Nuaj — infrastructure and cybersecurity software

NuajProtect · Edge Cyber Threat Protection · Now in beta

NuajProtect blocks
malicious traffic
before it reaches you.

Global threat intelligence and live attack detection, enforced inline at line rate. Known attackers are already on the list; floods, scanners and repeat offenders are worked out on the spot. Drop the NuajBridge appliance in front of any network — the 2.5-Gigabit model is in beta today, larger ones are in qualification — or run the same engine as software on the servers you already own.

Free during beta — and free for a full year after general availability, plus priority access to NuajBridge hardware.

NuajProtect dashboard showing a live global map of malicious traffic and cyberattacks blocked across endpoints, MikroTik routers, and Linux agents
Protects NuajBridge appliance Linux servers MikroTik routers Whole networks

How NuajProtect Works

Cyberattacks stopped at the edge,
in three steps.

Known attackers removed from a live global picture, unknown ones worked out on the spot — enforced in the kernel at your own edge, with no proxy in the path and no blocklists to hand-write.

01

Known attackers, already listed

NuajProtect continuously identifies malicious sources, botnets, and attack infrastructure, and keeps every protected location current in near real time — so the traffic you have never seen has usually already been seen somewhere else.

02

Unknown ones, worked out live

Every deployment is also a sensor. It measures floods against the baseline your link actually runs at, catches scanners the moment they touch a port nothing legitimate uses, escalates repeat offenders on their own record, and takes reports from your applications about abuse only they can see.

03

Everything it learns, shared

What one protected site works out, every other one enforces. Drop in a NuajBridge to cover a whole network, or run the same engine on the servers and routers you already have — one policy, applied consistently.

Engineering Philosophy

Built for operators,
by operators.

Performance First

We write code that respects your hardware — filtering in the kernel's earliest packet path, at line rate, without adding a routing hop or a userspace proxy.

Uncompromising Architecture

No hardware lock-in and no rip-and-replace. Our software runs natively on the Linux and MikroTik infrastructure you already own, and the appliance is an option, not a prerequisite.

Data Sovereignty

You own your operations. We design our platforms to support fully self-hosted, air-gapped, and privacy-first deployments worldwide.

Questions

Everything you need
to know.

What is NuajProtect?
NuajProtect is edge security that blocks malicious traffic before it reaches your servers, routers, and networks. It combines live global threat intelligence with detection that runs where your traffic actually arrives — floods, port scanners, repeat offenders and abuse your own applications report — and enforces the result inline at line rate.
What platforms does it run on?
The NuajBridge appliance protects a whole network with nothing to install. The same engine — intelligence and detection both — runs as software on your Linux servers and MikroTik routers, so every deployment is a sensor as well as an enforcement point. No re-architecting required.
How is it different from a traditional firewall?
A firewall enforces the static rules you write, and it can only act on what those rules already describe. NuajProtect adds the part a rule can't express. It feeds your edge a live picture of known-hostile infrastructure and removes it at line rate — and it decides about traffic nobody has classified yet: floods judged against the baseline your link actually runs at rather than a fixed number, scanners that give themselves away by touching ports nothing legitimate touches, repeat offenders escalated on their own record, and application-level abuse your own software reports from inside. What one protected site works out, the others enforce. It complements your firewall — it doesn't replace it.
Will it slow down my network?
There is no proxy and no extra routing hop: filtering runs in the kernel's earliest packet path, so accepted traffic is forwarded rather than reassembled. What you should watch for is not throughput but a wrong call — any filter can misjudge unusual but legitimate traffic. That is what the allowlist, the per-endpoint activity view, and monitor mode are for: run it watching before you run it blocking.
Is it self-hosted or SaaS?
Both. Run it fully self-hosted for data sovereignty and air-gapped environments, or use the managed SaaS and let us operate the control plane for you.
How do I get access?
NuajProtect is now in beta. Join free — and it stays free for a full year after we reach general availability, with priority access to NuajBridge hardware. Protect a server in software in minutes, reserve a NuajBridge for whole-network protection, or talk to us about a larger deployment.

Why we built it

I ran a data center for 15 years. One day I really looked at what was hitting the edge. Every server was under attack, several times a second, all day, every day. Nothing out there stopped it the way it should. So I built NuajProtect.

— Antoine Boucher, Founder

Why Nuaj

Modern IT has become
unnecessarily complicated.

More vendors. More products. More dashboards. More security alerts. More things to break — and IT teams spending more time managing technology than using it to move the business forward. Nuaj exists to change that.

We build infrastructure and cybersecurity solutions that reduce complexity, improve visibility, and strengthen operations. No unnecessary features. No unnecessary complexity. No unnecessary overhead — just practical platforms that help organizations operate securely, efficiently, and at scale.

Because technology should be an advantage, not a burden.