Skip to content

Prometeo

A complete cybersecurity platform aligned with NIST CSF 2.0, including the quantum dimension.

Vertical: Cybersecurity Solid base

What it is for

Cover an organisation’s cybersecurity obligations end to end, including the quantum threat.

What it does

Organises capabilities into seven pillars — identify, protect, detect, respond, recover, awareness and quantum — covering audit and compliance, endpoint and data protection, monitoring and detection, incident response and forensics, continuity, staff training and post-quantum migration. Includes a simulator for training defensive agents and a desktop application for field work.

Sector

Cybersecurity, compliance (ENS, ISO 27001, NIS2, DORA) and training.

What it improves

Removes the need to buy and coordinate ten separate products, and translates the NIST CSF 2.0 framework into concrete functionality.

Target client

Mid-size and large companies without a full security team, and consultancies that need a white-label tool.

Status and maturity

Very broad scope with many engines implemented. Given its ambition, this is the asset where prioritising a sellable subset matters most.

Differentiator

An unusual combination of regulatory compliance, autonomous operation and quantum readiness in a single product, with a proprietary training simulator.

Commercial fit

Subscription per module, entering the market through a single pillar — compliance and awareness — used as the door opener.

Architecture

Layered architecture

Seven capability pillars — the five of the international cybersecurity framework, plus awareness and the differentiating quantum pillar — orchestrated by an autonomous loop with a human supervisor above. Breadth is its strength and its risk: hence status is declared pillar by pillar.

  1. 01

    Human supervision

    Dashboard, conversation with the system, emergency stop and alerting. No autonomous capability sits above this layer.

  2. 02

    Autonomous orchestrator

    A loop of sensing, reasoning, decision, execution, verification and learning, with specialised language experts, trained decision agents, code generation in a confined environment and anomaly detection.

  3. 03

    Engines per pillar

    Identify: audit, inventory, risk under a public methodology, event correlation, compliance frameworks. Protect: data loss, hardening, data protection. Detect: threat intelligence and anomalies. Respond: incident management and response automation. Recover: backup, continuity and impact analysis.

  4. 04

    Quantum pillar

    Cryptographic audit and inventory, post-quantum migration plan, assessment of the harvest-now-decrypt-later threat, a gateway to quantum environments and benchmarks, with a classical fallback always on.

  5. 05

    Awareness

    Staff training modules and email-fraud simulation, measurable and repeatable.

  6. 06

    Field client and self-audit

    A desktop application for work on client premises, and a battery of checks the system applies to itself.

Inventory

Status per component

A real inventory of the asset’s components with their declared status. We publish capability, never code or internal figures.

Built and testedFunctional with declared debtDesigned, not implementedWired; depends on a third party
  • Orchestrator and autonomous loop

    Built and tested

    Full cycle with supervisor and emergency stop above autonomy.

  • Compliance and awareness pillars

    Built and tested

    The chosen commercial door opener: the most complete and the easiest for a client to audit.

  • Detection and response engines

    Built and tested

    Detection, response and automation operational, integrating public threat-intelligence sources.

  • Quantum pillar

    Functional with declared debt

    Cryptographic audit, migration plan and threat assessment operational. The quantum gateway indicates availability of an environment, never demonstrated advantage.

  • Training simulator

    Built and tested

    Proprietary environment where defensive agents are trained and validated before operating.

  • Field client

    Built and tested

    Desktop application for on-site audit and intervention.

  • Sovereign language model

    Built and tested

    The model runs locally: client data does not leave the perimeter to be reasoned about.

  • Scope prioritisation

    Functional with declared debt

    The asset’s declared risk: breadth forces selling a bounded subset rather than the whole platform. A product decision, not a technical defect.

This profile describes capabilities and status, not implementation. Code, architecture documentation and internal figures are shared under a confidentiality agreement during due diligence.