Sovereign DDI · identity-aware DNS security

Know who is on your network — not just what.

The DDI the big players sell to enterprises, right-sized for European SMEs: DNS, DHCP and IP address management on your own appliance, with identity-aware DNS security enforced in our EU cloud. Your DDI records and your long-term DNS log archive stay on your own box.

  • No agent on your domain controllers
  • EU-hosted enforcement, EU legal jurisdiction
  • Built for teams without an enterprise budget

The problem

Windows DHCP, the firewall’s DNS, and a spreadsheet of IPs.

Most SME networks grew one decision at a time. Nothing is wrong exactly — until someone asks a question the setup cannot answer.

  • DHCP on a domain controller, DNS on the firewall, IP addresses in a spreadsheet somebody keeps in their own folder.
  • An alert names an IP address. Finding the person behind it means correlating three systems by hand, if the logs still exist.
  • DNS logging is either off, or on and nobody keeps it long enough to answer an auditor.
  • Roaming laptops leave the network and leave your policy behind with it.
  • Replacing any of it means an enterprise DDI quote, an enterprise project, and an enterprise team to run it.

And now NIS2 is asking what you did, when, and who did it.

The solution

One sovereign stack, from one vendor.

An on-prem appliance for the network you run, and an EU-hosted cloud for the threats you do not want to chase. They are built together, so identity survives the trip.

DNS-security enforcement runs in our sovereign cloud; the appliance is your local resolver, identity layer, and long-term log archive.

How the suite fits together On your premises, the KoraxLabs DDI appliance serves DNS, DHCP and IP address management and correlates identity, and keeps your long-term DNS log archive. It forwards DNS queries, with the user identity attached, to KoraxDNS in the EU cloud, which enforces policy and keeps a short-term hot store for the console, and returns the decision and the record. Off the corporate network, Korax Connect sends laptop DNS to the same EU cloud, and hands DNS back to the appliance when the laptop returns to the corporate network. Your premises KoraxLabs DDI appliance DNS · DHCP · IPAM agentless identity correlation Long-term log archive stays on your box, for as long as you say EU cloud · OVHcloud, EU regions KoraxDNS DNS-security enforcement threat blocking and policy short-term hot store for the console Sees: the queried name, the time, a source identifier, the user. Never: page content, payloads, files. forwards, with identity decision and record back Korax Connect laptops, on the network and off it off-network back on-corp
Enforcement runs in the sovereign cloud. The appliance is the local resolver, the identity layer and the long-term archive.

KoraxLabs DDI

Preview

The on-prem appliance

DNS, DHCP and IP address management on your own hardware, with identity correlation, an HA pair, network discovery, a tamper-evident audit trail and on-box AI. This is where your records live and where the long-term DNS log archive is kept.

KoraxDNS

Available

The EU-hosted DNS-security cloud

Threat blocking and policy, enforced in the EU. The appliance forwards queries to it with the user identity attached; the cloud decides, keeps a short-term hot store for the console, and hands the record of truth back to your appliance.

Korax Connect

Preview

The roaming agent

Keeps laptops on policy off the corporate network, and hands DNS back to the on-prem appliance the moment they come back on it.

AI-Safety

Roadmap

Guardrails for AI use

Policy for how AI services are reached from your network, in the same place as the rest of your DNS policy.

Why KoraxLabs

Six things the alternatives do not combine.

Ranked the way we would rank them in a technical evaluation, not the way a brochure would.

Sovereign by design

An on-prem appliance plus an EU-hosted cloud. Production runs only with EU providers — currently OVHcloud, in EU regions, under EU legal jurisdiction. Your DDI data and your long-term DNS-security log archive stay on your own hardware. Not a US cloud, and not "trust us".

Identity-aware DNS security

Every DNS request is tied to the real user through agentless Active Directory correlation, enforced in our sovereign cloud, and archived long-term on your own appliance. Most tools tell you what was resolved. We tell you who asked.

Agentless — nothing on your domain controllers

No software on your DCs. We read the same native Windows interface Event Viewer uses (MS-EVEN6), which is why security teams approve it where agent-based or PowerShell-based approaches stall.

On-box AI

Ask Kora runs on the appliance itself, over your own DNS, DHCP and IPAM history. The value is that it is private and grounded in your data — not that it is a large model.

NIS2-ready out of the box

A hash-chained, tamper-evident audit trail, long retention and compliance reporting are part of the product, not an add-on module with its own price.

Enterprise DDI at an SME price

HA, migration tooling, discovery and SIEM export — the capabilities Infoblox and EfficientIP charge enterprise money for, at a price an SME can actually run.

Identity-aware, agentless

Who, not just what.

An IP address is not an answer. It is the beginning of an investigation you do not have time for.

The appliance correlates Active Directory sign-in events with the addresses on your network, so a DNS event carries the user, the device and the subnet it came from — not just a resolver log line.

That correlation is read through MS-EVEN6, the same native Windows event interface Event Viewer uses. No agent is installed on a domain controller, no WinRM, no PowerShell remoting, nothing for your EDR to quarantine and nothing to re-approve at the next change board.

Identity travels with the query to the enforcement cloud, so a block decision and the report that follows name a person, and the long-term archive on your appliance keeps that record for as long as your retention policy says.

Where no identity mapping exists, an event still carries its network and site — network DNS alone cannot always name the individual user.

The KoraxDNS console dashboard, showing protection status, queries per second, blocked requests, cache hit ratio and a 24-hour DNS traffic chart.
KoraxDNS console — demo data. The DDI appliance and Ask Kora screens come from the DDI team.

On-box AI

Ask Kora.

Ask your network a question in plain language and get the answer from the appliance itself, grounded in your own DNS, DHCP and IPAM history.

Ask Kora · on the appliance Preview
YouWhich users hit blocked domains last week?
KoraFourteen users across three sites. The largest share is one marketing workstation with repeated requests to a newly registered domain, blocked each time. Here is the list, by user, with the domains and the times.
YouWhich subnets are close to running out of addresses?
KoraTwo: the Antwerp guest network and the Ghent voice VLAN. Both have been climbing since the start of the month. Here is the trend and the next free range in each.

Ask Kora runs on the appliance. Your questions and the data behind the answers stay on the box; nothing is sent to an external AI service.

NIS2 and sovereignty

Answer the audit with records, not recollections.

NIS2 asks organisations that never had a compliance programme to show what happened on their network and who did it. That is a logging and retention problem before it is a policy problem.

Tamper-evident audit

Administrative actions and DNS events are written to a hash-chained audit trail, so a gap or an edit is visible rather than silent.

Retention you control

The long-term DNS-security log archive lives on your own appliance, so how long you keep it is your decision and your disk, not a retention tier on someone else’s price list.

Reporting and export

Built-in reports for the questions auditors actually ask, and SIEM export over TLS when the records need to go somewhere else too.

Data residency you can point at

Production is hosted only with EU providers, currently OVHcloud, in EU regions, under EU legal jurisdiction.

To be exact about what goes where: the queried domain, the time and a source identifier reach the enforcement cloud, because that is what a resolver decision is made of. Your DDI records, your identity correlation and the long-term archive stay on your appliance. Web page content, HTTP payloads and files are never inspected — this is a DNS-layer product.

At a glance

What you get, and why to believe it.

Each claim below is something you can check during a trial, not a capability matrix.

What you get, and the thing that makes it true.
ValueWhy to believe it
Keep your records at home On-prem appliance; the long-term DNS log archive stays on your box; EU-hosted enforcement; GDPR and DPA friendly.
See who, not just what Agentless Active Directory correlation of user, IP, device and subnet on DNS events.
No risk to your domain controllers MS-EVEN6, the native Windows event interface. No agent, no WinRM, no PowerShell remoting.
Answers in plain language On-box AI over your own DNS, DHCP and IPAM history; nothing leaves the appliance.
Pass your NIS2 audit Hash-chained audit trail, long retention, built-in reports, SIEM export over TLS.
Always on An on-prem HA pair with automatic failover, so DNS and DHCP do not go dark with one box.
Switch without pain Import from Windows DHCP and DNS, from pfSense and from Infoblox, with a guided migration.
Protected off-network Korax Connect keeps roaming laptops on policy and hands DNS back to the appliance on the corporate network.

What it is not: a DNS-layer product blocks a domain before the connection is made. It does not inspect encrypted application content, and it does not replace endpoint detection, data-loss prevention or a SaaS security broker. It reduces exposure to known and suspected risky domains; no DNS filter can promise every unknown threat.

Pricing

Three ways to run it.

Sized by the network, not by the seat. Tell us the shape of yours and we will quote it — the capability split is below.

Starter

A single appliance for a small, single-site network. You run it.

  • DNS, DHCP and IPAM on one appliance
  • Identity correlation
  • KoraxDNS enforcement
  • Local log archive

Contact us for a quote.

Pro

An HA pair across sites, with single sign-on and the compliance pack.

  • Everything in Starter
  • HA pair with automatic failover
  • Multi-site
  • SSO
  • The NIS2 reporting pack

Contact us for a quote.

Managed

We run it for you, or your MSP does. Hands off.

  • Everything in Pro
  • Managed operation and updates
  • Multi-tenant administration for MSPs
  • Reviews and reporting

Contact us for a quote.

Proof

The things a security team asks about first.

None of these are new commitments made for a web page — they are how the product is built.

EU hosting and residency

Production runs only with EU providers, currently OVHcloud, in EU regions, under EU legal jurisdiction.

GDPR and DPA

A data-processing agreement, and a clear record of which data reaches the enforcement cloud and which never leaves your appliance.

Agentless, EDR-friendly

Nothing is installed on a domain controller, so there is nothing for an endpoint agent to flag and nothing to exempt.

Sovereign on-box AI

Ask Kora answers from the appliance, over your own data, without calling an external AI service.

Next step

Talk to us about your network.

Start with the DNS security — it takes a resolver change and shows you who is on your network within the hour. The appliance conversation can follow.