TRINETRA reads copied traffic across a one-way boundary and turns behavioural signals into explainable incidents. It has no return path toward the network it watches, so the analysis can be trusted even where the network cannot be reached.
The scene above, read left to right.Source entities on the left — network devices and endpoints. A single boundary plane in the centre. The analysis enclave on the right, holding one fin per detector. Traces cross the boundary once and only once. Nothing returns, so the enclave is isolated from the network it observes.
One-way by construction
Copied traffic arrives on a receive-only interface with a host-enforced ingress drop. There is no socket, route or credential pointing back at the monitored network.
Nine detectors, one contract
RULE, STATISTICAL, SUPERVISED and HYBRID are all first-class. Every result records its technique, so an alert never overstates how much a model was involved.
Evidence travels with the alert
Observations are kept separate from the thresholds and baselines they were compared against, alongside detector, model and schema versions.
Models are promoted, not shipped
A champion has to be evaluated, gated and promoted by a person. Live traffic can only ever become a training candidate.
Product principles
Four commitments, each one checkable.
A passive product has to earn trust differently. TRINETRA states its limits up front, and every one of them is a property of the deployment rather than a promise in the documentation.
Passive
TRINETRA observes copied traffic. It does not probe, scan, complete a handshake, block, filter or mitigate, and it never decrypts — TLS is analysed as handshake metadata only.
How it is enforcedThe analysis modules open no sockets toward captured addresses. A test parses the AST of every module that touches captured data and fails if one imports socket, requests, urllib, httpx, subprocess, http or ftplib, or calls eval, exec, system or popen.
One-way
There is no return path toward the monitored network. Signals cross the boundary once; nothing crosses back, and nothing TRINETRA runs sits on the far side of it.
How it is enforcedThe live sensor runs on an unbridged veth pair with an all-protocol ingress drop installed while both ends are still down, and it holds NET_RAW and nothing else. The API reports sensor.read_only true and boundary_state HOST_BLOCKED.
Explainable
An alert is not a score. It carries what was observed, what it was compared against, the reason codes that fired, and the detector, model and schema versions needed to reproduce the decision.
How it is enforcedObservations are split from baseline comparisons by feature name, so a reader can tell measurement from reference. One threat class is an alert; two or more distinct classes on one subject inside 300 seconds become an incident.
Governed
A model is evaluated, gated and promoted by a person. Live traffic can only ever become a training candidate — no code path writes to a champion at runtime.
How it is enforcedTraining registers a CANDIDATE. Drift emits signals and calls nothing. Shadow inference is persisted for comparison and dropped by fusion, so a challenger can never become an alert. Every promotion is recorded with its actor, reason and gate results.
Detection coverage
Nine detectors. Rules, statistics and models side by side.
Every detector implements one contract and is fault-isolated, so one raising an exception does not stop the others seeing the window. technique is recorded on every result, so an alert never overstates how much a model was involved. Select a family to see its threat class, what it measures and the reason codes it can emit.
anomaly
BENIGN · STATISTICAL · 20260928-1
Behavioural outlier detector. It scores how far an entity's window sits from its own baseline and contributes corroboration. On its own it reports BENIGN, so it never becomes a threat verdict by itself.
Entity
HOST / DESTINATION / PAIR
Headline field
anomaly.anomaly_score
Compared against
anomaly.anomaly_threshold
Reason code
NETWORK_BEHAVIOUR_OUTLIER
Detector version
1.0.0 · schema 1.2.0
Reason codes
ANOMALY:NETWORK_BEHAVIOUR_OUTLIER
Explainable detection
Six detectors agreed. Here is what each one saw.
An isolated signal is not a verdict. Fusion records which detectors contributed, by how much, and the analyst can open every reading back to the threshold or baseline it was compared against.
Worked example. One stored incident, reproduced from the evidence the API returned for it: subject 172.20.0.10, observed from 2026-09-29T20:11:42Z to 2026-09-29T20:29:36Z, feature schema 1.2.0. Every number below is a measurement from that incident. The DGA entry is the one whose own alert carried severity: CRITICAL.
Six distinct threat classes on one subject inside a 300-second window became one incident. Confidence is combined from the detectors that actually fired; severity is scored separately, because a small event can be certain and still low impact.
Resolved record: confidence 0.99 · confidence_basis FUSION · severity HIGH · 7 alerts · status NEW. Lineage: detector versions anomaly 1.0.0, c2_beacon 1.0.0, recon 1.0.0, exfiltration 1.1.0; model versions anomaly 20260928-1; event schema 1.1.0; pipeline run 6ec65193bd01. Enough to reproduce the decision, and enough to tell a reader which parts were counted and which were modelled.
The one-way guarantee
A technical property, not a promise.
The boundary is enforced by the absence of a path, and checked by a test that parses the source of every module that touches captured data.
No return path
The intended deployment has no route back into the monitored production network. Signals cross the boundary once. Nothing crosses it the other way, so there is no channel for an attacker who reaches the enclave to use.
No listening socket toward the source
Analysis modules do not open sockets to captured addresses, never probe, never scan and never complete a handshake. It cannot query a source system even if something asked it to.
No credential path
There is no credential to store, rotate, expire or leak toward the protected environment, and no device-control code with a protocol to speak. The output is security intelligence and nothing else.
No decryption
Encrypted traffic is analysed as handshake metadata only: JA4 and JA4S fingerprints, SNI shape, offered ciphers, version, certificate attributes, and size and timing envelopes. Payload content is never present in any stored field.
What the guarantee does not claimThe live demonstration is a software enforcement boundary, not physical diode certification. A trusted privileged host controller provisions the receive interface and reconciles its lifecycle, and a Docker administrator can alter either — both are assumed not to be compromised. The reported boundary state is an infrastructure assertion supported by peer-capture and lifecycle proofs, not a cryptographic attestation. Deployments on TAP/SPAN or real diode hardware need their own boundary verification.
Built for
Networks where there is nothing to install and nothing to answer.
The one-way constraint is not a limitation worked around here. In these environments it is the deployment model, and it is the reason an analysis enclave can be trusted with a copy of the traffic.
Government and defence
Compartmented networks are the canonical unidirectional case. There is no route to push an indicator inward, so detection has to arrive from outside the boundary and be legible to an analyst who cannot query the source.
Critical infrastructure
Process and control networks often cannot carry an agent or tolerate a probe. A passive tap on a mirrored link is the only kind of deployment that fits the equipment as it already is.
OT and ICS
Long patch cycles and flat vendor networks produce long-lived beaconing. Inter-arrival regularity is measurable from copies alone, and the devices never learn that anything is watching them.
Data centres
East-west traffic is where a compromised workload talks to its controller. A span port on the internal fabric sees it. Nothing has to be deployed onto the host, so there is no agent to harden or attest.
Banking and telecom
Segmentation rules and change freezes make inline deployment expensive and slow. Copy-then-analyse keeps the monitored side untouched, which is usually the only option that clears review.
SOC and CERT operations
An analyst needs the evidence and the thresholds behind an alert, not a score. Every result ships with reason codes, baseline comparisons and lineage, so a decision can be defended and re-checked.
Cyber R&D
The detection mesh, the feature contract and the promotion gates are inspectable. A detector is a small program you can read end to end, and a rejected candidate leaves an audit record.
What the constraint rules out
The system cannot act
No inline path and no device-control code. It cannot block, filter or mitigate, and it will not claim to have.
The enclave cannot be pushed into
Indicators, patches and blocks are not delivered outward. TRINETRA publishes; the operator applies, on a network the operator controls.
Nothing is decrypted
Content never leaves the wire. What is read is handshake shape and size, which is also why a TLS match is a lead rather than a verdict.
No model changes itself
Live traffic becomes a candidate and stops there. A champion is a person’s decision, written to the registry with its actor and gate results.
The console
One screen per question an analyst actually asks.
These are the routes in this build, with the endpoints each one reads. Open any of them in the console against your own data — the store, the detector registry and the incident ledger are all live.
The architecture page walks the whole path — sensor, normalisation, streaming feature engine, baselines, the detection mesh, fusion, evidence — and states where each guarantee comes from.