Blackfort Technology
Blackfort Security Operations & Intelligence Platform
Eight products, one operator

Operated by Blackfort

Blackfort Security Operations & Intelligence Platform

Eight products for security operations: privileged access, event collection, vulnerabilities and hardening, log retention, certificates, and getting findings to the team that fixes them. Each one can be ordered on its own; each one is set up and run by us. Nothing stays on your side — no server, no database, no rule sets.

Came here from the BSI's Allianz für Cyber-Sicherheit? Have a look at our partner offer, the NIS2 Security Operations Pilot.
For NIS2/BSIG, ISO 27001 and IT-GrundschutzSeparate instance per customerGerman hosting providerArt. 28 GDPR data processing agreementNo management port exposed

Eight products — each one ordered on its own

Every product does one clearly defined job and can be ordered on its own. Which ones are worth having depends on what your environment turns up.

available = orderable, set up and operated by us · pilot phase = orderable, in active development · in preparation = not yet orderable

Privileged Access Bridge

available

Opens access to SSH, RDP and VNC in the browser, with no agent on the target. Every session is recorded, supervised live and can be stopped instantly; every join is in the audit log.

Event Intelligence

available

Collects the events from your systems in one place, checks them against a maintained rule set and reports what stands out — whatever the day or hour.

Log Vault

available

Retains logs tamper-evidently under separate administration — apart from the people whose activity they document.

Security Bridge

available

Moves Microsoft Defender findings into your ticketing system on a risk basis. Whatever crosses the threshold becomes a ticket for the responsible team.

Threat Exposure Filter

in preparation

Rates vulnerabilities by the business relevance of the affected system and turns that into the order of remediation.

Privileged Activity Review

in preparation

Reviews after the fact whether privileged actions were authorised and policy-compliant — independently of the people who performed them.

The same holds for every product

You book, we operate

No server on your side, no database, no rule-set maintenance. Where we operate a product for you, it runs on a separate instance — no shared environment, no mixing of data. Whether a product runs with us or in your environment is agreed in the initial call.

One contact, one contract

One place to ask, one contact for every product. And a single Art. 28 GDPR data processing agreement that names the components we use and the sub-processors involved.

Traceable connection

You get a written description of everything we install on your systems, and you can remove it at any time. Our administrative access runs through an outbound encrypted tunnel; no management port is reachable from outside.

Mapping to BSIG, ISO 27001 and IT-Grundschutz

In Germany, NIS2 is transposed through the BSIG, which is why we cite Section 30 BSIG rather than the directive itself. Treat the mapping as a starting point: whether a requirement is met depends on your implementation, and no tool satisfies it on its own.

StandardReferenceRequirementProduct
BSIG (Germany)Section 30(2) No. 1Policies on risk analysis and on information technology securityVulnerability Management, Event Intelligence
BSIG (Germany)Section 30(2) No. 5Security measures in acquisition, development and maintenance of information technology systems, components and processes, including vulnerability handling and disclosureVulnerability Management, Security Bridge
BSIG (Germany)Section 30(2) No. 6Policies and procedures to assess the effectiveness of risk management measures for information technology securityVulnerability Management — supplies the metrics for the assessment
BSIG (Germany)Section 30(2) No. 9Establishment of policies for human resources security, access control and the management of ICT systems, products and processesPrivileged Access Bridge (access control aspect)
ISO/IEC 27001Annex A.8.8Management of technical vulnerabilitiesVulnerability Management
ISO/IEC 27001Annex A.8.15 / A.8.16Logging and monitoring of activitiesEvent Intelligence
ISO/IEC 27001Annex A.8.2 / A.8.18Privileged access rights and use of privileged utility programsPrivileged Access Bridge
BSI IT-GrundschutzOPS.1.1.3Patch and change management — detection and evidence of open vulnerabilitiesVulnerability Management (detection and evidence side)
BSI IT-GrundschutzDER.1Detection of security-relevant eventsEvent Intelligence
Christian Gebhardt, founder of Blackfort Technology

Christian Gebhardt

Founder & Managing Director, Blackfort Technology

Previously Deputy CISO at Gothaer Solutions (DORA/VAIT context), audit lead in internal audit at Postbank and Deutsche Bank. Lead author of the BSI/ACS guide on penetration testing of LLMs and standing member of the AI working group of the Allianz für Cyber-Sicherheit (BSI).

How we run an instance for you

What follows describes how we operate the two products Event Intelligence and Vulnerability Management. For the other products we agree the operating model — with you or with us — in the initial call.

A separate instance per customer

No shared environment, no mixing of data. At the end of a pilot we wipe the instance entirely.

Location

Event Intelligence runs at a German hosting provider. For Vulnerability Management the location depends on the engine: the ones we operate run in Germany or in your environment, the vendor cloud services in the vendor's data centres — the vendor then becomes a sub-processor. We tell you in the initial call what each choice means.

Data processing agreement under Art. 28 GDPR

Before we start we conclude a data processing agreement describing the technical and organisational measures; the hosting provider and any further services in use are named as sub-processors.

Minimal attack surface

Exactly one port on the instance is reachable from outside, and only from your company's addresses. Our administrative access runs through an outbound encrypted tunnel.

What runs on your systems

A lightweight agent that reports events and inventory. The rights it holds are documented in the connection description, and you can uninstall it yourself at any time.

What falls to you

So that you can size the effort in advance:

  • A kickoff meeting of about an hour.
  • Rolling out the agent through your existing deployment tooling (Intune, SCCM or similar) — together in one session if you prefer.
  • One outbound firewall rule towards your instance.
  • A signed data processing agreement.
  • The onboarding and review sessions we agree on.

Frequently asked questions

Do I have to take several products?

No. Every product stands on its own and can be ordered individually. Many customers use exactly one. Event Intelligence and Vulnerability Management can also be ordered separately, even though they can technically run on the same instance.

How is a product set up?

We set it up and operate it: you provide no server, run no database and maintain no rule sets. Before you order, we tell you exactly what falls to you — rolling out an agent, one firewall rule and the onboarding sessions.

Is Event Intelligence a full SIEM?

It collects events centrally, evaluates them against a rule set and reports what stands out. What it is not: a permanently staffed SOC and a long-term archive. For durable, tamper-evident history there is the Log Vault.

When are alerts raised?

Rule violations trigger automatically, whatever the day or hour. During setup we agree how the alert reaches you and how often we review it. What you do not get is a permanently staffed analyst shift.

Where is my data held?

In Germany. What we operate for you runs on an instance dedicated to your company with a German hosting provider, which we name as a sub-processor in the Art. 28 GDPR data processing agreement. For Vulnerability Management you can instead choose the vendor cloud service; that vendor is then added as a further sub-processor.

How many systems can I connect?

We agree that up front — from a single server segment to your full endpoint estate.

What do I get from the platform if I only use one product?

One contact for setup and operation and a single data processing agreement, even if further products are added later. The value of the individual product does not depend on you booking more.

What does it cost?

The price depends on scope: which products, how many systems, how much guidance. You receive a fixed-price offer after the initial call.

Kontakt aufnehmen

We look at your environment before you order anything

In the first call we work out which product makes the biggest difference for you — and which one you can skip.