Are we secure? Can you prove it? And what about AI?
The questions every CISO is asked. Cybershen answers them with one score, one trusted workstation, and every connection verified.
One score
A letter and a number from 0 to 100 that your board understands, and the ten actions that move it.
One workstation
Every risky activity runs in its own sealed room. A breach stays where it landed.
Every connection
Verified every time, recorded when it matters. The proof is already there.
Backed and labelled by
- Bpifrance Deeptech
- SATT Paris-Saclay
- France 2030 laureate
- France Cybersecurity
- Incubateur Télécom Paris
- Cyberbooster
- Hi France
- Systematic
- Wilco
Member of
You will not find customer logos here. We do not publish who we protect, and our customers like it that way.
Three problems. All at once.
And regulators now want evidence, not intentions: NIS2, DORA, LPM and the Cyber Resilience Act.
The laptop is the battlefield.
Phishing and malware land on the same machine that holds your data, your admin credentials and your source code.
The perimeter is gone.
Your people work from anywhere and your applications live in three clouds. The VPN protects a network they left years ago.
Nobody can add up the stack.
Ten tools, ten dashboards, four thousand findings, and no single number for the board.
Your board wants one number. Your stack gives you four thousand findings.
One number your board understands.
Ten tasks, not four thousand.
The score moves when your real exposure moves, so you show progress instead of describing it.
Score 62 out of 100, grade B. Up 0 points. 0 of 10 actions done.
Today's ten actions
Ranked by effort. Tick one and watch the number move.
Points and grades are examples.
One score
From 0 to 100, with a letter grade and a 30-day trend. Web, laptops, cloud, internal network and governance all report into it.
Ten tasks
The actions that move the number, ranked by effort. Your team knows what to do on Monday morning.
Evidence on demand
ISO 27001, NIS2 and ANSSI guidance: assessed, tracked and exportable when the auditor asks.
It is not only a score. It shrinks every surface an attacker can use.
UASR stands for Unified Attack Surface Reduction. Know your posture, improve it with built-in guidance and tools, and shrink what an attacker can reach.
Your internet exposure
What an attacker sees from the outside, before they use it.
Laptops and devices
Hardened, graded A to F, and kept that way.
The browser and AI assistants
Which AI tools are in use, what is shared with them, and sensitive data stopped in real time.
Web access
Where people can go on the internet, and where they cannot.
Microsoft 365 and Google Workspace
The misconfiguration, found before someone else finds it.
Internal network and Active Directory
What is on your network, and how weak the directory really is.
Governance and crisis
Policies, business impact, a virtual CISO and playbooks ready for the bad day.
All of it feeds one score.
See everything UASR covers
One laptop. Several sealed rooms.
For the people whose work is riskiest: administrators, developers, analysts. The machine that reads your e-mail should not be the machine that runs your Active Directory. Now it is not, and nobody carries a second laptop.
Everyday work
E-mail, browsing, documents.
ContainedMalware contained here
Development
Install anything. There is no path to the rest.
Sealed
Administration
Privileged tools and sensitive applications.
Sealed
Analysis
Open the malware, then reset the room.
Sealed
A breach stays in one room
Malware stays where it landed. Administration, development and business data are out of reach.
One machine
No second laptop to buy, ship or carry. The UASR agent runs inside each sealed room, so every environment is covered too.
Back in minutes
A compromised room is reset to a known-good state. It is not rebuilt.
ZT-Station comes from Bitrustee Software, which has joined Cybershen. It is built on the workstation architecture ANSSI recommends for secure administration.
Nothing connects until the gateway says yes.
Every connection to your other resources is authenticated, encrypted and authorised, and granted on one condition: the state of the device asking. No changes to your applications.
Connection request
Finance laptop to the payroll application
- Checked
Who is asking?
The person, and the exact program on the device.
- Checked
From what device, in what state?
Patched, encrypted, on a trusted network, behaving normally.
- Checked
What is it allowed to reach?
Only what a rule explicitly grants. Nothing by default.
- Checked
Still allowed right now?
If the device state drops, the session is cut immediately.
Allowed. And asked again on the next connection.
Fewer boxes
It takes over from the remote-access VPN, the web proxy, the cloud access broker, the data-loss appliance and the jump host.
Learn first, then enforce
It watches, proposes the rules and tests them next to the live ones. Nobody flips the switch blind.
On your infrastructure if you need it
Run the control plane on your own servers.
Watch a bad day go right.
Pick a moment and follow what the platform does, step by step.Four ordinary moments, the kind that turn into incidents. Pick one and follow what the platform does, step by step.
UASR, ZT-Station and ZT-SSE are sold separately, and each works on its own.
Start with one. Add the next when it makes sense.
Nobody has to buy all three. Each purchase makes the previous one stronger.
Start with UASR
Learn where you stand and put a number on it. Improve it with built-in guidance and tools. Shrink your attack surface.
Then: add ZT-SSE, and your posture starts deciding who gets access.
Go deeper with ZT-Station
For the specific uses where one laptop must never mix worlds: administration, development, analysis.
Then: add the UASR agent to cover each environment, and ZT-SSE, designed to give each sealed room its own identity.
Connect with ZT-SSE
It covers the links to all your other resources, and grants them according to posture. That posture comes from UASR or from the ZT-Station.
Then: with all three, one score, one policy and one trusted system cover all six NIST CSF 2.0 functions.
We help you become compliant and we give you the evidence.
| Framework | What it asks of you | What you hand the auditor |
|---|---|---|
| NIS2 | A compliance score per control, playbooks, recorded privileged sessions.A compliance score per control, playbooks, recorded privileged sessions, secure administration. | |
| DORA | Asset criticality, decision logs, rooms restored in minutes.Asset criticality and a dependency map, decision logs, rooms restored in minutes. | |
| LPM, OIV and ANSSI | The workstation architecture ANSSI recommends, an Active Directory audit, bastion recordings.The multi-level workstation ANSSI recommends, an Active Directory audit against the ANSSI guide, bastion recordings. | |
| ISO/IEC 27001 | A control-by-control assessment and a complete audit trail.A control-by-control assessment, gaps tracked as issues, a complete audit trail. | |
| CRA and GDPR | Vulnerability and patch history, data-loss events, CNIL templates.Vulnerability history, patch reports, data-loss event history, CNIL notification templates. |
Your data stays where your law says it should.
Sovereignty is a design decision here, not a line in a contract.
Hosted by your country's rules
We follow local sovereignty requirements. Outside France, we can host with a sovereign provider in your country.
On your premises
ZT-SSE and the ZT-Station management console can run on your own infrastructure.
UASR as a service
UASR is delivered as a service. An on-premises deployment is possible case by case.
One platform. Four ways in.
CISO and IT directors
All six NIST CSF functions, with the team you have.
See where you standCEO and board
One number for the board, and everything behind it.
See the board viewMSSP and partners
Run every client from one console. Sell them zero trust, not tools.
Get a demo tenantPublic sector and regulated
Secure administration the way ANSSI describes it, on one device, with the evidence attached.
Get the architecture guide