Pitch Black
Transparent L2 insert between the internet handoff and your edge router. Observes inbound reconnaissance, runs deception for confirmed sources, and adds Egress Intel plus a local management API so SIEM, SOAR, and operators can use the box on your network. Zero config to evaluate.
Primary deployment is transparent inline bridge mode (L2). Place Pitch Black pre-firewall, post-firewall, or with no firewall — it does not require a firewall to be useful.
What Pitch Black is not
Pitch Black is focused. It is an autonomous edge defense layer, not a general-purpose security platform.
Not a firewall replacement
It complements or layers ahead of your existing firewall.
Not an IDS / IPS or NDR replacement
It does not replace those products. Egress Intel is handshake metadata versus known-bad feeds, not deep packet inspection or full flow analytics.
Not a TLS inspection middlebox
It does not decrypt, terminate, or MITM encrypted sessions. Handshake facts can be observed; payloads are not.
Not malware C2 detection
It is not an endpoint or malware-analysis product. Outbound C2 blocks apply to listed destinations at the bridge, not to payload inspection.
Pitch Black is an autonomous edge defense layer — it complements your existing stack rather than replacing it. The list above is the explicit non-goal line.
What Pitch Black is
An Autonomous Edge Defense System deployed as a transparent L2 appliance between the ISP modem and your edge router. It observes reconnaissance, fingerprints attacker tooling, and runs deception services, then autonomously blocks before traffic reaches your routable infrastructure. Egress Intel and a local API extend that same insert to outbound handshake visibility and operator automation.
Transparent L2 drop-in
Bridges the modem and the edge router at L2. No routing changes. No re-architecture. Approve traffic and the bridge forwards it.
Observes and fingerprints
Watches reconnaissance attempts and attacker tooling. Builds a per-source profile so the next contact is recognized, not re-discovered.
Deception engagements
Decoy services and credentials that waste attacker time and surface their intent before traffic ever reaches your real network.
Autonomously blocks
Reconnaissance and confirmed threats are dropped at the bridge. Decisions are made on the device, not as a control-plane request.
Zero-config evaluation
No policy authoring required to start observing. Pilot teams can evaluate the device live on their perimeter from day one.
Works with or without a firewall
Sits pre-firewall, post-firewall, or alone. It does not replace firewall policy, NAT, or VPN. It cuts inbound noise and can drop outbound callbacks to listed C2 and other known-bad destinations.
Egress Intel
Outbound TLS handshake intelligence: destination and certificate facts matched to known-bad feeds, without decrypting traffic. Optional destination-IP blocking stays off by default and never targets shared CDN addresses.
Local API and webhooks
Scoped keys on the management interface let operators and SOAR pull status, events, blocklist, and summary. A signed block.created webhook notifies a URL you own after the block is on the device.
Where Pitch Black sits in the network
Pitch Black is a transparent L2 bridge between the ISP modem and your edge router. Place it pre-firewall, post-firewall, or with no firewall. It adds autonomous inbound and outbound blocklist enforcement at the bridge without changing routing topology.
Animated teaching aid. The actual decisions are made on the appliance and are visible in the operator view.
Pre-firewall (upstream)
Use this when you want a dedicated autonomous layer before traffic ever reaches your firewall. It can reduce downstream load and improve signal quality.
Field-proven in the first 48 hours
First 48 hours · live field deployment
- 193Threats null-routed
- 4,717Events logged
- 850Unique source IPs observed
- 141Active blocklist entries
- 42Countries observed
- ~15 minAvg time between blocks
Metrics shown are the first 48 hours of a live field deployment. The underlying case-study report is not published and is not downloadable from this site.
Capabilities
Focused capabilities for the perimeter: observe, fingerprint, deceive, block, plus outbound handshake intel and local automation.
Autonomous threat neutralization
Decisions are made and applied on the device at the bridge — no control-plane round trip.
Reconnaissance visibility
Inbound probing and scanning are visible, profiled, and acted on before they become intrusion attempts.
Transparent L2 bridge
No routing changes required. Approved traffic passes through predictably; nothing else does.
Fingerprinting of attacker tooling
Per-source profile of cadence, tooling, and intent — built passively from observed behavior.
Deception services
Decoy endpoints and credentials that only confirmed-attacker sources ever see.
Inline 6-port mix
Practical 2.5GbE and 10GbE interface mix tuned for inline perimeter placement.
Hardware-enforced edge layer
A physical appliance engineered for consistent behavior at the outside edge of the network.
Operator-grade event trails
High-signal event trails that support response, review, and accountability.
Egress Intel: outbound TLS handshake intelligence
Matches observed outbound TLS handshake metadata against known-bad IP and certificate intelligence, without decrypting traffic. Requires the on-box sensor. Optional destination-IP blocking is off by default and excludes shared CDN infrastructure.
Local API + webhooks
Use scoped local API keys on the appliance management interface to pull status, events, blocklist data, and summary context. Receive a signed block.created webhook at a URL you own after a block is applied. Not a public internet API.
Shared threat intel
Aggregated indicators from curated feeds and other Pitch Black nodes become blocklist entries and are enforced inbound and outbound. Operator allowlists still take precedence.
Operating modes
Pitch Black ships with two public operating modes. Both are designed to be evaluated live on a pilot.
Transparent bridge
Inline L2 between the modem and the edge router. The device forwards approved traffic and applies autonomous decisions on the rest. No re-architecture required.
Deception services
Decoy endpoints, services, and credentials that engage confirmed-attacker sources. Useful as a stand-alone capability or layered on top of bridge mode.
Form factors
One public unit, shown in two form factors: inline 1U and S-unit compact. Both use the same 6-port public unit.
Explore the enclosure geometry, port-facing proportions, and front-panel presence without shifting the page’s visual language.
Built for racks, built for teams
Pitch Black uses one public unit with inline 1U and S-unit compact framing. Both form factors use the same 6-port public unit. Request the full datasheet for the complete interface mix and environmental details.
- Single public unit
- 6-port mix: 2x SFP+, 2x 2.5G, 2x 10G
- Built for transparent bridge-mode deployments
Inline 1U
Inline perimeter deployments.
- •Single public unit
- •2x SFP+, 2x 2.5G, 2x 10G
- •Optimized for transparent bridge-mode placement
S-unit Compact
Desktop or compact edge deployments.
- •Single public unit
- •Same 6-port mix, optimized for compact framing
- •Request full specs for the complete datasheet
Specifications (high-level)
We publish only high-confidence, operator-relevant specs here. Request full specs for the exact interface mix, performance envelope, and environmental details.
| Spec | Pitch Black |
|---|---|
| Form factor | Inline 1U / S-unit compact |
| Product family | Pitch Black |
| Network interfaces | 2x SFP+, 2x 2.5G, 2x 10G |
| Memory | Up to 48 GB DDR5 SO-DIMM |
| Storage | M.2 NVMe SSD(500 GB to 1 TB configurations) |
| Power | 12V/5A DC input |
| Material | Aluminium alloy |
| Operating temperature | 0–50°C |
| Primary mode | Transparent inline bridge mode (L2) |
| Operating modes | Transparent bridge · Deception services |
| Placement options | Pre-firewall, post-firewall, or no firewall |
| Management | Remote management + scoped local API on the management plane |
| Events | Signed block.created webhook after the block is applied |
| Egress Intel | Outbound TLS handshake metadata vs known-bad IP/cert feeds (no decrypt) |
| Egress blocking | Optional destination-IP block off by default; never CDN ASNs |
| Logging | Operator-grade logging |
Operator interface snapshot
A preview of the Pitch Black operator experience — designed for clarity and operational flow. UI shown for reference; production UX may evolve.

Main dashboard
A calm overview of perimeter posture, active controls, and the signals that matter.
- Status at a glance
- Operational clarity
- Designed for low-noise decisions

Live wire view
A real-time view of what’s traversing the perimeter, and what is being contained.
- On-the-wire telemetry
- Inline decision point visibility
- Fast investigation pivots

Logs
High-signal event trails meant to support investigations and post-incident review.
- Search + filter
- Audit-friendly trails
- Context that maps to operator questions
Attacker toolkit (future module)
A planned internal module for controlled scenario testing, vulnerability scanning, and network analysis-designed to pair technical metrics with IRP/DRP guidance. This is intentionally a roadmap item (not yet available) and not required for Pitch Black’s core perimeter function.
- Internal vulnerability scanning + common network metrics
- Concept: scenario-based testing for validating controls in authorized environments (not yet available)
- Report generation from observed threats and analyzed data
- IRP/DRP development guidance informed by findings
- Education-ready outputs for security awareness and training workflows
Note: roadmap items may change based on operator feedback and pilot learnings.
Pitch Black’s Quantum component integrates with ElephantSqlDB’s Quantum Cloud Database for centralized security log storage and querying-supporting investigations, reporting, and operational review.
Pitch Black remains focused on the perimeter: autonomous defense, reconnaissance visibility, logging, and remote management.
Where it fits
Branch & retail edges
Standardize autonomous defense and reconnaissance visibility across many small sites.
Datacenter ingress
Add a focused autonomous layer ahead of existing perimeter controls at the ingress.
Firewall-adjacent hardening
Reduce reconnaissance and inbound probing before traffic ever reaches your firewall.
Firewall-less environments
Provide an autonomous defense layer for sites that do not run a firewall today.
Why teams can rely on the device
Pitch Black is built for teams that have to justify every perimeter decision to operations, security leadership, and procurement. Clear scope, predictable behavior, and review-ready visibility are part of the product experience.
Validated in the field
First 48 hours of a live field deployment produced the metrics shown on the homepage — measured, not modeled.
Predictable autonomous behavior
Decisions are applied at the bridge and visible in the operator view. There is no ambiguous control-plane lag.
Operator-readable by design
Logs, policy language, and management workflows are built for engineers who need fast answers during incidents and review.
Procurement-safe specifications
The public page covers form factors, port mix, memory ceiling, storage class, power input, material, and operating temperature. Request full specs for the datasheet.
Deployment that fits your topology
Pre-firewall, post-firewall, or no firewall — Pitch Black is designed to fit the network you have without forcing redesign.
Claims grounded in what ships
Public capabilities are described in operational terms that can be reviewed, validated, and supported in real deployments.
FAQ
High-signal answers to the questions enterprise teams ask first.
Request a Pitch Black pilot
Share your topology and form factor preference. We will respond with pilot scoping, the launch brief, or the full datasheet.
Public details stay procurement-safe. Request the full datasheet if certification language or deeper interface detail matters for your review.

