prospectus · engineering: pilot-ready foundation · commercial: demo / pre-revenue ·

containment should assume the guest is already lost

DetCordon is a containment-first dynamic malware observation platform for hostile web payloads. It places the disposable victim on one host and the evidence sink on another, then authenticates the paths between them and preserves what was observed as portable, signed evidence. The engineering foundation is substantially ahead of the commercial maturity: the next decisive proof belongs in a real design-partner environment, not in a stronger marketing adjective.

Informational prospectus, not an offer or solicitation. This page describes DetCordon's present engineering state, commercial posture, market context, and intended direction. It does not offer or solicit securities and is not investment, legal, tax, or financial advice. Pricing is illustrative until owner sign-off and a customer order form. Future work describes intent and sequencing, not a delivery commitment. Third-party market figures are contextual estimates whose scopes differ.

executive summary

the core product works; the remaining gates are operational and commercial

DetCordon already has the pieces a serious pilot needs: Docker and Firecracker victims, a two-host containment model, tenant/source identity, authenticated remote transport, OIDC-gated operator access, retention and quotas, reliable event delivery, SIEM egress, signed evidence bundles, and offline verification. It is not yet presented as a production managed service because external deployment proof, production key custody and recovery, continuous SLO evidence, and a signed commercial rate card are still open gates.

engineering pilot-ready foundation

Phase-one trust and operator controls are delivered; much of the managed-service substrate also exists.

commercial demo / pre-revenue

The offer shape exists, but no public orderable SKU or signed rate card is claimed.

next proof external topology

Two isolated tenants, customer SIEM, customer-owned runtime provenance, recovery, and key operations.

destination measured GA service

Scale only after trust, durability, recovery, and support obligations are measurable and rehearsed.

what exists / what remains

depth first, then breadth

what is done

  • Disposable Docker and Firecracker victim backends with hard TTL lifecycle limits.
  • Separate sandbox and sink host roles; DetectionOnly HTTP observation and distinct event/sample paths.
  • Tenant-bound mTLS for event, sample, and heartbeat channels, with issuance, distribution, rotation, and revocation tooling.
  • Generated two-host authentication proof that exercises valid, revoked, restored, and rotated producer identities.
  • OIDC-gated remote dashboard access with named-operator audit records.
  • Signed, offline-verifiable evidence bundles containing encrypted sample references, digests, provenance, redaction policy, and custody lineage.
  • Per-source quotas and retention, acknowledged event delivery, SIEM/syslog egress, fleet visibility, and HA/failover groundwork.

what still has to be proven

  • Customer-owned victim and runtime provenance before claiming deterministic request → process → sample causality.
  • Production signing-key custody, rotation policy, and off-host recovery as an exercised operating routine.
  • Two isolated tenants concurrently on a real managed topology, with both redacted streams verified at the customer SIEM.
  • Continuous SLO measurement, alert routing, capacity ceilings, recovery objectives, and on-call discipline.
  • An external fixed-term pilot against written acceptance criteria and a commercial offer the operator is prepared to sign.

technical proof

make trust boundaries testable instead of rhetorical

The product's moat is not that virtual machines exist; mature malware sandboxes have had them for years. The bet is that containment, remote authentication, evidence custody, and explicit residual-risk accounting can be product features rather than deployment notes. A generated secure profile should fail closed when its trust prerequisites are absent, and an evidence recipient should be able to verify the handoff without trusting the original repository or sink host.

evidence

What DetCordon observed and preserved: runtime request identity, event and sample references, digests, source identity, time windows, component/configuration provenance, redaction policy, custody lineage, and bundle integrity.

enrichment

Analyst context, threat-intelligence labels, and later interpretations can make evidence more useful, but they should remain derived context. They must not silently rewrite the signed observation record or be presented as if the sensor observed them directly.

market context

large demand signals, unusually wide measurement uncertainty

Public malware-analysis market reports disagree sharply on category size and growth because they bundle different combinations of sandboxing, threat intelligence, security analytics, and adjacent services. That spread is useful as evidence of demand, not as a dependable DetCordon TAM.

Public report pages reviewed 13 August 2026: Strategic Market Research ($7.6B in 2024; 8.1% CAGR), Global Industry Analysts via Research and Markets ($34.4B in 2024; 10.4%), Mordor Intelligence ($15.43B in 2025; 26.97%), and The Business Research Company ($14.4B in 2025; 31.6% CAGR to 2030). Their methodologies and scopes are not interchangeable.

selected alternatives and the diligence distinction DetCordon is pursuing
Product / project Typical shape Where DetCordon differs today
VMRay / Joe Sandbox / ANY.RUN Commercial cloud or appliance malware-analysis products with broad mature coverage. DetCordon is far narrower, but makes two-host containment and offline evidence custody central to the product story.
WildFire / Falcon Sandbox / FortiSandbox-class platform add-ons Sandbox capability embedded in a broader firewall, endpoint, or security fabric. DetCordon can be evaluated as a standalone self-hosted or managed containment component rather than a fabric dependency.
CAPEv2 / Cuckoo3 / DRAKVUF Sandbox Self-hosted open-source analysis systems with substantial operator-owned hardening and integration work. DetCordon is trying to productize the trust boundary, deployment guardrails, and signed evidence contract as first-class controls.
DetCordon Web-payload-first, two-host, self-hosted or managed pilot path. Depth over breadth: authenticated evidence paths, explicit residual risk, and offline-verifiable handoff before general-purpose format coverage.

buyer motion

start where containment pain is visible

researcher / lab

self-hosted evaluation

Needs a controlled place to observe hostile web payloads and retain auditable evidence without rebuilding the containment plumbing.

blue team / SOC

managed pilot

Wants evidence delivered into existing operational tooling with authentication, redaction, retention, and a reviewable custody model.

research org / MSSP

managed production

Needs many analysts or customers behind an enforced tenant boundary, predictable capacity, recovery, support, and an SLA.

commercial model

three offer shapes; none presented as orderable GA today

The present commercial model follows the delivery path instead of hiding maturity behind one SKU. Pricing remains an internal reasoned estimate until owner sign-off and customer validation.

illustrative commercial frame
Tier Shape Illustrative signal Current status
Self-Hosted Appliance Annual customer-operated license $4,800 / year demo; not orderable as a public SKU
Managed Pilot Fixed 4–8 week design-partner engagement $9,500 one-time target next commercial motion
Managed Production Base subscription plus capacity / retention / support dimensions $2,400 / month base future GA offer; not yet claimed

roadmap

trust first, scale second, contract last

  1. Phase 1 — pilot-ready trust boundary

    delivered

    OIDC-terminated remote access, named-operator audit, signed offline- verifiable evidence, tenant/source identity, retention and quotas, and authenticated transport profiles provide the foundation for a real single-team pilot.

  2. Phase 2 — managed multi-tenant proof

    engineering advanced

    Tenant isolation, fleet visibility, reliable event delivery, SIEM egress, and tenant-bound mTLS are substantially implemented. The open gate is external operational proof: two tenants concurrently, customer SIEM verification, customer-owned runtime provenance, and production key/recovery practice.

  3. Phase 3 — scale / GA

    GA gate open

    Firecracker scaling and HA/failover engineering provide useful groundwork. GA requires continuous SLO evidence, rehearsed off-host recovery, explicit concurrency and durability ceilings, support/on-call routines, an external fixed-term pilot, and a signed rate card that matches the measured service.

risk factors

diligence should hear the open risks before sales asks

the next capital-efficient step

buy proof before buying breadth

The highest-value next work is not another catalogue of analysis features. It is the external pilot that exercises the complete trust boundary, recovery path, SIEM handoff, key operations, runtime provenance, and SLOs. Once those measurements exist, broader surfaces and ecosystem integrations can be added without weakening the evidence contract that differentiates the product.

contact

evaluate it against the boundary, not the brochure

DetCordon is developed within RAGBAZ. A serious evaluation can start with the public diligence pages and then move to a design-partner pilot whose acceptance criteria are agreed before hostile workloads are introduced.

Tobias Abenius RAGBAZ / DetCordon