Phase-one trust and operator controls are delivered; much of the managed-service substrate also exists.
prospectus · engineering: pilot-ready foundation · commercial: demo / pre-revenue ·
containment should assume the guest is already lost
DetCordon is a containment-first dynamic malware observation platform for hostile web payloads. It places the disposable victim on one host and the evidence sink on another, then authenticates the paths between them and preserves what was observed as portable, signed evidence. The engineering foundation is substantially ahead of the commercial maturity: the next decisive proof belongs in a real design-partner environment, not in a stronger marketing adjective.
Informational prospectus, not an offer or solicitation. This page describes DetCordon's present engineering state, commercial posture, market context, and intended direction. It does not offer or solicit securities and is not investment, legal, tax, or financial advice. Pricing is illustrative until owner sign-off and a customer order form. Future work describes intent and sequencing, not a delivery commitment. Third-party market figures are contextual estimates whose scopes differ.
executive summary
the core product works; the remaining gates are operational and commercial
DetCordon already has the pieces a serious pilot needs: Docker and Firecracker victims, a two-host containment model, tenant/source identity, authenticated remote transport, OIDC-gated operator access, retention and quotas, reliable event delivery, SIEM egress, signed evidence bundles, and offline verification. It is not yet presented as a production managed service because external deployment proof, production key custody and recovery, continuous SLO evidence, and a signed commercial rate card are still open gates.
The offer shape exists, but no public orderable SKU or signed rate card is claimed.
Two isolated tenants, customer SIEM, customer-owned runtime provenance, recovery, and key operations.
Scale only after trust, durability, recovery, and support obligations are measurable and rehearsed.
what exists / what remains
depth first, then breadth
what is done
- Disposable Docker and Firecracker victim backends with hard TTL lifecycle limits.
- Separate sandbox and sink host roles; DetectionOnly HTTP observation and distinct event/sample paths.
- Tenant-bound mTLS for event, sample, and heartbeat channels, with issuance, distribution, rotation, and revocation tooling.
- Generated two-host authentication proof that exercises valid, revoked, restored, and rotated producer identities.
- OIDC-gated remote dashboard access with named-operator audit records.
- Signed, offline-verifiable evidence bundles containing encrypted sample references, digests, provenance, redaction policy, and custody lineage.
- Per-source quotas and retention, acknowledged event delivery, SIEM/syslog egress, fleet visibility, and HA/failover groundwork.
what still has to be proven
- Customer-owned victim and runtime provenance before claiming deterministic request → process → sample causality.
- Production signing-key custody, rotation policy, and off-host recovery as an exercised operating routine.
- Two isolated tenants concurrently on a real managed topology, with both redacted streams verified at the customer SIEM.
- Continuous SLO measurement, alert routing, capacity ceilings, recovery objectives, and on-call discipline.
- An external fixed-term pilot against written acceptance criteria and a commercial offer the operator is prepared to sign.
technical proof
make trust boundaries testable instead of rhetorical
- 12 scored risks in a public risk register each tracked Accepted / Mitigated / Partial / Open
- 3 paths event, sample, and heartbeat can use authenticated transport tenant/source identity is checked before trusted ingest
- signed evidence bundles verify offline the verifier uses a caller-supplied trust anchor
- 1.36s native-snapshot restore time-to-ready vs. 7.4s cold boot — real hardware
The product's moat is not that virtual machines exist; mature malware sandboxes have had them for years. The bet is that containment, remote authentication, evidence custody, and explicit residual-risk accounting can be product features rather than deployment notes. A generated secure profile should fail closed when its trust prerequisites are absent, and an evidence recipient should be able to verify the handoff without trusting the original repository or sink host.
evidence
What DetCordon observed and preserved: runtime request identity, event and sample references, digests, source identity, time windows, component/configuration provenance, redaction policy, custody lineage, and bundle integrity.
enrichment
Analyst context, threat-intelligence labels, and later interpretations can make evidence more useful, but they should remain derived context. They must not silently rewrite the signed observation record or be presented as if the sensor observed them directly.
market context
large demand signals, unusually wide measurement uncertainty
Public malware-analysis market reports disagree sharply on category size and growth because they bundle different combinations of sandboxing, threat intelligence, security analytics, and adjacent services. That spread is useful as evidence of demand, not as a dependable DetCordon TAM.
- $7.6–34.4B published 2024 global malware-analysis estimates roughly a 4.5× spread between report definitions
- 8.1–31.6% published CAGR forecasts to 2030 category forecasts, not DetCordon revenue forecasts
- quote-led enterprise sandbox pricing remains mostly sales-gated useful room for a more inspectable self-hosted/pilot motion
- web first DetCordon deliberately starts narrower than incumbents containment and custody depth before file-format breadth
Public report pages reviewed 13 August 2026: Strategic Market Research ($7.6B in 2024; 8.1% CAGR), Global Industry Analysts via Research and Markets ($34.4B in 2024; 10.4%), Mordor Intelligence ($15.43B in 2025; 26.97%), and The Business Research Company ($14.4B in 2025; 31.6% CAGR to 2030). Their methodologies and scopes are not interchangeable.
| Product / project | Typical shape | Where DetCordon differs today |
|---|---|---|
| VMRay / Joe Sandbox / ANY.RUN | Commercial cloud or appliance malware-analysis products with broad mature coverage. | DetCordon is far narrower, but makes two-host containment and offline evidence custody central to the product story. |
| WildFire / Falcon Sandbox / FortiSandbox-class platform add-ons | Sandbox capability embedded in a broader firewall, endpoint, or security fabric. | DetCordon can be evaluated as a standalone self-hosted or managed containment component rather than a fabric dependency. |
| CAPEv2 / Cuckoo3 / DRAKVUF Sandbox | Self-hosted open-source analysis systems with substantial operator-owned hardening and integration work. | DetCordon is trying to productize the trust boundary, deployment guardrails, and signed evidence contract as first-class controls. |
| DetCordon | Web-payload-first, two-host, self-hosted or managed pilot path. | Depth over breadth: authenticated evidence paths, explicit residual risk, and offline-verifiable handoff before general-purpose format coverage. |
buyer motion
start where containment pain is visible
self-hosted evaluation
Needs a controlled place to observe hostile web payloads and retain auditable evidence without rebuilding the containment plumbing.
managed pilot
Wants evidence delivered into existing operational tooling with authentication, redaction, retention, and a reviewable custody model.
managed production
Needs many analysts or customers behind an enforced tenant boundary, predictable capacity, recovery, support, and an SLA.
commercial model
three offer shapes; none presented as orderable GA today
The present commercial model follows the delivery path instead of hiding maturity behind one SKU. Pricing remains an internal reasoned estimate until owner sign-off and customer validation.
| Tier | Shape | Illustrative signal | Current status |
|---|---|---|---|
| Self-Hosted Appliance | Annual customer-operated license | $4,800 / year | demo; not orderable as a public SKU |
| Managed Pilot | Fixed 4–8 week design-partner engagement | $9,500 one-time | target next commercial motion |
| Managed Production | Base subscription plus capacity / retention / support dimensions | $2,400 / month base | future GA offer; not yet claimed |
roadmap
trust first, scale second, contract last
-
Phase 1 — pilot-ready trust boundary
deliveredOIDC-terminated remote access, named-operator audit, signed offline- verifiable evidence, tenant/source identity, retention and quotas, and authenticated transport profiles provide the foundation for a real single-team pilot.
-
Phase 2 — managed multi-tenant proof
engineering advancedTenant isolation, fleet visibility, reliable event delivery, SIEM egress, and tenant-bound mTLS are substantially implemented. The open gate is external operational proof: two tenants concurrently, customer SIEM verification, customer-owned runtime provenance, and production key/recovery practice.
-
Phase 3 — scale / GA
GA gate openFirecracker scaling and HA/failover engineering provide useful groundwork. GA requires continuous SLO evidence, rehearsed off-host recovery, explicit concurrency and durability ceilings, support/on-call routines, an external fixed-term pilot, and a signed rate card that matches the measured service.
risk factors
diligence should hear the open risks before sales asks
-
containment
No formal sandbox-escape proof exists or is claimed. Containment rests on hardened system boundaries, host configuration, and the separate-sink assumption.
-
deployment
Authenticated remote profiles exist, but secure capability is not the same as a correctly operated customer deployment. Legacy compatibility paths must not be confused with the managed security posture.
-
evidence
Signed handoff protects what was exported; production-grade key custody, off-host archival practice, and deterministic request-to-process-to-sample lineage still need external proof.
-
commercial
No paying-customer traction or signed public rate card is claimed. Current prices are estimates and the product remains pre-revenue.
-
execution
A small team can move quickly but concentrates key-person and operating risk. Support, recovery, and on-call maturity must grow before GA commitments do.
-
scope
Coverage is intentionally narrower than mature general-purpose malware sandboxes: web-delivered payloads first, not every file format and operating system.
the next capital-efficient step
buy proof before buying breadth
The highest-value next work is not another catalogue of analysis features. It is the external pilot that exercises the complete trust boundary, recovery path, SIEM handoff, key operations, runtime provenance, and SLOs. Once those measurements exist, broader surfaces and ecosystem integrations can be added without weakening the evidence contract that differentiates the product.
- design partnerRun the real two-host / two-tenant topology against written success criteria.
- evidence durabilityExercise key custody, archival, recovery, and offline verification outside the build environment.
- operational truthMeasure SLOs, concurrency ceilings, recovery objectives, and alert/on-call behavior.
- commercial truthTurn measured scope into a rate card and support promise that can actually be signed.
contact
evaluate it against the boundary, not the brochure
DetCordon is developed within RAGBAZ. A serious evaluation can start with the public diligence pages and then move to a design-partner pilot whose acceptance criteria are agreed before hostile workloads are introduced.