse-engineering a number.

Reports that show gaps

If a query behind a compliance report times out, the report is marked incomplete and given no score.

You never file a passing result that the underlying data did not support.

04

Evidence, not adjectives

Our own certifications
ISO/IEC 27001:2022
Information security management
Certificate 26EQQV75
ISO 9001:2015
Quality management
Certificate 26EQQJ63

Both issued by AQC under EGAC accreditation, recognised through the IAF MLA, and valid through 20 April 2029. We hold no logo-use licence, so these are stated in text only.

Frameworks in the Vyrell policy library215 rules / 21 frameworks
PCI-DSS Extended
HIPAA
SOX
GDPR
NIST 800-53
ISO/IEC 27001
SOC 2
CCPA
GLBA
FERPA
Bangladesh Bank ICT v4.0
Defense Security

Nine further frameworks ship in the library.

Vyrell policy rules screen: 215 total rules, 215 active, 72 critical, 93 high, with the framework selector open showing ISO 27001, NIST 800-53, SOC 2, and more.
Vyrell / Policies, the rule library filtered by framework.
05

Who we build for

Financial services

Banks, NBFIs, insurers, mobile financial services, and payment service providers under PCI-DSS, SOX, and central-bank ICT guidelines, including the 26 Bangladesh Bank ICT rules that ship in the policy library.

Healthcare

Hospitals and health systems that must show who touched patient records, and when, without instrumenting clinical databases.

Government and defence

Agencies that require deployment inside their own boundary, with data and keys held in jurisdiction.

Enterprise IT

Regulated enterprises consolidating database oversight into one console with role-scoped access.

Service providers

Vyrell, Nothi, and Moncho are multi-tenant and licensable, so a CSP, MSP, or MFS operator can run them for their own customers instead of reselling someone else’s cloud. Dorbar deploys as a tenant of one, by design.

06 / Early customer programme

A 30-day proof of concept, at zero cost.

Open to qualified BFSI, government, and defence organisations. You keep the audit output whether or not you buy.

01
Technical call

Thirty minutes with an engineer, not a sales deck. Bring your estate: engines, versions, audit configuration.

02
Scoped deployment

We agree the targets, the read-only accounts, and the frameworks that matter to your auditor.

03
30-day proof of concept

Zero cost for qualified BFSI, government, and defence organisations. Real events, real reports, your data.