Your firewalls, routers and network services are constantly recording what is happening across your organisation.
Ignix collects that evidence, learns what is normal for your environment, and brings the things that deserve attention to someone competent.
No flood of alerts. No new security stack to manage. Just a clear, evidence-based picture of what is happening — and calm explanation when something matters.
Your firewall sees everything. Who's reading it?
A typical morning
If that ever stops looking like backup, we will say so.
Your firewall records who talked to whom, how much, and when. That is enough to know whether the office is behaving as it should. Most firms never look.
A phone, a backup, a cloud drive — or something that only looks like one of those. The difference is knowing the house.
New destinations, odd hours, a quiet trickle that was never there before. Easy to miss if you only glance at the log when something is already on fire.
The firewall already blocked most of it. Worth knowing if the pattern changed. Not worth a stack of alerts.
The firewall stays the firewall. No agents on endpoints. Nothing for you to run. One small collector, an encrypted tunnel, then we start paying attention.
How the office actually runs. What is normal, who to call, what not to panic about. The relationship starts here — not with a scan.
A lightweight collector on site (Raspberry Pi or a small Ubuntu VM). Your firewall sends traffic metadata to it locally; the collector forwards that to us over WireGuard. Never as a direct feed to the open internet.
Collection is continuous. Interpretation is deliberate. Morning report and evening update, in English. When syslog shows something that cannot wait, we look then. The analysis stays on our side.
Not a dashboard for you to check. A person who already knows your network reads the evidence, and writes at 07:00 and 17:00 — or when there isn't anything to say, which is most days.
Port scans, odd destinations, a device that changed its habits. You get a short explanation and what, if anything, to do. Not a pile of alerts.
Who used the bandwidth. What that device was doing at 3am. Ask in English; the answer comes from your live traffic, not a generic briefing.
portal.ignix.co.uk is there when you want to look. Status, the IPs we're watching, reports you can keep. It is a window into the relationship — not a SIEM for you to run.
Most security tools mean endpoint agents, rack appliances, and something for you to babysit. Ignix needs only a lightweight collector on site. Metadata travels to us over WireGuard. We read it. You get the relationship, not a stack to run.
Nothing installed on PCs or servers. Just a small collector (Pi or Ubuntu VM) that receives firewall metadata and tunnels it to us securely.
Every site connects over WireGuard. Traffic metadata never goes direct to our servers over the open internet — always through the tunnel.
MikroTik, SonicWall, Fortinet, Zyxel, and others. If it exports traffic metadata to the collector, we can use it. Ignix + MikroTik →
The work happens on our own servers in a secure EU data centre. We provision and watch the tunnel. You don't run a security stack.
By the size of the network, not by seats or alerts. No long-term contract.
If you already look after the IT, we can sit alongside that. Write to us about the network, not a quote request.
ignixip.com is a separate, public toolkit — look up an IP, check a blacklist, read a mail header. Useful on its own. It is not the service. Start with what is my IP.
Write when you want a conversation. We will tell you if we are a fit.
hello@ignix.co.uk