What Dunfaire does

Turn security and infrastructure alerts into one ranked incident queue.

Dunfaire brings in signals from endpoints, firewalls, switches, hypervisors and server hardware. It removes duplicate alerts, links related evidence into incidents, and ranks each incident by technical severity and business criticality—so your team knows what to investigate first.

Input: alerts and asset context. Output: one deduplicated, evidence-backed priority list.

Remove duplicates Build incidents Rank business impact
Operational picture Live
CriticalProduction service at risk3 related systems · 1 probable cause
HighAuthentication anomaly12 occurrences · 2 assets
Awaiting triageUnclassified assetNo business tier assigned

In plain English

We reduce alert noise, connect the evidence, and show you what to fix first.

Your existing tools keep detecting and reporting. Dunfaire sits above those signals: it consolidates repeat detections without deleting their evidence, groups related activity around the affected asset, and moves the incidents with the greatest operational impact to the top of the queue.

Multiple telemetry signals converging into one operational condition
01Alert overload

A queue you can finish.

Repeated detections collapse before they reach the operator, while the evidence behind every occurrence stays available.

Explore
Infrastructure signals connected into one incident timeline
02Root cause

A timeline, not a guess.

See member alerts, agent activity, commands, vulnerabilities, operator changes and raw device logs in one factual sequence.

Explore
Layered risk signals with the highest business priority elevated
03Business impact

Rank by what it costs you.

Combine technical severity with asset criticality. Unknown classifications remain awaiting triage instead of being treated as low risk.

Explore
Protected infrastructure targets behind a controlled action boundary
04Disconnected environments

Security that works cut off.

Support environments where operational data remains local, with passive discovery and an offline MAC vendor dataset.

Explore

One decision surface

Security tells you what happened.
Infrastructure tells you where.
Business context tells you what comes first.

Dunfaire brings all three into one operational picture—without hiding the evidence or pretending unknown means healthy.

From volume to consequence

Reduce the repetition.
Expose the impact.

Two different decisions happen before work reaches the top of the queue: repeated evidence is consolidated, then each remaining condition is placed in business context.

MEASURED EXAMPLE / ONE APPLIANCE Repeated detections become workable conditions
6,988open alerts
54workable alertsEvidence remains inspectable

Observed on one customer appliance after repeated firewall detections were deduplicated. It is a deployment result, not a universal reduction promise.

PRIORITY MODEL / CONCEPTTechnical severity meets business criticality
TECHNICAL SEVERITY ↑
Monitor
Review
Prioritise
Review
Prioritise
Act first
Prioritise
Act first
Act first
BUSINESS CRITICALITY →
Unclassified assets are marked awaiting triage—never silently treated as low.

Measured, qualified, inspectable

Claims you can verify.

Numbers without context create confidence theatre. Dunfaire publishes the method, scope and limit behind each claim.

6,988 54

Open alerts on one customer appliance after repeated firewall detections were deduplicated.

Single-deployment result
53,584

IEEE MAC assignments in the shipped offline vendor dataset, checksum-verified when loaded.

Offline discovery data
24 hours

A closed condition stays suppressed for 24 hours. Fresh evidence reopens it with an audit entry.

Documented behaviour
7 days

Unowned alerts with no fresh evidence may close automatically. Assigned work is excluded.

Operator ownership preserved

Mixed infrastructure

One operational queue across a mixed estate.

Dunfaire connects conditions across operational and security domains, then groups open alerts by problem family and affected asset.

How integrations are verified
01Endpoints
02Firewalls
03Switches
04Hypervisors
05Server hardware

Honest by design

No healthy status without evidence.

Every collector reports its own state on each heartbeat. The console resolves those signals into explicit health states and does not turn missing data into a reassuring green light.

  • Unknown assets remain awaiting triage.
  • Unavailable capabilities remain disabled.
  • Empty panels explain why they are empty.

Deployment

Run it where your environment requires.

01

On your own appliance

Keep Dunfaire and operational data inside environments where information cannot leave.

InfrastructureGuardianLocal console
02

Hybrid

Keep raw logs on site while forwarding identified conditions with stable occurrence information.

InfrastructureGuardianDunfaire Cloud
03

Connected

Use supported agents and connectors according to the selected connected architecture.

Agents+ConnectorsDunfaire Cloud

Safe action

See the blast radius before the button.

Before remediation runs, Dunfaire shows the target hosts, reachability, business criticality and any blocker in plain language.

Targets12 hosts
Reachable10 / 12
Business criticalYes
!

Explicit confirmation required
This action may interrupt a critical service.

Trust, then verify

Don’t take the website’s word for it.

See what has been proven against real equipment, what is implemented but awaiting field verification, and what remains in development.

VerifiedProven against real equipment or a live deployment.
ImplementedBuilt and tested; field verification is pending.
In developmentDesigned or partly built; not available today.

A practical demo, not a theatre script

Bring us your queue.

Show us the alerts, assets or operational conditions your team works today. We will demonstrate what Dunfaire can do with that scenario — including the limits.