Windows client 4.0 with a Microsoft-signed kernel driver

Block known attackers before they get in

WF SecurityCloud stops connections to and from IP addresses and domains that are already known for attacking. The protection is built on threat data from our own sensor network — not on reading your files, mail or documents.

One pool of licences covers every WF SecurityCloud product: the Windows client, the WordPress protection and the sensors.

Så stoppas trafiken Trafik kommer in från omvärlden. Anslutningar från adresser som är kända för att attackera stoppas vid skyddslagret, medan övrig trafik släpps vidare till dina enheter.

Four kinds of attack, one body of threat data behind them

What they have in common is that the attacker is almost always already known. The same addresses and domains turn up again and again, against different targets.

Malicious IP addresses and domains

Command-and-control servers, phishing domains and hosts distributing malware. The connection is stopped before it is established.

Brute force against logins

Repeated login attempts against remote desktop and other exposed services are detected, and the address behind them is blocked.

Attacks on WordPress

Injection attempts, vulnerability probing against themes and plugins, and login attacks are stopped in the site's own protection layer.

Scanning and reconnaissance

Port and vulnerability scans against your systems are recorded and blocked — often the first step before a real attack.

How the threat data is collected

Sensors around the world receive real attack attempts and report what they saw to the core. There the hits are weighed together into the block lists your devices fetch.

CoreSensorOwn collection systemRecorded attack

What the sensors record

  • Intrusion attempts against exposed services
  • Phishing and fraud attempts
  • Malicious email and links in messages
  • Attacks on websites
  • Attacks on databases
  • Login attempts against remote desktop

Beyond the sensor network we run collection systems of our own. We do not describe publicly how they work — that would make them easier to avoid. They contribute threat data that is hard to obtain any other way.

Read about the methodology

From an attack attempt somewhere else to a block at your end

The chain runs one way only. Threat data comes in to us from the sensors, and protection goes out to your devices.

  1. The sensors pick it up

    Sensors receive real attack attempts. Each attempt gives an address, a method and a point in time.

  2. Threat data is processed

    Hits are weighed together, duplicates are removed, and addresses that have stopped being dangerous drop out of the lists again.

  3. Your devices fetch the protection

    Your clients and websites fetch updated block lists continuously. Nothing about your operations travels the other way.

  4. Block and log

    The traffic is stopped locally on the device. The event is logged and appears in the panel with address, type and time.

Read about the methodology

One licence, every product

You buy a number of licences and distribute them yourself across the products you need. Five licences can be three Windows clients and two WordPress sites — and look different next month.

Needs change over time. When they do, you move the licence in the panel instead of buying a new one.

Förenklad bild av licensmodellen En gemensam licenspott överst fördelas nedåt på tre produktgrupper: Windows-klienter, WordPress-webbplatser och sensorer. Fyllda rutor är använda licenser, tomma rutor är lediga.
  • 99 kr per device per month, VAT included
  • Or 1 188 kr per device per year — the same monthly price
  • Monthly or annual billing chosen at checkout, by card through Stripe
  • Move the protection between devices and products when needed
  • Everything is administered in the customer panel

Built, operated and hosted by us

The whole system is developed in Sweden by us, and runs on our own servers in our own data centre. That includes the AI, which analyses the threat data locally on our hardware.

No contracted consultants, no external AI service that gets to see data, no American cloud providers and no external connections into the operating environment. The chain is short enough to describe on one page.

Read about how we operate

  • Our own servers in our own data centre
  • All the code written by us
  • The AI system runs locally on our own hardware
  • No data leaves the country
  • No ties to American technology companies

We analyse the threats, not your data

WF SecurityCloud works the opposite way to solutions that have to read through what you are working on in order to protect you. Our knowledge of what is dangerous comes from the outside — from attack attempts against the sensor network, not from your files.

What leaves your device are events about blocked traffic: an address, a type and a point in time. That is what makes it possible for you to see what was stopped.

Read about how we handle data

What we handle

  • Addresses and domains known for attacking
  • Events describing what was blocked on your devices
  • Details of your account and your licences

What we never touch

  • The contents of your files and documents
  • The contents of your email
  • Which websites you visit that are not blocked
Förenklad bild av kundpanelen Schematisk skiss av panelens instrumentpanel: meny till vänster med grupperna huvudmeny, administration och fakturering, fyra nyckeltal överst, en trendkurva och enhetsstatus i mitten, och en lista med senaste händelser längst ned. Skissen visar strukturen, inte verkligt innehåll.

Overview and control in one place

The panel is where you manage licences, see what is happening on your devices and control the services.

  • See which licences you hold and where they are used
  • Add and remove devices
  • Read logs of what the clients have blocked
  • Start and stop protection on an individual client
  • Get installation files and licence keys

More about the panel

Sell WF SecurityCloud on to your own customers

You get a dedicated reseller system for handling customers, licences and purchases. Commission and terms are agreed separately.

About the partner programme

Get started

Create an account in the panel and add your first device. If you would rather talk to someone first, that works just as well.