NODO 1 (N1) · GOVERNED AUTONOMY
Your weak spots, found before attackers find them.
Nodo 1 (N1) is the governed-agent foundation built by Orbexs. It finds what is truly exposed in your organization, fixes it alongside your team and tests it again until the fix is verified. The same foundation also serves your help desk.

Nodo 1 (N1) console, full size

A TOUR OF THE CONSOLE
What N1 does, in plain view.
The main screen of the console brings together cases, the status of your devices and the assessments under way. Walk through it one area at a time.
Activity
Every case is followed until it is closed: created versus resolved, day by day.
Traffic light
The status of devices, cases and approvals, at a glance.
Ticket status
What is in progress, what awaits your approval and what is already closed.
Recent cases
Every assessment, with its status and its findings.

FROM RISK TO CLOSURE
From risk to verified remediation.
We don't tell you you're at risk: we prove it, with evidence. And we don't stop at the finding: we work with your team until the fix is verified.
Identify
Autonomous agents and Orbexs specialists find what is truly exposed and test it with authorization, without extracting data. Every finding comes with its proof, its severity and a recommendation.
Remediate
We don't stop at the report: we close the exposures alongside your team and strengthen configurations and controls, within the agreed scope and timeline.
Verify
We test the fixes again to confirm the exposure no longer reproduces within the assessed scope.
Demonstrate
Every action and every finding is recorded with verifiable evidence, ready to show your posture to your leadership, your clients or an auditor.
What we assess
Exposed credentials
Passwords and access keys published where they shouldn't be.
Misconfigured services
Whatever was left open or on factory settings.
Interfaces exposed to the internet without protection
Entry points to your systems that answer anyone.
Injection flaws in applications
Forms and applications that accept commands they should never run.
Encryption and security headers
Whether your sites protect what travels between the browser and your servers.
Email authentication
Whether anyone can send email pretending to be your organization.
Content management systems
Sites built with WordPress and similar tools, with their plugins.
Attack surface and subdomains
Everything your organization exposes to the internet, including what nobody remembers.
This is how every finding arrives: with its severity, proof that the risk is real and a record that no business data was accessed.
Access credential published on the client's public website.
- Severity
- High
- Proof
- Access confirmed
- Business data
- Not accessed
Sealed evidence · valid chain
GOVERNANCE OF EVERY ACTION
Offensive power, under control.
Every agent works within an authorized scope: it proves the real risk without extracting data, within the windows and limits agreed with you.
Signed rules of engagement
Every assessment runs under rules signed with you: assets, windows and limits. Anything outside the authorized scope is blocked.
Deny by default
Every action needs a valid permission. Without one, it doesn't run: the block happens before acting, not after.
Human in control
Higher-impact actions ask for your approval. Denying is as easy as approving, and both decisions are logged.
Verifiable sealed log
Every step is recorded, and the report includes an integrity check that reveals any later alteration.
RESULTS IN REAL ENVIRONMENTS
We identify. We fix. We test again.
What the assessments Orbexs has already run leave behind, with sealed evidence and within an authorized scope.
- offensive assessments with sealed evidence
- +30
- technical findings identified and catalogued
- +500
- data exfiltrated during testing
- 0
- of actions within an authorized scope
- 100%
Aggregate figures from the assessments Orbexs has run in real environments.
Cases with anonymized clients
From finding to closure: what we found, what we did and how it ended up.
Technology and health
External surface
Before
Publicly exposed services and assets, with configurations that widened the attack surface.
What Orbexs did
Reconnaissance, validation of each exposure and remediation alongside the client's technology team.
After
Findings fixed and a strengthened surface.
Legal sector
Infrastructure
Before
Controls and configurations that needed strengthening.
What Orbexs did
Defensive and offensive assessment, plus strengthening of configurations and controls.
After
Controls reinforced and fixes verified in a second assessment.
Applications and services
Before
Technical findings with potential impact on the security of the environment.
What Orbexs did
Identification, technical remediation and a retest of the fixes.
After
Findings fixed, with evidence from the follow-up validation.
WAYS TO WORK WITH US
Start wherever you need to.
You can start with an assessment, bring Orbexs in as your cybersecurity arm or prepare your organization for an audit, alongside remediation.
One-off assessment
Red Team and Blue Team on the agreed scope: we test your defenses the way an attacker would and review your configurations and controls.
What you receive
- A sealed-evidence report with the severity of every finding
- A prioritized remediation plan
- Support with the fixes within the agreed timeline
- A retest of the fixed findings
Subscription
Your cybersecurity arm: continuous assessment, remediation and strengthening of your posture, without building an in-house team.
What you receive
- Periodic assessments
- Supported remediation
- Retests and tracking of your posture
Audit readiness
We prepare your organization for ISO 27001, SOC 2 and other frameworks, alongside remediation; the certification or audit report is issued by an independent third party.
What you receive
- A gap and controls assessment
- Evidence ready for the audit
- Support during the independent assessment
Clear rules in every engagement
- Signed scope. Assets, windows and limits are defined in the rules of engagement.
- Bounded remediation. We support the fixes within the agreed scope and timeline.
- Retest included. We verify the fixed findings within the assessed scope.
- Dependencies handled separately. Changes that require development work or third parties are planned on their own.
AGENTIC SUPPORT
The same foundation, at your help desk.
Most support is the same thing, over and over: a Wi-Fi password, a device that won't connect, a full disk. N1 doesn't stop at suggesting steps: it applies the fix on the device and closes the case. Anything sensitive stops and asks for your approval, with context, and everything is logged: what was done, when and under which permission.
How it resolves a case
The request comes in
In plain language, with no forms or codes.
It classifies the risk
From reversible to critical, and with that it decides what it can resolve on its own.
It resolves what is reversible
Whatever can be undone runs right away, is verified and the case is closed.
Anything sensitive, with your approval
It asks for permission with context. Without your approval, it doesn't proceed.
What it resolves
- Wi-Fi passwords
- Modem restarts
- Connectivity problems
- Driver installs
- Disk space
- Device status
With a safety net
A snapshot before acting
It saves the device's state, acts and verifies. If the result doesn't check out, it rolls back.
Even if the cloud goes down
It combines rules and artificial intelligence: if the artificial intelligence is unavailable, it keeps resolving with its rules.
At night, too
It picks up open cases and resolves them at any hour, without anyone having to push them.
On several devices at once
It connects to the devices in your operation and resolves on several at once, with a record for each one.
WHERE IT RUNS
It runs where your risk lives.
You decide where N1 works, in cybersecurity and at your help desk.
ON YOUR INFRASTRUCTURE
Inside your network
The engine works from inside your network and the evidence stays within your perimeter. Any use of external services is defined with you in the scope.
IN THE CLOUD
A dedicated environment per client
A cell of its own for your organization: N1 shares no instance or data with other clients.
WHO IT IS FOR
For those who need to prove their security, not assume it.
Companies without an in-house security team
They need a cybersecurity arm without building an internal department.
Health, legal and financial sectors
Organizations with sensitive data that must demonstrate their posture.
Companies with sites and portals on the internet
Everything anyone can reach from outside: sites, portals and services.
Those preparing for an audit
Or to meet the security requirements of their clients and third parties.
Technology teams with many repetitive cases
To take the cases that keep repeating off their plate and leave them what truly needs a person.
Frequently asked questions
What we are usually asked before starting.
Nodo 1 (N1) is the governed-agent foundation built by Orbexs. In cybersecurity, its autonomous agents and Orbexs specialists find what is truly exposed in your organization, fix it alongside your team and test it again until the fix is verified. The same foundation also serves your help desk: it takes the request, applies the fix on the device and closes the case.
It stops and asks for your approval, with context. Higher-impact actions don't run without your go-ahead; denying is as easy as approving, and both decisions are logged. On top of that, every action needs a valid permission within the signed scope: anything outside it is blocked.
You decide where it works. On your infrastructure, the engine works from inside your network and the evidence stays within your perimeter; any use of external services is defined with you in the scope. In the cloud, it works in an environment dedicated to your organization that shares no instance or data with other clients. And the tests prove the risk without extracting data from your organization.
No. We prepare your organization for ISO 27001, SOC 2 and other frameworks, alongside remediation, but the certification or audit report is issued by an independent third party. What we provide is the technical evidence and support during that assessment.
With a technical session: we review what your organization exposes and show you how we identify, validate and document an exposure. Then we agree in writing on the scope of the first assessment, with its assets, windows and limits, and work within it.
Access to the devices it will look after, with the permissions you define, and your rules: what it can resolve on its own and what needs your approval. It can live on your network, next to the devices, or in a dedicated cloud environment. We define it with you before starting.
See N1 on a real attack surface.
We start with a technical session: we review what your organization exposes and agree in writing on the scope of the first assessment.
Book a technical session