Security software that does
the job, not the demo.
XCloak builds two things: a platform that watches your systems after they're deployed, and one that finds what's wrong with them before an attacker does. Self-hosted where it counts, AI-assisted where it helps.
Pick what you need. Click for details.
Two products today. Click a card to see architecture, features, docs, and how to try it.
XCloak Security Suite
A unified NGFW, SIEM, EDR, SOAR, ITDR and MDM platform — one agent, one backend, one dashboard, self-hosted on your own infrastructure. AGPL-3.0.
- · 102 Sigma rules + 23 behavioral detectors
- · AI-recommended response playbooks
- · Android MDM, no per-device licensing
- · Docker Compose, Helm, or bare binaries
XCloak Recon
AI-orchestrated penetration testing. Describe a goal, the AI plans and runs nmap, nuclei, gobuster, sqlmap, nikto, ffuf, and whatweb, then synthesizes the results into a risk-scored report.
- · AI planning (GPT-4o, Claude, or local Ollama)
- · Live WebSocket scan streaming
- · Human approval before follow-up actions
- · PDF reports, findings DB, scan history
More products get a card here as they ship.
Our mission
Good security shouldn't need a huge budget or a dozen disconnected tools. XCloak Security Suite watches everything, all the time, after you've locked a system down. XCloak Recon finds what's wrong before an attacker does. Both are free to use, both are under active development, and both come from the same small team.
Built by 0xIdiot — India 🇮🇳
Get in touch, or just dive in.
Questions, bug reports, or partnership ideas — reach out any time.