FAQ

Frequently asked

Direct answers. Missing something? Open a portal ticket or mail kontakt@vyrex.cloud.

How is Vyrex different from a classic SIEM?

+

A classic SIEM collects events. Vyrex collects events, explains them in plain language, and — with your approval — runs remediation workflows. Including rollback plan, audit log, and success-rate tracking.

Does Vyrex auto-patch my servers?

+

Only if you explicitly allow it (customer_access.auto_fix_allowed). Default is safe mode: Vyrex suggests, you decide. In assist mode, Vyrex prepares everything and an operator runs it. Full-auto additionally requires a vetted recipe with high success rate.

What happens when a fix fails?

+

Pre-check, rollback marker, and post-check always run. On failure the fix run is marked 'failed', a debug event with severity=error is created, and the recipe success rate drops. After three failures the recipe is disabled for auto-run.

What is Vyrex Edge?

+

A Raspberry Pi sensor (or similar) sitting behind your router, monitoring the network: asset discovery, IDS (Suricata + Zeek), DNS analysis, internet outages. Talks to the Vyrex platform via WireGuard. Cost ~92 €, retail from 190 €.

Do I get access to the Wazuh backend?

+

No, the Wazuh backend stays with us. You see all relevant data — alerts, devices, compliance, reports — translated into plain language in your customer portal.

How GDPR-compliant is this?

+

All data lives in Hetzner data centers in Germany. Audit log documents every action with Who · When · What · Which customer. Data never leaves our 10.10.10.0/24 network. Per-operator separated SQLite databases (physically separate).

Are you NIS-2 ready?

+

We deliver audit-ready evidence for risk management, incident detection, patch management, and incident documentation. Backup strategy, MFA, and awareness you have to prove yourself — Vyrex provides the reporting scaffold and evidence center for uploads.

What does the platform cost?

+

Four packages: Basic (detection + reports), Operations (auto-fix pipeline), Compliance (NIS-2 evidence center), Transformation (everything + consulting). Concrete prices on /packages.

How fast can I onboard?

+

A bundle-link onboarding registers a Wazuh agent in under 5 min. Customer-portal login via OIDC (Authentik) or local. Edge hardware is ready in ~30 min (unbox, power, ethernet, Pi boots and does WireGuard handshake automatically).

Who operates the system?

+

TwoPixels GmbH (Christopher Schütz, Friesoythe). Complete infrastructure runs on our own VMs in Hetzner Falkenstein. No US cloud providers, no Microsoft, no Google.